Antoine Barthelemy
Kubernetes & Cloud Specialist
Summary
I thrive in environments where talented people collaborate respectfully, focusing on the best technical outcome rather than personal agendas. I’m looking for a long-term home with a team that shares this principle.
Kubernetes: All certifications and 6 years of at-scale experience (cloud & on-premise)
Infrastructure as Code: 6 years of at-scale experience (cloud & bare-metal)
Application Build & Security: 6 years of experience
Database Cluster Management: 2 years of experience with high-throughput systems
Professional Experience
Swan
- Worked short-term within a team of 4 platform engineers within a 300-person company undergoing significant restructuring
- Improved base images, eliminating all CVEs and reducing size (~1.5GB to ~200MB) using distroless techniques
- Cut Kubernetes node disk usage by approximately 60%
- Migrated pipelines from GitLab CI to GitHub CI
- Refactored critical Terraform IaC modules for GitHub, Vault, and IAM avoiding drift
- Developed an internal CLI tool to automate environment setup and streamline developer onboarding
Technologies: AWS, Kubernetes, Terraform, Terragrunt, GitHub Actions, Wiz
PrestaShop
- Led the strategic planning and execution of the infrastructure security roadmap
- Promoted DevOps best practices, focusing on secure deployments and architecture
- Improved monitoring with OpenTelemetry
- Orchestrated application migration to a new infrastructure, improving scalability, security, and reduced costs
- Optimized CI/CD pipelines and developed an open-source Go tool for Terraform/Terragrunt lock and module versioning
- Migrated Terraform to Terragrunt, modularizing IaC
Technologies: GCP, Go, Kubernetes, Terraform, Terragrunt, GitHub Actions, OpenTelemetry, Falco, Trivy, Wiz
Hublo
- Worked alongside two SREs within a 30-member engineering team
- Set up and scaled Kubernetes clusters on AWS using Pulumi for staging and production environments, followed by the migration of the ECS cluster to Kubernetes namespaces
- Deployed an SFTP server, a CRM, several web applications, and data applications using Pulumi and Helm, and improved build times for legacy applications
- Streamlined and secured networking in our AWS accounts by implementing appropriate security groups, peerings, and TLS. This also reduced costs and made the infrastructure easier to manage
- Automated the deployment of Snowflake and Metabase using Terraform, created Helm charts, and established a CI/CD pipeline for the data engineering team
- Deployed CDNs for the frontend applications
- Configured a Network Load Balancer to handle both layer 4 and layer 7 traffic for services
- Contributed to open-source efforts, including the sftpgo/helm-chart
Technologies: AWS, ArgoCD, Datadog, GitHub Actions, Helm, Kubernetes, Pulumi, Postgresql
Freelance (6Wind, Lengow)
- 6Wind a Cisco competitor (8 weeks), Contributed to a testing framework in Python and C to assess the load and functionality of a router OS. Executed tests on-premise using Ansible and KVM for durations of up to 8 hours
- Lengow a B2B marketplace feed management company (4 weeks), I co-designed a scalable AWS cloud infrastructure to support feature deployment, set up CI/CD services, and automated software release processes
- Additionally, I contributed to open-source projects like OpenTofu during this period
Technologies: AWS, Ansible, C, Github Actions, Kubernetes, KVM, Python, Terraform
Contentsquare
- As the most junior member of a 20+ platform engineering team in a 300+ person R&D department, I helped deploy and maintain key infrastructure technologies, including Kubernetes, Ansible, Terraform, Spinnaker, and GitHub Actions
- Migrated numerous Jenkins pipelines to GitHub Action workflows
- Led the refactoring of the Clickhouse Ansible deployment from Python 2.7 to Python 3.8 and built Ansible collections
- Created a Terraform provider for Pritunl VPN
- Worked on a proof of concept to implement Spinnaker, facilitating git-based workflows for creating and updating Managed Delivery configurations
- Developed a Python wrapper for Netflix Dispatch to enable quick deployment and scaling within our infrastructure as part of a proof of concept, serving as a replacement for PagerDuty
- Took an active role in managing multi-cloud deployments across Azure and AWS, optimizing cloud resources to ensure high availability
- Worked alongside developers to support feature rollouts, troubleshoot issues, and keep services running smoothly
- Contributed to several open-source projects, including Dispatch Netflix, Kibana Elasticsearch, Pritunl, Tfam, and Tfexe
Technologies: Ansible, AWS, Azure, Datadog, Github Actions, Go, Grafana, Helm, Jenkins, Kubernetes, PagerDuty, Prometheus, Python, Terraform, Vault
SII
- As the only DevOps engineer supporting a team of 12 developers, I managed four GKE clusters (about 5 nodes each), handling ~300 simultaneous users and maintaining their CI/CD pipelines for Brittany Ferries
- Led the migration of four terraformed GKE clusters to new infrastructure, incorporating FluxCD, ConfigConnector, Istio, Google KMS, and Sops
Technologies: FluxCD, GCP, GitlabCI, Istio, Kubernetes, Kustomize, SOPS, Terraform
CIL
- From intern to employee, as part of a team of 2 system administrators and 11 developers within an in-house data-center
- Deployed a Kubernetes cluster on bare metal servers with HAProxy, Heartbeat and MetalLB using Ansible
- Upgraded VMware vSphere on all servers to enable Kubernetes Datastore support via VMware CNS API and CSI driver integration
- Automated OSRM map builds, containerizing and deploying them on Kubernetes for scalability
- Deployed 3CX VoIP, maintained all Linux virtual machines and their associated services
- Contributed to open-source projects, including Rust-lang and Mattermost
Technologies: Ansible, Bash, Centreon, Docker, Kubernetes, Linux, Rust, SQL, VMWare
Certifications
- Kubestronaut July 2025
- Certified Kubernetes Application Developer (CKAD) July 2025
- Certified Kubernetes Security Specialist (CKS) July 2025
- Kubernetes and Cloud Native Associate (KCNA) July 2025
- SKF100: Understanding the OWASP Top 10 Security Threats July 2025
- LFC108: Cybersecurity Essentials June 2025
- LFS157: Introduction to Serverless on Kubernetes June 2025
- NVIDIA-Certified Associate: AI Infrastructure and Operations June 2025
- Kubernetes and Cloud Native Security Associate (KCSA) November 2024
- Remote Work at Scale (LFC114) November 2024
- 42 Cursus Advanced Developer Level 18 November 2023
- Certified Kubernetes Administrator (CKA) September 2024
- LFS266 DevOps for Network Engineers September 2023
- LFS261 DevOps and SRE Fundamentals - Implementing Continuous Delivery September 2023
- LFS244 Managing Kubernetes Applications with Helm March 2024
- SC104 Developing Helm Charts March 2024
- LFEL2001 Interacting with REST and HTTP-based APIs March 2024
- HashiCorp Certified Terraform Associate (003) May 2023
- LFS169 Introduction to GitOps April 2022
- LFS253 Containers Fundamentals April 2022