fixcomap/agustin

Disponible para proyectos remotos · Málaga, EspañaAvailable for remote projects · Málaga, Spain

Agustín Prieto

DevOps Engineer · SRE · Multi-cloud & Kubernetes

Ingeniero DevOps y SRE con diez años de trayectoria en IT, seis de ellos diseñando, automatizando y operando plataformas en Azure, AWS y GCP. Especializado en Kubernetes y OpenShift, integración y entrega continua (GitHub Actions, Jenkins, GitLab CI), infraestructura como código (Terraform, Ansible) y observabilidad (Grafana, Elastic). DevOps and SRE engineer with ten years in IT, six of them designing, automating and operating platforms on Azure, AWS and GCP. Specialised in Kubernetes and OpenShift, continuous integration and delivery (GitHub Actions, Jenkins, GitLab CI), infrastructure as code (Terraform, Ansible) and observability (Grafana, Elastic).

  • 10años en ITyears in IT
  • 6años DevOps / SREyears DevOps / SRE
  • 3clouds: Azure · AWS · GCP
  • 2países: Argentina · Españacountries: Argentina · Spain
Agustín Prieto
$ kubectl get pods -n api
NAME            READY   STATUS    RESTARTS   AGE
api-7d9f4-x2kq  1/1     Running   0          3m
api-7d9f4-p8ns  1/1     Running   0          3m
api-7d9f4-m1vc  1/1     Running   0          3m
$ kubectl rollout status deploy/api -n api
deployment "api" successfully rolled out
$ tofu plan -detailed-exitcode
No changes. Your infrastructure matches the configuration.

01 De un commit a producciónFrom a commit to production

Recorrido completo de un cambio de código, desde el commit hasta su operación en producción, con las herramientas que intervienen en cada fase. Es el modelo de entrega que implanto en cualquier equipo: automatizado de extremo a extremo, con identidades de mínimo privilegio y sin intervención manual sobre los entornos. El punto que recorre el diagrama representa el commit. The full journey of a code change, from commit to production operations, with the tools involved at each stage. It is the delivery model I put in place in any team: automated end to end, with least-privilege identities and no manual intervention on the environments. The dot moving across the diagram represents the commit.

  1. gitCommitfeature/* · pre-commit
  2. CIPull requestGitHub Actions · CodeQL · trivy · plan
  3. RevisiónReview1 aprobación · rulesets1 approval · rulesets
  4. imgBuildDocker · SBOM · cosign
  5. IaCInfraestructuraInfrastructureOpenTofu · OIDC
  6. k8sRolloutKubernetes · Cloud Run
  7. 200En producciónIn productionsmoke test · dominiosmoke test · domain
  8. obsOperaciónOperationsGrafana · alertas · driftGrafana · alerts · drift
$ git commit -m "feat(api): endpoint /orders" && git push
 pre-commit · gitleaks: sin secretosno secrets
$ gh pr create --base develop   #142
 lint  tests  CodeQL  trivy  tofu plan: 2 to add, 0 to destroy
 review: aprobada por agustinprieto97 · merge → mainreview: approved by agustinprieto97 · merge → main
$ docker build · syft · cosign sign --yes sha256:9f3c…
 imagen firmada · registry: api:v1.4.0image signed · registry: api:v1.4.0
$ tofu apply   (OIDC · identidadidentity: gh-deployer)
 Apply complete! 2 added, 0 changed, 0 destroyed
$ kubectl rollout status deploy/api
 3/3 ready · healthcheck OK
$ curl -sI https://app.fixcomap.com/orders | head -1
HTTP/2 200 · tag v1.4.0
 grafana: p95 118 ms · errores 0,0 % · alertas: ninguna · drift: limpiografana: p95 118 ms · errors 0.0% · alerts: none · drift: clean

02 ExperienciaExperience

  1. may 2024 — actualidadMay 2024 — present

    DevOps Engineer · agap2 EspañaSpain

    Diseño y mantenimiento de un sistema de CI/CD centralizado (Bitbucket Pipelines, GitHub Actions, Jenkins) para despliegue y pruebas automatizadas. Administración y optimización de la infraestructura en Microsoft Azure (AKS, Blob Storage, Enterprise Applications, WebApps). Despliegue y orquestación de aplicaciones contenerizadas en Kubernetes; observabilidad con Grafana y Elastic.Design and maintenance of a centralised CI/CD system (Bitbucket Pipelines, GitHub Actions, Jenkins) for automated deployment and testing. Administration and optimisation of Microsoft Azure infrastructure (AKS, Blob Storage, Enterprise Applications, WebApps). Deployment and orchestration of containerised applications on Kubernetes; observability with Grafana and Elastic.

