Lead DevOps Engineer

Sergey Krivopishin

Twenty-five years of building the ground other people ship on: from server rooms and Active Directory to multi-account Kubernetes platforms, GitOps and infrastructure for AI.

GitOps & platform engineering ArgoCD, FluxCD, Crossplane, AI infrastructure 2023 – now 3 yrs
Cloud & containers Azure, AWS, Docker, Kubernetes, Helm 2018 – now 8 yrs
Delivery automation Git, Chef, TeamCity, Terraform 2012 – now 14 yrs
Virtualization & scripting Hyper-V, VMware vSphere, PowerShell, Bash 2008 – now 18 yrs
Systems & networks Windows Server, Active Directory, Exchange, FreeBSD 2001 – now 25 yrs
Each bar is filled from the year I started working in that area up to today. The layers stack up: the older skills are still in daily use.

What I do now

BTB — P2P investment and lending platform

Lead DevSecOps Engineer, SoftTeco Nov 2023 – present

I run the infrastructure of a regulated fintech platform: three AWS accounts, three EKS clusters, everything defined in Terraform and delivered through GitOps. I lead a small DevOps team and work day to day with the product engineers.

Platform

  • Built and operate EKS clusters for staging, production and a shared tools account, kept current through version upgrades up to 1.34.
  • Karpenter autoscaling with spot and dedicated node pools; KEDA for event-driven workloads.
  • Replaced ingress-nginx with Gateway API on Istio and Envoy, then retired nginx completely.

Infrastructure as code

  • Introduced Crossplane alongside Terraform: Terraform for the foundation, Crossplane Compositions for resources that live with the application.
  • Refactored all Terraform modules for today's needs into a library of about 55 modules released by tag: EKS, RDS, DMS, networking, Cognito, SSO, Lambda and more.
  • 13 in-house Helm charts published as OCI artifacts with semantic-release.
  • Secrets as code: per-environment manifests to AWS Secrets Manager and KMS, synced by External Secrets Operator.

CI/CD

  • Moved the company from GitLab to GitHub: every repository and pipeline.
  • Self-hosted GitHub Actions runners on Kubernetes (ARC) plus an autoscaled EC2 fleet.
  • A library of 23 reusable composite actions: Nx affected builds, deploy matrices, image releases, caching, e2e reports.
  • Security scanning, CODEOWNERS reviews and AI-assisted pull request review in CI.

Developer self-service

  • Built automation that lets developers do most operations on their own, without involving DevOps: create a new app, spin up an environment, release, allowlist an IP, start a database.
  • On-demand preview environments through Crossplane Compositions and ArgoCD ApplicationSets.
  • Replaced a Google Docs handbook with a documentation portal that is written in git and published automatically.

Observability

  • Moved from Prometheus, Thanos, Loki and Grafana to SigNoz with OpenTelemetry auto-instrumentation.
  • Alerts and dashboards managed as Terraform.
  • An LLM-generated daily production health report built on Bedrock and an MCP server over telemetry.

Data & security

  • Migrated the core database from MS SQL to PostgreSQL with AWS DMS.
  • Table partitioning with pg_partman and pg_cron, archived to S3.
  • IPv6 dual-stack VPCs, Transit Gateway and site-to-site VPN, WAF allowlists, GuardDuty malware response, CloudTrail and flow logs.

AI infrastructure

  • Building an internal agent platform: LiteLLM gateway to Bedrock, Hatchet, isolated Kubernetes runners for coding agents.
  • Deployed an enterprise AI search over company knowledge.

Stack AWS, EKS, Terraform, Crossplane, ArgoCD, Argo Workflows, Helm, Istio, Karpenter, GitHub Actions, PostgreSQL, SigNoz, OpenTelemetry, LiteLLM

Loostra and Podify — print-on-demand platform

DevOps Engineer, SoftTeco Oct 2025 – present

A print-on-demand commerce platform with about 16 backend services and 3 frontends, running in two clouds: AWS for Loostra, Yandex Cloud for Podify. I built the infrastructure and delivery from scratch and now carry non-functional requirements, change requests and on-demand support.

