Work

Wellhead and terminal virtualization

Inspur hosts, network, and security for a terminal and a wellhead, delivered with drawings and a runbook.

A shore terminal and a wellhead platform needed the same kind of stack: servers under Inspur virtualization, a network that could be locked down, and room for the vendor subsystems that talk Modbus and TCP. The hardware had to be built and proven on land, packed, and brought up again at sea. We did that job.

The situation

Two sites, two racks, one pattern. Cabinets, bases, power, and internal wiring had to be drawn before anything was ordered. The hypervisor, switches, routers, firewall, and a security appliance (firewall, log audit, database audit) had to be chosen and staged together. Subsystems would arrive later and expect a ready environment — not a pile of unconfigured hosts.

Nothing useful could be invented offshore. The stacks had to work in a staging hall, survive a teardown and a voyage, and come up again on the platform with the same addresses and the same rules.

What we did

We planned the hardware and the virtualization layout, then drew the cabinets: placement, dimensions, base, power, internal cabling, and the network map. Two environments were racked on shore. RAID, Inspur virtualization, switching, routing, firewall, and the security appliance were installed and named so each site could be rebuilt the same way.

The wellhead cabinet was accepted, packed, and shipped. At the yard we racked it again, dressed the cables, and brought up part of the subsystem traffic. The terminal followed: VM templates, OS baseline, router and firewall, security appliance, then the same pack-and-ship step.

With the vendors we stood up runtimes, walked the designs, and fed simulated Modbus and TCP into each subsystem. High availability, backup, and the audit policies went on both sites. Before departure we moved the terminal onto production addresses, set the data diode, hardened the hosts, and wrote the cutover notes. Offshore we racked, migrated, opened the live firewall rules, and ran the joint tests. After a vulnerability scan we patched what it found. The handover set is the final PDF drawings, cable schedule, runbook, and test records.

Result

Both stacks left shore as working Inspur environments and came up on site. Subsystems had a network and a hypervisor they could actually use. The client kept drawings they can maintain, not a one-off rack that only the people who built it understand.

That is the work we still take: virtualization you can ship, a network you can lock, and the last mile on the platform.

Get started

Discuss a similar project

Tell us what is in China, what is remote, and what done looks like. We reply by email or WhatsApp.

  • On-site anywhere in China
  • Remote everywhere else
  • 24/7 on-call for incidents