Hi, I'm
Konstantin Makeikin
DevOps Engineer
Building and managing infrastructure at scale. Automation, monitoring, and reliability across 30+ countries.
01.About
DevOps / Platform Engineer with 20 years in infrastructure — from ISP backbone networks (180 Gbps, 14,000 subscribers, team of 35) to cloud-native platforms on Kubernetes. Currently the sole engineer on a high-traffic platform: 259 servers, 30+ countries, 99.9% uptime.
Day-to-day: Kubernetes, Terraform, Ansible, GitOps CI/CD (GitLab, ArgoCD) with blue-green deployments, Prometheus/Grafana/OpenTelemetry observability, DORA metrics tracking. Comfortable across the full stack when debugging requires it — tracing API calls, fixing auth flows, optimizing database queries, untangling Redis sessions. From kernel-level networking (nftables, eBPF/flowtable) to application-layer troubleshooting.
Full ownership of the infrastructure lifecycle: IaC (Ansible/Terraform), GitOps CI/CD (GitLab, blue-green deploys), SRE practices (Prometheus/Grafana, SLO/SLI-driven alerting, error budgets, MTTR < 5 min), DevSecOps (shift-left security, SBOM, supply chain scanning), FinOps, and incident management. One engineer with the right tooling and deep systems knowledge delivers what traditionally requires a full platform team.
Cisco CCNP, MikroTik MTCNA, AWS Cloud Practitioner certified. Based in Florianópolis, Brazil. Open to remote opportunities worldwide.
Languages
Strengths
Americas, Europe, Middle East
Remote, flexible on format
02.Skills
Cloud Platforms
Infrastructure & OS
Virtualization
Containers & Orchestration
IaC & Automation
CI/CD & GitOps
Monitoring & Observability
Security
Languages & Frameworks
Databases & Messaging
Networking
03.Experience
DevOps Engineer @ ShivaVPN
Feb 2022 — PresentFlorianópolis, Brazil · Remote
- > Sole engineer owning the full infrastructure lifecycle for a multi-cloud platform: 259 servers, 30+ countries, 5,000+ active users, 99.9% uptime
- > IaC with Ansible — automated provisioning, configuration management, and rolling updates across the entire fleet, reducing manual ops from hours to minutes per deploy
- > CI/CD pipelines (GitLab CI) with blue-green deployments, automated tests, SAST scanning, and zero-downtime releases — deploy frequency 5-10x/week
- > Full observability stack: Prometheus + Grafana (26 alert rules, 13 dashboards), Loki centralized logging, Alertmanager → Telegram + PagerDuty, MTTR < 5 min
- > Migrated L4 proxy from nginx to kernel-space nftables + flowtable — cut RAM 75% (1.6 GB → 400 MB per node), eliminated userspace bottleneck under peak load
- > Security hardening: Trivy container scanning in CI, CIS Benchmarks, automated credential rotation, compromised node detection and replacement
- > Automated TLS rotation across entire fleet (Let's Encrypt + Ansible), geo-distributed failover with healthcheck-based DNS routing — zero certificate-related outages
- > Capacity planning: per-region utilization dashboards, automated server pool scaling, canary deployments for critical config changes — handled 3x traffic growth without incidents
DevOps Engineer — Contract @ NaviScope — Maritime IoT Platform
Mar 2024 — Jan 2026Florianópolis, Brazil · Remote
- > Owned infrastructure and CI/CD for a 31-microservice platform (28 repos): real-time vessel monitoring and fleet management across international waters
- > CI/CD for all 31 services: GitLab pipelines with automated testing, container builds, staged rollouts — reduced release cycle from days to hours
- > Docker Compose for local dev, Docker Swarm for staging/production — service orchestration, rolling updates, zero-downtime deployments
- > Prometheus + Grafana monitoring: service health, latency percentiles (p95/p99), resource utilization, on-call alerting — reduced incident response time by 60%
- > Managed PostgreSQL + TimescaleDB cluster: 100K+ telemetry events/day ingestion, automated retention policies, query optimization — sub-second dashboard loads
- > Event-driven architecture: NATS JetStream + Redis Pub/Sub for reliable inter-service messaging with at-least-once delivery guarantees
- > Backend when needed: 15+ microservices (Java/Kotlin, Spring Boot), edge agent in Go for satellite-linked vessel data collection via MQTT/Modbus/NMEA-0183
DevOps Engineer — Contract @ Fintech / Crypto Platform — NDA
