$ kubectl describe engineer flerris
Ruslan Solovyov.
DevOps engineer · Python backend developer
✦About
DevOps engineer with hands-on experience building and running production infrastructure on Kubernetes. Main areas: container infrastructure, CI/CD, observability, security, networking and automation.
I work not only on the infrastructure side of a system but with the application code too: I build Python backends and understand how services, databases, queues and external APIs interact.
I prefer to automate repetitive operations, make infrastructure observable and reproducible, and dig into a problem across the whole chain — from the application and container to Kubernetes, the network and external infrastructure.
In my spare time I build EgressFox, an open-source Kubernetes operator in Go for adaptive outbound traffic routing.
⎈Experience
DevOps engineer / Python backend developer
November 2024 — present · 2 yearsINKVIZITOR.RF · Krasnodar · Taxi · internet services · software development
16k+users3–4kactive3availability zones2 days → ~10 minrelease time- Develop and maintain the production infrastructure of several services on Cloud.ru.
- Designed and deployed the project infrastructure on Managed Kubernetes; took part in reworking the application from a monolith and moving it to a new production environment.
- Built CI/CD on GitLab CI/CD, Sonatype Nexus and ArgoCD: automated versioning, checks, Docker image builds, artifact publishing and deployment. Releases went from a manual process of up to two days to about 10 minutes.
- Operate Kubernetes on Cloud.ru: ingress-nginx, cloud LoadBalancers, spreading services across nodes and three availability zones, autoscaling and zero-downtime deployments.
- Set up secrets and access management: HashiCorp Vault, least privilege, Kubernetes NetworkPolicy and isolated VPN access to internal services.
- Set up centralized observability: Grafana, Prometheus, Loki/Promtail, Zabbix and Uptime Kuma — logs, metrics, availability checks and alerting in one place.
- Work with PostgreSQL, PgBouncer, Redis, ClickHouse and RabbitMQ; use S3-compatible object storage for data, logs and infrastructure artifacts.
- Designed network connectivity between cloud and remote nodes with MikroTik CHR and WireGuard.
- Build and maintain backend services and internal APIs in Python: FastAPI, Aiogram 3, Pydantic; implement integrations between services and external systems.
KubernetesCloud.ruGitLab CI/CDArgoCDSonatype NexusHashiCorp VaultPrometheusGrafanaLokiPostgreSQLClickHouseRabbitMQMikroTikWireGuardPythonFastAPIEngineer
April 2023 — present · 3 years 7 monthsKuban State Technological University · Krasnodar · Higher education
200+Astra Linux workstationshundredsof students and staff on the cluster- Design the infrastructure of a teaching Kubernetes cluster on Proxmox VE and Talos Linux for several hundred students and teachers.
- Deployed and maintain virtualization on Proxmox VE with High Availability, Proxmox Backup Server and TrueNAS.
- Administer Linux infrastructure and 200+ workstations on Astra Linux 1.7/1.8.
- Automate software installation and configuration with Ansible; wrote and adapted playbooks for computer labs.
- Administer server and network infrastructure, help configure MikroTik and troubleshoot network incidents.
- Run the infrastructure for olympiads, exams and other events: servers, workstations, specialized software and network services.
Proxmox VETalos LinuxKubernetesTrueNASProxmox Backup ServerAnsibleAstra LinuxMikroTik
◆Projects
EgressFox
since September 2026Adaptive egress control plane for reliable outbound traffic · Author and maintainer · open source, Apache-2.0
180+commits2engines: Mihomo and sing-box3Kubernetes versions in e2eAn open-source project in Go: discovers external proxy gateways, checks their health per destination, keeps a history of observations and deterministically selects a stable working set. Renders and validates configuration for Mihomo and sing-box: they stay the data plane, EgressFox is the control plane.
- Kubernetes operator on controller-runtime: ProxyPool and EgressGateway CRDs (egressfox.io/v1alpha1), a Helm chart, namespace-scoped RBAC and a managed, authenticated SOCKS5 gateway.
- Adaptive Top-N selection without ML: a history window per endpoint revision and destination, hysteresis, cooldown and emergency replacement. An invalid configuration never displaces the last known good one.
- Supply chain: linux/amd64 and arm64 builds, SPDX SBOMs (Syft), vulnerability gates (Grype), cosign image signing and provenance attestations.
- envtest and e2e tests in kind on Kubernetes 1.32, 1.34 and 1.37; a threat model, and architecture decisions recorded in 20+ ADRs.
GoKubernetes operatorcontroller-runtimeHelmMihomosing-boxSQLitekindGitHub ActionscosignSyftGrypeKubSTU Schedule
4,000+usersA timetable service for KubSTU students: an iOS app, a Telegram bot, a VK bot, a web interface and a single API. Backend in Python/FastAPI with PostgreSQL, Redis and Docker. The project gave me hands-on experience designing an application, backend services and APIs on my own, containerizing them and running a real user-facing product.
PythonFastAPIPostgreSQLRedisDockeriOSTelegramVK
Resume updated: October 7, 2026 · ruslansoloviev.ru/en/cv