Infrastructure

  • Terraform for both clouds: VPC, EKS and Yandex Managed Kubernetes, RDS, ECR and Container Registry, S3, KMS, Route53, CloudFront, Lambda.
  • Four environments on AWS, including an isolated test environment with its own network and database, plus a dedicated performance environment.
  • Split the mockup editor into a separate product with its own infrastructure.

Delivery

  • GitOps with FluxCD and in-house Helm charts; cluster add-ons and apps from a shared base with per-environment overlays.
  • Bitbucket Pipelines with OIDC to the cloud, automatic plans and approved applies, self-hosted runners.
  • Scaled-down modes for non-production environments to cut cost.

Observability

  • Metrics, logs and traces with Prometheus, VictoriaLogs, VictoriaTraces and the OpenTelemetry Collector, with Grafana dashboards and alert rules as code.
  • Load testing with the k6 operator.

Security

  • Secrets as code with External Secrets, KMS and cross-region replication; no long-lived cloud credentials in CI.
  • cert-manager, external-dns and Reloader for hands-off certificates, DNS and config rollouts.

Stack AWS, Yandex Cloud, Terraform, Kubernetes, FluxCD, Helm, Bitbucket Pipelines, KEDA, RabbitMQ, Redis, MongoDB, PostgreSQL, VictoriaMetrics stack, OpenTelemetry, k6

Skills

Bar length is years of hands-on use, on a 25-year scale.

Systems

Windows Server
25 yrs
VMware / Hyper-V
6 yrs

Also: Ubuntu, CentOS, RHEL, Amazon Linux, FreeBSD, Active Directory, Exchange, SCVMM, WDS

Cloud

Azure
8 yrs
AWS
7 yrs
Google Cloud
2 yrs
Yandex Cloud
1 yr

Also: ARM templates, CloudFormation, AWS SSM, Azure Functions, Azure Automation

Infrastructure & delivery

Terraform
12 yrs
Azure Pipelines
9 yrs
Helm
8 yrs
Kubernetes
7 yrs
Docker
7 yrs
GitHub Actions
6 yrs
GitLab CI
4 yrs
TeamCity
4 yrs
Ansible
4 yrs
ArgoCD
3 yrs
FluxCD
3 yrs
Crossplane
3 yrs
Karpenter
3 yrs
Chef
2 yrs

Also: Istio, KEDA, Kustomize, Packer, Octopus Deploy, Jenkins, AWX

Languages

PowerShell
18 yrs
Bash
18 yrs
Python
8 yrs

Also: T-SQL, C#, Ruby, Go, JavaScript

Databases

MS SQL Server
20 yrs
PostgreSQL
5 yrs
MySQL
4 yrs
Redis
4 yrs
ClickHouse
1 yr

Also: Oracle, MongoDB, Solr, Elasticsearch, RabbitMQ

Observability

Prometheus
6 yrs
Grafana
6 yrs
Nginx
6 yrs
Loki / Thanos
3 yrs
SigNoz / OpenTelemetry
1 yr
VictoriaMetrics stack
1 yr

Also: Application Insights, ELK, Zabbix, Alertmanager

Collaboration

Git & GitHub
13 yrs
Jira
13 yrs
Azure DevOps
6 yrs
Bitbucket
1 yr

Also: SVN, TFS, Azure Boards

Earlier projects

Consulting and delivery work, newest first. Open a project to see what I was responsible for.

  1. 2026Performance testing for a Windows security productDevOps Engineer, SoftTeco

    Built the environment for load testing a Windows security product that analyses and signs documents on the fly as users open them.

    • Windows Server hosts on EC2 with access through SSM and RDP.
    • HAProxy and nginx in front, Prometheus and Grafana for metrics, supporting services in Docker Compose.

