Anton Novikov

Senior Cloud InfraDevOps Engineer

I design and run Kubernetes platforms — GitOps, CI/CD, observability. Own the AWS/EKS platform across 25 clusters, 6 AWS accounts and 5 regions.

●  Full-time @ Finstar Financial Group ▶  OPSLaika (Telegram) ▶  contact
Anton Novikov — DevOps Engineer

About

DevOps Engineer, 8 years in infra — started from helpdesk, ended up owning multi-account cloud architecture. Did enterprise: a Russian GDS at Amadeus scale, 500+ VMs, mission-critical 24/7. Did startup: sole DevOps, built everything from scratch. Now: 25 EKS clusters across 6 AWS accounts and 5 regions, GitOps via ArgoCD + FluxCD.

I put backups before features and runbooks before alerts. If I need a tool and it doesn't exist, I write it — FastAPI dashboards, Alertmanager webhooks, CLIs. It goes into version control, gets a container and a Helm chart. That's just how I work.

Da Nang, Vietnam (UTC+7) Remote-ready
8 years in infra
25 k8s clusters managed
500+ VMs migrated
99.9% core API uptime

Stack

Kubernetes & GitOps
Kubernetes k3s k0s Docker FluxCD Argo CD Helm Kustomize Karpenter
IaC, CI/CD & Automation
Terraform Ansible GitLab CI/CD GitHub Actions Kaniko n8n Linux
Cloud Platforms
Yandex Cloud MWS AWS EKS EC2 VPC IAM ECR ALB Route53 Yandex Managed Kubernetes Yandex Managed PostgreSQL Yandex Managed Redis Yandex Object Storage Yandex CDN Yandex Load Balancer
Yandex Cloud & MWS — Russian-market equivalents of AWS / GCP
Architecture & FinOps
Solution Architecture Multi-Account AWS FinOps Cost Optimization IAM Cross-Region DR
Observability
Prometheus Grafana VictoriaMetrics VictoriaLogs OpenTelemetry Vector ELK Loki Sentry Zabbix
Security & Secrets
Vault ESO cert-manager SealedSecrets Trivy SonarQube Keycloak Sonatype Nexus
Networking & Ingress
Nginx HAProxy Traefik APISIX Cilium Linkerd MetalLB WireGuard
Data & Messaging
PostgreSQL MySQL ClickHouse StarRocks YDB MongoDB Cassandra Redis Kafka Strimzi RabbitMQ MinIO S3
Development
Python FastAPI Bash .NET PHP JavaScript Go

Experience

Finstar Financial Group

Jul 2026 – Present

Senior Cloud InfraDevOps Engineer

Fintech lending group live in Vietnam, the Philippines, South Africa, India, Sri Lanka and Europe — each product (risk engine, communication platform, API gateway, DWH, KYC/scoring) on its own AWS EKS cluster. Own the reference architecture across 6 AWS accounts, 5 regions and 25 clusters — 100% Terraform + the shared Helm library chart, GitOps via ArgoCD and FluxCD, no manual console work.

  • Own the AWS/EKS reference architecture across 6 AWS accounts and 5 regions (Africa, Asia-Pacific, Europe) — 25 clusters, one per product/environment, 100% provisioned via Terraform, GitOps via ArgoCD and FluxCD, zero manual console work
  • Built a new production EKS cluster from zero for the Africa DWH team — networking, cross-account IAM, ArgoCD bootstrap — then added StarRocks with its load balancer, DNS and security groups
  • Rolled out the Linkerd service mesh to new namespaces via Terraform across two regions (Africa and Europe)
  • FinOps: Karpenter consolidation policies and node-class rightsizing keep compute spend flat as the fleet grows past 25 clusters
  • Added graceful shutdown to the shared Helm library chart — terminationGracePeriodSeconds + lifecycle hooks — shipping to 10+ clusters, documented in the platform's autoscaling/RBAC/secrets/jobs guides every dev team works from
  • Built and maintain an internal Kubernetes dashboard (FastAPI + vanilla JS) — workloads, RBAC, real disk usage, ingress health checks — dev teams' daily driver instead of kubectl
KubernetesAWS EKSFinOpsSolution ArchitectureTerraformArgoCDFluxCDKarpenterLinkerdVaultExternal Secrets OperatorKeycloakKafkaStrimziClickHouseStarRocksYDBPostgreSQLGitLab CI/CDKanikoSonarQubeSonatype NexusVictoriaMetricsOpenTelemetry

Sirena-Travel group

Aug 2022 – Present · 4+ yrs

InfraDevOps Engineer

Four years at Sirena-Travel, across three products. I ran the full infrastructure at each: cloud, Kubernetes, CI/CD, observability, and tooling.

Red Rose Traveltech EU division 2026

B2B corporate-travel platform for the European market — built the whole cloud from scratch.

  • All Yandex Cloud infra in Terraform — VPC, managed Postgres/Redis, S3, DNS, CDN, load balancers. 100% IaC, no console clicks
  • GitLab CI/CD per service: test → build → Helm deploy → promotion gates with auto-rollback — commit to prod in under 5 min
  • Prometheus + Grafana wired to SLO targets, alerts via Alertmanager, TLS from cert-manager — 99.9%+ on the booking APIs
  • Automated recurring ops with n8n: partner onboarding, SLA alerts, Terraform drift — no manual work needed
MixVel agent GDS division 2025 – 2026

Agent-facing real-time GDS with its own GDS code — built the GitOps platform from scratch.

