// My toolkit

What I run

Six years of production; the tools that earned their keep.

Cloud

AWS

EKS, ECS, Lambda, RDS

Azure

AKS, Storage, Key Vault

Hetzner bare metal

Cluster API, Crossplane

Linux fleet

200+ servers via Puppet

Containers

Kubernetes

CKA, 50+ prod clusters

Cluster API

self-hosted control planes

Kops · EKS · AKS

managed and not

Docker

distroless by default

Infrastructure as Code

Terraform

modular, small blast radius

Pulumi

when code beats HCL

Crossplane

compositions for Kops/AKS

Helm · Kustomize

packaging

Puppet

OS config at scale

CI/CD & GitOps

ArgoCD

zero-downtime releases

GitHub Actions

CI + reusable workflows

Gitea Actions · GitLab CI

self-hosted pipelines

Harness · Jenkins

migrated off the latter

Git

the one true state

Languages

Go

CLIs, operators, services

Python

automation, glue

Bash

everything else

Observability

Prometheus · Grafana

metrics, alerts, dashboards

OpenObserve · Graylog

logs at scale

OpenSearch · ELK

search, SIEM

CloudWatch

where AWS lives

Gatus

status pages, like this box

Security & networking

WireGuard · Netbird

zero-trust mesh

Vault

secrets, dynamic creds

Harbor + Kyverno

supply chain

Keycloak / OIDC

SSO everywhere

CrowdSec · Wazuh

IPS / HIDS

Caddy · TLS

edge, ACME, HSTS

Data

PostgreSQL

HA, backups, migrations

MongoDB

replica sets in prod

SQLite

for the small things

Artifactory

artifacts

Platforms I've run

AKS → Cluster API

migration to bare metal

Monolith → ECS/Lambda

50+ microservices

Local LLMs on GPU

internal Mattermost bots

PCI-DSS / RBI

fintech compliance

Certifications

CKA — Certified Kubernetes Administrator · 2026AWS SysOps Administrator – Associate · 2021Certified Ethical Hacker (CEH) · 2019

plus Cisco intro to cybersecurity, DHS ICS security, Pentester Academy web-app pentesting, ISOEH.