Abdellah
From France (UTC+2)
Lemon.io stats
1
projects done0
hours workedAbdellah – Kubernetes, Linux, Ceph
Abdellah is a Senior DevOps and SRE specialist with strong expertise in Kubernetes operations, on-prem infrastructure, and cluster networking at scale. He has led platform engineering initiatives for large environments, including managing 700+ Kubernetes clusters and designing custom open-source cloud solutions. Feedback highlights his analytical debugging, direct communication, and preference for evidence-based problem solving!
7 years of commercial experience in
Main technologies
Additional skills
Direct hire
PossibleReady to get matched with vetted developers fast?
Let’s get started today!Experience Highlights
Lead Kubernetes Engineer
Design and operation of a self-service container platform used by internal development teams to provision secure, monitored environments on demand. The product delivers Kubernetes-as-a-Service (hosted control planes via Kamaji, Helm-managed resources, Network Policies, and centralized Thanos/Prometheus monitoring) alongside a Namespace-as-a-Service offering on OpenShift (self-service namespace provisioning and resource quotas), plus bare-metal OpenShift deployments
- Managed a fleet of 750 Kubernetes clusters;
- Designed and implemented a Kubernetes-as-a-Service platform (v2);
- Used Kamaji for provisioning hosted control planes;
- Developed Helm charts to manage control plane resources;
- Implemented Network Policies to secure the control plane;
- Developed an API proxy in Go (Golang);
- Deployed centralized Kubernetes monitoring with Thanos and Prometheus;
- Integrated Alerta for centralized alerting;
- Evaluated Kubernetes Gateway API solutions;
- Led the architectural design and technical decisions for a Namespace-as-a-Service offering on OpenShift;
- Developed an API for provisioning namespaces, resource quotas, and associated resources;
- Created the product's automation workflows;
- Deployed OpenShift clusters on bare metal via ABI (Agent-Based Installer);
- Migrated Kubernetes clusters to a containerized version of Illumio;
- Deployed a Consul service mesh across Kubernetes clusters.
Kubernetes Engineer
Deployment and operation of a public cloud platform serving external paying customers, built on OpenStack (Kolla-Ansible) with Ceph and CephFS storage, OIDC SSO between Keystone and Keycloak, and Ironic bare-metal provisioning. Main features included custom CLI tools to migrate VMs into and between OpenStack platforms, managed Kubernetes on top via Cluster API (with MetalLB and Velero backups), Teleport-based access management, a private GitLab, and full observability through Prometheus, Grafana, VictoriaMetrics and the Loki logging stack.
- Deployed and managed a public cloud (OpenStack via Kolla-Ansible) alongside a private GitLab instance;
- Configured OIDC authentication integrating Keystone with Keycloak;
- Provisioned a Ceph cluster for VM storage, tuning CephFS with multiple active MDS and static pinning for load balancing and performance optimization;
- Set up Ironic to automate bare-metal node provisioning;
- Handled network operations and routing via VyOS;
- Engineered CLI tools to streamline VM migrations both from OVH to OpenStack and between distinct OpenStack platforms;
- Established full-stack infrastructure monitoring utilizing Prometheus, Grafana, and VictoriaMetrics;
- Implemented centralized logging using the Loki stack;
- Orchestrated Kubernetes clusters on OpenStack using Cluster API, integrated with MetalLB for service exposure;
- Executed cluster backups and disaster recovery readiness via Velero;
- Rolled out Teleport to secure access management across VMs and Kubernetes environments;
- Provided Level 3 (N3) technical support across OpenStack and Kubernetes ecosystems.
Infrastructure Expert
Design of an on-premise virtualization platform to replace an existing AWS deployment, hosting the customer's production applications across two datacenters. Built on Proxmox with a Ceph storage cluster and made highly available through Ansible-automated HAProxy/Keepalived, PostgreSQL replication (repmgr) with pgBackRest backups and WAL archiving, and automated TLS certificate renewal. The role implied an end-to-end delivery, from hardware procurement to application migration, with level-3 support.
- Installed and configured a multi-datacenter platform spread across two sites;
- Deployed a Ceph storage cluster;
- Managed end-to-end project lifecycles, spanning equipment procurement through to application migrations from AWS;
- Developed Ansible playbooks automating HAProxy/Keepalived high availability, VM user management, PostgreSQL with pgBackRest backups/WAL archiving, and repmgr inter-site replication;
- Engineered scripts to automate TLS certificate renewals via Certbot;
- Provided Level 3 (N3) technical support covering Proxmox, Linux, and PostgreSQL environments.
OpenStack Swift Expert
Maintenance and modernization of a public object-storage platform serving external paying customers, based on OpenStack Swift. Migrated the control plane from a single node to a resilient 3-node HA architecture and moved the platform to a containerized (Docker) deployment. Delivered Ansible playbooks to add and remove nodes from the Swift ring, scripts to detect orphaned partitions, and Prometheus/Grafana monitoring.
