I design and automate the environments your product lives on — from the first Dockerfile, through a CI/CD pipeline, to Kubernetes on Google Cloud. I also write the code that ties it all together.
Five areas, one rule: everything I build can be recreated from a repository and understood without me.
01CI/CDPipelines you can trust
Tests, security scans, builds and deployments in Jenkins or GitHub Actions. Every change takes the same path, production gets exactly the image that was verified, and rolling back doesn’t require a midnight rescue mission.
Jenkins
GitHub Actions
Argo CD
02ContainersAn app that runs the same everywhere
I package your application in a container so it behaves identically on a laptop, a server and in the cloud — no more “works on my machine”. Lean, secure images (no root privileges), and when the project grows, Kubernetes keeps the service available on its own.
Docker
Kubernetes
Kustomize
03CloudGoogle Cloud without the chaos
Google Cloud infrastructure described in Terraform: network, GKE cluster, Cloud SQL, Pub/Sub, Cloud Storage and IAM. You can rebuild the whole environment from a repository, every service gets only the permissions it needs, and secrets live in Secret Manager, not in code.
Google Cloud
Terraform
GKE
IAM
04MonitoringSee the problem before your customer does
Metrics and alerts that actually mean something: latency, errors, saturation. Plus security built into the process — image and infrastructure scans on every change, and policies that block unsafe configuration before it reaches the cluster.
Prometheus
Trivy
Checkov
Kyverno
05DevelopmentCode that holds it together
Backend services and APIs in Java (Spring Boot), business logic, process automation, integrations between systems and smaller tools that take repetitive manual work off your team.
Java
Spring Boot
TypeScript
SQL
REST API
02 / Packages
Clear scope, known price
Instead of an open-ended engagement you can start with a package that has a clearly defined outcome. I confirm scope and price after a short call — before any work starts.
P1
Docker & CI/CD on your VPS
For whomYour app runs on your own VPS (OVH, Hetzner or similar) and you deploy it by hand over SSH — or it “somehow works”.
What you get
your app in a Docker container (lean image, no root privileges) with docker compose
nginx as a reverse proxy, HTTPS and security headers
automatic deployment from GitHub Actions on every change, with a health check and rollback to the previous version
a how-to: deploying, rolling back and checking logs
Scope and price confirmed in writing before we start — no surprises on the invoice.
If the result doesn’t match the package description, I fix it at no extra cost.
I’ll sign an NDA on request before getting access to your systems.
I work with access you can revoke at any time.
Indicative prices for a typical scope. Something unusual? Describe it — I’ll send a custom quote within 48 hours.
Google Cloud✳Kubernetes✳Docker✳Terraform✳Jenkins✳GitHub Actions✳Argo CD✳Kyverno✳Trivy✳Prometheus✳Linux✳Nginx✳Java✳Spring Boot✳TypeScript✳
Google Cloud✳Kubernetes✳Docker✳Terraform✳Jenkins✳GitHub Actions✳Argo CD✳Kyverno✳Trivy✳Prometheus✳Linux✳Nginx✳Java✳Spring Boot✳TypeScript✳
03 / Protocol
How I work
01
First contact
A short conversation about what you want to achieve and a calm look at what already works. No commitment — at the end you know what is worth doing first.
02
Plan
Concrete scope, milestones and a quote. You know what you pay for and when you get it.
03
Quick wins
I fix what hurts most first — so you see a concrete improvement in the first days, before we move on to bigger changes.
04
Delivery
Small, reversible steps. Everything in the repository, every change visible in history.
05
Handover
Documentation, runbooks and a short training. The infrastructure stays yours, not mine.
Standards I stick to
R1Everything as code
R2Least privilege, always
R3No passwords or keys in the repository
R4Docs are part of the delivery
R5No dependency on a single person
04 / Projects
Projects
WL-01Google Cloud · own projectOwn project · open source
Image processing platform on GCP — without a single static key
A complete, event-driven platform: an API accepts uploads and an independent worker processes them in the background via Pub/Sub. Built the way production systems are built — with a focus on security, repeatability and an honestly documented scope.
push
test
scan
build
digest
argo cd
Architecture
Two Java 21 (Spring Boot) services on a private GKE cluster. The job and its event are written in one transaction (transactional outbox pattern), so no request gets lost between the database and the queue. Failed messages go to a dead-letter topic instead of retrying forever.