Sep 2023 — Aug 2024Remote
- > Managed multi-AZ EKS clusters in a 5-person platform team: namespace isolation, RBAC, network policies, pod security standards for regulated fintech workloads
- > HashiCorp Vault secrets management: dynamic DB credentials, transit encryption, PKI for internal mTLS — eliminated hardcoded secrets across all services
- > Terraform IaC: multi-environment provisioning (dev/staging/prod), remote state with locking — infrastructure changes peer-reviewed via merge requests
- > GitLab CI/CD with SAST/DAST scanning, container image signing, automated compliance checks — zero security incidents during tenure
- > Blue-green deployment strategy for payment-critical services — zero-downtime releases with instant rollback capability
- > Observability for EKS: Prometheus + Grafana pod metrics, HPA scaling events, FinOps cost dashboards (identified 20% cloud spend savings), PagerDuty integration
Infrastructure Consultant — Freelance @ Independent Practice
Oct 2019 — Nov 2025- > Independent consulting practice serving 15+ SMB/mid-market clients: architecture design, capacity planning, cloud and on-prem migration strategies
- > Provisioned and managed 40+ Linux servers (Docker, Ansible) across dedicated and cloud environments — standardized deployments, cut provisioning time from days to hours
- > Zabbix monitoring across all client environments — 200+ hosts, 99.5%+ uptime SLA, automated incident escalation via Telegram and email
- > Backup strategies with daily verification, DR runbooks, security hardening (CIS benchmarks, SSH hardening, fail2ban) — zero data loss incidents across all clients
Network Operations Lead @ ISP Operations (Multiple Companies)
2008 — 2021- > Progressed from Network Admin to Operations Lead managing a regional ISP: 14,000+ subscribers, team of 35, multi-city coverage
- > Built long-haul fiber backbone (DWDM, redundant optical links, multi-operator interconnects) — peak 180 Gbps, 99.95% backbone availability
- > Designed and launched local IX (Internet Exchange) for regional operator peering — reduced transit costs by 30% through direct peering agreements
- > Managed 500+ switches, GPON/xPON terminals, DOCSIS infrastructure — automated monitoring with Zabbix, handling 500+ tickets/week
- > Built bare-metal DC from scratch: rack-mount servers, PDU/UPS, cooling — 50+ servers provisioned and maintained with Ansible automation
- > Full ISP service stack: BGP/IX peering, VRF, DHCP/DNS HA, CGNAT, NetFlow, IPAM — all documented with runbooks and DR procedures
- > Led disaster recovery after catastrophic DB failure — restored service for 14,000+ customers with zero data loss within SLA
Senior System & Network Administrator @ Pushkino-Telecom — ISP
Feb 2006 — Aug 2008Moscow Region, Russia
- > Promoted twice in 2 years (Support → Admin → Senior Admin), managed DOCSIS 2/3 cable infrastructure for 5,000+ subscribers
04.Projects
Global VPN Platform
Multi-cloud VPN infrastructure spanning 30+ countries with automated provisioning, health checks, account pool management, and 5,000+ active subscribers.
Maritime IoT Platform
31-microservice platform for real-time vessel monitoring and fleet management. CI/CD for all services, Docker Swarm orchestration, event-driven telemetry pipeline.
Kernel-Space Proxy Migration
Replaced nginx stream proxies with nftables + flowtable for zero-copy TCP forwarding at kernel level.
Monitoring & Alerting Stack
Full observability stack: Prometheus metrics, Grafana dashboards, Alertmanager with multi-channel routing, centralized logging with Loki + Promtail.
EKS Platform Engineering
Multi-AZ Kubernetes clusters for fintech workloads: namespace isolation, RBAC, network policies, HashiCorp Vault secrets, Terraform IaC, blue-green deployments.
ISP Backbone Infrastructure
Regional ISP serving 14,000+ subscribers: DWDM fiber backbone, BGP/IX peering, bare-metal DC build, GPON/DOCSIS last-mile, full service stack.
05.Education
State University of Management (SUM)
Bachelor's — Organization Management
2021 — 2025
International University of Kyrgyzstan
Bachelor's — Computer Science
2019 — 2023
Gymnasium Shchyolkovo
Silver Medal — Secondary Education
2008 — 2019
06.Certifications
07.Contact
Open to remote DevOps / SRE opportunities. Feel free to reach out.