Websites and server infrastructure that actually work.
I build advanced websites and self-hosted server infrastructure — from a single business site to a cluster of devices unified into one secure fleet.
Services
Full range: from the site itself, through the server it runs on, to security and automation.
Advanced websites & web stores
Custom-built WordPress themes and integrations tailored to your business — not an off-the-shelf template. Fast, responsive, optimised for SEO and conversion.
HomeLab & self-hosted server infrastructure
Server environments built from scratch: Docker, reverse proxy, databases, backups, monitoring. From a single box to a cluster of several devices working as one system.
Local AI instead of the cloud
Deploying language and generative models on your own hardware — full data control, no per-query licensing, GDPR-friendly by design.
Security & monitoring
Security audits, server hardening, SIEM-based monitoring, automated attack detection and blocking, end-to-end encrypted backups.
Automation & custom dashboards
Automation agents for repetitive work (n8n), custom-built management dashboards — the same kind I use every day to run my own server fleet.
Invoicing & finance for sole proprietorships
I set up a self-hosted finance stack: invoicing, business budgeting, document archiving with OCR — with an optional AI assistant that drafts invoices from a plain-language request.
MMO game servers & multiplayer networking
I design and run multiplayer game servers and the networking layer that keeps game state in sync between players — regardless of engine or genre. Hands-on networking experience across nearly every kind of multiplayer game.
My proof, not just a promise
Instead of just describing skills — I show the infrastructure I designed, built and run every day: four devices unified into one server fleet. This site itself runs on a separate, dedicated VPS — the fleet is my private proving ground and proof of skill, not client hosting.
Illustrative visualisation — real monitoring (Grafana + Prometheus + Wazuh) runs 24/7 inside the fleet.
Reverse proxy & auth gateway for the whole fleet, media server and photo backup, network-level DNS filtering, a Telegram notification bot. Has a SIM card fitted — if the wired connection drops, the whole fleet automatically fails over to LTE. Its attached screen runs as a simple information kiosk — ~16.5 TB of storage.
Shared database for every service, internal wiki, fleet-wide monitoring (metrics + alerts). Runs a standing daily job: creating and verifying encrypted backups for the whole fleet. Also runs full sole-proprietorship bookkeeping: invoicing, business budgeting, OCR document archive — with an AI assistant drafting invoices from plain-language requests. It even controls a 3D printer (Klipper/Mainsail).
Security analysis & operations environment: fleet-wide SIEM aggregation, a full vulnerability-management pipeline (scan → track → report), honeypots, OSINT reconnaissance, DevOps automation — 100+ tools. Has its own monitor attached and often runs in Desktop mode as a regular hands-on workstation.
37 local language models (including Polish-tuned ones) on dedicated GPU, image/audio/3D generation, speech transcription. Connected via HDMI to a 55" TV — the source of the Sunshine/Wolf game streaming. Also game development (Godot), 3D graphics (Blender), and a live code-executing AI agent — zero data sent to the cloud.
37 local AI models running on owned hardware — roughly 130 GB of models total, no data ever leaves to third-party clouds.
Four independent devices unified into one encrypted mesh network — key-only access, zero passwords exposed on the network.
Custom MCP servers on every node — AI agents can operate the fleet directly. Real agentic integration, not a single API wrapper.
Four access modes per device: headless NODESKTOP (SSH + web panel, no GUI at all), on-demand noVNC in the browser, and Sunshine/Wolf for streaming — on-demand services spin up only what's needed, otherwise the laptops run 24/7 headless with automatic VRAM cleanup.
SIEM (Wazuh) aggregating security events from all four nodes in one place, 24/7.
Custom IoT hardware (ESP32 Cardputer, LoRa mesh) integrated into the automation — security here means real hardware too, not just code.
Full sole-proprietorship bookkeeping on owned infrastructure: invoicing, business budget and document archive — an AI assistant can draft an invoice from a single plain-language request.
A complete vulnerability-management pipeline (scan → track → report) and a self-hosted AI search engine — the same approach used in a professional SOC, not a handful of standalone tools.
From idea to physical object: game development (Godot), 3D graphics (Blender) and 3D-printer control — the same fleet that watches security also creates tangible things.
