# Ilya Papou (Ilya Popov) — CV > Ilya Papou, Senior Platform & SRE Engineer. 8 years in IT · 5+ in DevOps & SRE. Based in Buenos Aires, Argentina. Ilya Papou is also known as Ilya Popov, PILPROD and pilprod. PILPROD and pilprod are capitalization variants of the same professional handle. All these names refer to the same person and the same professional profile at https://papou.work/. I’ve built and operated production Kubernetes platforms and reusable DevSecOps pipelines. My personal R&D includes agent infrastructure prototypes for software engineering with MCP, A2A and human-in-the-loop workflow design. I prefer AWS and Google Cloud for cloud projects, and RKE2, Proxmox and Ubuntu for bare-metal and self-hosted infrastructure. ## CV links English is the primary version. The optional [Russian CV](https://papou.work/ru/) and [Russian portfolio](https://papou.work/ru/portfolio.html) contain the same facts and source relationships. [Russian agent-readable overview](https://papou.work/ru/llms.txt). - [Project sources and lab photographs](https://papou.work/portfolio.html): Three R&D projects mapped to eleven public GitHub repositories, their LinkedIn Projects and associated Experience entries, with nine photographs of the aeroponics lab. - [Portfolio in Markdown](https://papou.work/portfolio.md): Repository scope, fork provenance, archival limitations and captioned photograph links. Five photographs have AI-retouched backgrounds or identifying areas; the root-chamber photograph has not been redrawn. - [Structured portfolio graph](https://papou.work/portfolio.jsonld): Separate Person, CreativeWork, SoftwareSourceCode and ImageObject identities, with explicit project/repository/photo relationships. LinkedIn section links are not individual public project permalinks. - [Full CV](https://papou.work/): Profile, contact details, spoken languages, professional experience, technical skills and personal projects. - [Download CV as PDF](https://papou.work/assets/Ilya%20Papou%20CV%20%E2%80%94%20DevOps%20%26%20SRE.pdf?v=20260907-no-dash): The same CV in a fixed two-page A4 layout, with a high-resolution portrait and clickable contact, repository and project portfolio links, under 1 MB. - [Professional experience](https://papou.work/#experience): Sirena-Travel, Sberbank Insurance Broker, I-Teco, Flant & Freelance and the MTS (Mobile TeleSystems) internship. - [Agent Orchestration Infrastructure](https://papou.work/#projects): Personal R&D in agent infrastructure, orchestration and release workflows. - [Technical skills](https://papou.work/#technologies): Platform and delivery, cloud infrastructure, software engineering, security and reliability, ML and data infrastructure, and agent infrastructure. - [Home Aeroponics & IoT automation](https://papou.work/#home-aeroponics): Home growing automation, climate control and monitoring. - [Zero-Trust Mesh & Open-source NGFW](https://papou.work/#zero-trust-mesh): Encrypted lab networks, GitOps-managed ACLs and OPNsense experiments. ## Profile ### Contact - Also known as Ilya Popov - Buenos Aires, Argentina - [Email: ilya@papou.email](mailto:ilya@papou.email) - [Website: papou.work](https://papou.work/) - [WhatsApp: papou.work](https://wa.me/papou.work) - [Telegram: pilprod](https://t.me/pilprod) - [LinkedIn: pilprod](https://www.linkedin.com/in/pilprod/) - [GitHub: pilprod](https://github.com/pilprod) ### Spoken languages - Russian: Native - English: B1 - Spanish: A1 - German: A1 ### Core strengths - Platform ownership - Production reliability - Delivery automation - Team leadership ### Environments - Cloud & bare metal - Isolated, air-gapped - Product & consulting - Remote teams ### Domain experience - Finance & insurance - Aviation & travel - iGaming & anti-fraud - Public sector ## Professional experience ### [Sirena-Travel](https://sirena-travel.com/) — Senior SRE & Platform Engineer Mar 2025 — Sep 2026 · Contract · Thailand · Remote Aviation & travel - Built and operated a bare-metal RKE2 platform with encrypted etcd and mTLS for inter-DC Kafka, service-to-service traffic, PostgreSQL and Redis. Managed certificates centrally in Vault and propagated updates using External Secrets Operator (ESO), webhooks