status: open to work · remote · 🇺🇸 🇨🇦 🇪🇺 time-zone overlap

Arkadiusz Tomala

$ whoami → Senior DevOps Engineer

I design, ship and run cloud platforms that don't page people at 3 AM. 15+ years in infrastructure — from building ISP fibre networks with BGP to operating multi-account AWS, Kubernetes and GitOps platforms for enterprise teams.

  • AWS SA
  • CKA
  • CKAD
  • GCP
scroll ↓
01

What you get when you apply me

An engineer who understands the whole stack — from the cable and the BGP session up to the Helm chart and the pull request.

~/career $ terraform plan

        
Portrait of Arkadiusz Tomala
arkadiusz@tomalait:~

It started with Pascal, Bash and the first servers I ran for my neighbourhood network. By 2009 I was building a wireless — and later fibre — ISP network with VLANs, BGP and multicast routing.

Then I met AWS and felt like a fish in water. Since then I've migrated data centres to the cloud (and, when it made financial sense, back again), automated delivery for dozens of teams and built platforms that let developers ship faster and safer.

Today I run my own consultancy, TomalaIT, helping companies design, migrate and operate their cloud and Kubernetes platforms.

0years in infrastructure
0cloud & k8s certifications
0public clouds in production
0infrastructure as code
02

$ git log --career

Every commit shipped to production.

  1. 5e19b0d (HEAD -> main) Dec 2013 — present

    Founder & Principal Cloud / DevOps Consultant @ TomalaIT

    • Built a multi-account AWS landing zone from scratch — Organizations, Control Tower, SCPs, IAM Identity Center, GuardDuty, Security Hub.
    • Operate EKS + Karpenter and ECS; GCP on GKE & Cloud Run; FinOps with Savings Plans, RIs and Spot.
    • Hybrid networking across AWS, GCP and on-prem — Direct Connect, Transit Gateway, Cloud Interconnect, HA VPN.
    • SRE & observability: SLOs, on-call, postmortems; OpenTelemetry, Prometheus, Grafana, Loki, on-prem OpenSearch.
    • DevSecOps: Trivy, Checkov, Kyverno/OPA, SBOM, cosign, Renovate; platform engineering with Backstage.
    • Work with AI agents and MCP servers — LLM-driven automation for cloud, Kubernetes and CI/CD.
    • Moved a crypto exchange from EKS to on-prem Kubernetes — significant cost savings.

    aws-landing-zone · eks · karpenter · gke · cloud-run · terraform · argocd · backstage · opentelemetry · devsecops · finops · ai-agents · mcp · bgp

  2. c02e8f4 Nov 2021 — Mar 2022

    DevOps Engineer @ Softkraft

    • Built dev / stage / prod AWS environments with Terraform + Terragrunt.
    • Designed a bastion-host security model isolating private infrastructure.
    • CI/CD from GitHub to ECR & ECS with automatic task-definition rollout.
  3. 9b4d7a1 Dec 2020 — Aug 2021

    DevOps Engineer @ Webanywhere

    • Migrated workloads to AWS and codified the infrastructure in Terraform.
    • Monitoring with Zabbix and Grafana; unblocked developers on infrastructure issues.
  4. 3d8a6e2 Dec 2018 — Dec 2020

    Systems & Network Administrator @ Polish Mining Group

    • Redesigned the corporate network with OSPF; managed Cisco / Juniper / MikroTik.
    • Modernised DHCP, DNS and NFS services and planned network growth.
  5. 7c41f09 Apr 2011 — Dec 2013

    Network Engineer @ Orange Poland

    • Provisioned, configured and maintained DSL / ADSL broadband services in a national carrier network.
    • Diagnosed and resolved access-network and connectivity faults with field and NOC teams.
  6. 0000001 Jan 2009 — Dec 2013

    Network Administrator @ Tech-LAN

    • Designed, built and managed WLAN and LAN networks — from planning to day-to-day operation.
    • Administered DHCP, DNS and FTP servers.
03

$ kubectl get pods -n skills

All pods healthy. Restarts are learning.

kubectl get pods -n skills -o wide
NAMEREADYSTATUSAGENODE
04

Verified credentials

Hands-on, exam-proven. Move your cursor over the cards.

Amazon Web Services

Solutions Architect

Associate

aws

CNCF · Linux Foundation

Kubernetes Administrator

CKA

k8s

CNCF · Linux Foundation

Kubernetes App Developer

CKAD

k8s

Google Cloud

Google Cloud Certified

GCP

gcp
05

Case studies — problem → fix → outcome

cost · kubernetes

Cloud repatriation for a crypto exchange

AWS EKSon-prem k8s

Moved a production exchange from EKS to a multi-node on-prem Kubernetes cluster, keeping the dev experience and cutting infrastructure spend significantly.

networking · hybrid

Data centre ↔ AWS hybrid network

DCDirect ConnectTGW

Connected a customer data centre to AWS with Direct Connect and advanced routing policies, separating public traffic from private resources.

delivery · gitops

From manual deploys to GitOps

PRGH ActionsArgo CD

End-to-end CI/CD from image build to QA-driven automated tests, with all infrastructure in Terraform — enabling parallel teams to release independently.

security · vpn

WireGuard edge with filtering DNS

clientWireGuardDNS filter

Private-network access for public apps with a proprietary filtering DNS layer, tuned hosts and full traffic monitoring.

governance · security

Multi-account AWS landing zone from scratch

OrganizationsControl TowerSCPs

Designed the account structure, SCP guardrails, IAM Identity Center SSO and a centralised security baseline with GuardDuty, Security Hub, CloudTrail and Config.

virtualisation · ha

High-availability private cloud

ProxmoxHAbackup

Proxmox cluster with high availability and dedicated backup storage for company-critical data.

06

Interview me in the shell

Type help. Try sudo hire arkadiusz.

guest@tomalait: ~

$ kubectl apply -f offer.yaml

Have a platform that needs a senior hand?

Open to full-time remote roles and B2B contracts with teams in the US, Canada and the EU. Happy to overlap with US Eastern hours.

All systems operationaluptime since 2009