name: Veinar
role: DevOps / Platform Engineer
focus: Kubernetes platforms, GitOps delivery, infrastructure automation
mindset: "If it is not in Git, it does not exist."
languages: [English, Polski]
currently: Hardening clusters, polishing pipelines, writing runbooksI build and run internal platforms: clusters that rebuild from code, pipelines that promote builds without drama, and runbooks that make sense at 3 a.m.
| Principle | In practice | |
|---|---|---|
| π | GitOps over clickops | Git is the source of truth, ArgoCD reconciles, humans review |
| π§± | Small, composable overlays | Kustomize base plus thin per-environment overlays |
| π | Least privilege by default | Scoped RBAC, non-root numeric UIDs, dropped capabilities |
| π | Docs are part of the product | Runbooks written for the person on call, not for the author |
| π§ͺ | Prove it, then ship it | Evidence before claims, tested rollbacks, no silent assumptions |
| π | Plan for the bad day | Backups verified, disaster runbooks written before the disaster |
flowchart LR
DEV([Developer]) -->|push| GIT[(Git)]
GIT --> CI{{CI pipeline}}
CI -->|build and scan| REG[(Container registry)]
CI -->|write-back tag| GIT
GIT -->|pull-sync| ARGO[Argo CD]
ARGO --> K8S[[Kubernetes]]
K8S --> POL{Admission policy}
POL -->|allowed| APP((Workload))
classDef hot fill:#0e75b6,stroke:#0e75b6,color:#fff;
class ARGO,K8S hot;
- π Moving workloads to a full pull-based GitOps rollout
- π‘οΈ Tightening cluster security with admission policies and least-privilege RBAC
- π Turning every incident into a runbook and every runbook into automation
Kubernetes (RKE2) Β· Kustomize overlays Β· ArgoCD Β· Ansible roles Β· CI/CD promotion Β· Harbor and image hygiene Β· Kyverno policies Β· Incident runbooks
Built with YAML, caffeine and a healthy distrust of manual changes.
This README was created with Claude Code.



