DevOps Engineer | Cloud & Automation

David Rubin

From Enterprise Systems to Production Infrastructure

DevOps engineer with hands-on Kubernetes, Helm, Terraform, and AWS delivery from production-style platforms built end to end, backed by AWS Certified Solutions Architect - Associate (SAA-C03, 893/1000). Four years running mission-critical enterprise IT and ERP systems bring a production-aware mindset to CI/CD and GitOps.

AWS SAA-C03
893/1000
IITC GPA
86.28
Program
688h

01 / Projects

Projects

Six builds. Each one links to its repository.

k8s-launchpad Diagnostics page listing four pods - field-guide-api, field-guide-api-mongodb, launchpad and launchpad-mongodb - each Running and Ready 1/1, above a Deployments table where all four report Ready 1/1 and one available replica

Kubernetes

An Internal Developer Platform on kind: two Flask workloads plus MongoDB packaged with Helm, brought up by a single idempotent Makefile command.

160 Unit Tests at 100% Coverage
46 STRIDE Threats Closed Across 5 Phases, Zero Open
27/27 Milestone Requirements Audited

Kubernetes · Helm · Docker · Flask · MongoDB · Python

Runtime diagram of CloudCart inside a single VPC box labelled 10.0.0.0/16, 3 AZ, EKS 1.31. Users over HTTPS 443 reach an ALB that is internet-facing with target-type ip, terminates ACM TLS and redirects port 80 to 443. The ALB forwards to an nginx gateway doing path routing, which fans out to six workloads: /api/auth/ to auth, /api/products to catalog, /api/cart to cart, /api/orders to order, /api/payments to payment, and an unlabelled edge to the static frontend. The five FastAPI services all write to a standalone MongoDB 8.0 with no PVC. Along the bottom of the same VPC box sit four unconnected platform components: External Secrets using IRSA service account app-secrets-sa, Prometheus with Grafana, the AWS load balancer controller using EKS Pod Identity, and a single NAT gateway.

Platform & GitOps Lead - team of 4

Five FastAPI microservices behind an nginx gateway, under a single Helm umbrella chart on AWS EKS, provisioned by Terraform and delivered through Argo CD GitOps with zero static AWS credentials.

Platform & GitOps Lead, team of 4
5 FastAPI Microservices + nginx Gateway, Single Helm Umbrella Chart
Terraform: VPC across 3 AZs, EKS, ECR, ALB Controller

AWS EKS · Terraform · Helm · Argo CD · FastAPI · GitHub Actions

Terminal running gh run watch on the Deploy microservices to ECS workflow. Two jobs, Deploy inventory and Deploy orders, each show a green tick against Set up job, Checkout, Configure AWS credentials, Log in to Amazon ECR, Build and push image, Render task definition and Deploy to ECS

Open Source

Public open-source knowledge base documenting DevOps principles, iron rules, and production lessons. Tagged across 10 GitHub topics.

9 Iron Rules from Production Experience
Public Repository, 10 GitHub Topics
Covers Full DevOps Stack

Linux · Docker · Kubernetes · Terraform · Ansible · GitHub Actions

GitHub Actions workflow graph for ci.yml on push: a green lint-typecheck job finishing in 16 seconds, feeding a Matrix: test node reading 5 jobs completed, feeding a green report job finishing in 2 seconds

CI/CD

Six public GitHub Actions repositories worked front to back - event triggers, artifacts and outputs, caching, secrets handling, and matrix builds.

6 Public Repositories, One Concept Each
Event Triggering and Flow Control
Artifacts and Job Outputs

GitHub Actions · CI/CD · YAML · Docker · TypeScript · Python

Architecture diagram: a developer pushes to a GitHub repository, which triggers a GitHub Actions workflow. The workflow assumes an IAM role via OIDC, uploads the built dist files to an Amazon S3 bucket, and creates a CloudFront invalidation. CloudFront fetches the static files from S3 and serves cached responses to browsers

Infrastructure as Code

Three public HCL repositories covering Terraform Cloud remote state, a full application infrastructure stack, and Terraform driven from GitHub Actions.

3 Public HCL Repositories
Terraform Cloud Remote State and Runs
Full Application Infrastructure Stack

Terraform · HCL · Terraform Cloud · AWS · GitHub Actions · Infrastructure as Code

AWS Certified Solutions Architect - Associate badge

Certification

SAA-C03, scored 893 out of 1000 against a 720 pass mark. Passed 13 August 2026, valid through 13 August 2029.

Scored 893/1000 (Pass Mark 720)
Passed 13 August 2026
Valid Through 13 August 2029

AWS · VPC · IAM · EC2 · S3 · RDS

02 / Capabilities

Capabilities

Tooling, and what each one was used for.