Infrastructure & delivery
Everything in Terraform (modules: network, GKE, Cloud SQL, IAM, Pub/Sub, Storage, Secret Manager, Artifact Registry), dev and prod environments. GitHub Actions tests, scans (Trivy, Checkov) and builds the images; Argo CD deploys them the GitOps way. Production runs an image pinned by its immutable digest.
Security
Workload Identity instead of keys — CI included. Each service has its own least-privilege account. Network is closed by default (NetworkPolicy), and Kyverno in Enforce mode blocks root containers, missing resource limits and :latest tags. Prometheus alerts on errors, latency and restarts.
More projects — including a multi-environment Jenkins pipeline on GKE — are already on my GitHub. The write-up will appear here soon.
05 / About
Who is behind whiteitlab
I’m Piotr Białas. I’ve been working in IT since 2022 — I started in technical support and administration, and today I develop business logic and automation in a web application running in production, prepare releases and help with diagnostics. I also administer Linux servers and networking.
After hours I build complete cloud projects on Google Cloud: infrastructure in Terraform, Kubernetes (GKE), CI/CD in Jenkins and GitHub Actions, and GitOps with Argo CD. All the code is public — you can see how I work before you get in touch.
whiteitlab is my brand for smaller DevOps and software projects. I’m at the start of my commercial DevOps path, so I take on work where I can deliver a concrete, verifiable result — and I’m upfront about what I haven’t done yet.
Experience
IT since 2022 · releases, automation, Linux administration
Education
BEng in IT · Master’s in information systems security (in progress)
How much does CI/CD or moving an app to the cloud cost?
Typical scopes have a fixed “from” price — see the Packages section (e.g. a CI/CD pipeline from €500). I confirm the final price after a short call and review, before anything starts. For unusual projects I send a custom quote within 48 hours.
Q2
What does working together look like?
We start with a short call and a review of where things stand. Then you get a plan with scope and a quote split into milestones. I work remotely, in your repository and your cloud accounts — with access you can revoke at any time. After each milestone I show the result, and at the end I hand over the documentation.
Q3
What technologies do you work with?
Google Cloud (GKE, Cloud SQL, Pub/Sub, Cloud Storage, IAM, Secret Manager), Terraform, Docker and Kubernetes (Kustomize), Jenkins and GitHub Actions, Argo CD, Kyverno, Trivy and Checkov, Prometheus, Linux and nginx. On the code side: Java (Spring Boot), TypeScript, SQL and REST APIs.
Q4
Can you clean up an existing environment?
Yes. I start by reviewing and documenting the current state, then clean it up in small, reversible steps — so you can always go back to the previous version instead of rewriting everything from scratch.
Q5
What do I get when the project is finished?
All configuration as code in your repository, documentation, runbooks for common incidents and a short training for your team. The infrastructure is fully yours — no dependency on a single person or vendor.
Q6
Do you also build applications, not just infrastructure?
Yes, mostly backend: services and APIs in Java (Spring Boot), business logic, process automation, integrations and SQL databases. Day to day I develop the logic of an application running in production. I don’t take on large frontend applications — a frontend specialist will serve you better there.
Q7
Do I need Kubernetes?
Often not. With one or two applications, Cloud Run or a VM with Docker is usually enough — cheaper and simpler to maintain. Kubernetes pays off when you run many services, need autoscaling or several environments. I’ll tell you honestly what makes sense in your case.
Q8
Do you work with AWS or Azure?
My specialisation is Google Cloud — that’s where my complete, public projects are. I know Azure at a fundamentals level, and tools like Terraform, Docker, Kubernetes and Jenkins work the same in every cloud. For a project on another cloud I’ll tell you honestly whether it’s a fit.
07 / Contact
Tell me what needs building.
A few sentences are enough. I reply within one business day and send an initial quote within 48 hours.