Pedro José Barbero Iglesias
PBI-2026Madrid

Senior Linux Infrastructure & Production Process Automation Engineer

PedroJoséBarberoIglesias

Linux. Automation. Compliance. At enterprise scale.

available_from: 2026-12 work_auth: ES / EU
View full CV
Years in enterprise IT
25+
Systems managed (Audatex/Solera)
5,000–10,000
Servers (Santander/Produban)
20,000+
Countries supported
13+

Enterprise environments

Audatex / Solera Santander / Produban BBVA Repsol British Telecom Indra AENA NH Hotels

…and other corporate organizations across banking, energy, telecom and public-sector environments.

Selected work

Multi-source infrastructure reconciliation

Virtual estate exports, patch management, endpoint security, vulnerability scanning, identity and monitoring each hold a partial truth about the same servers. The pipeline normalises all of them, crosses them against each other, and turns every mismatch into a ticket for the team that owns it — instead of a spreadsheet nobody reads.

SOURCES vSphere / RVTools Satellite / Katello CrowdStrike Tenable FreeIPA Icinga 24 vCenters · EU / US / APAC / ZA extract · filter · normalise − ESX / iLO / iDRAC − powered off − NIC disconnected ± physical / virtual ± product IDs ± OS: Linux / Windows / ? → one FQDN identity per host crossover 23 filters · 8 merge joins match each host across every source gap? yes Jira tickets routed to owning team no reports 13 XLSX · per region e-mail + GitLab push notification & audit trail every run leaves a trace
The value is the crossover: no single tool knows the whole estate, so the mismatches between them are the actual findings.
FIG. 01 MULTI-SOURCE RECONCILIATION SCALE: N.T.S. REV. C
Pentaho Data IntegrationVMware vSphereCrowdStrikeTenableFreeIPAIcingaJiraGitLab

Discovery, dependency mapping and the reconciled register

Credentialed agentless scanning looks inside each host — running processes, installed packages, configuration files, listening ports — and a pattern engine turns those raw findings into recognised software instances and the dependencies between them. That is what populates the CMDB datasets, which are then reconciled against the automation register before any host is managed on its planes.

A · HOST INSPECTION credentialed scan agentless · ssh / wmi INSIDE EACH HOST processes packages config files listening ports pattern engine raw data → instances relationships what depends on what B · POPULATE THE RECORD CMDB datasets hosts · software instances · dependencies · business services C · RECONCILIATION CMDB declared estate reconcile declared vs. actually managed automation register BladeLogic · agents declared managed enrol missing flag stale D · MANAGED PLANES, PER HOST OS? LINUX WINDOWS provisioning configuration mgmt patching audit & compliance OS hard. database application provisioning configuration mgmt patching audit & compliance OS hard. database application compliance state baselines · deviations · evidence state back to the record
A register nobody verifies drifts, and everything downstream — provisioning, patching, hardening — inherits that drift.
FIG. 02 DISCOVERY → CMDB → RECONCILED REGISTER SCALE: N.T.S. REV. C
BMC Atrium DiscoveryDependency mappingCMDBBMC BladeLogicLinuxWindowsCompliance

Automated content view release & promotion

A scheduled job reads each lifecycle from configuration and decides, per content view, whether a new version is due, whether it was already published in this run, and which environments are ready to receive it. Promotion walks the lifecycle backwards, so every environment inherits the exact version already proven in the one before it.

DECISION CHAIN cron region · org promotion due? release due? published today? no publish version from Library no → log and skip this cycle new version enters the lifecycle PROMOTION PATH Library DEV INT UAT PRE PROD +6 d +6 d +6 d +6 d six days per environment · five environments · a full cycle lands in production about a month after release purge old versions retention policy: 1 git commit + push config & log audit trail
Nothing reaches production that has not already run in every environment before it; the schedule, not a person, decides when each hop happens.
FIG. 03 CONTENT VIEW RELEASE & PROMOTION SCALE: N.T.S. REV. C
Red Hat SatelliteKatelloPythonBashcronGit

Patch execution on the host

The content policy decides what a host may install; this is what actually runs on it. The inventory is generated from Satellite host groups at run time, and every host passes a set of gates — free space, staged downloads, exclusion lists — before a single package is applied. Reboots happen only where the kernel actually requires one.

INVENTORY Satellite host groups by region · by product dynamic inventory generated per run AWX / Ansible tags: update · reboot EXECUTION GATES, PER HOST disk space ok? / and /var ≥ 1 GiB no abort host · report run continues elsewhere yes refresh subscriptions clean Katello repo cache download only exclusion list · marker file packages staged before the window system update services saved before / after needs restart? yes reboot facts saved back errata state to Satellite extra task sets by tag: freeIPA · docker · nfs · DR patching · VMware tools
Staging the downloads ahead of the window is what turns a risky maintenance slot into a short, predictable one.
FIG. 04 PATCH EXECUTION ON THE HOST SCALE: N.T.S. REV. C
AnsibleAWXRed Hat SatelliteKatelloRHEL / OEL / CentOSYAML

About

Over two decades in international enterprise environments, across the whole lifecycle of the systems a business runs on. A deep Linux background — Red Hat and most major distributions — alongside Windows systems administration: provisioning, configuration, patching, auditing and technical compliance on both. A long track record of building automation and integrations for concrete operational problems: scripting, tooling and pipelines that wire corporate platforms together across vendors — BMC suites, Satellite and Katello, identity, monitoring, vulnerability and endpoint security tooling, Jira and Confluence. Currently completing a master's degree in Applied AI and Production Process Optimisation.

Focus areas

Linux & Red Hat Windows Server Provisioning Automation & Scripting Enterprise tooling integration Patch & Vulnerability Mgmt Audit & Compliance

Want the full picture?

Every role, every stack, every documented metric — laid out like the systems I maintain: structured, current and easy to scan.

Open the full CV →
Madrid, Spain / Remote phone / email on request