and Ansible. - Standardized service delivery through GitLab CI/CD, shared Helm charts and Argo CD. - Owned on-call response, investigated failures and documented recovery and prevention steps. - Centralized images and dependencies in Nexus. Enforced SAST, GitGuardian and Trivy gates blocking releases and Argo CD sync to production. Assigned developers tasks for vulnerability and dependency fixes, secret removal and development password rotation. - Integrated kagent and Mattermost for AI-assisted engineering, with agent definitions and platform configuration managed through IaC and GitOps. ### [Sberbank Insurance Broker](https://www.sberbank.com/) — Head of DevOps Jun 2023 — Mar 2025 · Full-time · Russia · Hybrid Finance & insurance - Built and led a DevOps team with 4 direct reports. Coordinated work across a wider infrastructure group of ~10 people. Established shared standards, documentation and knowledge sharing. - Provisioned ~8 Kubernetes clusters (20+ nodes total) with Terraform and GitOps. Integrated Cloud.ru Advanced (Huawei Cloud technology) services with VMware on bare-metal servers at Cloud.ru. - Built a Jenkins DevSecOps pipeline for 30–40 microservices: Jira-triggered releases with shared Helm charts, security checks, tests and approvals. Build and delivery took ~5 min for >6 services. Full releases with cross-department approvals completed within a day. The pipeline remained in use and supported new services after my departure. - Built a Keycloak SSO PoC with Nginx. Coordinated microservice changes and handed off requirements and technical specs to Security and Development. Introduced Vault, encrypted service traffic, centralized monitoring and tested disaster recovery. ### [I-Teco](https://www.i-teco.ru/) — Senior DevOps Engineer Apr 2022 — Jun 2023 · Full-time · Russia · Remote Public sector - Managed development and test infrastructure on ~10 Hyper-V & Windows Server hosts, each running ~50 VMs, including Linux guests and shared engineering services. - Built Kubernetes on Alt Linux 9.2 in an air-gapped environment. Prepared releases on USB drives for security-controlled physical transfer and deployed them using scripts. - Maintained Airflow, Cassandra, RabbitMQ, PostgreSQL & Patroni, Docker Swarm, TeamCity and Nexus. Automated operations with Ansible, Python and Bash and used OpenVPN for isolated access. ### [Flant](https://flant.ru/) & Freelance — Development & DevOps Nov 2019 — Mar 2022 · Selected projects · Remote Cross-industry IT consulting - Delivered cloud infrastructure and web applications across freelance and Flant projects using AWS (S3, Lambda, Kubernetes and IAM) and Yandex Cloud. - Built React & Next.js and Node.js & Express applications. Deployed Java & Spring workloads to Kubernetes with Helm, GitHub Actions and Ansible. - Supported delivery and operations with Prometheus, Grafana, ELK and PostgreSQL & Patroni. ### [MTS (Mobile TeleSystems)](https://mts.ru/) — Information Security Intern Feb 2018 — Nov 2019 · Internship · Belarus · Remote Telecommunications - Configured Linux, including Kali Linux, and analyzed boot flow and core OS components. Evaluated major virtualization models and built isolated security-testing labs. - Mapped networks and assessed exposed services with Nmap and reconnaissance tools. Identified vulnerabilities and validated findings in controlled Metasploit exercises. - Configured and tested VPN, Tor and I2P traffic routing. Encrypted and decrypted binary files. - Used cryptocurrency wallets and transactions to study blockchain validation and data flow. ## Engineering experience & technical skills [Project sources & lab photographs · papou.work/portfolio.html](https://papou.work/portfolio.html) ### Agent Orchestration Infrastructure Jun 2026 – Present · Personal R&D · PoCs · Buenos Aires, Argentina Personal R&D platform for developers and AI coding agents working on software and infrastructure tasks. Designed to preserve context across agent handoffs, connect tools and long-running workflows, and keep changes under human review and approval. - Deployed platform components on Google Cloud and built four reusable Helm workload profiles with configuration validation and automated