flerris
cat resume.mdRU

$ kubectl describe engineer flerris

Ruslan Solovyov.

DevOps engineer · Python backend developer

📍 Krasnodar, Russiaexperience: 3 years 7 monthsRemote · UTC+3Open to relocation abroadOpen to business tripsFull-time, part-time, projectsSelf-employed statusRussian citizen

✦About

DevOps engineer with hands-on experience building and running production infrastructure on Kubernetes. Main areas: container infrastructure, CI/CD, observability, security, networking and automation.

I work not only on the infrastructure side of a system but with the application code too: I build Python backends and understand how services, databases, queues and external APIs interact.

I prefer to automate repetitive operations, make infrastructure observable and reproducible, and dig into a problem across the whole chain — from the application and container to Kubernetes, the network and external infrastructure.

In my spare time I build EgressFox, an open-source Kubernetes operator in Go for adaptive outbound traffic routing.

⎈Experience

  1. DevOps engineer / Python backend developer

    November 2024 — present · 2 years

    INKVIZITOR.RF · Krasnodar · Taxi · internet services · software development

    16k+users
    3–4kactive
    3availability zones
    2 days → ~10 minrelease time
    • Develop and maintain the production infrastructure of several services on Cloud.ru.
    • Designed and deployed the project infrastructure on Managed Kubernetes; took part in reworking the application from a monolith and moving it to a new production environment.
    • Built CI/CD on GitLab CI/CD, Sonatype Nexus and ArgoCD: automated versioning, checks, Docker image builds, artifact publishing and deployment. Releases went from a manual process of up to two days to about 10 minutes.
    • Operate Kubernetes on Cloud.ru: ingress-nginx, cloud LoadBalancers, spreading services across nodes and three availability zones, autoscaling and zero-downtime deployments.
    • Set up secrets and access management: HashiCorp Vault, least privilege, Kubernetes NetworkPolicy and isolated VPN access to internal services.
    • Set up centralized observability: Grafana, Prometheus, Loki/Promtail, Zabbix and Uptime Kuma — logs, metrics, availability checks and alerting in one place.
    • Work with PostgreSQL, PgBouncer, Redis, ClickHouse and RabbitMQ; use S3-compatible object storage for data, logs and infrastructure artifacts.
    • Designed network connectivity between cloud and remote nodes with MikroTik CHR and WireGuard.
    • Build and maintain backend services and internal APIs in Python: FastAPI, Aiogram 3, Pydantic; implement integrations between services and external systems.
    KubernetesCloud.ruGitLab CI/CDArgoCDSonatype NexusHashiCorp VaultPrometheusGrafanaLokiPostgreSQLClickHouseRabbitMQMikroTikWireGuardPythonFastAPI
  2. Engineer

    April 2023 — present · 3 years 7 months

    Kuban State Technological University · Krasnodar · Higher education

    200+Astra Linux workstations
    hundredsof students and staff on the cluster
    • Design the infrastructure of a teaching Kubernetes cluster on Proxmox VE and Talos Linux for several hundred students and teachers.
    • Deployed and maintain virtualization on Proxmox VE with High Availability, Proxmox Backup Server and TrueNAS.
    • Administer Linux infrastructure and 200+ workstations on Astra Linux 1.7/1.8.
    • Automate software installation and configuration with Ansible; wrote and adapted playbooks for computer labs.
    • Administer server and network infrastructure, help configure MikroTik and troubleshoot network incidents.
    • Run the infrastructure for olympiads, exams and other events: servers, workstations, specialized software and network services.
    Proxmox VETalos LinuxKubernetesTrueNASProxmox Backup ServerAnsibleAstra LinuxMikroTik

◆Projects

  • EgressFox

    since September 2026

    Adaptive egress control plane for reliable outbound traffic · Author and maintainer · open source, Apache-2.0

    180+commits
    2engines: Mihomo and sing-box
    3Kubernetes versions in e2e

    An open-source project in Go: discovers external proxy gateways, checks their health per destination, keeps a history of observations and deterministically selects a stable working set. Renders and validates configuration for Mihomo and sing-box: they stay the data plane, EgressFox is the control plane.

    • Kubernetes operator on controller-runtime: ProxyPool and EgressGateway CRDs (egressfox.io/v1alpha1), a Helm chart, namespace-scoped RBAC and a managed, authenticated SOCKS5 gateway.
    • Adaptive Top-N selection without ML: a history window per endpoint revision and destination, hysteresis, cooldown and emergency replacement. An invalid configuration never displaces the last known good one.
    • Supply chain: linux/amd64 and arm64 builds, SPDX SBOMs (Syft), vulnerability gates (Grype), cosign image signing and provenance attestations.
    • envtest and e2e tests in kind on Kubernetes 1.32, 1.34 and 1.37; a threat model, and architecture decisions recorded in 20+ ADRs.
    GoKubernetes operatorcontroller-runtimeHelmMihomosing-boxSQLitekindGitHub ActionscosignSyftGrype

    egressfox.iocode: github.com/egressfox-io/egressfox

  • KubSTU Schedule

    4,000+users

    A timetable service for KubSTU students: an iOS app, a Telegram bot, a VK bot, a web interface and a single API. Backend in Python/FastAPI with PostgreSQL, Redis and Docker. The project gave me hands-on experience designing an application, backend services and APIs on my own, containerizing them and running a real user-facing product.

    PythonFastAPIPostgreSQLRedisDockeriOSTelegramVK

Resume updated: October 7, 2026 · ruslansoloviev.ru/en/cv