DevOps / Platform / Site Reliability Engineer building and running production Kubernetes platforms end to end — from bare Talos Linux nodes on Hetzner Cloud and AWS, through GitOps delivery, to the observability, backups, and security guardrails that keep them reliable.
I work daily across the whole stack: provisioning clusters with Terraform, shipping apps via ArgoCD + Helm, wiring up SSO/OIDC with Keycloak, hardening the supply chain with automated security scans, and making failures observable and recoverable before they become incidents.
- 🏗️ I run a self-hosted Talos Kubernetes platform (
talos-k8s) on Hetzner, plus a GitOps app monorepo (om) delivering Mattermost, Vaultwarden, XWiki, Keycloak & more - 🔐 Big on zero-trust: mesh-only access (NetBird), SSO everywhere, least-privilege IAM, secrets in AWS Secrets Manager via External Secrets
- 📈 I care about the boring-but-critical: verified backups, restore tests, alerting that routes to the right channel, pipeline metrics
- 🦀 Systems-minded — Rust, Go, and low-level networking are where I like to go deep
Orchestration & IaC
Cloud & Platforms
GitOps · Observability · Data
Identity · Security · Networking
Languages
| Project | What it is | Stack |
|---|---|---|
| talos-k8s | Self-hosted Talos Linux Kubernetes platform on Hetzner Cloud — the cluster foundation | Terraform · Talos · Cilium · ingress-nginx · cert-manager |
| om | GitOps app monorepo — delivers Mattermost, Vaultwarden, XWiki, Keycloak, iviss, azamra via ArgoCD | Helm · ArgoCD · CNPG · External Secrets |
| global-gateway | Self-hosted NetBird mesh (zero-trust VPN) control plane on AWS | Terraform · Ansible · coturn · ALB/ASG/RDS |
| keycloak-spi-registry | Custom Keycloak SPIs (auth flows, device registration) | Kotlin · Keycloak |
| observability & backups | Prometheus/Grafana/Loki stack, CNPG backups with daily catalog + monthly restore-test, severity-routed alerting | PromQL · Alertmanager · barman/S3 |
"A task is not done until it's proven done."



