Skip to content
View Veinar's full-sized avatar

Block or report Veinar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
veinar/README.md

$ whoami

name:      Veinar
role:      DevOps / Platform Engineer
focus:     Kubernetes platforms, GitOps delivery, infrastructure automation
mindset:   "If it is not in Git, it does not exist."
languages: [English, Polski]
currently: Hardening clusters, polishing pipelines, writing runbooks

I build and run internal platforms: clusters that rebuild from code, pipelines that promote builds without drama, and runbooks that make sense at 3 a.m.


🧰 Tech Arsenal

Orchestration and GitOps

Kubernetes RKE2 Rancher Argo CD Helm Kustomize Traefik Longhorn

Automation and CI/CD

Ansible Azure DevOps Docker Harbor Git Bash PowerShell

Security and policy

Kyverno Trivy cert-manager OWASP

Code and tooling

Go Python TypeScript YAML Linux Markdown


🧭 What I Care About

Principle In practice
πŸ” GitOps over clickops Git is the source of truth, ArgoCD reconciles, humans review
🧱 Small, composable overlays Kustomize base plus thin per-environment overlays
πŸ” Least privilege by default Scoped RBAC, non-root numeric UIDs, dropped capabilities
πŸ“š Docs are part of the product Runbooks written for the person on call, not for the author
πŸ§ͺ Prove it, then ship it Evidence before claims, tested rollbacks, no silent assumptions
πŸ›Ÿ Plan for the bad day Backups verified, disaster runbooks written before the disaster

πŸ›°οΈ Platform at a Glance

flowchart LR
    DEV([Developer]) -->|push| GIT[(Git)]
    GIT --> CI{{CI pipeline}}
    CI -->|build and scan| REG[(Container registry)]
    CI -->|write-back tag| GIT
    GIT -->|pull-sync| ARGO[Argo CD]
    ARGO --> K8S[[Kubernetes]]
    K8S --> POL{Admission policy}
    POL -->|allowed| APP((Workload))
    classDef hot fill:#0e75b6,stroke:#0e75b6,color:#fff;
    class ARGO,K8S hot;
Loading

πŸ“ˆ GitHub Stats

GitHub stats Top languages Streak stats

🌱 Currently

  • πŸ”­ Moving workloads to a full pull-based GitOps rollout
  • πŸ›‘οΈ Tightening cluster security with admission policies and least-privilege RBAC
  • πŸ“ Turning every incident into a runbook and every runbook into automation

πŸ’¬ Ask Me About

Kubernetes (RKE2) Β· Kustomize overlays Β· ArgoCD Β· Ansible roles Β· CI/CD promotion Β· Harbor and image hygiene Β· Kyverno policies Β· Incident runbooks


Built with YAML, caffeine and a healthy distrust of manual changes.

This README was created with Claude Code.

footer

Pinned Loading

  1. dracan dracan Public archive

    Dracan is a lightweight middleware for Kubernetes that enhances filtering and validation capabilities. It ensures that only valid requests reach your applications, featuring HTTP method filtering, …

    Python 66 4