Med Aymen Chakroun

DevOps & Platform Engineer

KubernetesAWS EKSGitOpsGolang

Engineering high-availability platforms that transform complexity into scalable competitive advantages.

Automate the complex
Secure the critical
Scale what matters
50%
FasterDeployments
90%
VulnerabilitiesBlocked
30%
CostReduction
7+
FreelanceProjects
Systems Identity

About Me

The professional evolution from hardware precision to cloud-scale architecture.

My Story

From Electrical Engineering to Cloud Architecture

My foundation was forged in Electrical Engineering, where I learned that 99.9% reliability is a structural requirement, not just a goal. I was trained to think in complex systems where every interconnection is an opportunity for optimization. That hardware-originated precision still drives my approach to architecting resilient, mission-critical infrastructure.

As a Platform & DevOps Engineer, I have delivered end-to-end cloud solutions for 7+ international projects across Dubai, Tunisia, and Europe. From containerizing Django hospitality platforms on Azure to architecting construction-tech GitOps pipelines on on-prem Kubernetes, I specialize in transforming raw complexity into scalable competitive advantages.

Today, at YaiGlobal, I lead the design of automated, multi-tenant cloud infrastructure and on-premise immutable environments. Whether I'm engineering Go CLI tools like onboardctl to automate tenant onboarding or managing the scaling of 20+ microservices, my focus remains on shifting security left and eliminating manual legacy workflows.

I view infrastructure as code, security as a chain, and every deployment as a mission. By merging systems-engineering fundamentals with cutting-edge SRE philosophies, I architect environments that are not just functional they are immutable, auditable, and resilient by design.

SRE Philosophy

Obsessed with 99.99% availability and system resilience.

Core Mission

Automate the complex, secure the critical, scale what matters.

Elite Security

90% reduction in critical production vulnerabilities.

Rapid Velocity

60% increase in deployment frequency via GitOps.

What I Bring to Your Team

  • Deterministic systems thinking from hardware foundation
  • Proven track record in infrastructure cost-efficiency
  • Security-centric architecture with 90% risk reduction
  • Multicultural collaboration across international boundaries
  • Reliability-first engineering for 99.9% uptime and zero-downtime growth
  • Adaptive leadership in rapidly scaling, high-complexity environments
  • Strategic architecting of developer-centric platforms for max engineering velocity
Active Role

Current Position

Leading infrastructure automation and multi-tenant scaling at YaiGlobal.

YaiGlobal

Operator Status: ACTIVE
Designation
Platform & DevOps Engineer
Employment Status
CURRENT ROLE
Fleet Telemetry
20+Microservices
15GBProd Database
6 NodesHA Clusters
99.98%SRE Uptime
Identity Verified
Clearances: MISSION_CRITICAL

Mission Impact Logs

Live_Update_v2.6
GOLANG / tfexec
onboardctl Automation

Engineered a production-ready Go CLI that fully automates tenant onboarding via Helm value generation and GitOps workflows.

SYSTEM RELIABILITY
Configuration Safety

Utilized mergo (deep YAML) and validator (JSON schema) reducing deployment-related errors by 99%.

DEVSECOPS
3-Layer Security Chain

Architected image security using Trivy scanning, Cosign cryptographic signing, and Kyverno cluster gate enforcement.

TERRAFORM / GIT
Zero-Touch Lifecycle

Integrated tfexec & go-git for automated EKS provisioning and declarative repository management.

DATABASE / STORAGE
Stateful Data Resilience

Orchestrated zero-loss migration of 15GB production databases and implemented Rancher Longhorn for block storage.

NETWORKING
P2P Private Tunnels

Developed secure remote access for FTP services using ZeroTier sidecars, creating encrypted private network tunnels.

Core Technology Stack

Tools & Frameworks

The infrastructure, automation, and security pipelines I use to build and manage environments.

