Senior DevOps & Platform Infrastructure Engineer
I build the infrastructure
cities run on.
And I build it sovereign — infrastructure you own, open source end to end, with no hyperscaler dependency and no proprietary lock-in.
Owned, bare-metal infrastructure · Linux + Kubernetes + GitOps · 100,000+ IoT sensors in production · zero vendor lock-in
I'm Belhadj Kessas. I design and operate digital infrastructure that organizations truly own — Linux, Kubernetes and GitOps on bare metal they control, open source from the kernel up. The flagship proof: one of France's largest municipal Smart City deployments, at Montpellier Méditerranée Métropole, serving 500,000+ citizens — 100,000+ IoT sensors in production across air quality, waste management, water and energy metering, and mobility. Not a pilot, not a demo. A live city, running on infrastructure it owns.
Montpellier, France · CKA — Certified Kubernetes Administrator, in progress (CNCF, 2026)
Owned, not rented
Migrated off the cloud, onto infrastructure we own
I moved this platform off managed cloud — from Docker containers on rented VMs to a fully on-premise, GitOps-driven multi-cluster architecture the organization owns outright. A deliberate sovereignty decision: the data lives on infrastructure we control, every change is auditable in Git, and the entire stack is open source, from the Linux kernel up.
Today it's four bare-metal Kubernetes clusters with every layer declared in Git. A git push triggers a self-hosted runner that calls the hypervisor API and stands up a complete cluster — RKE2, Cilium, MetalLB, ArgoCD — with zero manual steps. Destroy it, push again, get an identical one back.
No hyperscaler dependency. No proprietary lock-in. Infrastructure you own, can audit, and can operate without me.
$ git push origin main → self-hosted runner picks up the pipeline → hypervisor API provisions bare-metal VMs → RKE2 bootstraps the cluster → Cilium · MetalLB · ArgoCD roll out ✓ complete cluster — 0 manual steps
Edge to cloud
One platform, sensor to dashboard
Shipped 2026
Observability with its own cluster
In 2026 I shipped a centralized, multi-tenant observability platform on a dedicated three-node cluster: Mimir for long-term metrics and Loki for logs, both backed by Rook-Ceph S3 object storage. Grafana Alloy collectors on production and pre-production remote-write into it, separated into three isolated tenants — production, pre-production, and the monitoring cluster watching itself. One Grafana federates every data source.
Provisioned the same way as everything else — OpenTofu → Ansible → GitLab CI → RKE2 → ArgoCD — and fed by real production traffic from 100,000+ sensors.
The architectural point is separation of concerns: the observability substrate lives on its own cluster, so losing a monitored cluster never means losing the ability to see it.
What I master
Depth where it counts
Kubernetes & platform engineering
RKE2/Rancher multi-cluster on bare metal — production on VMware vSphere, pre-production on Proxmox. No managed control plane, no cloud dependency. MetalLB, Rook-Ceph, Cilium (eBPF), Envoy Gateway, Helm.
CKA in progress — CNCF, expected 2026
GitOps & infrastructure as code
ArgoCD, GitLab CI/CD, OpenTofu, Terraform, Ansible. Full lifecycle as code: cluster provisioning, app rollout, drift detection, environment promotion. Built a self-service platform where external partners deploy via Git without ever touching cluster internals.
Owned, auditable, hyperscaler-free
Large-scale IoT & networking
End-to-end LoRaWAN at city scale: RF planning, gateway deployment, VLAN segmentation, a multi-tenant LoRaWAN network server on Kubernetes. Automated device provisioning and OTA updates for a 100k+ fleet. Edge-to-cloud pipelines that survive partial outages.
Observability & SRE
Designed a dual-layer telemetry stack from zero — Zabbix outside the clusters; a centralized multi-tenant Mimir + Loki platform with Grafana Alloy collectors inside, on its own dedicated cluster. Proactive degradation thresholds, not post-failure alarms.
Detection in minutes, not days
Programming & emerging
Python (Django), Rust, Bash. Computer vision on the GPU edge lab: YOLO inference experiments on a Jetson Orin cluster, GPU-aware Kubernetes scheduling. Prototyping on-prem Kubeflow for AI-assisted log analysis.
Proof, not promises
Independently verifiable
- T+0:00 A LoRa gateway goes silent — physical power failure.
- T+1 min Monitoring fires. Not when sensor data goes missing — when the gateway stops responding.
- Same hour A technician is on site and finds the fault — resolved before the data gap mattered.
“The real measure of an observability platform isn't how many incidents it helps resolve — it's how many it prevents.”
Beyond the day job
Radio is the passion
Contact
Let's talk.
If you're building infrastructure people depend on — or you just want to talk radio and Kubernetes — I'd like to hear from you.
contact@belhadj.dev