A photograph of me, Kevin Gimbel, in front of a grey background

Hiya! I'm Kevin Gimbel

I'm a Senior DevOps Engineer working at AOE GmbH in Wiesbaden, Germany.

I've spent the last 15 years learning to build websites & run servers; worked in e-Commerce from 2013 to 2023, and started focusing on Platform Engineering in early 2023. Right now I'm part of a DevOps/Platform Team running and building a Kubernetes based Platform for multiple developer teams.

My main website is kevingimbel.de, and you can contact me via e-Mail at kevin@gimbel.dev

Skills, tools, and work stuff

🐝 Buzzwords: Cloud Computing Kubernetes Automation Monitoring

Cloud Computing 🌩

Computers! Computers! Computers! 👏

I've worked with Amazon Web Services since 2018.

Between 2018 and 2021 I was involved in planning and provisioning infrastructure for a microservice-based product called Konekti while working for Synoa GmbH.

Some areas I've experience with:

  • Elastic Kubernetes Services (EKS)
  • Elastic Compute Cloud (EC2)
  • Automatic resource tagging to monitor budgets
  • Security Groups and Ingress Control
  • AWS Load Balancers
  • VPC and subnet management

Linux 🐧

$ cowsay "moo I'm a cow"

I've worked with Linux since roughly 2012, both as Desktop OS and as server OS. I'm comfortable running Linux servers in production both in Cloud environments (AWS, Hetzner, etc.) as well as on-site using a Raspberry Pi (my home setup 😃).

I've used the following Linux distributions in production environments:

  • Debian and Ubuntu
  • CentOS
  • Amazon Linux 1 and 2
  • Raspberry Pi

Containers 🐳

"It's no use Mr., it's virtualization all the way down" 🐢

In 2017 I drove the initial adoption of Docker for local development at Synoa GmbH.

In the years following until I departet in 2023 we used Docker locally, in ECS, in TeamCity CI/CD pipelines, and as runtime on simple Ubuntu servers.

Some areas I've gained knowledge in over the years include:

  • Running CI/CD pipelines in containers
  • Multi-stage docker builds
  • Running Traefik in Production from 2018 to 2023
  • Distributing CLI tools as Docker containers
  • Deploying docker with Docker Remote API
  • Running production workloads with docker-compose

Kubernetes ⛵️

Since starting at AOE I deepend my knowledge of Kubernetes, working with multiple clusters, developing tools, and working with Developer Teams everyday. I've also started co-teaching the "Kubernetes 101" Workshop where a co-host and me give a introduction to Kubernetes concepts.

  • Elastic Kubernetes Services (EKS)
  • Helm Chart maintenance
  • Debugging with teams
  • Tools like k9s and stern
  • Kyverno
  • connaisseur
  • Istio

Monitoring 👀

Keeping tabs on everything

Proper monitoring is incredibly helpful in debugging, and should be implemented from the start.

Some monitoring tools I've maintained and used in production:

  • Prometheus
  • Thanos
  • Alertmanager
  • Grafana
  • Loki
  • node_exporter
  • blackbox_exporter
  • cadvisor
  • AWS Incident Manager
  • AWS CloudWatch metrics
  • AWS CloudWatch alarms

Automation 🦾

Predictability and reliability through automation and scripting

Setting up infrastructure in the cloud is lot of work and the more manual steps are involved, the more likely errors will be introduced.

Over the past years I've gained a lot of experience building, managing, and upgrading infrastructure with terraform and Ansible.

  • Terraform module creation and maintenance
  • Ansible role creation and maintenance
  • Terraform integration with CI/CD pipelines
  • Handling of breaking infrastructure changes
  • Maintenance of Helm Charts
  • Custom tooling in Python, Go, and Rust

Terraform 🤖

I 🧡 Terraform (... and OpenTofu!)! I've experience with the creation and maintenance of complex modules that integrate various different services, including the following technologies

  • AWS VPC and subnets
  • AWS VPC networking & routing
  • AWS EC2 servers
  • AWS EC2 Auto-scaling groups
  • AWS Security Groups and ingress rules between servers, including ingress across AWS accounts
  • AWS Route 53 domains and sub-domains
  • AWS ECS clusters and services
  • AWS S3 buckets and access policies
  • AWS IAM users for S3 access
  • MongoDB Atlas Cloud
  • MongoDB Atlas Cloud and AWS VPC peering connections
  • Hetzner Cloud

Security 🔐

◼︎◼︎◼︎◼︎◼︎ ◼︎◼︎ ◼︎◼︎◼︎◼︎◼︎ ◼︎◼︎◼︎◼︎ ◼︎◼︎◼︎◼︎◼︎◼︎◼︎◼︎◼︎ ◼︎◼︎◼︎◼︎◼︎

Security must be considered from the start. Period.

Don't give all-access to a entity because it's easy. Don't open all ports because it's easy. Don't run your code as root because it's easy.

Some rules I follow:

  • Zero Trust principal
  • Encrypt data at rest and in-transit
  • Use password managers
  • Always use random, auto-generated passwords
  • Integration with Single-Sign On wherever possible
  • Never share passwords in plain-text

Contact 💌

Well, well, well, ... you've reached the end of this very lovely and pretty ✨cool✨ website.

If you want to connect with me, hit me up on:

If you write me on LinkedIn or request to connect please be patient: I get a lot of messages and catch up only once a week!

While this page is more like a fancy vCard, I do publish lots of things on my main website at kevingimbel.de. Check it out!