Buğra Gökçek
DevOps, SRE & System Specialist
CKAD Certified · 85%
I build, run, and harden production Kubernetes platforms — from bare-metal hypervisors up to release pipelines. Currently working remotely with Alpata Yazılım ve Teknoloji and OCTAPULL.
About
I'm a DevOps, SRE & system specialist working remotely from Türkiye, currently at Alpata Yazılım ve Teknoloji and OCTAPULL. My day-to-day focus is running reliable Kubernetes workloads in production — operating multi-tenant clusters, authoring Helm-based deployments, designing CI/CD pipelines (GitLab CI → GitHub Actions migrations with self-hosted runners, Nexus/Harbor registries, ArgoCD), and stabilizing real-time media infrastructure (LiveKit SFU, HAProxy, nginx, Redis) under live traffic. Most recently I designed and delivered a from-scratch HA production cluster on RKE2 with Traefik + Gateway API and migrated 200+ applications onto it with a NAT-swap cutover.
I also work hands-on at the hypervisor and bare-metal layer. Greenfield on-premises rollouts on Proxmox and VMware vSphere — full lifecycle from rack-up and provisioning, OS installation (Linux and Windows), network and firewall configuration, TLS/certificate management, observability (Prometheus, Grafana, Graylog), and backup/DR with Ceph. Comfortable owning the stack end-to-end: Kubernetes on top, Linux/Windows VMs in the middle, hypervisors at the bottom.
Day-to-day stack: Kubernetes (RKE2, microk8s), Traefik & Gateway API, Helm, Kustomize, ArgoCD, Docker, GitHub Actions, GitLab CI, Nexus, Harbor, HAProxy/keepalived, Kafka, RabbitMQ, MSSQL, ClickHouse, Graylog, Prometheus/Grafana, Proxmox, VMware vSphere, Ceph, Linux & Windows Server administration, and hybrid AWS + on-prem. Linux Foundation CKAD (Certified Kubernetes Application Developer, 85%) holder.
I care about systems that stay healthy on their own. When something does break, I dig to the root cause — not just until the alert clears.
What I do
-
Hypervisor & On-Prem Infrastructure
Greenfield rollouts on Proxmox and VMware vSphere — VM provisioning, OS install (Linux, Windows), networking, firewall, TLS/certs, capacity planning, lifecycle.
-
Kubernetes Platform
Production cluster operations — Helm charts, ingress, configmaps, secrets, persistent storage, rolling releases. Docker Compose where it fits.
-
CI/CD & Release Engineering
GitHub Actions, GitLab CI, self-hosted runners, Nexus private registry. Image build, sign, push and Kubernetes deploy flows. GitLab → GitHub Actions migrations.
-
Reliability & Observability
Prometheus, Grafana, Graylog. Production incident response — debugging to the root cause, not until the alert clears. Real-time media hardening (SFU, TURN, HAProxy, Redis Sentinel).
Experience
-
DevOps & System Specialist
Alpata Yazılım ve TeknolojiSole owner of production infrastructure for a multi-tenant .NET/Kubernetes platform serving 20+ customer environments (commodity exchanges, manufacturing, aviation) — on-premises, hybrid cloud and Windows/IIS estates. Selected work:
- Re-platformed production Kubernetes (Sept 2026): designed and built a new HA cluster on RKE2 — 3 masters + 3 workers + 2 HAProxy/keepalived load balancers + NFS, sized from a year of Zabbix telemetry (58 vCPU / 236 GB RAM). Replaced host-nginx + NodePort with Traefik + Gateway API (HTTPRoutes), cert-manager wildcard TLS and Cloudflare Full (strict). Converted the live state of 200+ applications across 9 namespaces with a custom manifest converter, rehearsed on a 6-VM Proxmox lab with chaos/failover drills (measured 1–4 s VIP failover), migrated 2.47 TB via rsync pull and cut over with a NAT swap for a one-step rollback. Post-cutover Traefik tuning (gzip at entrypoint, 3 replicas, anti-affinity) cut page payloads by 77%.
- CI/CD & artifact infrastructure: migrated pipelines from GitLab CI to GitHub Actions on a fleet of self-hosted runners; private Nexus and Harbor registries; ArgoCD GitOps for newer services; .NET 10 base-image upgrades. Stood up a hardened self-hosted GitLab on Proxmox (Omnibus, DNS-01 Let's Encrypt, ufw, AD DNS) to replace an externally hosted instance.
- Incident forensics & recovery: root-caused a company-wide NuGet outage to an accidental storage wipe via shell-history forensics, recovered 419 package versions from developer caches and introduced a hybrid Package Source Mapping strategy. Repaired a failed VMware ESXi 7 boot device while preserving the VMFS datastore (zero VM data loss); recovered production MSSQL databases from provider VM snapshots via isolated clone VMs.
