nadtoka.dev

Senior DevOps • Platform • Reliability

Oleksandr Nadtoka

Oleksandr Nadtoka

I help teams ship faster and keep production stable: CI/CD, Terraform, cloud infrastructure, observability and pragmatic security.

  • CI/CD
  • Terraform
  • Cloud (AWS/GCP/OpenStack)
  • Prometheus/Grafana
  • Security baseline

Let's Build Something Reliable. Available for:

  • Rapid Infrastructure & Cost Audit (1–3 days) — Quick stack verification to uncover hidden tech debt, reduce cloud spend, and align your tech roadmap.
  • Core Implementation Workloads — End-to-end deployment of production-grade container clusters (Kubernetes/Swarm), Terraform baselines, and HashiCorp Vault security layers.
  • Ongoing Production Governance — Continuous SLA-driven maintenance, reliable disaster recovery drills, and modern monitoring that surfaces signals over noise.

Remote services • Kyiv, Ukraine • Small-to-mid projects • Clear runbooks and handover

Security & Reliability
Ops pulse
Provider updates + market snapshot (cached)
Loading…
Security headers
Quick snapshot of HTTPS response headers.
$ curl -I https://nadtoka.dev
HTTP/2 200
strict-transport-security: max-age=31536000
content-security-policy: default-src 'self' ...
x-content-type-options: nosniff
x-frame-options: DENY
Visitor diagnostics
Read-only snapshot of what your browser sends.
Loading…

Services

Practical DevOps services focused on uptime, delivery speed, and cost control.

CI/CD & Release Engineering

Fast, reliable releases with predictable pipelines and secure container supply chains.

  • GitHub Actions / GitLab CI pipelines (build, test, deploy).
  • Reusable templates, intelligent caching & parallelism.
  • Self-hosted runners setup, scaling, and troubleshooting.
  • Secure delivery: least-privilege configurations + strict secrets hygiene.

Infrastructure as Code (Terraform)

Reproducible environments with safe, reviewable changes.

  • Terraform modules, remote state management, and environment isolation patterns.
  • Provisioning automation: strict plan → review → apply workflows.
  • Drift control, state recovery, and infrastructure lifecycle governance.
  • Network segregation, IAM roles, and security group baselines.

Managed Infrastructure (Cloud + Hybrid)

Ongoing maintenance and production stability for small-to-mid projects.

  • AWS / GCP / OpenStack (Open Telekom Cloud) production environments.
  • Hybrid datacenter-cloud setups matching local office/on-prem nodes with clear runbooks.
  • OS upgrades, kernel patching, capacity management, and incident response.
  • Predictable infrastructure updates with minimal production drama.

Observability (VictoriaMetrics & Grafana)

Actionable metrics, dashboards, and alert routing where signal outweighs noise.

  • High-throughput time-series storage using VictoriaMetrics as a drop-in Prometheus replacement.
  • Custom Grafana dashboards pre-provisioned for Node Exporter, cAdvisor, and DB engines.
  • SLO-aware, pragmatic alerting via Alertmanager (integrated with DevOps mail/Telegram).
  • Log aggregation using Loki paired with explicit disaster triage playbooks.

Security & Networking Baseline

Reasonable security by default — securing assets without blocking active delivery.

  • IAM / RBAC audit, resource governance, and access control policies.
  • Secure gateways (pfSense), HAProxy-based routing, and automated TLS/SSL.
  • VPN / IPsec site-to-site tunnels interconnecting multi-cloud and office networks.
  • Centralized access control patterns (LDAP integration and HashiCorp Vault implementation).

Backups & Disaster Recovery

No-surprises recovery procedures for core applications and data layers.

  • Multi-tiered storage backup architecture (AWS S3, restic, Proxmox Backup Server).
  • Point-in-time recovery strategy and database replication patterns.
  • Documented DR playbooks, recovery path drills, and clear RPO/RTO planning.

MLOps & Local AI Infrastructure

Deploying, monitoring, and managing the full lifecycle of open-source models and pipelines.

  • Continuous training (CT) infrastructure, feature engineering engines, and automated MLOps pipelines.
  • Private, secure local LLM inference setups (Ollama, LM Studio) on bare-metal or hybrid mini PC hardware.
  • Automated dataset and model synchronization using the Hugging Face Hub registry.
  • Testing and deployment configurations for models like Llama 3.x, Qwen, and DeepSeek-R1.

Containers (pragmatic)

Docker, Swarm, or Kubernetes — selected strictly based on your actual workload complexity and budget limitations.

  • Advanced containerization, multi-stage builds, and Docker Compose/Swarm architecture.
  • Practical Kubernetes platform deployments when structural scaling or high availability demands it.
  • Secure container tracking with local Harbor registry deployments and automated replication to cloud registries (AWS ECR).
  • Automated GitOps continuous delivery workflows utilizing ArgoCD and production Helm charts.

The Engagement Standards (What you get)

Delivery Workflows

  • PR-Driven Infrastructure — Every single modification is executed via clean Pull Requests with structured code reviews, avoiding ad-hoc console changes and tracking infrastructure changes explicitly in Git.
  • Guaranteed Rollback Engineering — Zero blind deployments. Every architectural shift, environment migration, or pipeline change comes with a pre-engineered, fully verified rollback path.
  • High-Signal Observability — Dashboards, log routing, and active alerting are meticulously tuned around actual SLOs to eliminate alert fatigue and ensure actionable metrics outweigh background noise.

