DevOps / Platform / Site Reliability Engineer building and running production Kubernetes platforms end to end — from bare Talos Linux nodes on Hetzner Cloud and AWS, through GitOps delivery, to the observability, backups, and security guardrails that keep them reliable.
I work daily across the whole stack: provisioning clusters with Terraform, shipping apps via ArgoCD + Helm, wiring up SSO/OIDC with Keycloak, hardening the supply chain with automated security scans, and making failures observable and recoverable before they become incidents.
- 🔐 Big on zero-trust: mesh-only access (NetBird), SSO everywhere, least-privilege IAM, secrets in AWS Secrets Manager via External Secrets
- 📈 I care about the boring-but-critical: verified backups, restore tests, alerting that routes to the right channel, pipeline metrics
- 🦀 Systems-minded — Rust, Go, and low-level networking are where I like to go deep
Orchestration & IaC
Cloud & Platforms
GitOps · Observability · Data
Identity · Security · Networking
Languages
| Project | What it is | Stack |
|---|---|---|
| Self-hosted Kubernetes Platform | Production Talos Linux Kubernetes cluster on Hetzner Cloud — automated provisioning, networking, and ingress for the entire organization | Terraform · Talos · Cilium · ingress-nginx · cert-manager |
| GitOps Application Delivery | Monorepo that delivers 10+ production applications (messaging, wikis, identity, monitoring, backups) via GitOps — fully declarative, auditable, and self-healing | Helm · ArgoCD · CloudNativePG · External Secrets |
| Zero-Trust Network Mesh | Self-hosted wireguard mesh control plane on AWS — replaces VPN concentrators with peer-to-peer encrypted tunnels for all team access | Terraform · Ansible · coturn · ALB/ASG/RDS |
| Custom Identity Extensions | Custom Keycloak SPIs for SSO-based device registration, passwordless auth flows, and user-storage federation | Kotlin · Keycloak |
| Observability & Disaster Recovery | Full Prometheus/Grafana/Loki monitoring stack with CNPG backups, daily catalog verification, monthly restore-tests, and severity-routed alerting via Discord | PromQL · Alertmanager · barman/S3 |
"A task is not done until it's proven done."