- Maintained a public OpenStack Swift object storage platform;
- Migrated the control plane from a single node to a 3-node high-availability architecture;
- Transitioned the existing OpenStack platform to a containerized Docker architecture;
- Developed Ansible playbooks to automate adding and removing nodes from the Swift ring;
- Engineered custom scripts to detect and clean up orphaned partitions;
- Implemented an infrastructure monitoring solution using Prometheus and Grafana.
Kubernetes Expert
Designed and built of a hybrid-cloud Kubernetes cluster (GCP + on-premise, via Rancher) hosting MetaTrader 4 and 5 trading agents. Chose a BGP-based L3 network architecture (over traditional L2) using FRR for routing, BFD for fast failure detection, and ECMP for scalability, with Cilium and BGP handling service exposure
- Created a hybrid cloud Kubernetes cluster via Rancher spanning GCP and on-premises environments;
- Architected a scalable Layer 3 network foundation utilizing BGP, BFD, and ECMP;
- Configured FRR to establish robust BGP routing alongside rapid fault detection via BFD;
- Deployed Cilium integrated with BGP for high-performance Kubernetes service exposure;
Site Reliability Engineer
Site Reliability Engineering mission focused on defining and implementing a backup strategy, upgrading and managing Hardware Security Modules (HSMs), supporting developers in resolving performance issues, and deploying a monitoring and alerting stack with Grafana, Prometheus and Alertmanager
- Defined and implemented a backup strategy.
- Designed a multi-site architecture for the new on-premises data center.
- Managed custom GitHub runners with layer caching and resource optimization.
- Deployed a monitoring solution using Grafana, Prometheus, and Alertmanager.
- Maintained logging and monitoring platforms.
- Improved existing Kubernetes deployments.
- Upgraded different Terraform modules.
- Performed a performance test on Thanos.
Kubernetes Expert
Design and delivery of a Kubernetes-as-a-Service (CaaS) solution used by internal teams, built on Cluster API. The product automates the full cluster lifecycle (provisioning, scaling, upgrades), with centralized SSO/OIDC authentication via Pinniped and Keycloak and an integrated logging and monitoring stack for every provisioned cluster.
- Designed and implemented a CaaS (Kubernetes-as-a-Service) solution utilizing Cluster API;
- Automated the full provisioning lifecycle and ongoing management of guest clusters;
- Centralized cluster authentication by integrating Pinniped with Keycloak for SSO/OIDC;
- Integrated a unified logging and monitoring stack across all provisioned clusters.
OpenStack Expert
End-to-end delivery of an OpenStack platform and the migration of an application from AWS onto it. Produced the design and technical requirement documents (network, OpenStack, Ceph), deployed OpenStack via Kolla-Ansible and a Ceph storage cluster via cephadm, and built Terraform modules to provision VMs, load balancers and related resources.
- Authored comprehensive design documents and technical requirements spanning network, OpenStack, and Ceph architectures;
- Led end-to-end platform deployment and overall AWS-to-OpenStack migration initiatives;
- Deployed OpenStack utilizing Kolla-Ansible;
- Provisioned a Ceph storage cluster using cephadm (ceph orch);
- Developed custom Terraform modules to automate VM, load balancer, and infrastructure provisioning;
- Successfully migrated a proof-of-concept application off AWS onto the new OpenStack platform.
OpenStack / Kubernetes Consultant
Overview: Audit of an existing OpenStack platform followed by the design and build of a highly available Kubernetes cluster on top of it (via Rancher) to host a Spring Boot / Angular / PostgreSQL application stack. Configured user management and access rights, and delivered complete administration documentation covering Rancher installation and per-environment cluster provisioning (production, test, training).
- Audited and validated an existing multi-node OpenStack platform deployed via Kolla-Ansible;
- Designed and implemented a high-availability Kubernetes cluster on OpenStack via Rancher to host Spring Boot, Angular, and PostgreSQL workloads;
- Configured role-based access control and user management across all clusters;
- Authored comprehensive administrative documentation detailing Rancher setup and multi-environment cluster provisioning for production, testing, and training.
DevOps / Kubernetes & OpenShift Expert
Build-out of an OpenShift-based delivery platform for internal teams. Deployed OpenShift clusters and ArgoCD in non-privileged mode, developed a custom OpenShift operator to automate Network Policies and Resource Quotas, and set up CI/CD pipelines with Tekton, centralized logging with OpenDistro for Elasticsearch, and identity and access management with Keycloak.
- Set up OpenShift clusters;
- Established ArgoCD in non-privileged mode;
- Developed an OpenShift operator for automated management of Network Policies and Resource Quotas;
- Designed and implemented CI/CD pipelines with Tekton;
- Deployed and configured OpenDistro for Elasticsearch on OpenShift;
- Implemented and configured Keycloak (identity and access management).