tests. - Built a Go Agent Host for native and Docker execution, with adapters for official Codex and Claude clients. Implemented A2A streaming, session continuation and cancellation, with TLS and short-lived access for host connections. - Added declarative agent configuration, model selection and separate development and production environments. Prepared Kubernetes workload isolation and default-deny network policies. - Designed A2A task handoffs and long-running workflows with kagent and Temporal, including retries and Human-in-the-loop approval gates for code and infrastructure changes. - Implemented MCP tool allowlists and a Go policy API with strict request validation, deny-by-default decisions and audit records. Pinned runtime skills to immutable artifact digests. - Built and ran container-image and Helm-chart release workflows. Prepared Google Cloud scanning and approval-based promotion pipelines. - Tested release policies and validated Agent Host contracts with simulated Codex and Claude providers. Code: [Platform](https://github.com/pilprod/yourown-chat) · [Agent runtime](https://github.com/pilprod/substrate) · [kagent fork](https://github.com/pilprod/kagent) · [kagent integration](https://github.com/pilprod/yourown-chat-kagent) · [Mattermost fork](https://github.com/pilprod/mattermost) · [Image build](https://github.com/pilprod/yourown-chat-mattermost) ### Technical skills #### Platform & delivery - Linux · Kubernetes · RKE2 · Docker - Terraform · HCP Terraform Stacks - Helm · Argo CD · Ansible - GitLab CI/CD · Jenkins - GitHub Actions · Nexus #### Cloud infrastructure - AWS · GCP - S3 · Lambda · EKS · IAM - GKE · Cloud SQL · GCS - Artifact Registry · Cloud Build & Deploy - WIF · Secret Manager - Cloud KMS · Pub/Sub · Cloudflare #### Software engineering - Go · Python · Bash · JavaScript - React · Next.js · Node.js · Express - Java · Spring · C++ - OpenAPI · gRPC - Schema validation · contract tests #### Security & reliability - Vault · ESO · Keycloak · mTLS · Kyverno - GitGuardian · Trivy - Prometheus · VictoriaMetrics - Grafana · ELK · OpenTelemetry - Tailscale · OPNsense #### ML & data infrastructure - Airflow · Slurm · JupyterHub · MLflow - PostgreSQL · Patroni · Redis - Kafka · RabbitMQ · Cassandra - MinIO · VectorDB · BigQuery #### Agent infrastructure & R&D - kagent · agentgateway - MCP · A2A · RAG - Temporal · Human-in-the-loop - LangChain · ADK - Codex · Claude Code · Gemini - vLLM · Langfuse ### Home Aeroponics & IoT automation Aug 2024 — Jan 2025 · Personal R&D · Moscow City, Russia - Designed and built an integrated aeroponic system: drew wiring schematics, soldered electronics, and connected ESP32, Arduino, Raspberry Pi, sensors and actuators. - Developed C++ sensor firmware and Python automation for climate control, mist generation, water supply and circulation, tank-to-tank transfers and leak detection. - Automated lighting and collected light-quality data to guide adjustments. Used computer vision to assess experimental results through changes in leaves. - Connected ESP and Zigbee devices through Mosquitto and Zigbee2MQTT using JSON over MQTT, with Home Assistant as the control, monitoring and alerting interface. - Automated Raspberry Pi setup with Ansible, prototyped pH, TDS and EC monitoring, and began preparing Prometheus metrics collection. Code: [Controllers](https://github.com/pilprod/aeroponics-iot-control) · [Sensor firmware](https://github.com/pilprod/aeroponics-sensor-firmware) ### Zero-Trust Mesh & Open-source NGFW Jan 2025 — Mar 2025 · Personal R&D · Bangkok City, Thailand - Built an encrypted, multi-region Tailscale lab mesh linking devices and private networks across cloud, bare metal and homelabs. - Automated network configuration and enabled one-click onboarding of new nodes. - Managed all mesh ACLs through GitOps, with distinct user and service-account permissions for DNS discovery and service access. - Tested OPNsense as an NGFW for subnet routing, network segmentation and traffic filtering. Code: [Ansible](https://github.com/pilprod/lab-network-automation) · [Access policy](https://github.com/pilprod/zero-trust-mesh-policy) · [GCP network lab](https://github.com/pilprod/gcp-ngfw-network-lab)