    • Kubernetes
    • Azure
    • GitHub Actions
    • Bitbucket Pipelines
    • Jenkins
    • Docker
    • Grafana
    • Elastic
  2. abr 2023 — feb 2024Apr 2023 — Feb 2024

    DevOps Engineer · Talan Málaga

    Administración de servicios en Azure y AWS, implantación de pipelines de Ansible para la gestión de post-configuración y automatización de operaciones con Python y Terraform.Administration of Azure and AWS services, implementation of Ansible pipelines for post-configuration management, and operational automation with Python and Terraform.

    • Azure
    • AWS
    • Terraform
    • Ansible
    • Python
    • Grafana
  3. may 2022 — jun 2023May 2022 — Jun 2023

    DevOps Engineer · OTG — Open Technologies Group São Paulo, Brasil · remotoSão Paulo, Brazil · remote

    Construcción y mantenimiento del servidor GitLab y de los pipelines de CI/CD con Jenkins (Groovy) y Docker; gestión de la infraestructura con Ansible y monitorización con Grafana en entornos Linux y Windows.Build and maintenance of the GitLab server and CI/CD pipelines with Jenkins (Groovy) and Docker; infrastructure management with Ansible and Grafana monitoring across Linux and Windows environments.

    • GitLab CI
    • Jenkins
    • Groovy
    • Docker Swarm
    • Ansible
  4. nov 2021 — may 2022Nov 2021 — May 2022

    DevOps Engineer · SRE · Contabilium Argentina

    Orquestación de pipelines de Jenkins en Groovy, administración de Azure Cloud Services y automatización de tareas con Bash, Python y PowerShell.Orchestration of Jenkins pipelines in Groovy, administration of Azure Cloud Services and task automation with Bash, Python and PowerShell.

    • Jenkins
    • Azure
    • Bash
    • Python
    • PowerShell
  5. may 2020 — nov 2021May 2020 — Nov 2021

    DevOps Engineer · ICBC Argentina bancabanking

    Orquestación de pipelines de Ansible, administración de la plataforma OpenShift e implantación del stack ELK y Grafana para la monitorización integral. Integración continua con GitLab CI.Orchestration of Ansible pipelines, administration of the OpenShift platform and implementation of the ELK and Grafana stack for end-to-end monitoring. Continuous integration with GitLab CI.

    • OpenShift
    • Ansible
    • ELK
    • GitLab CI
    • Docker Swarm
  6. 2019 — 2020

    System Administrator · DevOps Consultant Global Hitss · Thomson Reuters · Magnético

    Administración de sistemas y consultoría DevOps en proyectos de corta duración en Buenos Aires.Systems administration and DevOps consulting on short-term engagements in Buenos Aires.

  7. nov 2015 — mar 2019Nov 2015 — Mar 2019

    Help Desk Technician · FixComAp Buenos Aires

    Inicio de la trayectoria profesional y origen del nombre de la marca.The start of the professional journey and the origin of the brand name.

03 Stack

Cloud

  • Azure · AKS, WebApps, Blob, Entra ID
  • AWS · EC2, S3, RDS, KMS, CloudWatch
  • GCP · Cloud Run, WIF, Artifact Registry, Secret Manager

ContenedoresContainers

  • Kubernetes
  • OpenShift
  • Docker
  • Docker Swarm
  • distroless

CI/CD

  • GitHub Actions
  • GitLab CI
  • Jenkins · Groovy
  • Bitbucket Pipelines
  • Azure DevOps
  • TeamCity
  • Renovate

