Senior infrastructure engineer with 10+ years building and operating production systems at scale — from architecture and IaC through observability, incident response, and mentoring across remote, globally distributed teams. I work the whole delivery path (application code → the pipelines that ship it → the infrastructure it runs on) with a security-first eye, and I like finding the sharp edge in a system and fixing it at the root.
- Modernizing legacy workloads into Dockerized services on Kubernetes / AWS EKS; Kubernetes in production since 2022.
- Read source, not just docs — Kubernetes
kubeletsecurity research (subPath traversal, authorization bypass,ImageVolume, Pod resource consistency). - Currently: modernizing
kubernetes-zfs-provisionertogether with its maintainer, and hunting reproducible bugs across CI/CD toolchains.
| Platform | AWS (EKS, IAM, RDS, Route53, CloudFront), Kubernetes, Helm, ArgoCD, Flux, Docker |
| Delivery & IaC | Terraform, Terragrunt, Ansible, GitHub Actions, GitLab CI, TeamCity, Jenkins |
| Observability & Security | Prometheus, Grafana, Loki, OpenTelemetry, OPA/Gatekeeper, FreeIPA, secrets management |
| Languages & Data | Go, Python, Bash, PHP, HCL, PostgreSQL, MySQL, Redis |
I fix real, reproducible bugs in the tools I run in production. Every patch starts from a failing reproduction and lands with a regression test and a root-cause writeup; the bug classes repeat across ecosystems, so the method carries across Go, PHP, Python and JS.
29 merged upstream pull requests across 14 projects — Kubernetes autoscaler, Argo Workflows & Argo CD, Symfony, Ansible, Spinnaker, goreleaser, Laravel, sigstore/cosign, PHP-CS-Fixer, iTerm2 and others → all merged PRs
- Security fix released in Symfony v8.1.4 — hardened the weak-secret guard in
Uuid47Transformerfor secrets longer than 16 bytes (#65105, release notes), one of four merged Symfony fixes - Kubernetes
autoscaler/addon-resizer— eliminated its reachable CVEs, fixedgo vet, and gave the subproject its first CI workflow (#10112-#10114) kubernetes-zfs-provisioner— modernizing it together with the maintainer: leader election moved to coordination Leases, the SSH shell wrappers replaced with a native Go SSH runner, and provisioning made production-safe with in-process volume expansion (5 merged PRs and counting)- Argo — fixed a
ParseProgresspanic in Workflows including the release-branch backports (#16537), and surfaced theSuspendedcondition for suspended Jobs in Argo CD (#28738) - Supply chain / release tooling — checksum validation of the TUF root of trust in
cosign initializerejected valid uppercase digests (#5036); unanchoredgoarm64validation in goreleaser (#6727)
Numbers as of August 2026; the search link above is live.
- helmtide — a maintained fork of helmwave: helm3-native release management with current dependencies and tests that don't need a live cluster.
- ansible-secops-linter — security-focused static analysis for Ansible: hardcoded secrets, disabled TLS/host-key checks, missing
no_log, world-writable modes. - mr-rca-toolkit — infrastructure merge review and incident RCA utilities.
Best reached via sannikov.dev


