kubectl apply -f deployment.yaml
terraform plan -out=infra.tfplan
docker compose up -d --build
ansible-playbook deploy.yml
prometheus.io/scrape: "true"
pipeline { agent any }
ssh -i key user@server

Hi, I'm

Konstantin Makeikin

DevOps Engineer

Building and managing infrastructure at scale. Automation, monitoring, and reliability across 30+ countries.

259
Servers
30+
Countries
99.9%
Uptime

01.About

DevOps / Platform Engineer with 20 years in infrastructure — from ISP backbone networks (180 Gbps, 14,000 subscribers, team of 35) to cloud-native platforms on Kubernetes. Currently the sole engineer on a high-traffic platform: 259 servers, 30+ countries, 99.9% uptime.

Day-to-day: Kubernetes, Terraform, Ansible, GitOps CI/CD (GitLab, ArgoCD) with blue-green deployments, Prometheus/Grafana/OpenTelemetry observability, DORA metrics tracking. Comfortable across the full stack when debugging requires it — tracing API calls, fixing auth flows, optimizing database queries, untangling Redis sessions. From kernel-level networking (nftables, eBPF/flowtable) to application-layer troubleshooting.

Full ownership of the infrastructure lifecycle: IaC (Ansible/Terraform), GitOps CI/CD (GitLab, blue-green deploys), SRE practices (Prometheus/Grafana, SLO/SLI-driven alerting, error budgets, MTTR < 5 min), DevSecOps (shift-left security, SBOM, supply chain scanning), FinOps, and incident management. One engineer with the right tooling and deep systems knowledge delivers what traditionally requires a full platform team.

Cisco CCNP, MikroTik MTCNA, AWS Cloud Practitioner certified. Based in Florianópolis, Brazil. Open to remote opportunities worldwide.

Languages

English C1 — Advanced
Portuguese A2 — Elementary
Russian Native

Strengths

Incident management & on-call Decision-making under pressure Cross-team collaboration Async communication Root cause analysis Pattern recognition in logs & metrics Runbook & documentation culture Capacity planning & forecasting Postmortem-driven improvement Self-driven & autonomous
Open to opportunities
Time zones: UTC-3 — UTC+3

Americas, Europe, Middle East

Engagement: Full-time / Contract

Remote, flexible on format

02.Skills

Cloud Platforms

AWS Yandex Cloud Cloud.ru (SberCloud) VK Cloud DigitalOcean Hetzner

Infrastructure & OS

Linux Nginx nftables DNS TLS/SSL

Virtualization

KVM Proxmox VMware

Containers & Orchestration

Docker Docker Compose Multi-stage builds Kubernetes Helm Kustomize Istio/Envoy

IaC & Automation

Ansible Terraform Bash Python

CI/CD & GitOps

GitLab CI/CD GitHub Actions ArgoCD Git

Monitoring & Observability

Prometheus Grafana Loki Elasticsearch / ELK Fluentd Fluent Bit Promtail Node Exporter OpenTelemetry Alertmanager PagerDuty Zabbix

Security

HashiCorp Vault Trivy SAST/DAST

Languages & Frameworks

Python Go Java/Kotlin FastAPI Spring Boot SQL

Databases & Messaging

PostgreSQL Redis Kafka NATS TimescaleDB

Networking

TCP/IP BGP VLAN/VRF/Trunking VPN Firewall MikroTik Cisco/Juniper 10GbE/DWDM

03.Experience

DevOps Engineer @ ShivaVPN

Feb 2022 — Present

Florianópolis, Brazil · Remote

  • > Sole engineer owning the full infrastructure lifecycle for a multi-cloud platform: 259 servers, 30+ countries, 5,000+ active users, 99.9% uptime
  • > IaC with Ansible — automated provisioning, configuration management, and rolling updates across the entire fleet, reducing manual ops from hours to minutes per deploy
  • > CI/CD pipelines (GitLab CI) with blue-green deployments, automated tests, SAST scanning, and zero-downtime releases — deploy frequency 5-10x/week
  • > Full observability stack: Prometheus + Grafana (26 alert rules, 13 dashboards), Loki centralized logging, Alertmanager → Telegram + PagerDuty, MTTR < 5 min
  • > Migrated L4 proxy from nginx to kernel-space nftables + flowtable — cut RAM 75% (1.6 GB → 400 MB per node), eliminated userspace bottleneck under peak load
  • > Security hardening: Trivy container scanning in CI, CIS Benchmarks, automated credential rotation, compromised node detection and replacement
  • > Automated TLS rotation across entire fleet (Let's Encrypt + Ansible), geo-distributed failover with healthcheck-based DNS routing — zero certificate-related outages
  • > Capacity planning: per-region utilization dashboards, automated server pool scaling, canary deployments for critical config changes — handled 3x traffic growth without incidents

DevOps Engineer — Contract @ NaviScope — Maritime IoT Platform

Mar 2024 — Jan 2026

Florianópolis, Brazil · Remote

  • > Owned infrastructure and CI/CD for a 31-microservice platform (28 repos): real-time vessel monitoring and fleet management across international waters
  • > CI/CD for all 31 services: GitLab pipelines with automated testing, container builds, staged rollouts — reduced release cycle from days to hours
  • > Docker Compose for local dev, Docker Swarm for staging/production — service orchestration, rolling updates, zero-downtime deployments
  • > Prometheus + Grafana monitoring: service health, latency percentiles (p95/p99), resource utilization, on-call alerting — reduced incident response time by 60%
  • > Managed PostgreSQL + TimescaleDB cluster: 100K+ telemetry events/day ingestion, automated retention policies, query optimization — sub-second dashboard loads
  • > Event-driven architecture: NATS JetStream + Redis Pub/Sub for reliable inter-service messaging with at-least-once delivery guarantees
  • > Backend when needed: 15+ microservices (Java/Kotlin, Spring Boot), edge agent in Go for satellite-linked vessel data collection via MQTT/Modbus/NMEA-0183

