Resume · Updated August 2026

Site Reliability & Platform Engineer

Ten years in infrastructure: two in systems and network administration, then eight in DevOps and SRE, including eight running Kubernetes in production. I build and operate internal and public cloud platforms end to end — from physical hardware to developer self-service — and own the run, the rota and the improvement that come with them.

Today I operate a private OpenStack platform across three datacenters: 13 Kubernetes clusters and 250 nodes, 200 applications, 72 RabbitMQ clusters, 127 PostgreSQL databases and an on-premise LLM platform. Previously at Kering, I supported 500+ microservices across ECS/Fargate and six Kubernetes clusters, plus a 2 TB multi-region Couchbase estate. In parallel, I have audited and built AWS and GCP infrastructure for around ten clients.

SLI/SLO and error-budget culture, everything as code. Since 2025, focused on running large language models on-premise and applying them to operations.

Download PDF
Contact gabin@chambon.io +33 7 69 79 53 63 Paris, France · Remote
Work authorization

French citizen, Paris. Eligible for Express Entry (STEM and French-language categories) and the Global Talent Stream. Permanent or contract; start date negotiable.

Experience
Jun 2025 — present Inherent Group (Unyc) SRE / Platform Engineer

B2B telecom operator. Seven-person SRE team owning the full technical foundation — private OpenStack cloud across 3 datacenters, servers, storage arrays, 13 Kubernetes clusters and the delivery platform. Availability target 99%.

  • Operate the group's entire technical foundation, hardware to applications: private OpenStack cloud across 3 datacenters (Kolla, bare metal via Bifrost/Ironic), Pure Storage arrays and 13 Kubernetes clusters totalling 250 nodes and 200 applications.
  • Designed and maintain the platform Helm chart that deploys every application in the group, plus the data layer: 72 RabbitMQ clusters, 127 PostgreSQL databases under CNPG, 60 Redis/Valkey instances, a 3 TB / 18-node Cassandra cluster and MySQL.
  • Migrated 110 applications and servers from internal IT to the private OpenStack/Kubernetes cloud with no interruption on business-critical scope.
  • Initiated and shipped the on-premise LLM agent platform (vLLM, llm-d, GAIE, KServe, HolmesGPT) with RBAC and a Milvus/RagFlow knowledge base: automated alert triage, incident qualification time down ~80%.
  • Migrated all 13 clusters from Kubespray to Talos — build time 1 hour → 5 minutes — and wrote and rehearsed the disaster-recovery plan: etcd restore, full cluster rebuild, backups, RTO and RPO per scope.
  • Standardised GitOps (Argo CD, Helm, Kustomize), policy-as-code (Kyverno) and elasticity (KEDA on RabbitMQ queues); automated access (Boundary), identity (Keycloak/OIDC via Terraform) and upgrades (Renovate).
Jun 2024 — Jun 2025 Kering Site Reliability Engineer

Global luxury group. Ten-person infrastructure team. Multi-cloud AWS / Alibaba platform, with most workloads on ECS/Fargate and the rest on 6 Kubernetes clusters (3 EKS, 3 Alibaba ACK), 500+ microservices under continuous deployment and Crossplane self-service for ~50 product teams. Availability target 99.9%.

  • Co-owned production support for the group's worldwide customer and loyalty database on Couchbase / Amazon EKS: 2 TB, 18 nodes, Magma, XDCR across three regions.
  • Owned observability for that scope end to end — instrumentation, dashboards and alerting on Mimir / Loki / Grafana — to catch replication and capacity drift before customer impact.
  • Ran both deployment planes day to day: 6 Kubernetes clusters totalling about 200 nodes and the group's ECS/Fargate stacks in Terraform, sized to absorb private sales, product drops and Fashion Week.
  • Tuned fleet elasticity with Karpenter and KEDA on SNS and RabbitMQ queues, ingress and system metrics — capacity matched to load rather than provisioned for peaks.
  • Industrialised AWS and Alibaba infrastructure across 5 Terraform / Terragrunt / Terramate foundation stacks, working daily in a Crossplane model where a team ships app and infrastructure in one merge request.
  • Maintained the shared Helm chart used by every group microservice and its GitHub Actions pipelines; Kyverno policies, IAM/IRSA and Vault for secrets.
  • Joined crisis calls for major incidents, coordinating diagnosis and recovery across infrastructure, database and product teams.
Jun 2021 — Jun 2024 Ministère de la Transition écologique DevOps Engineer

3 days/week for three years, alongside one other engagement at a time. Shared internal GitLab platform for central government IT — five-person product team serving 2,500 developers across 350 projects.

