DevOps · Google Cloud · Backend

Infrastructure that won’t wake you up at 3 a.m.

I design and automate the environments your product lives on — from the first Dockerfile, through a CI/CD pipeline, to Kubernetes on Google Cloud. I also write the code that ties it all together.

pipeline — productionlive
  1. $ git push origin main
  2. → pipeline #482 started
  3. ✓ lint & test12.4s
  4. ✓ build image41.0s
  5. ✓ trivy scan0 critical
  6. ✓ push ghcr.iosha256:9f2c…
  7. ✓ deploy (rolling)3/3 healthy
  8. ✓ smoke testspassed
  9. ● production @ v2.14.0 — 0 downtime
Model
one-person lab
Location
Poland · remote
Reply
1 business day · quote in 48 h
Status
taking on work

01 / Services

What I do

Five areas, one rule: everything I build can be recreated from a repository and understood without me.

01 CI/CD Pipelines you can trust

Tests, security scans, builds and deployments in Jenkins or GitHub Actions. Every change takes the same path, production gets exactly the image that was verified, and rolling back doesn’t require a midnight rescue mission.

  • Jenkins
  • GitHub Actions
  • Argo CD
02 Containers An app that runs the same everywhere

I package your application in a container so it behaves identically on a laptop, a server and in the cloud — no more “works on my machine”. Lean, secure images (no root privileges), and when the project grows, Kubernetes keeps the service available on its own.

  • Docker
  • Kubernetes
  • Kustomize
03 Cloud Google Cloud without the chaos

Google Cloud infrastructure described in Terraform: network, GKE cluster, Cloud SQL, Pub/Sub, Cloud Storage and IAM. You can rebuild the whole environment from a repository, every service gets only the permissions it needs, and secrets live in Secret Manager, not in code.

  • Google Cloud
  • Terraform
  • GKE
  • IAM
04 Monitoring See the problem before your customer does

Metrics and alerts that actually mean something: latency, errors, saturation. Plus security built into the process — image and infrastructure scans on every change, and policies that block unsafe configuration before it reaches the cluster.

  • Prometheus
  • Trivy
  • Checkov
  • Kyverno
05 Development Code that holds it together

Backend services and APIs in Java (Spring Boot), business logic, process automation, integrations between systems and smaller tools that take repetitive manual work off your team.

  • Java
  • Spring Boot
  • TypeScript
  • SQL
  • REST API

02 / Packages

Clear scope, known price

Instead of an open-ended engagement you can start with a package that has a clearly defined outcome. I confirm scope and price after a short call — before any work starts.

P1

Docker & CI/CD on your VPS

For whomYour app runs on your own VPS (OVH, Hetzner or similar) and you deploy it by hand over SSH — or it “somehow works”.

What you get

  • your app in a Docker container (lean image, no root privileges) with docker compose
  • nginx as a reverse proxy, HTTPS and security headers
  • automatic deployment from GitHub Actions on every change, with a health check and rollback to the previous version
  • a how-to: deploying, rolling back and checking logs
Delivery time
3–7 business days
Price
from €400
Package details Ask about this package
P2

CI/CD pipeline

For whomYou have an app in a repository, but deployments are manual or the pipeline is unreliable.

What you get

  • a Jenkins or GitHub Actions pipeline: tests → build → deploy
  • security scan of code and image (Trivy) on every change
  • automatic rollback when a deployment fails
  • documentation and a how-to for your team
Delivery time
5–10 business days
Price
from €500
Package details Ask about this package
P3

Your app on Google Cloud

For whomYou want to launch or move an application to the cloud without manual clicking in the console.

What you get

  • containerised application (lean image, no root privileges)
  • infrastructure in Terraform: Cloud Run or GKE, database, network, permissions
  • secrets in Secret Manager, a separate account for each service
  • documentation: how to rebuild and extend the environment
Delivery time
7–15 business days
Price
from €600
Package details Ask about this package

How I work with clients

  • Scope and price confirmed in writing before we start — no surprises on the invoice.
  • If the result doesn’t match the package description, I fix it at no extra cost.
  • I’ll sign an NDA on request before getting access to your systems.
  • I work with access you can revoke at any time.

Indicative prices for a typical scope. Something unusual? Describe it — I’ll send a custom quote within 48 hours.

Google CloudKubernetesDockerTerraformJenkinsGitHub ActionsArgo CDKyvernoTrivyPrometheusLinuxNginxJavaSpring BootTypeScript

03 / Protocol

How I work

  1. 01

    First contact

    A short conversation about what you want to achieve and a calm look at what already works. No commitment — at the end you know what is worth doing first.

  2. 02

    Plan

    Concrete scope, milestones and a quote. You know what you pay for and when you get it.

  3. 03

    Quick wins

    I fix what hurts most first — so you see a concrete improvement in the first days, before we move on to bigger changes.

  4. 04

    Delivery

    Small, reversible steps. Everything in the repository, every change visible in history.

  5. 05

    Handover

    Documentation, runbooks and a short training. The infrastructure stays yours, not mine.

