DevOps Engineer & Architect · Azure · Kubernetes · GitOps
I design cloud platforms that are secure and automated.
I help teams cut infrastructure complexity, speed up delivery, and build systems that can actually be operated reliably — on Azure and on-prem Kubernetes.
years in DevOps · in IT since 2017
teams served by a self-service platform
edge devices automated with Ansible
to provision multi-cloud infrastructure
Experience across
Deutsche Telekom · DHL IT Services · OX Point · SikaLabs
Platform thinking
Not tools. A connected system.
Infrastructure, delivery, security and observability aren't separate pieces — I design them as one flow that can be operated with confidence.
How I think
How I think about platforms
Technologies change. Principles stay.
I don't only care whether a system works today — but whether the team will be able to use, evolve and reliably operate it two years from now.
Security is part of the design
I don't treat security as an extra layer. It's part of the architecture from the first decision.
Repeatable work gets automated
If something repeats, it shouldn't stay a manual process.
Platforms should hide complexity
A good platform hides complexity from teams instead of passing it to them.
Operability matters
A system that can't be operated reliably is not a finished system.
Case studies
Selected work
Real work from practice, with outcomes.
Enterprise AKS platform
Challenge
Teams needed to ship to production safely and repeatably — without manual cluster access and without shared secrets.
Solution
Private AKS with separated node pools (system/user/spot), Azure CNI, AAD integration, Workload Identity and Network Policies. Workloads deployed via GitOps (FluxCD HelmReleases), with Dynatrace and Ingress NGINX.
Outcome
Secure-by-default, fully GitOps delivery
On-prem Kubernetes platform
Challenge
A bare-metal environment with no load balancer and no governance — container workloads had no production foundation to build on.
Solution
A production on-prem platform on RKE2 with Cilium CNI (L2 Announcements, LB IPAM) and KubeVIP in ARP mode. A secure, scalable foundation for container workloads on bare metal.
Outcome
2 production clusters, governance via Kyverno
GitOps delivery — FluxCD & ArgoCD
Challenge
Deployments via manual kubectl and helm were unauditable and inconsistent across environments — nobody knew exactly what was really running in the cluster.
Solution
Declarative Kubernetes management via Git: FluxCD (clusters/dev·test·prod, HelmReleases, Kustomizations, environment overlays) on Azure and ArgoCD app-of-apps on-prem. Environment state driven by reconciliation, no manual kubectl.
Outcome
Auditable, repeatable deployments
Observability at scale
Challenge
Dozens of clusters, each with its own monitoring — no unified view and slow root-cause analysis during incidents.
Solution
Full-stack observability: Dynatrace (DynaKube, Operator, OneAgent) for AKS, plus federated Prometheus → Thanos, Grafana and Loki/Alloy on-prem. A single view of metrics and logs across environments.
Outcome
Federated metrics from 20+ clusters
Collaboration fit
Who I work best with
Working with me makes sense when you need someone who doesn't think about a single deployment, but about the whole system — how infrastructure is created, deployed, secured, monitored and recovered when something fails.
- Azure / AKS platform architecture
- Kubernetes delivery & GitOps (FluxCD / ArgoCD)
- Terraform / Terragrunt infrastructure
- Azure DevOps CI/CD pipelines
- OIDC / Workload Identity / secretless auth
- Observability (Dynatrace, Prometheus, Loki)
- Disaster recovery and cloud governance
AI-assisted engineering
AI in everyday work
I use AI as a working tool — not as a substitute for thinking.
- design solutions faster
- analyze architecture
- prepare documentation
- build prototypes
- automate repetitive work
The result isn't more AI. The result is more time for the decisions that matter.
$ contact --start
Got a platform that needs clearer structure?
If you need to bring order, automation and a safer delivery model to your cloud infrastructure — reach out. I most enjoy work that's built to last and to be operated.
Get in touchEngineering notebook