    Stack AWS, EC2 Windows Server, SSM, HAProxy, nginx, Prometheus, Grafana, Docker Compose

  2. 2025 – 2026AI-driven supplier threat intelligence and alert managementDevOps Engineer, SoftTeco

    An AI-based Kubernetes application that collects and analyses security incidents across suppliers.

    • Built and delivered the Azure infrastructure as code.
    • Owned build, release and deployment of the applications.

    Stack Azure, Azure Pipelines, Terraform, Helm, Docker, FluxCD

  3. 2025Deployment consultingConsultant, SoftTeco

    Advised a client team on how to deploy and run their application.

  4. 2024 – 2025AKS migration and security reviewArchitect, DevOps Engineer, SoftTeco

    Discovery, architecture and plan for moving a production AKS cluster and its registry to a new Azure subscription.

    • Designed the target setup and a step-by-step cutover: service principals, image transfer, CI secrets, DNS switch.
    • Security and reliability review with prioritised fixes: secrets out of git into Key Vault, everything as code, HA for Redis and RabbitMQ, resource requests and limits, spot nodes for dev.
    • Proposed Helm and GitOps for application delivery and estimated the whole programme.

    Stack Azure, AKS, ACR, Key Vault, Helm, Prometheus, Grafana, ingress-nginx, cert-manager

  5. 2023 – 2026Scores and More — app for the diving communityConsultant, Lead DevOps, SoftTeco

    A social and competition platform for divers, parents, judges and coaches, on web and mobile.

    • Led the DevOps engineers and made infrastructure decisions on scalability, security and cost.
    • Worked with developers on application architecture.
    • Troubleshot production incidents and set deployment and monitoring practices.
    • Stayed on for ongoing support in 2025–2026.

    Stack GCP, GitHub, Kubernetes, Terraform, PostgreSQL

  6. 2023 – 2026Pre-sales architecture and estimatesArchitect, SoftTeco

    Answered client requests for proposals with infrastructure designs, CI/CD plans and cost estimates.

    • An AI product covering NLP and video and audio comprehension: infrastructure, CI/CD and MVP cost.
    • A smart mirror that lets shoppers try on clothes virtually: software and hardware architecture around a GPU and neural networks.

    Stack Azure, AWS, Kubernetes, GitHub Actions

  7. 2023 – 2026Travel Commerce Solutions — .NET on AzureConsultant, DevOps Engineer, SoftTeco

    Rescued and then supported the delivery of .NET applications on Azure for Travel Commerce Solutions and its Groupadoo product.

    • Audited and fixed the CI/CD pipelines and planned the next improvements.
    • Set up and maintained Web Apps and Azure SQL, with automatic certificate renewal.

    Stack Azure Web Apps, Azure SQL, .NET, MSBuild, Jenkins, GitHub

  8. 2023 – 2024ADX and Injazat — secure microservices platform on AzureLead DevSecOps Engineer, SoftTeco

    An urgent, security-first build of dev, test, pre-prod and prod environments on Azure, under least-privilege access.

    • Refactored all Terraform and built the Azure DevOps pipelines and Dockerfiles.
    • Private AKS cluster in a hub-and-spoke network, with access locked down by port and IP.
    • Designed service-to-service communication and wrote the communication matrix.
    • Worked through the customer's security team for every access; documented the architecture and implementation.

    Stack Azure, AKS, Azure DevOps, Terraform, Docker, Helm, Python

  9. 2023Sparkasse — AI document analysis for a bankDevOps Engineer, SoftTeco

    Infrastructure for an AI tool that analyses bank documents automatically.

    • Terraform for the cloud resources, Azure DevOps pipelines, Helm charts.

    Stack Azure, Azure DevOps, Terraform, GitHub Actions, Kubernetes

  10. 2022The Real Deal — real estate news portal redevelopmentLead DevOps Engineer, Exadel

    A multi-regional US real estate news portal rebuilt from the ground up. Team of four developers, an architect and me as the only DevOps engineer.

