About
I build and run container platforms on bare metal, mostly for telco infrastructure. Fifteen years in IT, the last eight on Kubernetes and OpenShift, the last five at telco scale across eight datacentres.
I’m most useful where the platform is the hard part: bare-metal OpenShift, multi-cluster GitOps, software-defined storage, and migrations that can’t take downtime.
Availability
Open to remote contract and permanent roles. Based in Brussels (CET/CEST). Dutch (native) · English · French · German (basic)
Reach me at nino@taiki.be.
Current work
Senior infrastructure engineer at a telecom carrier, since 2020. The estate is 8+ datacentres globally, 400+ HPE bare-metal servers, 1500+ VMs, RHEL 7 through 10, and nine OpenShift clusters.
Four pieces of it written up properly:
- VMware to OpenShift Virtualization — 2,500 VMs, array-side data movement, automated guest preparation. The Forklift xcopy patches came out of it.
- Two-site Ceph object storage — RHCS 8, RGW multisite replication, and the monitoring that was missing.
- Vault Enterprise: HSM-rooted seal and DR replication — hardware key custody, and why we bought disaster recovery replication but not performance replication.
- Ansible Tower to AWX, twice — licence economics, then a platform standard set elsewhere, then the team changed shape and the original argument expired.
The rest of the day job: bare-metal and hybrid OpenShift, agent-based install, A-to-Z architecture of the cluster stack; dedicated multi-site management clusters, day-0 agent-assisted install with day-1/2 via FluxCD, local ODF plus SAN; ArgoCD and FluxCD across the estate, consolidating onto FluxCD; Vault multi-site with KV, JWT and Kubernetes auth; FreeIPA and Keycloak with Kerberos trust and SSO; Ansible, Terraform and Packer across day 0/1/2; self-managed GitLab CI with runners on OpenShift.
Also in the estate: Rancher and RKE2, StackGres PostgreSQL HA, Prometheus / Alertmanager / Grafana, BIND9 hidden-master with FreeIPA zone transfer, F5 LTM, a KMIP-to-AWS-KMS proxy, an in-house Django provisioning app, and iTop / NetBox / Sirius CMDBs.
Before that
Telenet (2020) — RHEL/CentOS estate across 4 datacentres, RHEL 5/6/7→8 migration planning, Satellite/Foreman, and 2PB of SUSE Ceph including a vendor migration and a Nautilus→Octopus upgrade.
Stepstone (2019–2020) — AWS infrastructure for the Search and Match team. Nginx/OpenResty load balancing with Lua, Kafka, InfluxDB, Grafana.
MLOZ-IT (2018–2019) — first OpenShift work: 3.9 through 3.11 cluster deployment and management, alongside WebSphere and IBM Integration Bus.
Proximedia / Publicis (2017–2018) — vSphere estate, Ceph-backed Elasticsearch, Puppet and MCollective, pfSense, SSO.
Earlier: systems support and web development. I came into infrastructure sideways — social-cultural work, then Drupal and PHP, then Linux.
Depth
Expert-level, day to day: Linux, Kubernetes, OpenShift, Ansible, Ceph and software-defined storage, VMware vSphere, HAProxy/keepalived, Bash.
Strong: ArgoCD, Terraform, Packer, Docker, PostgreSQL, Nginx, Python, LDAP/FreeIPA, Keycloak, KVM, SAN/NAS, firewalls, packet analysis.
Outside work
Member of Hackerspace Brussels. I run a self-hosted service estate — federated chat and ~60 services on a single host — and contribute to mainline Linux for ARM64 Qualcomm laptop platforms.