DevOps Engineer · CI/CD · Kubernetes · Infrastructure as Code · Observability
I'm a DevOps engineer with about two years of hands-on experience, currently working at a cybersecurity company. I came to DevOps through Linux administration, and I still think like an admin: reliability first, then automation, then speed.
I've built infrastructure from scratch for a microservice product in the cloud and now support deployments in a security-focused environment. My daily work is turning manual operations into code: CI/CD pipelines, Ansible and Terraform, Helm releases on Kubernetes, and monitoring that tells us something is wrong before the users do.
How I work
- Build once, promote everywhere — one image per commit travels from dev to prod without rebuilding
- Everything as code — infrastructure, configs and pipelines live in Git and go through merge requests
- Secure by default — secrets in Vault and CI variables, never in repositories; hardened Linux baselines
- Alert on symptoms, not noise — 5xx, latency and disk space instead of every CPU spike
DevOps Engineer — Rostelecom Solar · Apr 2026 – present
Cybersecurity company. Deployment automation and support for internal services.
- Maintain and extend GitLab CI pipelines: Docker builds, tests, publishing to the registry, deployment to environments
- Ansible roles and playbooks for service rollout and Linux host configuration across dev / stage / prod
- Kubernetes deployments with Helm: per-environment values, rollbacks, troubleshooting pods (CrashLoopBackOff, Pending, requests/limits, liveness/readiness probes)
- Secrets management with HashiCorp Vault and GitLab CI variables; monitoring and alerting with Prometheus and Grafana
DevOps Engineer — Ai Lapki · Jan 2025 – Apr 2026
Built the infrastructure from scratch for Python / FastAPI microservices in Yandex Cloud.
- CI/CD: self-hosted GitLab CI with fast checks first, then a single image tagged
version + commit SHApromoted through all environments; faster builds with multi-stage Dockerfiles, layer caching and parallel jobs - IaC: moved the infrastructure to Terraform (VPC, networks, VMs) with remote state and locking,
changes reviewed as
planin merge requests; Ansible roles for hosts, Docker and monitoring agents - Observability: Prometheus + Grafana dashboards for hosts and services, symptom-based alerts to Telegram, centralized logging with ELK
- Networking: Nginx reverse proxy with TLS, HAProxy load balancing with health checks, VPN for the team (WireGuard, OpenVPN), nftables / iptables, fail2ban
- Kubernetes: delivering services to existing clusters with Helm and Argo CD
- Troubleshooting: OOM killer, disk and inode exhaustion, 502/504 between proxy and app, Docker network routing
| Area | Tools |
|---|---|
| OS & Virtualization | |
| Cloud & IaC | |
| Containers & Orchestration | |
| CI/CD | |
| Observability | |
| Security | |
| Networking & Messaging | |
| Languages & Data |
Turns a fresh Debian / Ubuntu server into a hardened, consistently configured host for dev, stage and prod
from the same set of roles.
SSH hardening with lock-out protection, UFW, fail2ban, unattended upgrades, kernel sysctl hardening,
secrets in ansible-vault, typed role arguments and an ansible-lint production profile.
Ansible · Linux · Security · Make
A VS Code extension that tracks time spent in the editor and per file.
TypeScript · VS Code API
IoT monitoring in agriculture — backend and infrastructure for real-time temperature and humidity monitoring of grain storage: sensor data over MQTT, processing in Go, storage in PostgreSQL, dashboards and alerting. Commercial project, source code is private.
- CI for the Ansible baseline: GitHub Actions lint pipeline and Molecule tests for every role
- A public IoT monitoring platform demo: Terraform, Kubernetes, GitOps with Argo CD, Prometheus and Grafana
- Improving my Go for internal tooling and automation
When I'm not writing pipelines, I do street photography — city geometry, light and mood. Have a look at my channel: Немного не отсюда (Telegram, photos speak any language).