Handover & Long-Term Ownership

  • Production-Grade Runbooks — Exhaustive day-2 operational documentation covering internal environment states, edge cases, and explicit step-by-step troubleshooting playbooks.
  • Dedicated Handover Briefings — Structured interactive walkthrough calls with your internal development or engineering team to guarantee absolute operational confidence during the ownership transfer.
  • Strict Secrets & State Hygiene — Complete, secure handover of cryptographic variables, deployment credentials, and Terraform state logs aligned with strict least-privilege principles.

Results

Experience
15+ years

DevOps, platform and reliability leadership across multiple domains.

Automation
−70% provisioning time

Achieved through workflow automation (IaC + configuration + pipelines).

Cloud cost
−30–40% cost reduction

Optimization and environment automation (especially non-prod).

Freelance track record
120+ projects • 8,000+ hours

Remote delivery for clients worldwide (small-to-enterprise).

Approach

Calm ops, predictable changes: read-only first, small blast radius, rollback always.

1

Triage (read-only first)

Quick read-only diagnostics and identify the top 1–2 risks.

2

Plan + rollback

Small change plan, blast radius, rollback steps, success criteria.

3

Implement via PRs

Reviewable changes in Git, automation-first, predictable deployments.

4

Operate + handover

Dashboards, alerts, runbooks, and calm day-2 operations.

Selected cases

A few examples of production work.

Ticket → CI/CD → Terraform automation

Automated provisioning with Jira ↔ GitLab CI ↔ Terraform ↔ configuration workflows.

  • Infrastructure lifecycle controlled by ticket status
  • Dynamic parameters (versions, IPs, tags)
  • Result: faster provisioning and fewer manual errors

Centralized Identity & Access (LDAP + Replication)

Single source of truth for internal authentication across cloud and office infrastructure.

  • Primary LDAP in cloud + office replica for local availability
  • LDAP auth for office Wi-Fi and Linux workstation logins
  • LDAP auth for HashiCorp Vault and SSH access to dev servers
  • Outcome: centralized access control and cleaner offboarding

Self-hosted ActiveCollab on Kubernetes

ActiveCollab in Kubernetes with MySQL + Elasticsearch + PHP-FPM + NGINX.

  • Persistent storage and health checks
  • CI/CD delivery pipeline
  • Production-grade maintainability

Office Virtualization Platform (Proxmox VE)

Built a secure virtualization baseline for an office server.

  • Storage + networking baseline (segmentation, templates)
  • RBAC roles and least-privilege access
  • Multi-VM dev/test platform with templates
  • Result: scalable layout and simpler admin

On-prem Observability Stack (Prometheus/VictoriaMetrics + Grafana + Alertmanager)

Developed a centralized monitoring architecture featuring VictoriaMetrics (as a high-performance drop-in Prometheus replacement), Grafana, and Alertmanager across distributed server nodes.

  • Coverage across 5 servers (LB, DB, core, maintenance, services)
  • IaC via Terraform + repeatable builds (Chef Kitchen)
  • Dashboards for Node Exporter, Blackbox, cAdvisor, PostgreSQL
  • Alert routing with clear ownership
  • Result: reliable visibility and faster triage

Cloud Security Gateway (pfSense + VPN + Reverse Proxy)

Hardened perimeter for cloud workloads.

  • VPN-only administrative access with restricted policies
  • HAProxy TLS termination and routing policies
  • IDS/IPS baseline with tuned rules
  • Result: reduced attack surface and safer access

Centralized Identity & SSH Access Management

Designed a secure, centralized authentication system using HashiCorp Vault and LDAP to eliminate static credentials.

  • Configured HashiCorp Vault to act as a Certificate Authority (CA) for dynamic SSH key signing, mitigating long-lived key risks.
  • Integrated LDAP to deliver unified role-based access control (RBAC) across distributed Linux environments, OpenVPN, and XRDP.

Automated MLOps & Asset Modeling Pipeline

Continuous training (CT) pipeline deployed on a self-hosted Proxmox environment for predictive asset modeling.

  • Built an ingestion engine tracking 5-year rolling windows with 14 concurrent parameters (including S&P 500 macro returns, VIX, and RSI-14 indicators).
  • Implemented an isolated training strategy using hyperparameter-tuned Random Forest ensembles and strict time-series normalization.
  • Automated artifact versioning via Hugging Face Hub (Model Registry & Datasets) and integrated real-time report delivery via Telegram Bot API.

Local AI & LLM Lab Deployment

Private hybrid environment built on bare-metal and mini PC hardware for secure model inference and agent testing.

  • Configured an Ubuntu VM on a private bare-metal office server for CPU-based LLM inference and agentic workflows.
  • Deployed LM Studio on a Windows 11 mini PC with hybrid CPU/GPU offload for accelerated testing.
  • Evaluated multiple open-source models, including Llama 3.1, Qwen 2.5, and DeepSeek-R1.

Contact

The easiest way to reach me is email or LinkedIn.

Email

alex.nadtoka@gmail.com

Prefer a short context: company, tech stack, what’s broken, and urgency.

Links

Security contact: security.txt

How to start

  1. Send a short context: your stack, what’s broken, urgency, and constraints.
  2. We’ll review diagnostics and align on a minimal plan with rollback.
  3. Implementation via PRs with clear handover and runbooks.