Stability-First Infrastructure
Stable, documented, and recoverable. The way it should have been built the first time.
Matthias Goodman · Phoenix, AZ
Fixed-fee turnkey handoff. Hybrid vSphere, Azure Arc, and immutability.
Strategic Fit
Expertise that transfers. Your team gets stronger, not more dependent. Healthcare, manufacturing, professional services, and multi-site operations across Arizona and beyond.
Selected work
Real engagements. Anonymized details.
Daily backup jobs reported green status in the legacy MSP management portal.
VSS SQL Writer failed silently after an unrecorded maintenance reboot 340 days prior. Backups were capturing empty database pointer stubs while transactions accumulated without truncation.
Re-registered SQL VSS writer, provisioned an isolated Veeam hardened Linux repository with immutable flags, executed cold restore simulations to a verification host, and scheduled automated weekly integrity test runs.
Broadcom contract renewal required a 300% fee increase with a mandatory per-core licensing shift.
Legacy SAN architecture and vSphere dependencies were coupled to proprietary VMDK snapshots without a documented export or hypervisor conversion pipeline.
Scoped and tested non-disruptive Proxmox VE clustering on existing Dell PowerEdge hardware. Re-architected storage pools to native Ceph and migrated 42 production VMs over two weekend maintenance windows with zero data loss.
Azure monthly invoice climbed from $4,200 to $9,800 over 14 months without headcount or patient volume growth.
Orphaned managed disks from decommissioned patient portal test nodes, unattached public IPs, and non-reserved SQL instances running 24/7 without tagging or cost-center ownership.
Audited every cloud resource against clinic billing codes, decommissioned $2,800/month of unattached storage, reserved baseline SQL capacity, and enforced Azure Policy locks preventing unbudgeted instance provisioning.
Principal
I design for predictable operations, not heroic 3 AM recoveries.
I am Matthias Goodman. For over 25 years, I have stabilized hybrid systems, built landing zones, and designed recovery architecture for organizations across Arizona.
After a decade as the sole IT leader taking a regional healthcare group from peer-to-peer networking and paper charts to a fully integrated VMware datacenter across 21 sites and 250+ employees with zero external consultants, I now work as a specialized partner for teams who own their systems. Current projects include stabilizing their entire digital platform (Next.js multi-brand architecture with SEO, localization, and patient portals), leading patient communication API integrations, and evaluating portal upgrades while working side-by-side with their internal team.
I run this practice without sales reps, junior handoffs, or artificial retainers. I audit your dependencies, eliminate configuration drift, verify recovery paths in a sandbox, transfer clear documentation to your team, and exit.

Phoenix, AZ
A short, repeatable process designed for low-risk change.
Define outcomes, constraints, and risk surface.
Map dependencies, drift, and operational gaps.
Clear tradeoffs and phased implementation paths.
Small, reversible steps with validation.
Restore testing, cutover checks, stability verification.
Docs, diagrams, and runbooks you can operate.
Monday mornings where nothing is on fire. A team that handles what comes next without calling for backup.
Stabilize vSphere and hybrid dependencies so your team stops firefighting and starts operating.
Quarterly restore tests with documented results. Not assumptions that fail when it matters.
Hardening baked into the baseline, so compliance checks become routine instead of scrambles.
Clear ownership boundaries and documented procedures that survive staff turnover.
Services
Project-led work for teams that need stability now and a clear modernization path.
Your vSphere environment drifted from its baseline and nobody noticed. I map the dependencies, score the risk, and hand you a runbook so your team can keep it from drifting again.
Migrations fail when someone skips the dependency map and hopes for the best. I move workloads in phased waves with a rollback path at every stage. If something breaks, I roll back. No drama.
Your backups run every night. Have you ever restored from one? I run the restore test, document the RTO and RPO, and hand you the proof that your recovery plan actually works.
Azure spending tripled and nobody can explain why. I set up the guardrails: policy baselines, RBAC, cost alerts, and a landing zone your team can build on without creating the next mess.
IT Provider Collaboration
Project-scope work your MSP or internal IT doesn't have bandwidth for. Migration engineering, backup redesigns, drift remediation. Everything goes back to your team with full documentation.
Ongoing support stays with your team. I come in for scoped projects with clear start and end dates.
Architecture docs, runbooks, and validated configs your team can own and operate from day one.
I have built the process around clean collaboration, not competition.
Credibility
What I actually deliver, and what it looks like when it works.
Azure foundations aligned to Microsoft CAF so your cloud does not become another source of drift.
Veeam immutability plus quarterly restore testing. Untested backups are not verified backups.
Runbooks and ownership boundaries that survive staff changes and reorgs.
Reduced unplanned downtime from weekly incidents to quarterly maintenance windows. Their team stopped dreading Mondays.
First successful restore test in 3 years. Recovery time dropped from unknown to 4 hours.
Stabilizing their Next.js multi-brand platform, leading patient communication API integrations, and evaluating portal upgrades while collaborating with their internal team.

A small medical practice relayed patient appointment requests through a five-year-old pipeline nobody had traced. When I...

Small practices spend five figures a year on BAA-covered vendor stacks to move appointment requests around. Some of thos...
How recent and upcoming HIPAA regulations force fundamental engineering changes across web analytics, shared logins, and...
Direct Technical Scoping
Direct conversation with Matthias Goodman, Principal Infrastructure Architect. Review current topology, downtime risks, or licensing renewals. Zero sales reps or junior discovery calls.
Choose a starting point