  • Deployed and operated the ministry's internal GitLab CE platform: first on OpenStack with Ansible and NGINX, then migrated onto Kubernetes, for 2,500 developers and 350 projects.
  • Industrialised the runner fleet on Kubernetes (RKE2, OpenStack Magnum, Helm, Argo CD) with a shared Squid egress proxy: job queue time down 70%.
  • Published reusable OpenStack Terraform modules adopted across the ministry's DevOps community — full environment provisioning 1 day → 2 hours.
  • Migrated infrastructure as code from OpenStack HEAT to Terraform and relocated the platform to a new government tenancy with no interruption.
  • Built the observability stack (Prometheus, Grafana, Loki, Mimir, Fluent Bit) and DevSecOps pipelines for Terraform and Ansible; administered Vault on a Consul backend.
2020 — present Independent clients (~10) Cloud consultant & auditor — AWS / GCP

Short freelance engagements alongside the long missions, exclusively on public cloud: infrastructure audit, and build / industrialisation. Clients are unnamed for confidentiality; references available on request.

  • Infrastructure audits for around ten clients: architecture and reliability review, security posture (IAM, network exposure, secrets), observability coverage and cost — delivered as a prioritised remediation plan.
  • Rebuilt a client's entire GCP estate after a security breach: assessment, full reconstruction as code, GKE and Pub/Sub redeployed with hardened access and exposure.
  • Migrated a WordPress fleet from AWS Lightsail to EC2 — Terraform and Ansible, databases to RDS, perimeter protection through Cloudflare (WAF, CDN, TLS).
Jul 2023 — Jun 2024 RAS Intérim DevOps Engineer

2 days/week alongside the Ministry engagement. Staffing group, 20-person digital division. Objective: exit Elastic Beanstalk and containerise the estate.

  • Migrated 40 microservices off Elastic Beanstalk in one year, choosing service by service between Amazon ECS and Kubernetes.
  • Cut delivery pipeline duration from 20 minutes to 3 (−85%) while improving application performance and observability coverage.
  • Onboarded developers onto Docker to full autonomy; hardened IAM and network, implemented CloudWatch alerting, administered RDS and MongoDB Atlas.
Jul 2022 — Jul 2023 Coffreo DevOps Engineer

2 days/week alongside the Ministry engagement. Five-person infrastructure team moving from Proxmox / LXC to Kubernetes at OVHcloud.

  • Introduced blue/green deployment for 50 applications through DNS CNAME switching, on infrastructure that previously went down at every release: zero downtime, instant rollback, lead time 30 minutes → 5.
  • Migrated 50 applications from LXC on Proxmox to Kubernetes on OVHcloud with Helm, GitLab CD and SOPS-managed secrets.
  • Deployed the LGTM observability stack (Loki, Grafana, Tempo and Mimir) across all 50 migrated applications.
  • Deployed Consul Service Mesh and trained development teams on Kubernetes, Helm, Kustomize and SOPS to deployment autonomy.
Mar 2020 — Jul 2022 Blocs et Compagnie DevOps Engineer

Founding technical hire — full-time until June 2021, then 2 days/week alongside the Ministry engagement. Architecture, automation and R&D on confidential computing in secure enclaves.

  • Designed end to end the OpenStack / RKE2 platform hosting the Geowallet application and Intel SGX enclave workloads (Scone), and owned production support.
  • Migrated all AWS resources and their CouchDB and PostgreSQL data to an OVHcloud OpenStack / RKE2 platform, with provisioning automated through Terraform and Ansible.
  • Built the GitLab CI/CD pipelines, Helm templates, observability and security controls for the Node.js microservices (Trivy, Falco, Snyk); developed a Go automation tool on the OVHcloud API.
Mar 2019 — Mar 2020 Atawiz Cloud & DevOps Engineer

Cloud services agency. AWS and Azure work across multiple client accounts.

  • Designed and delivered AWS and Azure architectures for several client accounts.
  • Administered managed Kubernetes on EKS, AKS and GKE.
  • Built a Hyperledger Fabric proof of concept with smart contracts in Go.
Jun 2018 — Aug 2019 Equativ Systems Engineer — apprenticeship

Ad-tech platform. Infrastructure team, on-premise and AWS.

  • Deployed and operated on-premise Kubernetes with Kubespray on KVM.
  • Wrote reusable AWS Terraform modules and Ansible playbooks.
  • Administered AWS day to day: EC2, S3, IAM, Route 53.
Jun 2016 — Jun 2018 Microcred · Baobab Group Systems & Network Administrator — apprenticeship

Microfinance group operating across Africa and China.

  • Administered Linux and Windows servers across the group’s subsidiaries.
  • Ran Ubiquiti networking and VMware virtualisation.
  • Handled tier 1–2 support for internal users.
Certifications

Certified Kubernetes Security Specialist (CKS) — Linux Foundation, 2022

Certified Kubernetes Administrator (CKA) — Linux Foundation, 2021

HashiCorp Certified: Terraform Associate — 2022

AWS Certified Solutions Architect – Associate — 2019

Recertification in progress across all four.

Education & languages

Licence in IT Systems Analysis — CFA Insta, Paris, 2019.

BTS SIO, Infrastructure, Systems & Networks — CFA Insta, Paris, 2018.

French — native speaker · English — C1, used daily in international engineering teams.

References available on request.