01
Zero Trust, IAM & InfraSecOps
Identity, devices, networks, workloads and data—connected through evidence, IAM, modern authentication protocols and continuous improvement.
- Zero Trust maturity
- OIDC & RBAC
- Privileged access
IT Expert · Netherlands
I’m Ivan Versluis, an experienced, hands-on IT professional working across enterprise IT, telco and operational technology environments. Since 2000, I have turned complex infrastructure, connectivity and cloud challenges into secure, observable and repeatable systems.
What I do
I connect strategy, architecture and hands-on engineering—so decisions survive contact with production.
About / 01

Since 2000, I have worked with the infrastructure and connectivity that keep enterprise environments running—and helped them evolve.
I act as a technical partner to CIOs, directors and managers: understanding the need, challenging assumptions and translating direction into solid technical solutions. My experience spans enterprise infrastructure, connectivity, cloud-native platforms, identity, API gateways and security architecture across enterprise IT, telco and OT environments.
I combine architectural thinking with hands-on engineering. By connecting infrastructure, security, applications and operations, I help teams turn strategy into solutions they can implement, operate and continuously improve.
Networknet.nl came online in 2001. Its name grew from my fascination with networking and the “net” behind the internet. It became the place where I documented problems I solved, lessons learned and ideas worth sharing—a habit that still defines the site today.
Areas of practice / 02
Deep enough to be technical. Broad enough to see the chain.
01
Identity, devices, networks, workloads and data—connected through evidence, IAM, modern authentication protocols and continuous improvement.
02
Cloud-native foundations that connect infrastructure, Kubernetes and delivery practices without losing operational control.
03
Composable Terraform and delivery pipelines designed around ownership, small blast radii and understandable change.
04
API gateways, WAF and Cloudflare edge controls, Prometheus observability and applied AI used to enforce policy across systems.
The homelab / 03
My homelab brings cloud-native ideas into daily practice across a bare-metal Kubernetes platform, Synology NAS and Raspberry Pi services. It includes encrypted DNS with Pi-hole and Unbound, IoT collectors, API and AI gateways, and end-to-end observability—all managed as code and improved through real use.
Explore the public homelab repositoryGoodWe solar · Daikin climate · Shelly devices · DSMR P1 energy
Working principles / 04
A control only becomes meaningful when its operation and outcome can be demonstrated.
Automation should clarify ownership, reduce risk and make change repeatable—not obscure complexity.
The real test starts after deployment: upgrades, incidents, drift, access reviews and handovers.
Writing forces precision. Sharing the result turns a solved problem into reusable knowledge.
The notebook / 05
Practical lessons from infrastructure, networking and the homelab.
Applying default-deny NetworkPolicies per use case to segment Kubernetes traffic and turn application data flows into explicit rules.
Using Pi-hole to make local DNS behavior visible, introduce basic filtering and move upstream resolution towards encrypted DNS.
Exporting solar, climate, smart-device and energy-meter signals from GoodWe, Daikin, Shelly and DSMR P1 into Prometheus—and making them useful in Grafana.
The archive / 06
From Windows, VMware and Linux troubleshooting to Azure and command-line tooling, the original Networknet archive captures earlier chapters of the same journey.
Visit the original archiveDocumenting what works, what breaks and what comes next.