Skip to content
View semx's full-sized avatar

Block or report semx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
semx/README.md

About

Senior infrastructure engineer with 10+ years building and operating production systems at scale — from architecture and IaC through observability, incident response, and mentoring across remote, globally distributed teams. I work the whole delivery path (application code → the pipelines that ship it → the infrastructure it runs on) with a security-first eye, and I like finding the sharp edge in a system and fixing it at the root.

  • 🛠️ Modernizing legacy workloads into Dockerized services on Kubernetes / AWS EKS; Kubernetes in production since 2022.
  • 📈 Track record of 99.95% uptime SLAs, deployment time cut 45 → 12 min, and −30% incident MTTR.
  • 🔎 Read source, not just docs — Kubernetes kubelet security research (subPath traversal, authorization bypass, ImageVolume, Pod resource consistency).

Core expertise

Cloud & Platforms AWS (EC2, EKS, RDS, S3, IAM, Route53, CloudFront, CloudWatch, ELB, WAF), Azure, GCP
Containers & GitOps Kubernetes, Helm, RBAC, HPA, cert-manager, Docker, ArgoCD, Flux
Infrastructure as Code Terraform, Terragrunt, Ansible, Pulumi
CI/CD TeamCity, GitLab CI, GitHub Actions, Jenkins
Observability Prometheus, Grafana, Loki, OpenTelemetry, Datadog, New Relic, ELK
Security & Identity IAM, OPA/Gatekeeper, FreeIPA, Active Directory, VPN, hardening, secrets management
Databases PostgreSQL, MySQL, SQL Server, Redis, MongoDB, Neon
Languages Bash, Python, Go, HCL, PHP, JavaScript/Node.js

Open-source contributions

I fix real, reproducible bugs in the tools I run in production — each with a failing test and a root-cause writeup. The same class of bug shows up across Go, Python, PHP and JS; reproducing and root-causing it is the transferable skill.

Project Contribution PR Status
symfony/symfony Yaml parsed .nan as +INF and never round-tripped NAN #64915 ✅ Merged
symfony/symfony ISBN-10 validator accepted a misplaced X check character #64877 ✅ Merged
laravel/framework Number::forHumans() returned "-0" for tiny negatives #60736 ✅ Merged
ansible/ansible is_netmask accepted non-contiguous (invalid) netmasks #87235 ✅ Merged
ansible/ansible Uncaught OverflowError in check_type_int for inf #87253 ✅ Merged
argoproj/argo-cd Surface the Suspended condition message for suspended Jobs #28738 ✅ Merged
nodejs/node assert.deepStrictEqual TypeError on a null Map key / Set member #64449 🟢 Approved
kubernetes/kubernetes Quantity.String() dropped the suffix for DecimalSI above 10¹⁸ #140459 ⏳ Open
kubernetes/kubernetes Label Gt/Lt selectors silently dropped values above int64 #140462 ⏳ Open
hashicorp/terraform Clean error from log()/pow() when the result is NaN #38883 ⏳ Open
python-humanize/humanize fractional() emitted degenerate output ("2 1/1") on whole-rounding #354 ⏳ Open

Selected — more across Symfony, Kubernetes, docker-py, croniter, Spinnaker.


Selected experience

  • Senior DevOps Engineer — Nitka · 2021 – present · Windows→Linux migration, Dockerized workloads on K8s/EKS, GitLab CI · TeamCity · ArgoCD, IaC with Terraform/Terragrunt/Ansible, full observability stack; led Ubuntu/PHP upgrades across 85+ servers.
  • DevOps Engineer — Accenture · 2017 – 2021 · HA infrastructure for mission-critical apps, CI/CD automation, AWS + VMware/Proxmox, monitoring across 50+ services, 99.95% uptime over 12 months.
  • System Administrator — VK · 2014 – 2017 · 1,000+ Linux/Windows servers, AD/FreeIPA/DNS/VPN, Bash/Python automation, PXE imaging and Windows→Debian migrations.

Projects

  • ansible-linter — dependency-light static analysis for Ansible playbooks.
  • mr-rca-toolkit — infrastructure merge review and incident RCA utilities.
  • claude-arena — cost-aware model routing and orchestration for dev tooling.



Open to Senior DevOps / Platform / DevSecOps / SRE roles — best reached via sannikov.dev

Pinned Loading

  1. ansible-linter ansible-linter Public

    Dependency-light static analysis for Ansible playbooks and roles

    Python

  2. ansible-secops-linter ansible-secops-linter Public

    Security-focused static analysis for Ansible: hardcoded secrets, disabled TLS/host-key checks, missing no_log, world-writable modes, and more.

    Python

  3. claude-arena claude-arena Public

    Cost-aware model routing and orchestration for developer workflows

    Python

  4. mr-rca-toolkit mr-rca-toolkit Public

    Infrastructure merge review and incident RCA utilities

    Python

  5. semx semx Public

    Developer → DevOps → DevSecOps · open-source contributor (Symfony, Kubernetes, Ansible, Laravel)