
The Translation Layer: Kubernetes on Hetzner Cloud
A deep dive into the Hetzner Cloud Controller Manager — how it bridges Kubernetes abstractions to Hetzner infrastructure, its modular controller archi...
I design, deploy, and operate cloud infrastructure for teams that need it to actually work — all managed as code, all documented, all yours at the end.
It starts at the edge: Route 53 steers users to the closest healthy region, CloudFront caches and terminates TLS, and AWS WAF + Shield absorb bots and DDoS before anything reaches your origin. I design the routing, cache strategy and rule sets — and tune them against real traffic.
A multi-AZ VPC with clean public / private / data subnet tiers, Internet & NAT gateways, and least-privilege security groups and NACLs. Segmented, observable and hybrid-ready from day one — not an accidental flat network you're scared to touch.
ALB / NLB with health checks and TLS, fronting Kubernetes ingress controllers. Blue/green and canary releases, connection draining and graceful rollouts — deploys that don't drop requests, even at peak.
Managed node groups or Karpenter, IRSA for pod-level IAM, GitOps with ArgoCD, autoscaling and rehearsed upgrade paths across AZs. A platform your team operates with confidence — not one that pages them at 3am.
RDS Multi-AZ / Aurora with a synchronous standby, ElastiCache for hot paths, connection pooling, point-in-time recovery and restores I actually rehearse — plus S3 with VPC gateway endpoints. Performance tuned with evidence, not guesses.
Transit / VPN Gateway with Site-to-Site IPSec or Direct Connect into on-prem Kubernetes, Hetzner and Proxmox — one operating model across AWS and bare metal. Everything reproducible, documented and handed over to your team.
Fixed-scope engagements with clear deliverables. You always know what's coming, what it costs, and when.
60-minute call. I review your stack, current pain, and goals. No deck.
Fixed-scope proposal: outcomes, deliverables, timeline, price. You decide.
I build it — usually with Terraform — in a fork of your repo. PRs reviewed by your team.
Docs, runbooks, recorded walkthrough. Optional retainer for ongoing ops.
Hands-on writeups from real production — Terraform, AWS, Kubernetes, networking.

A deep dive into the Hetzner Cloud Controller Manager — how it bridges Kubernetes abstractions to Hetzner infrastructure, its modular controller archi...

A visual guide to Kubernetes health probes — why process status is not application health, how liveness, readiness, and startup probes work, and how t...

A visual deep dive into Kubernetes controller patterns — how the reconciliation loop works, when to use Deployment vs StatefulSet vs ReplicaSet, and a...

Monitor MikroTik routers (and any SNMP device) in AWS CloudWatch using a fully serverless Terraform module — no Zabbix, no Nagios, no dedicated monito...

Stop writing repetitive aws_cloudwatch_metric_alarm blocks. This Terraform module lets you define all your CloudWatch alarms in a single YAML file — w...

A Terraform module that wraps the AWS Serverless Application Repository — deploy any SAR app with just its ARN, and get automatic required-parameter v...