Kubernetes / OpenStack Engineer (via Objectif Libre)
Engineering of multi-region OpenStack and Kubernetes platforms used by internal teams. Automated deployment and pre/post-provisioning with Ansible modules and playbooks, built custom monitoring tooling (federated Prometheus, a custom OpenStack exporter for database-inconsistency detection, an Alertmanager webhook), managed a HashiCorp Vault cluster, designed CI/CD pipelines, packaged applications as Helm charts, and ran 250+ Kubernetes clusters via GitOps with FluxCD.
- Deployed multi-region OpenStack platforms utilizing Kolla-Ansible;
- Developed custom Ansible modules and pre/post-provisioning playbooks;
- Automated and deployed federated infrastructure monitoring across OpenStack and Kubernetes using Prometheus, Alertmanager, Grafana, and VictoriaMetrics;
- Engineered an Ansible playbook to streamline VM migrations between distinct OpenStack platforms;
- Created a custom Prometheus exporter to detect database inconsistencies within OpenStack;
- Developed a custom Alertmanager webhook integration;
- Deployed and managed a high-availability HashiCorp Vault cluster;
- Designed and implemented automated CI/CD pipelines;
- Managed 250+ Kubernetes clusters using FluxCD via GitOps methodologies;
- Packaged core applications into reusable Helm charts;
- Provided Level 3 (N3) technical support for OpenStack and Kubernetes ecosystems.
Cloud Consultant
Cloud consulting mission maintaining and evolving an internal Ansible-based tool for automated OpenStack deployment — validating new OpenStack releases, integrating new components (Octavia, Skydive, Prometheus), and fixing bugs. Also deployed Kubernetes clusters on OpenStack via Heat and Kubespray, setup an OpenStack cluster for a hosting provider via Kolla-Ansible, and built federated monitoring (Prometheus, Alertmanager, Grafana) and centralized logging (Fluentd, Elasticsearch).
- Maintained and evolved an internal Ansible-based framework for automated OpenStack deployment;
- Developed and validated new OpenStack releases while integrating key components including Octavia, Skydive, and Prometheus;
- Analyzed, debugged, and resolved system issues;
- Deployed Kubernetes clusters on OpenStack using Heat and Kubespray;
- Designed and implemented an OpenStack cluster for a hosting provider via Kolla-Ansible;
- Deployed federated monitoring across OpenStack and Kubernetes utilizing Prometheus, Alertmanager, and Grafana;
- Established a centralized logging infrastructure based on Fluentd and Elasticsearch.
DevOps Kubernetes
DevOps engineering on a Web3 infrastructure platform — provisioning cloud infrastructure on DigitalOcean with Terraform, building a generic Helm chart for microservices with a GitHub Actions CI/CD pipeline, automating the deployment of Algorand indexer nodes and IPFS gateways on Kubernetes, and managing the full stack (Prometheus, OpenSearch, Apollo Router, External Secrets, RabbitMQ, Redis) through a GitOps workflow with ArgoCD.
- Developed Terraform scripts to automate infrastructure provisioning on DigitalOcean;
- Created a generic microservices Helm chart backed by CI/CD automation via GitHub Actions;
- Authored Ansible playbooks to streamline the installation of Algorand indexer nodes;
- Automated the dynamic creation and management of IPFS gateways on Kubernetes;
- Managed GitOps deployments via ArgoCD for core infrastructure including Prometheus, OpenSearch, Apollo Router, External Secrets, RabbitMQ, and Redis.
OpenStack Expert
Design and build of a private cloud from scratch on OpenStack, backed by a distributed Ceph storage cluster. Produced the platform architecture and design documentation and provided level-3 (N3) operational support on OpenStack and Ceph.
- Authored platform architecture and technical design specifications;
- Designed and implemented an enterprise private cloud based on OpenStack;
- Deployed and managed a distributed Ceph storage cluster;
- Provided Level 3 (N3) technical support across OpenStack and Ceph platforms.
Design of a Virtualized OpenStack Platform
Design and deployment of a multi-node OpenStack platform (controller, compute, storage) in a fully virtualized environment, including the Ironic service for bare-metal provisioning, with bare-metal nodes simulated via VirtualBMC (IPMI protocol). Delivered complete technical documentation: step-by-step deployment procedure, backup/restore, and logical and physical topology diagrams.
- Designed and deployed a multi-node OpenStack platform featuring Ironic for bare-metal provisioning across virtualized controller, compute, and storage nodes;
- Simulated bare-metal nodes using VirtualBMC over the IPMI protocol to enable smooth integration with Ironic;
- Authored comprehensive technical documentation covering step-by-step deployment workflows, disaster recovery protocols, and logical/physical network topology diagrams.