  • FluxCD v2 hub-and-spoke: one hub reconciles five spokes via SealedSecrets — no kubectl apply in prod
  • 3-layer Kustomize (base / overlays / per-env) — 90%+ config shared, zero drift; k3s + Cilium on-prem, Yandex Managed Kubernetes, APISIX
  • Whole data layer as HelmReleases — Kafka, RabbitMQ, Cassandra, ClickHouse, MongoDB, Redis, MinIO; new cluster in 30 min via Ansible
  • kube-prometheus-stack, Victoria Logs, ELK, OpenTelemetry; Vault + Trivy Operator; −20% compute by rightsizing pods
  • Wrote the team's daily tooling — env-view, abot, trivy-to-sonarqube, confluence-publisher — all Helm-packaged
Sirena-Travel parent GDS 2022 – 2026

Russian GDS at Amadeus/Sabre scale — 500+ VMs, polyglot (Java, Python, PHP, .NET, C++), 24/7.

  • Moved from bare VMs to containers — XEN/libvirt → Docker Swarm → Kubernetes, 500+ nodes, +40% utilisation, no downtime
  • CI/CD from scratch for every stack — deploys from hours to under 10 min
  • Promotion gates + auto-rollback cut bad-deploy incidents by 65%; on-call with runbooks — MTTR 120 → 20 min
  • Prometheus on 500+ nodes, 30+ dashboards; Ansible config (zero drift); zero-downtime quarterly OS patching
KubernetesFluxCD v2KustomizeTerraformAnsibleGitLab CI/CDCiliumAPISIXKafkaVaultPrometheusGrafanaYandex Cloud

ADV/web-engineering

Feb 2020 – Aug 2022 · 2 yrs 7 mos

Middle Sysadmin / Junior DevOps Engineer

Ran hybrid infra for web apps on Proxmox and VMware ESXi — introduced Docker and Kubernetes. Set up CI/CD with GitLab CI and Jenkins, managed config with Ansible, replaced Zabbix with Grafana/Prometheus. Automated routine tasks in Bash/Python and kept the hardware running — MikroTik/HP/DELL/SuperMicro.

ProxmoxVMware ESXiDockerKubernetesAnsibleGitLab CIJenkinsZabbixGrafana

TenderTech

Nov 2018 – Feb 2020 · 1 yr 4 mos

Junior / Middle Sysadmin

Where it started — sysadmin and user support (Windows/Linux, MS Office, 1C), accounts in AD/Atlassian/GitLab. Ran Proxmox VMs (Nginx, PHP-FPM) and kept the office hardware running — SuperMicro/DELL/MikroTik, AXIS/UniFi.

ProxmoxLinuxNginxPHP-FPMActive DirectoryMikroTikSuperMicro

Projects & contract work

MTS contract

2026

DevOps Engineer

MTS crypto/fintech division — blockchain settlement (VED) and two B2C exchanges. Deployed 8 environments on bare kubeadm, GitOps with ArgoCD, and a shared GitLab CI library (Kaniko, Trivy + OPA policy, SonarQube, Semgrep). Ansible managed the full cluster lifecycle; Kafka via Strimzi, secrets in Vault, node access over WireGuard.

KuberneteskubeadmArgoCDTerraformAnsibleGitLab CIStrimziVault

Flowerave contract

2024 – 2025

DevOps Engineer

Ticketing startup, sole engineer on infra — built it from an empty account. Full IaC on Yandex Cloud, k8s, self-hosted GitLab. Postgres backups with WAL archiving (RPO < 1 hr, RTO < 30 min), env provisioning from 3 days down to 30 min. 15 months, zero data loss.

TerraformKubernetesGitLab CIYandex CloudSentryELKPostgreSQL

Infrastructure tooling

2025 – Present

I treat internal tools as production code. env-view — a FastAPI dashboard of live ingress/service/pod state with HTTP/TCP checks (Helm chart, in every cluster). abot — an Alertmanager webhook receiver with per-team routing (~300 lines of Python, Helm). trivy-to-sonarqube — converts Trivy findings to SonarQube external issues. confluence-publisher — auto-syncs Markdown docs from git to Confluence.

env-viewabotAlertmanagerTrivySonarQubeHelm

antonnovikov.com

2023 – Present

Personal site & homelab

Site and homelab on a single VPS (k0s, Prague). FastAPI + Jinja2 behind APISIX, per-host TLS from Let's Encrypt via cert-manager, a private Docker registry, WireGuard and IKEv2, HTTP/SOCKS5/Shadowsocks proxies with health checks, one-command deploys (build → push → rollout). Full observability — metrics, logs, alerts, dashboards — within ~452 MiB of memory requests. A dozen more services run on the same VPS, ~€130/year all-in.

k0sFastAPIAPISIXcert-managerWireGuardLitestream

Weblog & Cheatsheet

2026 – Present

Technical write-ups from real infrastructure — FluxCD, observability, security, self-hosting; not rewrites of docs, but real solutions from production. Plus a working cheatsheet: 1600+ commands across 100+ tools (kubectl, helm, terraform, vault, linux and more), published and maintained.

KubernetesObservabilitySecuritySelf-hosting

Latest writing

I write about what I build — Kubernetes, observability, security, self-hosting.

★  A DevOps career path: eight years in infrastructure →

all posts →

DevOps cheatsheet — kubectl, helm, docker, terraform commands →
Relocation guides — 30 countries: visas, prices, cities →