Lukáš
From Slovakia (UTC+2)
Lukáš – Golang, Kubernetes, Python
Lukáš is a senior DevOps and platform engineer with deep expertise in Linux, Kubernetes, Go, and CI/CD automation. He has led infrastructure migrations, developed Kubernetes operators, and built end-to-end platforms, demonstrating strong ownership and troubleshooting skills. His experience spans cloud, observability, and automation, with a focus on practical implementation and platform reliability. Communication is structured and concise, though formal SRE measurement practices are less developed.
11 years of commercial experience in
Main technologies
Additional skills
Direct hire
PossibleReady to get matched with vetted developers fast?
Let’s get started today!Experience Highlights
Founder & Tech Lead & DevOps Engineer
Direct-to-consumer e-commerce platform for recovery and wellness products operating across 10 EU markets with localized storefronts and live card payments. Built around 21 Go services covering core commerce, payments, supplier integrations, and operational tooling, with PostgreSQL, GitOps, self-managed Kubernetes, and end-to-end observability. Product data is automatically ingested from multiple suppliers, with Meta and Google Ads integrations for customer acquisition and server-side conversion tracking. The platform was built and operated by a single engineer.
- Designed and built the entire platform from scratch, including 21 Go services with a schema-per-service PostgreSQL architecture, 255 versioned migrations, a Next.js 14 storefront, and Stripe checkout. The platform went from the first commit to live card payments in 7 weeks;
- Implemented a self-managed Kubernetes infrastructure with GitOps delivery using ArgoCD, Helm, and Vault-backed secrets, covering payments, identity, observability, and CI;
- Delivered features end-to-end, from requirements and database schema design through API and frontend development to deployment, including multi-currency pricing, EU VAT, coupons, loyalty, referrals, B2B pricing, and guest/account order flows;
- Localized the storefront into 10 languages with versioned translation migrations to automatically detect and manage source-copy changes;
- Built automated release gates with synthetic checkout probes, post-deployment Core Web Vitals checks, and real-user monitoring to prevent regressions from reaching production;
- Automated product catalog ingestion from three supplier feeds with reconciliation safeguards to prevent data loss caused by incomplete feeds;
- Developed an AI-assisted operations agent to detect OOM kills and crash loops, propose fixes via pull requests, and escalate issues requiring human intervention;
- Maintained unit, integration, and end-to-end test coverage across Go and TypeScript services while supporting multiple production releases per day;
- Integrated Meta and Google advertising, server-side conversion tracking, Google Merchant feeds, and supplier purchasing workflows, connecting the technical platform with core e-commerce and business operations.
Technical Product Owner & Senior Platform & SRE Engineer
Europe's largest sovereign public cloud, run under data-residency and auditability obligations that are license conditions rather than features. The work covers the internal platform underneath it: the infrastructure-as-code estate that provisions it, GitOps delivery to the fleet of Kubernetes clusters that host CI, identity, monitoring, and internal tooling, and the secrets, backup, and observability foundations those clusters depend on.
- Architected the Infrastructure-as-Code portfolio using Ansible, Terraform, and Python to provision the platform’s internal infrastructure, reducing deployment time and costs by 70%;
- Designed and implemented GitOps delivery with ArgoCD across 5+ Kubernetes clusters, replacing manual releases with reproducible and auditable deployments, including an ArgoCD Vault Plugin integration to ensure secrets are never committed to source control;
- Built a Gitea driver for Zuul CI in Go, enabling self-hosted source control integration for the platform’s CI pipelines;
- Introduced HashiCorp Vault with HA Raft, AppRole, and Kubernetes authentication as the centralized secrets backend, eliminating long-lived credentials from automation. Added nightly Raft snapshots to object storage and implemented regular restore testing;
- Remediated a CVSS 9.1 credential leak caused by an Ansible task exposing a Kubernetes Secret in public CI logs. Rotated the credential, purged the affected logs, audited the codebase, and introduced a linting gate that fails CI when Secret-bearing tasks lack, validated with a negative control;
- Implemented nightly logical database backups to object storage for core platform services, including CI, identity, wiki, and source control, with restore testing and least-privilege, bucket-scoped IAM credentials;
- Owned platform observability using Grafana, VictoriaMetrics, and Loki across Kubernetes and VM fleets. Rebuilt dashboards after a data source migration and resolved silent 401 errors hidden by the provisioning API;
- As Product Owner, translated ambiguous operational requirements into scoped and prioritized platform initiatives across development and DevOps teams, while creating the runbooks and guidelines used by the team.
Senior DevOps Engineer & Senior Back-End Developer
Greenfield sovereign cloud platform built on Kubernetes and Gardener with strict software supply-chain controls. Every container image deployed to the platform must originate from an internal, signed registry. The project involved developing Go-based operators to extend cluster capabilities, a shared CI/CD pipeline library used across platform repositories, and automated dependency management to keep the platform’s components secure and up to date.
