Platform foundations
Stand up a Kubernetes platform on GKE with GitOps and a real pipeline, so a small team ships daily instead of weekly, with a rollback path you have tested.
Google Cloud, Kubernetes and CI/CD, built so a small team can run them. I design it, ship it, and stay on call for it. Błażej Lubecki, Lead DevOps Engineer.
Live · my own hardware
this page is served from a machine in my flat
Clusters, Cloud Run, Cloud Functions and networking, built so a small team can run them. Migrations off click-ops and legacy lift-and-shift, with a plan you can roll back. More about GKE →
Pipelines, GitOps and release automation that make shipping routine. Build once, deploy anywhere, roll back fast, so a small team ships like a big one.
Terraform or OpenTofu with Terragrunt, and Ansible, turning infrastructure into versioned, reviewed code. Reproducible environments, auditable changes, and nothing that exists only in someone's browser history. More about infrastructure as code →
Metrics, logs and alerts that stay quiet until something is genuinely wrong. SLOs you meet, and on-call that doesn't burn people out.
A B2B SaaS startup, February to July 2026. One engineer, about 600 hours, from an empty Google Cloud organization to production in two regions.
Along the way: a planned Apigee layer became Gateway API routing GKE already provides, and Kafka stayed out until there is a reason for it.
Dev and prod on GKE, Cloud SQL and private networking, all in OpenTofu with Terragrunt. GitHub Actions builds, Argo CD deploys, and no workload holds a service-account key.
Production moved off Heroku after hours, behind Cloudflare. Zero-downtime rolling deploys from then on, plus SOC 2 hardening: no public database, WAF rules, audit logging.
A Kubernetes cluster outside Google Cloud for Saudi data residency, on the same GitOps flow. Keyless through workload identity federation, with the origin locked to Cloudflare by mTLS.
Nightly database dumps into a segregated project with 30-day locked retention that only the owner can delete. It met the insurer's requirement.
A production outage traced to a schema migration deadlocking live tables. Guardrails on the migration user and a deadlock alert, so it cannot come back quietly.
Authentication moved into an Envoy layer in front of the services. The SSO switchover took 19 minutes one evening, with a guarded rollback path.
Moving a bank's on-prem applications to GCP, redesigned cloud-native. HSBC.
CI/CD rebuilt with security scanning and automated tests. HSBC.
Running on GCP foundations I engineered in Terraform and Ansible. HSBC.
Data warehouse and data lake platforms for financial analytics. HSBC.
Stand up a Kubernetes platform on GKE with GitOps and a real pipeline, so a small team ships daily instead of weekly, with a rollback path you have tested.
Move a system off legacy hosting to Google Cloud with a zero-downtime cutover plan, IaC from day one, and an escape hatch the whole way through. More about migrations →
Add SLOs, alerting that pages a human only when needed, and right-size cloud spend so uptime climbs while the bill comes down, and you can prove both. More about cost reduction →
You tell me what's running and where it hurts. I look at the real state and what it is costing you. No sales deck.
A short written proposal: what I'd change, in what order, and what it maps to in time and spend.
Small, reviewable increments you can see and roll back. No big-bang cutovers, no surprises on the invoice.
Handover and docs so your team can run it, with the option of me staying on call.
Tell me what you're running on and where it hurts. I'll reply with how I'd tackle it. Concrete, no obligation, no jargon.