Infra thatstays up.

Google Cloud, Kubernetes and CI/CD, built so a small team can run them. I design it, ship it, and stay on call for it. Błażej Lubecki, Lead DevOps Engineer.

Live · my own hardware

-- uptime
connecting…

this page is served from a machine in my flat

blaze@homelab connecting

What your app really needs

02 / 06 the platform
Your application
the thing that makes you money

--

What I do

01

Google Cloud & GKE

Clusters, Cloud Run, Cloud Functions and networking, built so a small team can run them. Migrations off click-ops and legacy lift-and-shift, with a plan you can roll back. More about GKE →

02

CI/CD & platform

Pipelines, GitOps and release automation that make shipping routine. Build once, deploy anywhere, roll back fast, so a small team ships like a big one.

03

Infrastructure as code

Terraform or OpenTofu with Terragrunt, and Ansible, turning infrastructure into versioned, reviewed code. Reproducible environments, auditable changes, and nothing that exists only in someone's browser history. More about infrastructure as code →

04

Observability & on-call

Metrics, logs and alerts that stay quiet until something is genuinely wrong. SLOs you meet, and on-call that doesn't burn people out.

Recent work

Off Heroku, onto Google Cloud and Cloudflare

A B2B SaaS startup, February to July 2026. One engineer, about 600 hours, from an empty Google Cloud organization to production in two regions.

Along the way: a planned Apigee layer became Gateway API routing GKE already provides, and Kafka stayed out until there is a reason for it.

  • GKE
  • OpenTofu
  • Terragrunt
  • Argo CD
  • Cloudflare
  • Envoy
  1. Foundations

    Dev and prod on GKE, Cloud SQL and private networking, all in OpenTofu with Terragrunt. GitHub Actions builds, Argo CD deploys, and no workload holds a service-account key.

  2. Cutover

    Production moved off Heroku after hours, behind Cloudflare. Zero-downtime rolling deploys from then on, plus SOC 2 hardening: no public database, WAF rules, audit logging.

  3. Second region

    A Kubernetes cluster outside Google Cloud for Saudi data residency, on the same GitOps flow. Keyless through workload identity federation, with the origin locked to Cloudflare by mTLS.

  4. Backups

    Nightly database dumps into a segregated project with 30-day locked retention that only the owner can delete. It met the insurer's requirement.

  5. Reliability

    A production outage traced to a schema migration deadlocking live tables. Guardrails on the migration user and a deadlock alert, so it cannot come back quietly.

  6. Auth

    Authentication moved into an Envoy layer in front of the services. The SSO switchover took 19 minutes one evening, with a guarded rollback path.

Track record

~35%lower infra cost

Moving a bank's on-prem applications to GCP, redesigned cloud-native. HSBC.

~60%faster deploys

CI/CD rebuilt with security scanning and automated tests. HSBC.

10+delivery teams

Running on GCP foundations I engineered in Terraform and Ansible. HSBC.

PBscale on BigQuery

Data warehouse and data lake platforms for financial analytics. HSBC.

previously HSBC, InPost, Devoteam G Cloud certified Google Professional Cloud Architect, HashiCorp Terraform Associate

What an engagement looks like

  • GKE
  • GitOps
  • CI/CD

Platform foundations

Stand up a Kubernetes platform on GKE with GitOps and a real pipeline, so a small team ships daily instead of weekly, with a rollback path you have tested.

  • Google Cloud
  • IaC
  • Zero-downtime

Cloud migration & modernization

Move a system off legacy hosting to Google Cloud with a zero-downtime cutover plan, IaC from day one, and an escape hatch the whole way through. More about migrations →

  • SLOs
  • Alerting
  • FinOps

Reliability & cost

Add SLOs, alerting that pages a human only when needed, and right-size cloud spend so uptime climbs while the bill comes down, and you can prove both. More about cost reduction →

How we'd work together

  1. Audit

    You tell me what's running and where it hurts. I look at the real state and what it is costing you. No sales deck.

  2. Plan

    A short written proposal: what I'd change, in what order, and what it maps to in time and spend.

  3. Build

    Small, reviewable increments you can see and roll back. No big-bang cutovers, no surprises on the invoice.

  4. Own

    Handover and docs so your team can run it, with the option of me staying on call.

Stack

Let's build
something
that stays up.

Tell me what you're running on and where it hurts. I'll reply with how I'd tackle it. Concrete, no obligation, no jargon.

replywithin a day, usually sooner
hostedon my own homelab
scoperemote-first · GCP & platform