Senior Platform & SRE Engineer
Ilya Papou
8 years in IT · 5+ in DevOps & SRE
I’ve built and operated production Kubernetes platforms and reusable DevSecOps pipelines. My personal R&D includes agent infrastructure prototypes for software engineering with MCP, A2A and human-in-the-loop workflow design. I prefer AWS and Google Cloud for cloud projects, and RKE2, Proxmox and Ubuntu for bare-metal and self-hosted infrastructure.
Professional experience
- Built and operated a bare-metal RKE2 platform with encrypted etcd and mTLS for inter-DC Kafka, service-to-service traffic, PostgreSQL and Redis. Managed certificates centrally in Vault and propagated updates using External Secrets Operator (ESO), webhooks and Ansible.
- Standardized service delivery through GitLab CI/CD, shared Helm charts and Argo CD.
- Owned on-call response, investigated failures and documented recovery and prevention steps.
- Centralized images and dependencies in Nexus. Enforced SAST, GitGuardian and Trivy gates blocking releases and Argo CD sync to production. Assigned developers tasks for vulnerability and dependency fixes, secret removal and development password rotation.
- Integrated kagent and Mattermost for AI-assisted engineering, with agent definitions and platform configuration managed through IaC and GitOps.
- Built and led a DevOps team with 4 direct reports. Coordinated work across a wider infrastructure group of ~10 people. Established shared standards, documentation and knowledge sharing.
- Provisioned ~8 Kubernetes clusters (20+ nodes total) with Terraform and GitOps. Integrated Cloud.ru Advanced (Huawei Cloud technology) services with VMware on bare-metal servers at Cloud.ru.
- Built a Jenkins DevSecOps pipeline for 30–40 microservices: Jira-triggered releases with shared Helm charts, security checks, tests and approvals. Build and delivery took ~5 min for >6 services. Full releases with cross-department approvals completed within a day. The pipeline remained in use and supported new services after my departure.
- Built a Keycloak SSO PoC with Nginx. Coordinated microservice changes and handed off requirements and technical specs to Security and Development. Introduced Vault, encrypted service traffic, centralized monitoring and tested disaster recovery.
- Managed development and test infrastructure on ~10 Hyper-V & Windows Server hosts, each running ~50 VMs, including Linux guests and shared engineering services.
- Built Kubernetes on Alt Linux 9.2 in an air-gapped environment. Prepared releases on USB drives for security-controlled physical transfer and deployed them using scripts.
- Maintained Airflow, Cassandra, RabbitMQ, PostgreSQL & Patroni, Docker Swarm, TeamCity and Nexus. Automated operations with Ansible, Python and Bash and used OpenVPN for isolated access.
- Delivered cloud infrastructure and web applications across freelance and Flant projects using AWS (S3, Lambda, Kubernetes and IAM) and Yandex Cloud.
- Built React & Next.js and Node.js & Express applications. Deployed Java & Spring workloads to Kubernetes with Helm, GitHub Actions and Ansible.
- Supported delivery and operations with Prometheus, Grafana, ELK and PostgreSQL & Patroni.
- Configured Linux, including Kali Linux, and analyzed boot flow and core OS components. Evaluated major virtualization models and built isolated security-testing labs.
- Mapped networks and assessed exposed services with Nmap and reconnaissance tools. Identified vulnerabilities and validated findings in controlled Metasploit exercises.
- Configured and tested VPN, Tor and I2P traffic routing. Encrypted and decrypted binary files.
- Used cryptocurrency wallets and transactions to study blockchain validation and data flow.
Personal R&D platform for developers and AI coding agents working on software and infrastructure tasks. Designed to preserve context across agent handoffs, connect tools and long-running workflows, and keep changes under human review and approval.
- Deployed platform components on Google Cloud and built four reusable Helm workload profiles with configuration validation and automated tests.
- Built a Go Agent Host for native and Docker execution, with adapters for official Codex and Claude clients. Implemented A2A streaming, session continuation and cancellation, with TLS and short-lived access for host connections.
- Added declarative agent configuration, model selection and separate development and production environments. Prepared Kubernetes workload isolation and default-deny network policies.
- Designed A2A task handoffs and long-running workflows with kagent and Temporal, including retries and Human-in-the-loop approval gates for code and infrastructure changes.
- Implemented MCP tool allowlists and a Go policy API with strict request validation, deny-by-default decisions and audit records. Pinned runtime skills to immutable artifact digests.
- Built and ran container-image and Helm-chart release workflows. Prepared Google Cloud scanning and approval-based promotion pipelines.
- Tested release policies and validated Agent Host contracts with simulated Codex and Claude providers.
Code Platform Agent runtime kagent fork kagent integration Mattermost fork Image build
Technical skills
Platform & delivery
- Linux
- Kubernetes
- RKE2
- Docker
- Terraform
- HCP Terraform Stacks
- Helm
- Argo CD
- Ansible
- GitLab CI/CD
- Jenkins
- GitHub Actions
- Nexus
Cloud infrastructure
- AWS
- GCP
- S3
- Lambda
- EKS
- IAM
- GKE
- Cloud SQL
- GCS
- Artifact Registry
- Cloud Build & Deploy
- WIF
- Secret Manager
- Cloud KMS
- Pub/Sub
- Cloudflare
Software engineering
- Go
- Python
- Bash
- JavaScript
- React
- Next.js
- Node.js
- Express
- Java
- Spring
- C++
- OpenAPI
- gRPC
- Schema validation
- contract tests
Security & reliability
- Vault
- ESO
- Keycloak
- mTLS
- Kyverno
- GitGuardian
- Trivy
- Prometheus
- VictoriaMetrics
- Grafana
- ELK
- OpenTelemetry
- Tailscale
- OPNsense
ML & data infrastructure
- Airflow
- Slurm
- JupyterHub
- MLflow
- PostgreSQL
- Patroni
- Redis
- Kafka
- RabbitMQ
- Cassandra
- MinIO
- VectorDB
- BigQuery
Agent infrastructure & R&D
- kagent
- agentgateway
- MCP
- A2A
- RAG
- Temporal
- Human-in-the-loop
- LangChain
- ADK
- Codex
- Claude Code
- Gemini
- vLLM
- Langfuse
- Designed and built an integrated aeroponic system: drew wiring schematics, soldered electronics, and connected ESP32, Arduino, Raspberry Pi, sensors and actuators.
- Developed C++ sensor firmware and Python automation for climate control, mist generation, water supply and circulation, tank-to-tank transfers and leak detection.
- Automated lighting and collected light-quality data to guide adjustments. Used computer vision to assess experimental results through changes in leaves.
- Connected ESP and Zigbee devices through Mosquitto and Zigbee2MQTT using JSON over MQTT, with Home Assistant as the control, monitoring and alerting interface.
- Automated Raspberry Pi setup with Ansible, prototyped pH, TDS and EC monitoring, and began preparing Prometheus metrics collection.
Code Controllers Sensor firmware
- Built an encrypted, multi-region Tailscale lab mesh linking devices and private networks across cloud, bare metal and homelabs.
- Automated network configuration and enabled one-click onboarding of new nodes.
- Managed all mesh ACLs through GitOps, with distinct user and service-account permissions for DNS discovery and service access.
- Tested OPNsense as an NGFW for subnet routing, network segmentation and traffic filtering.
Code Ansible Access policy GCP network lab