DevOps Engineer & Architect · Azure · Kubernetes · GitOps

I design cloud platforms that are secure and automated.

I help teams cut infrastructure complexity, speed up delivery, and build systems that can actually be operated reliably — on Azure and on-prem Kubernetes.

Open to work📍 Košice, Slovakia
denis@platform — zsh
KubernetesRKE2TerraformTerragruntAnsibleArgoCDFluxHelmCiliumKubeVIPPrometheusThanosGrafanaLokiAlloyHashiCorp VaultKyvernoRancher FleetAzureAKSHetznerCloudflareDockerPodmanGitLab CIGitHub ActionsAzure DevOpsPythonBashKubernetesRKE2TerraformTerragruntAnsibleArgoCDFluxHelmCiliumKubeVIPPrometheusThanosGrafanaLokiAlloyHashiCorp VaultKyvernoRancher FleetAzureAKSHetznerCloudflareDockerPodmanGitLab CIGitHub ActionsAzure DevOpsPythonBash
0+

years in DevOps · in IT since 2017

0+

teams served by a self-service platform

0+

edge devices automated with Ansible

<0 min

to provision multi-cloud infrastructure

Experience across

Deutsche Telekom · DHL IT Services · OX Point · SikaLabs

Platform thinking

Not tools. A connected system.

Infrastructure, delivery, security and observability aren't separate pieces — I design them as one flow that can be operated with confidence.

committrigger · build · testpush imageupdate manifests · PRimage pullIaC · configpull & deploywatchmetrics · logsApp repoCI/CDRegistryGitOps repoKubernetesObservability

How I think

How I think about platforms

Technologies change. Principles stay.

I don't only care whether a system works today — but whether the team will be able to use, evolve and reliably operate it two years from now.

Security by design01

Security is part of the design

I don't treat security as an extra layer. It's part of the architecture from the first decision.

Automation first02

Repeatable work gets automated

If something repeats, it shouldn't stay a manual process.

Reduce complexity03

Platforms should hide complexity

A good platform hides complexity from teams instead of passing it to them.

Operability matters04

Operability matters

A system that can't be operated reliably is not a finished system.

Case studies

Selected work

Real work from practice, with outcomes.

azure / aks2025–2026

Enterprise AKS platform

Challenge

Teams needed to ship to production safely and repeatably — without manual cluster access and without shared secrets.

Solution

Private AKS with separated node pools (system/user/spot), Azure CNI, AAD integration, Workload Identity and Network Policies. Workloads deployed via GitOps (FluxCD HelmReleases), with Dynatrace and Ingress NGINX.

Outcome

Secure-by-default, fully GitOps delivery

AzureAKSFluxCDWorkload IdentityDynatrace
on-prem / rke22026

On-prem Kubernetes platform

Challenge

A bare-metal environment with no load balancer and no governance — container workloads had no production foundation to build on.

Solution

A production on-prem platform on RKE2 with Cilium CNI (L2 Announcements, LB IPAM) and KubeVIP in ARP mode. A secure, scalable foundation for container workloads on bare metal.

Outcome

2 production clusters, governance via Kyverno

RKE2CiliumKubeVIPKyverno
gitops2024–2026

GitOps delivery — FluxCD & ArgoCD

Challenge

Deployments via manual kubectl and helm were unauditable and inconsistent across environments — nobody knew exactly what was really running in the cluster.

Solution

Declarative Kubernetes management via Git: FluxCD (clusters/dev·test·prod, HelmReleases, Kustomizations, environment overlays) on Azure and ArgoCD app-of-apps on-prem. Environment state driven by reconciliation, no manual kubectl.

Outcome

Auditable, repeatable deployments

FluxCDArgoCDHelmKustomize
observability2024–2026

Observability at scale

Challenge

Dozens of clusters, each with its own monitoring — no unified view and slow root-cause analysis during incidents.

Solution

Full-stack observability: Dynatrace (DynaKube, Operator, OneAgent) for AKS, plus federated Prometheus → Thanos, Grafana and Loki/Alloy on-prem. A single view of metrics and logs across environments.

Outcome

Federated metrics from 20+ clusters

DynatracePrometheusThanosGrafanaLoki

Collaboration fit

Who I work best with

Working with me makes sense when you need someone who doesn't think about a single deployment, but about the whole system — how infrastructure is created, deployed, secured, monitored and recovered when something fails.

  • Azure / AKS platform architecture
  • Kubernetes delivery & GitOps (FluxCD / ArgoCD)
  • Terraform / Terragrunt infrastructure
  • Azure DevOps CI/CD pipelines
  • OIDC / Workload Identity / secretless auth
  • Observability (Dynatrace, Prometheus, Loki)
  • Disaster recovery and cloud governance

AI-assisted engineering

AI in everyday work

I use AI as a working tool — not as a substitute for thinking.

  • design solutions faster
  • analyze architecture
  • prepare documentation
  • build prototypes
  • automate repetitive work

The result isn't more AI. The result is more time for the decisions that matter.

$ contact --start

Got a platform that needs clearer structure?

If you need to bring order, automation and a safer delivery model to your cloud infrastructure — reach out. I most enjoy work that's built to last and to be operated.

Get in touch