Achievements
- Designed, implemented and rolled out a reusable shared release step now adopted across ~20 services in a ~30-microservice AWS estate, with canary deployments and back-merge support
- Rebuilt the container build pipeline around BuildKit and ECR caching, mitigating the Docker Hub pull-rate limit and cutting build times across the estate
- Authored the official EKS Cluster Upgrade Runbook for a critical, irreversible control-plane procedure (Upgrade Insights, kubent/Pluto scanning, add-on compatibility validation)
- Designed and operated a self-hosted EC2 runner fleet with per-runner systemd services, an inotify-based cleanup service and a usage-based storage reclamation strategy
- Acted on 170 Jira tickets (130 created, 109 released) and authored 20+ internal runbooks, procedures and technical proposals
- Appointed company System Administrator with 11 formal security duties (authentication/authorization, GDPR Art. 32, backup & restore, periodic controls)
- Remediated penetration-test findings (OWASP API2), a committed AWS IAM access key and a root-RCE in an internal CI service; replaced long-lived AWS credentials with OIDC-based pipeline authorization
- Built internal self-service QA environments (devops-manager) used by non-technical teams to spin up isolated environments on demand
- Led a team of 3 Junior DevOps engineers at Abika, owning project intake, task breakdown and technical escalation
- Architected a single-node kubeadm Kubernetes homelab with Cilium eBPF (full kube-proxy replacement), Gateway API, Flux GitOps, SOPS-encrypted secrets, Keycloak OIDC/RBAC and a Headscale control plane