DevSecOps & Platform Engineer
I automate the boring parts of infrastructure - from a project's CI/CD up to provisioning a whole K8s cluster with monitoring and GitOps from a single form.
Day-to-day: Kubernetes, Terraform, GitOps, Vault, Ansible, AWS/GCP; ex-Developer (PHP, Node.js), which is why I still like writing tooling in Python & Go.
I maintain a few things you can actually use:
- 🪖 Helm charts - starting with a RouterOS (MikroTik) exporter for Prometheus, because no sensible chart existed and I didn't want to babysit static manifests.
- 🗄 Vault Snapshot Agent - a small binary that automates HashiCorp Vault backups. Vault secures your secrets; someone should secure Vault.
- 👹 Terraform modules - mostly built for specific cases, but the Fork button is right there.
- 😈 LeDo - a CLI that makes working with Docker on a project less painful. A friend's project I help develop.
- 📖 Symfony: The Fast Track - I've helped translate the Polish edition since day one.
- 📺 Twitch Helix Provider for OAuth 2.0 - One of my first creations in the open-source world. Still active - still popular!
Also regularly: Helm, Kustomize, Packer, Prometheus, Grafana, Go, PostgreSQL, Redis, Nginx.
Clouds - most production experience on AWS (EKS, EC2 & ASG, DynamoDB, R53, SQS, SNS), GCP is evolving 😋
My playground, and where most of the above gets tested before I trust it anywhere else.
Hardware
| Toy | Spec |
|---|---|
| Lenovo ThinkCentre M720q Tiny | i5-8500T, 64 GB RAM, 1 TB NVMe |
| Lenovo ThinkCentre M720q Tiny | i5-8500T, 32 GB RAM, 1 TB NVMe |
| Lenovo ThinkCentre M920q Tiny | i7-8700T, 64 GB RAM, 1 TB NVMe |
| Synology DS720+ | 2× 4 TB, 512 GB NVMe cache |
| Network | MikroTik RB5009UG+S+IN, UniFi U6+ |
Software
- Proxmox + Packer - virtualization and image building
- K3s - the cluster itself
- Terraform - Proxmox VMs, cloud envs, Vault, Cloudflare, and much more
- Ansible - stateless provisioning for K3s, Vault, load balancers, and so much other stuff!
- ArgoCD - GitOps
- HashiCorp Vault (+ VSO) - secrets
- Cloudflare & Traefik - DNS and reverse proxy
- HAProxy, Keepalived, MetalLB - load balancing and VIPs
- Prometheus, Grafana - monitoring; Pushover for alerts
- Tailscale - VPN
- Renovate - dependency updates
I started working with GitLab in 2019 at one of the companies I worked for, and for some reason, I really liked working with it! Probably because it has group support, is self-hosted, and a few other things.
Most of the homelab stuff has already been moved there, and recently I've also started contributing more, mainly because of one project I really liked!
Questions, ideas, or want to compare homelab notes? Reach out on LinkedIn.