Cloud & Infrastructure

AWSAWS
AzureAzure
OpenStackOpenStack
ProxmoxProxmox
Talos LinuxTalos Linux
VagrantVagrant
KVMKVM
KarpenterKarpenter

Container Orchestration

KubernetesKubernetes
DockerDocker
HelmHelm
K3sK3s
KustomizeKustomize
RancherRancher
eBPF / CiliumeBPF / Cilium
LonghornLonghorn

Security & NetSec

TrivyTrivy
KyvernoKyverno
KeycloakKeycloak
CosignCosign
Aqua Sec
Sealed SecretsSealed Secrets
KSOPS/SOPS
ZeroTierZeroTier

Automation & GitOps

TerraformTerraform
AnsibleAnsible
GitGit
JenkinsJenkins
ArgoCDArgoCD
GitHub ActionsGitHub Actions
BitbucketBitbucket
CloudFormationCloudFormation

Monitoring & Observability

PrometheusPrometheus
GrafanaGrafana
ELK StackELK Stack
LokiLoki
AlertmanagerAlertmanager
kube-vipkube-vip
KubecostKubecost
SRE PracticesSRE Practices

Development & Languages

GoGo
PythonPython
BashBash
TypeScriptTypeScript
SQLSQL
DjangoDjango
FlaskFlask
SpringBootSpringBoot
Simulation Engine

Live Deployment Pipeline

A real-time simulation of automated CI/CD workflows and security gates.

Automated CI/CD Pipeline Demo
60% Faster
Declarative Commit
Go-Git / SOPS
Pending
2m 15s
Multi-stage QA
SonarQube
Pending
1m 45s
3-Layer Security Scan
Trivy / Cosign
Pending
3m 30s
Docker Build
Docker
Pending
1m 20s
Artifact Registry
AWS ECR
Pending
45s
Cryptographic Signing
Cosign / Bash
Pending
5s
Zero-Touch Provision
Terraform / tfexec
Pending
2m 10s
Admission Control
Kyverno
Pending
10s
GitOps Rollout
ArgoCD / K3s
Pending
1m 30s
Health Telemetry
Prometheus
Pending
30s
Interactive DevOps Terminal
Live Demo
medaymen@devops-portfolio:~/portfolio$Welcome! Type 'help' to explore my expertise
medaymen@devops$
Infrastructure Dashboard

System Observability

Real-time metrics and diagnostic telemetry from production-grade environments.

System Uptime

99.980%

+0.01%

SLA Compliance

Vulnerabiltity Scans

120

+12 today

+60% faster scanning with automation

Security Score

98.0/100

+2.1 this week

90% vulnerabilities blocked

Cost Savings

35.0%

-$2.5K this month

Through smart automation
System Performance
CPU Usage
45%
Memory Usage
62%
Network I/O
28%
Disk Usage
71%
Infrastructure Status
24
Active Services
47
Healthy Pods
1.00%
Error Rate
42ms
Response Time
Kubernetes Cluster Management
Multi-Environment
7
Microservices
Production Ready
+2 this month
47
Running Pods
Auto-Scaling
Stable
3
Environments
Dev/Stage/Prod
All healthy

Cluster Features

Horizontal Pod Autoscaling (HPA)
Karpenter Cluster Autoscaling
Istio Service Mesh
Prometheus Monitoring
ArgoCD GitOps
Featured Engineering Project

onboardctl:
The Tenant Automation Engine

Engineered a production-ready Go CLI at YaiGlobal to automate complex multi-tenant Kubernetes provisioning. It replaces manual hours of configuration with reliable, schema-validated automation.

Hours → Minutes

98% reduction in manual setup time.

Zero Drift

Enforces consistent GitOps states automatically.

GitOps Integrated

Bridges the gap between code and infrastructure.

Multi-Cloud Ready

Native support for AWS EKS and on-prem K8s.

onboardctl — v2.4.0
$ onboardctl create tenant --name corp-x --region eu-west-1
🔍 Validating AWS infrastructure requirements...
🏗️ Provisioning dedicated EKS namespaces and RBAC...
🔄 Generating Helm values from enterprise templates...
🚀 Pushing GitOps manifests to private repository...
✅ Tenant 'corp-x' onboarded in 42s (Manual equiv: 4h)
Proof of Work
./onboardctl --help
onboardctl CLI executing in terminal
GOLANG V1.22
K8S CLIENT-GO
Technical Training

Professional Certifications

Key Milestones in My Learning Path

☁️
AWS Cloud Practitioner (CLF-C02)
KodeKloud
2025
Completed
Beginner

AWS Cloud Practitioner (CLF-C02)

Advanced skills in provisioning, operating, and managing distributed application systems on AWS

KodeKloud2025

Key Skills

AWS Core Services
EC2
S3
RDS
Lambda
Shared Responsibility Model
IAM & Access Management
Security & Compliance
Billing & Pricing Models
AWS Global Infrastructure
VPC Networking Fundamentals
☸️
Certified Kubernetes Administrator (CKA)
KodeKloud
2025
Completed
Associate

Certified Kubernetes Administrator (CKA)

Comprehensive preparation and hands-on skills for Kubernetes cluster administration.