Standards I stick to

  • R1Everything as code
  • R2Least privilege, always
  • R3No passwords or keys in the repository
  • R4Docs are part of the delivery
  • R5No dependency on a single person

04 / Projects

Projects

WL-01 Google Cloud · own project Own project · open source

Image processing platform on GCP — without a single static key

A complete, event-driven platform: an API accepts uploads and an independent worker processes them in the background via Pub/Sub. Built the way production systems are built — with a focus on security, repeatability and an honestly documented scope.

Architecture

Two Java 21 (Spring Boot) services on a private GKE cluster. The job and its event are written in one transaction (transactional outbox pattern), so no request gets lost between the database and the queue. Failed messages go to a dead-letter topic instead of retrying forever.

Infrastructure & delivery

Everything in Terraform (modules: network, GKE, Cloud SQL, IAM, Pub/Sub, Storage, Secret Manager, Artifact Registry), dev and prod environments. GitHub Actions tests, scans (Trivy, Checkov) and builds the images; Argo CD deploys them the GitOps way. Production runs an image pinned by its immutable digest.

Security

Workload Identity instead of keys — CI included. Each service has its own least-privilege account. Network is closed by default (NetworkPolicy), and Kyverno in Enforce mode blocks root containers, missing resource limits and :latest tags. Prometheus alerts on errors, latency and restarts.

static keys or passwords
0
Terraform modules
9
Kyverno policies (Enforce)
5
  • Java 21
  • Spring Boot
  • GKE
  • Pub/Sub
  • Cloud SQL
  • Terraform
  • GitHub Actions
  • Argo CD
  • Kyverno
  • Trivy
  • Checkov
See the code on GitHub
WL-02 Reserved slot

The next project lands here

More projects — including a multi-environment Jenkins pipeline on GKE — are already on my GitHub. The write-up will appear here soon.

05 / About

Who is behind whiteitlab

I’m Piotr Białas. I’ve been working in IT since 2022 — I started in technical support and administration, and today I develop business logic and automation in a web application running in production, prepare releases and help with diagnostics. I also administer Linux servers and networking.

After hours I build complete cloud projects on Google Cloud: infrastructure in Terraform, Kubernetes (GKE), CI/CD in Jenkins and GitHub Actions, and GitOps with Argo CD. All the code is public — you can see how I work before you get in touch.

whiteitlab is my brand for smaller DevOps and software projects. I’m at the start of my commercial DevOps path, so I take on work where I can deliver a concrete, verifiable result — and I’m upfront about what I haven’t done yet.

Experience
IT since 2022 · releases, automation, Linux administration
Education
BEng in IT · Master’s in information systems security (in progress)
Focus
Google Cloud · Kubernetes · CI/CD · Java
Languages
Polish · English (B2)
github.com/Pioti2252

06 / FAQ

Frequently asked questions

Q1

How much does CI/CD or moving an app to the cloud cost?

Typical scopes have a fixed “from” price — see the Packages section (e.g. a CI/CD pipeline from €500). I confirm the final price after a short call and review, before anything starts. For unusual projects I send a custom quote within 48 hours.

Q2

What does working together look like?

We start with a short call and a review of where things stand. Then you get a plan with scope and a quote split into milestones. I work remotely, in your repository and your cloud accounts — with access you can revoke at any time. After each milestone I show the result, and at the end I hand over the documentation.

Q3

What technologies do you work with?

Google Cloud (GKE, Cloud SQL, Pub/Sub, Cloud Storage, IAM, Secret Manager), Terraform, Docker and Kubernetes (Kustomize), Jenkins and GitHub Actions, Argo CD, Kyverno, Trivy and Checkov, Prometheus, Linux and nginx. On the code side: Java (Spring Boot), TypeScript, SQL and REST APIs.

Q4

Can you clean up an existing environment?

Yes. I start by reviewing and documenting the current state, then clean it up in small, reversible steps — so you can always go back to the previous version instead of rewriting everything from scratch.

Q5

What do I get when the project is finished?

All configuration as code in your repository, documentation, runbooks for common incidents and a short training for your team. The infrastructure is fully yours — no dependency on a single person or vendor.

Q6

Do you also build applications, not just infrastructure?

Yes, mostly backend: services and APIs in Java (Spring Boot), business logic, process automation, integrations and SQL databases. Day to day I develop the logic of an application running in production. I don’t take on large frontend applications — a frontend specialist will serve you better there.

Q7

Do I need Kubernetes?

Often not. With one or two applications, Cloud Run or a VM with Docker is usually enough — cheaper and simpler to maintain. Kubernetes pays off when you run many services, need autoscaling or several environments. I’ll tell you honestly what makes sense in your case.

Q8

Do you work with AWS or Azure?

My specialisation is Google Cloud — that’s where my complete, public projects are. I know Azure at a fundamentals level, and tools like Terraform, Docker, Kubernetes and Jenkins work the same in every cloud. For a project on another cloud I’ll tell you honestly whether it’s a fit.

07 / Contact

Tell me what needs building.

A few sentences are enough. I reply within one business day and send an initial quote within 48 hours.

Rather see the code first? Repositories, tools and experiments from the lab. github.com/Pioti2252

OFFLINE The contact form is temporarily disabled — it will be back soon. In the meantime, have a look at my GitHub. github.com/Pioti2252

What is it about
0 / 5000

The data controller is Piotr Białas (whiteitlab). Your data is used only to reply to your inquiry. Privacy policy