DevOps Engineer — Contract @ Fintech / Crypto Platform — NDA

Sep 2023 — Aug 2024

Remote

  • > Managed multi-AZ EKS clusters in a 5-person platform team: namespace isolation, RBAC, network policies, pod security standards for regulated fintech workloads
  • > HashiCorp Vault secrets management: dynamic DB credentials, transit encryption, PKI for internal mTLS — eliminated hardcoded secrets across all services
  • > Terraform IaC: multi-environment provisioning (dev/staging/prod), remote state with locking — infrastructure changes peer-reviewed via merge requests
  • > GitLab CI/CD with SAST/DAST scanning, container image signing, automated compliance checks — zero security incidents during tenure
  • > Blue-green deployment strategy for payment-critical services — zero-downtime releases with instant rollback capability
  • > Observability for EKS: Prometheus + Grafana pod metrics, HPA scaling events, FinOps cost dashboards (identified 20% cloud spend savings), PagerDuty integration

Infrastructure Consultant — Freelance @ Independent Practice

Oct 2019 — Nov 2025
  • > Independent consulting practice serving 15+ SMB/mid-market clients: architecture design, capacity planning, cloud and on-prem migration strategies
  • > Provisioned and managed 40+ Linux servers (Docker, Ansible) across dedicated and cloud environments — standardized deployments, cut provisioning time from days to hours
  • > Zabbix monitoring across all client environments — 200+ hosts, 99.5%+ uptime SLA, automated incident escalation via Telegram and email
  • > Backup strategies with daily verification, DR runbooks, security hardening (CIS benchmarks, SSH hardening, fail2ban) — zero data loss incidents across all clients

Network Operations Lead @ ISP Operations (Multiple Companies)

2008 — 2021
  • > Progressed from Network Admin to Operations Lead managing a regional ISP: 14,000+ subscribers, team of 35, multi-city coverage
  • > Built long-haul fiber backbone (DWDM, redundant optical links, multi-operator interconnects) — peak 180 Gbps, 99.95% backbone availability
  • > Designed and launched local IX (Internet Exchange) for regional operator peering — reduced transit costs by 30% through direct peering agreements
  • > Managed 500+ switches, GPON/xPON terminals, DOCSIS infrastructure — automated monitoring with Zabbix, handling 500+ tickets/week
  • > Built bare-metal DC from scratch: rack-mount servers, PDU/UPS, cooling — 50+ servers provisioned and maintained with Ansible automation
  • > Full ISP service stack: BGP/IX peering, VRF, DHCP/DNS HA, CGNAT, NetFlow, IPAM — all documented with runbooks and DR procedures
  • > Led disaster recovery after catastrophic DB failure — restored service for 14,000+ customers with zero data loss within SLA

Senior System & Network Administrator @ Pushkino-Telecom — ISP

Feb 2006 — Aug 2008

Moscow Region, Russia

  • > Promoted twice in 2 years (Support → Admin → Senior Admin), managed DOCSIS 2/3 cable infrastructure for 5,000+ subscribers

04.Projects

Global VPN Platform

Multi-cloud VPN infrastructure spanning 30+ countries with automated provisioning, health checks, account pool management, and 5,000+ active subscribers.

259
Servers
30+
Countries
99.9%
Uptime
Ansible Docker Linux PostgreSQL Redis

Maritime IoT Platform

31-microservice platform for real-time vessel monitoring and fleet management. CI/CD for all services, Docker Swarm orchestration, event-driven telemetry pipeline.

31
Microservices
100K+
Events/Day
99.5%
Uptime
Docker Swarm GitLab CI Prometheus NATS TimescaleDB

Kernel-Space Proxy Migration

Replaced nginx stream proxies with nftables + flowtable for zero-copy TCP forwarding at kernel level.

75%
RAM Saved
0
Downtime
9
Proxies Migrated
nftables Linux Networking

Monitoring & Alerting Stack

Full observability stack: Prometheus metrics, Grafana dashboards, Alertmanager with multi-channel routing, centralized logging with Loki + Promtail.

26
Alert Rules
13
Dashboards
259
Targets
Prometheus Grafana Alertmanager Loki

EKS Platform Engineering

Multi-AZ Kubernetes clusters for fintech workloads: namespace isolation, RBAC, network policies, HashiCorp Vault secrets, Terraform IaC, blue-green deployments.

3
Environments
0
Downtime Deploys
5
Team Size
Kubernetes Terraform Vault Helm AWS

ISP Backbone Infrastructure

Regional ISP serving 14,000+ subscribers: DWDM fiber backbone, BGP/IX peering, bare-metal DC build, GPON/DOCSIS last-mile, full service stack.

180
Gbps Peak
14K+
Subscribers
500+
Switches
BGP DWDM Cisco MikroTik Zabbix

05.Education

State University of Management (SUM)

Bachelor's — Organization Management

2021 — 2025

International University of Kyrgyzstan

Bachelor's — Computer Science

2019 — 2023

Gymnasium Shchyolkovo

Silver Medal — Secondary Education

2008 — 2019

06.Certifications

CCNP
Cisco · 2010
MTCNA
MikroTik · 2012
AWS Cloud Practitioner
AWS · 2023

07.Contact

Open to remote DevOps / SRE opportunities. Feel free to reach out.