    Architecture

    • Acted as solution architect for the new platform.
    • Designed a secure AWS infrastructure and a disaster recovery plan with a preliminary estimate.

    Delivery

    • Infrastructure as code with Terraform, deployed into EKS.
    • CI/CD for the microservices with Docker, Helm and GitHub Actions; branching and versioning strategy.

    Team

    • Guided developers on performance and security issues.

    Stack AWS, EKS, Terraform, Helm, Docker, GitHub Actions, Bash, WordPress

  11. 2019 – 2022Wolters Kluwer — cloud resources at enterprise scaleLead DevOps Engineer, Exadel

    A DevOps practice of 10 to 20 engineers serving the internal departments of a large enterprise with many Azure subscriptions and AWS accounts.

    Platform

    • Built and supported a container-as-a-service offering for internal customers.
    • Refactored the CI/CD pipeline for the move to the newest Windows Server version.

    Configuration and hardening

    • A configuration and validation service for Azure VMs and EC2 instances on Ansible and AWX, driven through the Azure agent and AWS SSM, with custom Ansible plugins in Python.
    • CIS hardening automation for the whole fleet.

    Tooling

    • Designed and ran a cloud inventory solution on Azure Automation and Azure Functions.
    • Designed the migration from Azure AD SSO to AWS SAML 2.0 SSO.

    Leadership

    • Led teams of 2 to 4 engineers as scrum master and coordinator.

    Stack Azure DevOps, Terraform, ARM, CloudFormation, Kubernetes, Ansible, AWX, AWS SSM, Python, PowerShell, Bash, Azure Automation, Azure Functions, Logic Apps

  12. 2021Instructure — education platform, Azure to AWSSenior DevOps Engineer, Exadel

    An educational platform for schools and universities that had to move from Azure to AWS.

    Migration

    • Designed the migration strategy for the ASP.NET applications.
    • Moved the applications from Azure Web Apps to AWS Lightsail.
    • Moved the database from Azure SQL to Amazon RDS with AWS DMS.

    Stack Azure, AWS, Lightsail, RDS, DMS, MS SQL, Docker

  13. 2020 – 2021Verint — enterprise feedback managementDevOps Engineer, Exadel

    A feedback management platform whose legacy components kept failing to install.

    Automation

    • Automated the CI/CD pipeline and the configuration of legacy software.
    • Moved application provisioning from PowerShell scripts to Ansible.
    • Tracked down the root causes of old installation failures.

    Team

    • Supported the development team in daily work.

    Stack Octopus Deploy, Ansible, PowerShell, GitLab

  14. 2019Exadel — AWS cost calculatorLead DevOps Engineer, Exadel

    An internal Exadel project: automated calculation of AWS costs.

    Stack AWS, PowerShell

  15. 2019Deloitte — Tax TipsCI/CD and Support Engineer, Exadel

    An internal tax calculation application whose microservice delivery needed an update.

    • Refactored the Docker deployment.
    • Automated work item updates in Azure DevOps.
    • Scheduled start and stop of VMs by resource group and tags to cut cost.

    Stack Azure DevOps, Azure IaaS, Docker, PowerShell

  16. 2015 – 2018Luxottica — digital asset managementSupport Team Lead, Technical Architect, EPAM

    Luxottica's Content Lab and DAM, built on ADAM Software. Grew from coordinating a four-person support team into the stream's lead and technical architect.

    Process

    • Built the support process from zero, following ITIL practices.
    • Reporting and Jira visibility for the customer and the team, with regular customer meetings.
    • Backlog reviews and onboarding of newcomers.

    Engineering

    • Solution design as the stream's technical expert.
    • CI/CD and deployment improvements, infrastructure changes, bug fixing.
    • Developed the ADAM PowerShell module.

    Support

    • Customer and internal support, root-cause analysis of problems.

    Stack MS SQL, Solr, Elasticsearch, TeamCity, PowerShell, Visual Studio, MSBuild, MSDeploy, Sonar, Application Insights, Azure IaaS, .NET

  17. 2015McKesson — DAM deployment automationEngineer, EPAM

    A digital asset management system on ADAM Software.