Infrastructure & OS

Linux (Ubuntu/CentOS)
Server management
Networking (TCP/IP, DNS, HTTP)
Infrastructure
Nginx / Reverse Proxy
Load balancing
Bash
Automation scripts
System Administration
Multi-site retail chain

Cloud & Containers

Docker / Compose
Service deployment
Kubernetes
Container orchestration
AWS (EC2, S3, IAM, VPC)
Cloud infrastructure
Terraform
Infrastructure as code
Ansible
Configuration management

CI/CD & GitOps

GitHub Actions
CI/CD pipelines
Jenkins
Build automation
ArgoCD
GitOps deployments
Helm
K8s package management
Git
Version control

Languages & Monitoring

Python
Automation & scripting
Bash
Shell scripting
SQL (PostgreSQL)
Database management
Prometheus / Grafana
Metrics & dashboards
ELK Stack
Log aggregation
Three-layer EKS diagram. The infrastructure layer shows a Makefile and eks.yaml creating the cluster, VPC, subnets, node group and OIDC provider. The IAM layer shows iam-policy.json attached to an IAM role, with two trust policies side by side: IRSA trusting the cluster OIDC URL, and Pod Identity trusting pods.eks.amazonaws.com. The Kubernetes layer shows both paths pointing at one ServiceAccount named app, used by a deployment whose aws-cli initContainer copies a file from S3 before nginx starts
EKS IRSA - IAM roles for service accounts, three-layer trust
raw kubectl outputaccount ID, node hostname and bucket name redacted
$ kubectl get nodes
NAME                    STATUS   ROLES    AGE    VERSION
<node>.ec2.internal     Ready    <none>   2m4s   v1.34.9-eks-93b80c6
$ kubectl get sa app -o yaml
apiVersion: v1
kind: ServiceAccount
metadata:
  annotations:
    eks.amazonaws.com/role-arn: arn:aws:iam::<account-id>:role/eksctl-cluster-addon-iamserviceaccount-defaul-Role1-<suffix>
  labels:
    app.kubernetes.io/managed-by: eksctl
  name: app
  namespace: default
$ kubectl get pods
NAME                               READY   STATUS    RESTARTS   AGE
nginx-deployment-f99b956b6-bj5kf   1/1     Running   0          46m

03 / Experience

Experience

02/2019 - 08/2021

work

IT & Systems Engineer

Ivory

Windows and Linux servers, networking, POS, ERP, and inventory systems for a multi-site retail chain.

09/2021 - 02/2023

work

ERP Implementation Specialist

EMUSE Israel Ltd

SAP Business One implementations and integrations across 10 clients.

02/2023 - 06/2023

work

ERP Implementation & Analysis

Ziv Systems

ERP implementation and business process analysis.

10/2024 - 09/2025

work

Teaching Assistant (paid)

School of Hi-Tech, Bar-Ilan University

Taught Generative AI, Python, REST APIs, and Docker to 79 students, with 120 attendees at the flagship lecture.

02/2026 - 08/2026

education

DevOps Developer Expert

IITC College, Ramat Gan

Lohamim LeHightech track, in partnership with Atidim

Completed - 688 hours. Planned career transition into DevOps engineering following extended IDF reserve duty.

04 / Credentials

Credentials

Certifications

AWS Certified Solutions Architect - Associate (SAA-C03)
Amazon Web Services
Passed August 2026 - valid through August 2029 · 893 / 1000
DevOps Developer Expert Program
IITC College - Lohamim LeHightech track with Atidim
Completed 11 August 2026 - 688 hours · GPA 86.28
SAP Business One & Project Management Office (PMO)
SAP
2021

Education

B.A. Technology Management
Bar-Ilan University
10/2023 - 06/2026
Practical Engineer Diploma, Industrial & Management Engineering
Tel Aviv Academic College of Engineering
10/2019 - 08/2021 · Grade 90

Program results

DevOps Developer Expert, IITC College - 688 hours, completed August 2026. Lohamim LeHightech track in partnership with Atidim.

Programme GPA
86.28
Training hours
688
AWS SAA-C03
Certified

Recommendations

David does amazing things. He does amazing things and you can talk to him and consult with him, and everything he does is self-taught, which is amazing. After this course, you will have the ability to reach where David is today.
HYProf. Hanan Yaniv · Course Instructor - Generative AI · Bar-Ilan University
video ↗
David entered this field alone, it took him long months, but he entered it alone, and he's playing with it. You can consult with him. He does beautiful things, but he's one of 50, that's 2%.
HYProf. Hanan Yaniv · Course Instructor - Generative AI · Bar-Ilan University
video ↗

Operating rules

  1. 01An application is not code - it is a solution living inside an organization.
  2. 02Tech decisions are also organizational decisions.
  3. 03No change without a rollback path.
  4. 04Any system too open will be breached.
  5. 05What you don't need, don't use.
  6. 06Always think worst case.
  7. 07A requirement not defined correctly doesn't disappear - it comes back as bugs.
  8. 08Bug in code = incident. Bug in data = crisis.
  9. 09Code that works in dev is not necessarily production-ready.

Prior work

  • RAG Intelligence Platform ↗RAG observability showcase - 3D embedding space, knowledge graph, multi-model comparison
  • Personal Command Center + JARVIS RAG ↗Productivity dashboard with a multi-provider LLM assistant, offline-first single file
  • n8n Automation WorkflowsProduction n8n workflows on Docker with OAuth 2.0 integrations and custom nodes
  • Genspark RTL Toolbox ↗Chrome extension adding Hebrew/Arabic/Persian RTL support and chat export
  • AI Curriculum - Bar-Ilan UniversityGenerative AI, Python, REST APIs and Docker taught to 79 students, 120 at the flagship lecture

05 / Contact

Contact

Open to DevOps roles. Available immediately, based in Ramat Gan.