Kubernetes Delivery Platform — k3s and Argo CD
YEAR
2026
MY ROLE
Platform engineering: infrastructure, CI/CD, GitOps and operations
INDUSTRY
DevOps training project
STACK USED
- Proxmox
- Terraform
- Ansible
- k3s
- Helm
- Argo CD
- GitLab CI
- Traefik
- cert-manager
- Prometheus
- Grafana
- Loki
Project Overview
A small FastAPI service and the full platform around it. Terraform creates the Proxmox virtual machines, Ansible builds them into k3s clusters for staging and production, and a Helm chart packages the application with its database, ingress and backups.
GitLab CI tests, builds and scans each image, then records the new release in Git. Argo CD pulls that change and reconciles both clusters. The application is deliberately small, so the platform decisions stay easy to see.
Key Features
Releases pulled from Git
CI writes the new image tag to Git; Argo CD reconciles staging and production from that state.
Production is a manual step from the production branch.
Scanned before it ships
The pipeline scans configuration, secrets, dependencies and the image before any deploy.
A scheduled job rescans the image running in production.
A hardened runtime
The container runs as a non-root user with a read-only root filesystem and dropped capabilities.
Production has a PodDisruptionBudget, so maintenance can't take every replica down at once.
Project Gallery
Challenges Solved
Secrets in a GitOps setup
Argo CD reconciles everything from Git, but credentials never go there. CI creates the Kubernetes secrets from protected variables, and the manifests only reference them.
Backups an attacker can't erase
Nightly database dumps are verified, and production copies them off-site with restic to object storage, using credentials that cannot delete remote objects.
Rebuilding from nothing
A bootstrap script rebuilds an environment from bare virtual machines, and the repository documents the disaster-recovery and staging-rebuild procedures step by step.
Check other similar projects
Hetzner and Cloudflare as Code — Terraform
Terraform for a role-segmented Docker Swarm cluster on Hetzner Cloud. Public manager nodes sit behind Cloudflare; workers and database nodes have no public address at all. Three firewalls give each role only the ports it needs, and Cloudflare — the zone, DNS, R2 storage and Turnstile — is managed as code too. It was extracted from a production deployment. Terraform provisions the infrastructure and stops there: joining the cluster and deploying stacks are left to configuration management, which handles re-runs far better.
Read more
PostgreSQL High Availability — Ansible
Ansible roles for self-hosted PostgreSQL with automatic failover. A monitor node watches a primary and a standby, and promotes the standby in about 30 seconds if the primary dies. Authentication is scram-sha-256 end to end, and backups and restore rehearsals run on systemd timers. They were extracted from a production deployment on Hetzner Cloud. The README documents the sharp edges of running pg_auto_failover with strict authentication — the parts most guides leave out.
Read more
OpenedX Deployment
This Open edX deployment project involved end-to-end implementation of a scalable open-source learning management system. Starting from a clean Ubuntu server install, I configured essential security layers (firewalls, DNS, SSL) and deployed Open edX using Docker. Beyond deployment, I customized the platform extensively—modifying the frontend and backend via a GitHub fork of the brand-edx-platform repo. Custom features like enhanced course navigation, branding integration, and user interface tweaks were implemented, transforming the platform into a production-ready, user-centric LMS tailored to organizational needs.
Read more
Docmost Deployment
Docmost was deployed as a private knowledge and productivity platform to replace cloud-based tools like Notion. I installed and configured the service on an existing Ubuntu server using Docker, securing it with firewall rules, domain-based HTTPS access, and persistent storage. The platform now serves as a centralized hub for documentation, planning, and project tracking. Its self-hosted nature ensures data privacy and full administrative control. I customized workspace settings, optimized performance, and integrated it into my daily workflow for personal knowledge management and internal team collaboration.
Read more