- Observability: designed and deployed an isolated monitoring host — ClickHouse, Graylog (MongoDB + OpenSearch), Prometheus, Grafana, Alloy and Tempo — after evaluating and cutting Mimir, Loki and OpenObserve; kept existing dashboards working unchanged by aliasing datasource UIDs.
- Messaging, data & real-time: Kafka (KRaft, 3 brokers), RabbitMQ, Redis and Supabase self-hosted on Kubernetes; MSSQL/MongoDB provisioning, cross-server backup/restore and daily DB sync; LiveKit SFU + Whisper transcription with region-split Redis (TR/Gulf); Ocelot API gateway routing for 20+ microservices.
- Windows & hypervisor ops: IIS + SQL Server 2025 server migrations for customer sites, Proxmox/ESXi VM lifecycle (Ceph → local NVMe ZFS migrations, iLO firmware, LVM online extends), FortiGate policies, VPN and AD administration.
- Platform hygiene: moved legacy crontab jobs into Kubernetes CronJobs with Kustomize and Sealed Secrets; NFS-backed PVCs replacing hostPath; Headlamp RBAC for developers; automated Hipcall call-recording sync (33k records) and an OSRM routing dataset for Türkiye.
-
DevOps & System Specialist
OCTAPULLProduction operations and platform engineering for OctaMeet (real-time video conferencing) and OctaPull SFA (mobile field-sales) deployed on Kubernetes. Owning the release cycle, observability, load-balancing (nginx, HAProxy) and TLS/certificate lifecycle. Hardening the real-time media path (SFU, TURN, Redis Sentinel) and the cluster ingress layer for stability under live traffic. Working across multiple environments with cross-cluster image and data flows.
-
DevOps & System Specialist
KloudserWorked across DevOps engineering and system administration, building hybrid infrastructure on on-prem, hybrid, and AWS environments. Administered Proxmox virtualization, Linux (Ubuntu, Debian, Kali) and Windows VMs, NAS storage and physical servers, OPNsense firewalls.
Designed and deployed scalable architectures on AWS (EC2, S3, IAM, DynamoDB, SQS, Lambda, API Gateway, Cognito). Set up GitLab CI/CD pipelines, self-hosted runners, Nexus Repository Manager. Containerized workloads with Docker, Docker Compose, Kubernetes. Worked with Android Cuttlefish emulator + MITMProxy for traffic analysis. MinIO and Keycloak as on-prem S3/IAM equivalents.
-
DevOps & System Specialist
OCTAPULLManaged critical infrastructure projects with a focus on scalability and high availability. Led production environment migrations, on-prem deployments, and designed test environments with Kubernetes, Docker, Docker Compose and Nginx load balancing.
Built observability with Zabbix, Prometheus, and Grafana — including custom dashboards integrated with Jitsi-based video conferencing data. Deep Linux administration, systemd, Bash automation.
-
Intern Software Engineer
Anadolu UniversityAWS EC2 provisioning, secure remote access (SSH, RSA Key-Pairs, Elastic IP). Bash scripting: recursive directory size, tar backup utility, public IPv4 tracking, curl-based REST API automation.
-
Intern Software Engineer
KONNEKA Information and Communication TechnologiesLinux (Ubuntu) administration with Netplan networking. Contributed to an enterprise Sandbox security product by refactoring/localizing Python backend scripts. Researched Android malware families (Cerberus, Golden Cup, Defensor ID) with static/dynamic analysis.
-
Intern Computer Technician
Turkish Republic State Railways (TCDD A.Ş.)First-tier IT support, peripheral hardware diagnosis. Digitized HR records into Excel and enterprise systems with careful data handling.
Education
-
Karadeniz Technical University
Software Engineering — Bachelor's -
Gazi Vocational and Technical High School
Information Technologies
Certifications
-
CNCFCertified Kubernetes Application Developer (CKAD) 85%Hands-on certification covering application design, deployment, observability, and configuration on Kubernetes — pods, deployments, services, ingress, configmaps/secrets, probes, and resource management. -
Linux FoundationIntroduction to GitOps (LFS169)GitOps principles and workflows — Git as the single source of truth for declarative infrastructure and application delivery pipelines. -
Linux FoundationIntroduction to Linux (LFS101)Linux command-line, filesystem hierarchy, user and permission management, essential system administration. -
Linux FoundationIntroduction to Kubernetes (LFS158)Core Kubernetes concepts — cluster architecture, workloads, services, storage, container orchestration at scale. -
BTK AcademyDocker FundamentalsDocker installation, container testing and deployment, container security topics. -
BTK AcademyLinux OS in Cyber SecurityLinux security fundamentals and shell programming for security workflows. -
BTK AcademyVersion Controls: Git and GitHubGit version control and GitHub workflows for software development. -
BTK AcademyRust Programming LanguageSafe, concurrent systems programming in Rust — fast web development and multi-core utilization.
Portfolio
Open-source playgrounds and tooling. Production work is documented under Experience.
More on github.com/bugra-gokcek ↗
Contact
Open to interesting conversations — drop a line.

