# whoami

DevOps Engineer building data and AI infrastructure that survives production.

I work where architecture meets the shell prompt - data warehouse / data-lake platforms, high-performance AI inference pipelines, and the Python and Bash tooling that keeps them running. I lead a small team of engineers, contribute hands-on to the implementation, and spearhead the DevOps practices of my department.

Bias toward decoupled, stateless, fault-tolerant design, reproducible infrastructure, and keyboard-first tooling that needs no babysitting. I build for real constraints: air-gapped environments, least privilege, GitOps ownership, and the enterprise overhead everyone pretends isn't there.

Israel - Ramat Gan · Meitar Learning + Having fun! 2.5 years

## stack

languages
GoPython TypeScript / Node.jsBashPowershell
ai_infra
Ollama vLLMNVIDIA Triton Whisper (STT)Pyannote (diarization) OCR pipelines
devops tools
Kubernetes HelmDocker MinikubeTerraformGit
observability
PrometheusGrafana ELK StackOpenSearchSplunk
cloud & hosting
GCPAWSOpenShift
ci/cd tools
GitLab CI/CDCloud Build Google Cloud BuildGitHub ActionsArgo CD
Operating Systems
Arch LinuxUbuntu Windows
data and streaming
KafkaksqlDB Redis StreamsPostgreSQL

## projects # selected public work

capture

Go

Static-analysis CLI that catches the drift between environment variables declared in .env / Dockerfiles and the ones actually referenced in source across Go, Python, JS/TS. Pattern-based instead of full AST parsing - deterministic output and streaming file reads so it drops straight into CI without slowing the pipeline.

Gostatic analysis CLICI/CD
★ 2updated 2026-05

my-ai-brain

Python

A self-hosted RAG stack that turns a WhatsApp export into an Obsidian knowledge vault - per-contact and per-project summaries, a relationship graph, and queryable retrieval. The batch processor keeps SQLite as its source of truth and pins one resident model on an 8 GB GPU, so ingestion is resumable and the whole thing runs on homelab hardware.

PythonRAG OllamaQdrant WhisperDocker Compose
★ 0updated 2026-06

ETL that pulls the full Magic: The Gathering universe from the Scryfall API and Scryfall Tagger into a normalized Postgres schema (sets → oracle cards → printings → faces, plus community tags/relationships). Split extractor / transformer / loader layers and a containerized job process make it a clean base for analytics or LLM training data.

PythonETL PostgreSQLScryfall API Docker Compose
★ 0updated 2026-06

Production-grade Terraform for a hardened Tailscale exit node on AWS: zero inbound rules, SSM Session Manager instead of SSH, IMDSv2 enforced, encrypted EBS, and a least-privilege IAM role that can read only the auth key. Secrets live in Secrets Manager and never touch Terraform state or instance logs.

TerraformAWS Tailscaleleast privilege IaC
★ 0updated 2026-06

## how_i_work

State lives in storage, not memory

For batch and microservice workloads I push wait-state and system state out of process into durable storage (e.g. GCS) so a pod eviction or crash never costs data integrity. Decoupled, stateless, fault-tolerant by default.

Pragmatic infrastructure over ideology

I engineer around real organizational and bureaucratic constraints - reaching for a GCS-backed state flow when Cloud Tasks or Cloud Workflows add more friction than value. The design that ships and holds up wins.

Enterprise- and air-gap-aware by design

Air-gapped environments, internal registries, least privilege, CI/CD ownership, and GitOps compatibility are inputs to the architecture, not afterthoughts. Helm over ad-hoc YAML, containers over host installs, declarative over imperative.

Production readability over cleverness

Small, focused services with clear separation of concerns and no magic behavior. I plan for failure modes, observability, rollout and rollback from the start - reproducibility and automation over one-off heroics.

## contact

Open to conversations about platform engineering, AI infrastructure, and internal developer platforms.