KodeKloud2025

Key Skills

Cluster Administration
Workload Management
Networking & Services
Security & RBAC
Config & Secrets
Monitoring & Troubleshooting
Backup & Restore
🐧
Linux Foundation Certified System Administrator (LFCS)
KodeKloud
2025
Completed
Beginner

Linux Foundation Certified System Administrator (LFCS)

Information security management and governance expertise

KodeKloud2025

Key Skills

System Management
Filesystems & Storage
Networking & Firewall
Security & Hardening
User & Permission Management
Troubleshooting & Logs
🛡️
Cisco Network Security
Cisco Network Academy
2024
Completed
Associate

Cisco Network Security

Industrial network security expertise with digital badge verification.

Cisco Network Academy2024

Key Skills

Access Control (ACLs, AAA)
Site-to-site IPsec VPN
Remote-access VPNs
Firewalls (Stateful, ZPF, ASA)
Authentication
Data Encryption & Integrity
Troubleshooting
Intrusion Prevention Systems
4
Knowledge Certs
2
Active Prep
2026
Next Milestone
85%
Lab Mastery

Latest Insights

Sharing knowledge and best practices from the field

GitOps
DevOps

GitOps ArgoCD Deployment with Jenkins and Kubernetes

Master GitOps workflows using ArgoCD, Jenkins, and Kubernetes for automated deployments. Learn how to implement a...

Dec 15, 20248 min read
GitOpsArgoCDCI/CDKubernetes
Infrastructure
Infrastructure

Secure Multi-Environment Deployments with Kustomize

Explore how I architected secure, automated multi-environment deployments using AWS EKS for Kubernetes clusters and Crossplan...

Dec 10, 202412 min read
KustomizeKubernetesSecurityDevOps
Cost Optimization
Cost Optimization

How to Use LocalStack for Testing AWS Services Locally

Learn how to set up LocalStack for local AWS development and testing with Docker. Master S3, DynamoDB, Lambda, and other AWS...

Dec 5, 202410 min read
LocalStackDockerAWS S3Lambda
Engineering Methodology

Strategic Engineering

Deterministic infrastructure designed for production. I build systems that are repeatable, observable, and secured by design.

Deterministic Strategy

Every infrastructure component is defined as code. I ensure environments are immutable, repeatable, and audited through automated GitOps pipelines.

TerraformGitOpsImmutable Arch

Reliability & Observability

Moving beyond basic uptime to focus on the four golden signals. I build observability into the core of the platform to catch issues before users are impacted.

SLIs/SLOsPrometheusSRE

Industrial Hardening

Security is baked into the design, not added as a layer. Implementing zero-trust principles and automated compliance to meet EU/US standards.

Zero-TrustRBACCompliance
Professional Impact

Collaborator Insights

Real feedback from the project owners, leads, and engineers I build infrastructure for.

Verified Manager
"I have the pleasure of working with Aymen on our DevOps team. He brings strong expertise in Kubernetes, networking, on-premises solutions, automation, and containerization. His problem-solving mindset consistently drives us to deliver reliable and efficient solutions."
Hajer Frigui

Hajer Frigui

DevOps & Cloud Engineer
YaiGlobal

High-Efficiency Ops
Verified Engineer
"Aymen is one of the most reliable Cloud & DevOps engineers I’ve worked with. He took full ownership of critical tasks, deploying Django and React/Flask apps for major ventures in Dubai. His ability to research and implement creative, cost-effective solutions under budget constraints is truly impressive."
Ahlem Laajili

Ahlem Laajili

Software Engineer
Flouci (Kaoun)

Low-Cost Scaling
Verified Engineer
"Med Aymen's approach to Infrastructure as Code and system hardening is top-tier. He doesn't just build systems; he builds resilience. His work on automating complex CI/CD pipelines has significantly reduced our manual overhead and improved our security posture."
Houssem Slimani

Houssem Slimani

Full-stack Developer
Avaxia Group

99.9% Pipeline SLA
Connect_v2.0.4
READY_TO_BUILD
Contact

Start a
Conversation

Direct Communication

You'll coordinate directly with me to define technical requirements and infrastructure constraints.

Fast Assessment

I respond to all professional inquiries within one business day for initial technical alignment and discovery.

uptime99.98%
localityTunisia (GMT+1)
relocationAVAILABLE (EU/US/UAE)