IaC y automatizaciónIaC & automation

  • Terraform · OpenTofu
  • Ansible
  • Python
  • Bash
  • PowerShell
  • Go

ObservabilidadObservability

  • Grafana
  • Prometheus
  • Elastic · ELK
  • Zabbix
  • Cloud Monitoring

Seguridad en el pipelinePipeline security

  • OIDC · WIF
  • cosign
  • trivy
  • checkov · tflint
  • gitleaks
  • CodeQL

04 Caso realCase study: fixcomap/platform

Implementación de este modelo, operativa y de código abierto: infraestructura en Google Cloud gestionada con OpenTofu y GitHub Actions, sin credenciales de larga duración y sin cambios aplicados manualmente. Desarrollada junto a mi hermano como base de plataforma para fixcomap; esta misma página se publica a través de ese pipeline. Coste de explotación mensual: el dominio. A working, open-source implementation of this model: Google Cloud infrastructure managed with OpenTofu and GitHub Actions, with no long-lived credentials and no manually applied changes. Built together with my brother as the platform foundation for fixcomap; this very page is published through that pipeline. Monthly operating cost: the domain.

Autenticación sin claves de servicioKeyless authentication

GitHub Actions se autentica en Google Cloud mediante OIDC (Workload Identity Federation). Cada service account está vinculada a un repositorio, una rama y un environment concretos; las pull requests operan exclusivamente en modo lectura.GitHub Actions authenticates to Google Cloud through OIDC (Workload Identity Federation). Each service account is bound to a specific repository, branch and environment; pull requests operate in read-only mode.

wif.tf →

Cuatro capas, cuatro identidadesFour layers, four identities

Estados de OpenTofu independientes: bootstrap, platform (IAM y secretos, con aprobación humana), app (Cloud Run, sin acceso a IAM) y dns. El radio de impacto de cualquier fallo queda acotado a su capa.Independent OpenTofu states: bootstrap, platform (IAM and secrets, with human approval), app (Cloud Run, no IAM access) and dns. The blast radius of any failure is contained within its layer.

README →

Un único camino a producciónA single path to production

Cada merge en main ejecuta plan, apply con aprobación únicamente si existen cambios, construcción de la imagen, análisis de vulnerabilidades, firma con cosign, despliegue y etiquetado de versión. Ningún cambio se aplica desde un equipo local.Every merge into main runs plan, apply with approval only when changes exist, image build, vulnerability scanning, cosign signing, deployment and version tagging. No change is ever applied from a workstation.

deploy.yml →

Control de deriva y de costeDrift and cost control

Una ejecución nocturna planifica todas las capas y abre una incidencia ante cualquier cambio manual. Un segundo control bloquea en las pull requests los recursos de coste fijo (balanceadores, NAT, bases de datos gestionadas) salvo justificación explícita.A nightly run plans every layer and opens an issue on any manual change. A second control blocks fixed-cost resources (load balancers, NAT, managed databases) in pull requests unless explicitly justified.

drift.yml →

Pipelines reutilizablesReusable pipelines

Los sitios estáticos de la organización no mantienen pipeline propio: invocan dos reusable workflows con una configuración de doce líneas. Previews por pull request, despliegue en Cloudflare Pages y smoke tests se mantienen en un único lugar.The organisation's static sites keep no pipeline of their own: they invoke two reusable workflows through a twelve-line configuration. Pull request previews, Cloudflare Pages deployments and smoke tests are maintained in a single place.

rw-pages-deploy.yml →

Operable sin dependencia de una personaOperable without a single point of failure

Comprobaciones de disponibilidad con alertas al equipo, aprobaciones distribuidas y un runbook con los escenarios reales: despliegue fallido, rollback, deriva, credenciales caducadas y fin del periodo de prueba.Availability checks with team-wide alerting, distributed approvals and a runbook covering the real scenarios: failed deployment, rollback, drift, expired credentials and end of the trial period.

Runbook →

05 Certificaciones e idiomasCertifications & languages

CertificacionesCertifications

  • Red Hat DO380 · OpenShift Administration III: Scaling Kubernetes Deployments in the Enterprise
  • Red Hat DO447 · Advanced Automation: Ansible Best Practices
  • AWS · Storage Gateway Deep Dive: Amazon S3 File Gateway
  • Docker · de principiante a expertofrom beginner to expert
  • Técnico en hardware de PCPC hardware technician

IdiomasLanguages

  • Español · nativoSpanish · native
  • Inglés · profesional · B2English · professional · B2

06 ContactoContact

Abierto a proyectos de ingeniería de plataforma, migraciones a Kubernetes y cloud, CI/CD y observabilidad, en remoto o en Málaga.Open to platform engineering projects, Kubernetes and cloud migrations, CI/CD and observability, remote or in Málaga.