- Developed and maintained Kubernetes operators in Go using Kubebuilder, extending the platform with custom controllers, including a Garden Linux node upgrade controller;
- Served as a code owner for the shared GitLab CI pipeline library, contributing ~150 of 450 commits. Built an image auto-mirroring workflow that pulls upstream images, re-tags and pushes them to an internal Harbor registry, signs them with Cosign, and adds provenance metadata, ensuring every workload runs from a signed internal source;
- Added Helm chart scanning, packaging, and publishing stages to the shared pipeline. Introduced ShellSpec unit tests for the shell-based components, transforming an untested collection of scripts into a versioned and tested library;
- Onboarded platform repositories to a centrally hosted Renovate instance and developed custom regex managers for Gardener image vectors, including digest-pinned tags, ensuring dependency updates and image mirroring remained synchronized;
- Led the team’s DevOps transformation, covering CI/CD pipelines, testing frameworks, release automation, and security compliance evidence for audits.
DevOps Engineer & Back-End Developer
All-in-one office IoT platform combining compute, networking, printing, and video analytics, delivered as a managed service to European SMEs. The platform hosted customer applications in LXC containers and required reliable in-place upgrades across a distributed fleet of devices deployed at customer premises.
- Maintained the LXC-based application platform across the device fleet, delivering platform upgrades and scalability changes without site visits;
- Built the "Kitting Server" - the provisioning service that prepares each device's software bundle — on a Kappa (stream-first) architecture with RabbitMQ and Ruby, replacing a batch process where we were deploying the OS of the Workplace Hub to all European customers;
- Contributed to the Video Analytics System in Python, where we were enhancing the machine learning algorithms, based on the customer's refined requests.
L3 Support Engineer & QA Engineer
Launch of an all-in-one managed office appliance for European SMEs, combining an on-premise server, network gateway, printer, and IoT sensors in a single device. Customer applications were hosted in Linux containers (LXC/LXD), with new features delivered over the air. The project covered the transition from development to production, including third-line engineering support, troubleshooting across containers, networking, printing, and hardware integration, as well as establishing the operational and support processes required to manage a distributed fleet of devices across Europe.
- Defined the European service structure for a new managed product from the ground up, including support tiers (L1 country desks → L2 regional support → L3 engineering), escalation paths, and handoff rules. The model was adopted by [N] country organizations before general availability;
- Defined roles, responsibilities, and operational runbooks for support teams, including ownership by tier, response and resolution targets, on-call responsibilities, and escalation procedures, enabling country offices to onboard new support staff without engineering involvement;
- Acted as the final escalation point before the development team for the full device stack, including the container platform (LXC/LXD), networking, print subsystem, server, and application layers. Reproduced field issues in a lab environment and converted them into reproducible engineering tickets, reducing defect investigation cycles from days to hours;
- Conducted structured pre-release testing for each firmware and application release, providing direct feedback to engineering and blocking [N] releases that contained customer-facing regressions;
- Created customer-facing and internal documentation, including installation guides, network integration documentation, and troubleshooting manuals. Delivered product demonstrations and hands-on training for country teams responsible for sales and support;
- Resolved customer integration escalations involving network topology, printing workflows, and partner applications.
Linux System Administrator (Operations, L2/L3)
Large-scale managed hosting platform for enterprise customers, supporting hundreds of bare-metal and virtual Linux servers running business-critical workloads under strict zero-outage SLAs. The team managed the full server lifecycle, from provisioning and network/storage integration to monitoring, incident management, maintenance, patching, and decommissioning. A significant part of the infrastructure used clustered environments with high-availability pairs and shared Fibre Channel storage, requiring carefully controlled changes to minimize the risk of customer-facing outages.
- Owned the full server lifecycle end to end — from SAP delivery order through OS installation, LVM configuration, NIC bonding, routing, HBA/multipath zoning, and customer handover to change management and decommissioning — for hundreds of bare-metal and virtual servers, meeting delivery SLAs 99% of the time;
- Administered high-availability bare-metal clusters using Veritas Cluster Server and Veritas Volume Manager on shared Fibre Channel storage. Planned and executed node patching and failover tests without service interruption, maintaining the required zero-outage target for clustered services;
- Managed the network layer for server builds and changes, including NIC bonding for redundancy, static routes to customer segments, and coordination of VLAN and firewall requests with the network team, reducing build rework caused by connectivity issues to near zero;
- Handled incidents and customer requests through the ITIL queue at L2/L3 level, performing root-cause analysis for recurring hardware, storage-path, and filesystem incidents and converting them into problem records and standard changes to prevent repeat occurrences;
- Executed production change windows under strict approval and rollback procedures, including pre-checks, back-out plans, and post-change verification, completing multiple changes without causing service outages;
- Created and maintained build and operational runbooks for the platforms under administration, providing the primary reference for the on-call rotation.