Skip to content
View AlrightLad's full-sized avatar
🍊
Learning
🍊
Learning

Block or report AlrightLad

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AlrightLad/README.md

Zach Boogher

Infrastructure & Integrations Engineer — York, PA

The longer version: live demos of the automation, the homelab, and writing.

I build the automation that keeps a multi-thousand-endpoint managed fleet running: RMM tooling, PSA integrations, workflow orchestration, and the server lifecycle work underneath it. Most of what I write exists because something was being done by hand several hundred times a week.

What I work on

Automation & orchestration — PowerShell at fleet scale against NinjaOne RMM, Halo PSA integrations, and scheduled workflow orchestration in Windmill. Idempotent, single-instance, transcript-logged, exit-code-correct.

Windows infrastructure — Hyper-V host builds and standards, Server 2016→2025 lifecycle and P2V migration, Active Directory upgrade paths, Dell PowerEdge provisioning and bare-metal deployment pipelines.

Backup & disaster recovery — Veeam Backup & Replication design, fleet-wide upgrade waves, and verified restore testing.

Compliance-adjacent engineering — building and documenting controls for HIPAA-regulated and CMMC L2 / NIST 800-171 environments, where the evidence trail matters as much as the implementation.

Documentation — I own the internal knowledge base as document controller. An automation nobody can operate is a liability, not an asset.

How I work

  • Evidence before conclusions. Hypotheses get labeled as hypotheses and tested before anything is called a root cause.
  • Every commit GPG-signed. Every PR through PSScriptAnalyzer and Pester before it is opened.
  • Fix by class, not by instance.
  • Placeholders and sanitized examples by default in anything reusable.

Selected work

  • msp-automation — production PowerShell for managed Windows fleets. RMM-safe by construction: no interactive prompts, single-instance locking, transcript rotation, explicit exit codes. Sanitized from scripts running against a multi-thousand-endpoint fleet.
  • Veeam v13 fleet upgrade — convergent state machine for upgrading a Veeam B&R estate across mixed source builds: preflight gating, config backup, restore-point baselining, checksum-verified ISO staging, and deferred reboot. Detects Windows servicing corruption that blocks the upgrade path rather than failing silently mid-run.
  • stale-access-audit — dormant privileged-account reconciliation between an RMM and a PSA, joined on an organization-owned GUID pair instead of vendor ids. An evidence model that tells "no login observed" from "no evidence below a floor", and a feed walker that either proves continuity or says it could not.
  • ringcentral-queue-presence — a small client that makes exactly one member of a RingCentral call queue the enabled one and proves it did: every member written explicitly under the API's partial-update semantics, protected members never touched, one cached bearer, read-back verification that fails loudly. Pairs with the rotation scheduler reference implementation in msp-automation.
  • Upstream contributions to DTC-Inc/msp-script-library.

Elsewhere

LinkedIn · zboogher@gmail.com


"And let us not grow weary of doing good, for in due season we will reap, if we do not give up." — Galatians 6:9

Pinned Loading

  1. msp-automation msp-automation Public

    Sanitized production PowerShell for managed Windows fleets: Veeam B&R upgrade orchestration, server lifecycle and RAID health audits. RMM-safe by contract, gated by PSScriptAnalyzer and Pester

    PowerShell

  2. ringcentral-queue-presence ringcentral-queue-presence Public

    Makes exactly one member of a RingCentral call queue the enabled one and proves it: explicit full-member writes under partial-update semantics, protected members, one cached bearer, read-back verif…

    TypeScript

  3. stale-access-audit stale-access-audit Public

    Dormant privileged-account reconciliation between an RMM and a PSA, joined on an organisation-owned GUID pair. Evidence-based dormancy (observed vs no-evidence-below-floor), a feed walker that prov…

    TypeScript