Game streaming (Sunshine + Wolf) from Reaktor, HDMI-connected to a 55" TV, also reaches Xbox Series X, Nvidia Shield, Nintendo Switch and Android phones.
Ordinary consumer laptops, not a data-center rack — yet they run as fully-fledged fleet servers, managed through a simple web panel understandable even without a technical background.
The full fleet arsenal — not a summary
What's above is just the introduction. Below is the real, documented inventory of 80+ tools and services running day to day across 4 machines — grouped so it's actually scannable.
Media & files
Movies, TV & music server
Audiobook library
Photo gallery with face recognition
Downloads sorted onto drives
Torrent indexer search
File sync across nodes
Browser-based file management
SSH terminal in the browser
Network & access gateway
Reverse proxy & SSL certs
Two-factor login gateway
DNS filtering & ad blocking
LTE backup when the line drops
Encrypted VPN mesh between nodes
Security event collection
System security audit
Management, knowledge, DevOps
Fleet's internal knowledge base
Self-hosted Git server
Database management UI
Monitoring dashboards
Fleet-wide metrics collection
Home automation & IoT
Personal notes sync
Quick notes & microblog
Deployment automation
No-code process automation
Handy online dev utilities
Fleet-wide AI model management
Business & sole-proprietorship finance
Invoicing & client CRM
Business budgeting & finance
OCR document archive
Task management (Kanban)
AI-assisted brainstorming
3D printer control
RSS feed aggregator
Privacy-friendly web analytics
Cybersecurity
Central threat-detection system
Vulnerability management
Infrastructure vulnerability scanning
Web app security testing
Penetration testing framework
Phishing simulations (training)
Data decoding & analysis
Mobile app security analysis
Automated OSINT reconnaissance
SSH/Telnet attacker honeypots
Full pentest desktop in-browser
Anonymous network browsing
Open-source intel gathering
WiFi network analysis
Safe range for attack testing
AI — assistants & automation
Local language models
Chat interface for AI models
OpenAI-compatible API, fully local
Experimental LLM interface
Code-executing AI agent
Self-hosted AI answer engine
Security-analysis assistant
Chatbot that knows the fleet's docs
AI reads & summarises files
PL/EN translation via local model
AI-assisted research
Test bench for AI agents
Detects AI-generated content
Writing assistant
Local coding assistant
Creative & generative media
Image generation (SD/Flux)
Generative image models
3D models generated from photos
Standalone image generator
Voice synthesis & cloning
AI audio generation
Speech-to-text transcription
3D graphics & animation
Game development engine
Game streaming to any screen
Alternative game-streaming server
Hardware & IoT
Pocket-sized hacking tool
On-demand LoRa mesh network
Gateway for IoT devices
RF & IoT testing modules
GPS positioning
USB-based attack simulation
What you're seeing is running code
This node network and the panel next to it are computed live in your browser — no external libraries. A small sample of what modern web tech can do.
What I use
Proven, production-grade technology — the same stack that runs my own fleet every day.
How working with me looks
Discovery call
We talk through your goal, budget and real needs — no selling you things you don't need.
Design & architecture
I design the solution: a site mockup or a server architecture, choosing technology that fits your actual scale.
Build & deploy
I build, test and deploy — with automatic SSL, backups and monitoring configured from day one.
Monitoring & support
After launch, the infrastructure is watched 24/7. I stay available for support and further development.
Questions I hear most often
By default, no. I prefer infrastructure I fully control — my own servers, my own AI models, my own backups. If a project genuinely needs a third-party service (e.g. payments), we agree on that explicitly before starting.
A simple business site: usually 1–2 weeks. A store or more complex server infrastructure: 3–6 weeks depending on scope. I always give a realistic timeline before starting, not after.
No. Every deployment includes monitoring, automated backups and my ongoing support — the same approach I use every day to run my own four-node server fleet.
Sometimes a cloud API is genuinely the best choice, and I use them too — but when data privacy, cost at scale, or offline operation matter, local models on owned GPU hardware are a real, battle-tested alternative.
Have a project that needs solid foundations?
A website, a store, a server, or full infrastructure — let's talk before you pick an off-the-shelf solution you'll need to rebuild anyway.
Get in touchHave a project in mind?
Tell me in a few sentences what you need — a website, a store, a server, or a full infrastructure build. I reply personally.
kontakt@lechovia.pl