    • Automated the whole product deployment from scratch.
    • One-touch deployment that updates Jira tickets and versions and emails release notes.
    • Automatic rollback.

    Stack TeamCity, PowerShell, DSC, Web Deploy, Jira API, MS SQL 2012

  18. 2008 – 2014Invention Machine, acquired by IHS — IT for an R&D officeLead Engineer, System Administrator

    Started as the sole administrator of a 60-person office of developers and testers running about 50 self-assembled desktops as servers. After IHS bought the company, I led the Minsk side of moving the office, by then 100 people, into IHS, with a team of network, support and phone engineers.

    Infrastructure

    • Upgraded the Windows 2000 domain controllers and Exchange 2000 to 2007.
    • RIS and WDS for OS deployment; Forefront central antivirus in place of NOD32.
    • Built a new server room with a blade chassis and 3PAR storage.

    Acquisition

    • Moved the office to the IHS domain: accounts, trusts, servers, workstations, user profiles and data.
    • Owned hardware design and procurement and the risk discussions for the Minsk office.
    • Integrated digital phones and conference rooms; audited the network of the expanded office and took part in the vendor choice.

    Virtualization

    • Moved from VMware Workstation to Hyper-V with SCVMM 2008.
    • Later migrated nearly all VMs to vSphere; installed and ran vCenter, fixed storage connectivity to ESXi, set up PowerChute Network Shutdown.

    Network

    • Ran the IPsec site-to-site link to the US office: Cisco ASA on one side, FreeBSD on the other.
    • Remote access through RRAS VPN and later Remote Desktop Gateway; brought up a new fibre link from the UK.
    • Monitoring with munin, mrtg and softflowd; rebuilt the server room network during an office move.

    QA tooling

    • Rewrote the web UI of the QA test framework: the main page now loads in 1–2 seconds instead of minutes or a timeout.
    • Cut the daily test report from 40 minutes – 4 hours down to 5–8 minutes across 20,000 tests.
    • Prepared dev and test environments, including PTC Windchill, EMC Documentum and Oracle.

    Delivery

    • Introduced Chef for deploying the product on the production site, with a cookbook for the index node.
    • Built a web portal for the physical access system on Web API 2 and AngularJS.

    Stack Windows Server 2000–2012, AD, Exchange, WSUS, WDS, GPO, SharePoint, Hyper-V, SCVMM, vSphere, ESXi, 3PAR, FreeBSD, Chef, Ruby, C#, AngularJS, MS SQL, Oracle 10g, Paradox, PowerShell

  19. 2008AlliedTesting — QA infrastructureSystem Administrator

    One of two administrators in a 60-person testing office.

    • Clean OS reinstalls for testers and regular software audits.
    • Automated installs with RIS, then upgraded to WDS with backward compatibility.
    • Proposed and started the move to virtualization.

    Stack Windows Server 2003, RIS, WDS

  20. 2001 – 2008N.N. Alexandrov National Cancer Center of BelarusLead Engineer, System Administrator

    Started as a technician and grew the center's IT from one server and 20 PCs to 4 servers and about 200 PCs.

    Infrastructure

    • Replaced an ad-hoc network with Active Directory, DNS and DHCP.
    • Exchange as the mail server; a Squid proxy with AD authentication and traffic shaping.
    • Planned and cabled the network expansion.

    Medical imaging

    • On the team that built a system storing X-ray images from every machine and serving them to any doctor's PC.
    • Found and adapted an open-source DICOM server and wrote its management UI.
    • Saved the center about $250,000 a year and let doctors see every image of a patient, not just the printed few.

    Events

    • Ran the technical side of medical conferences, including the 3rd Congress of CIS Oncologists.

    Stack Windows 2000 Server, AD, DNS, DHCP, Exchange 2000, FreeBSD, Squid, Apache, MS SQL 2000, C#