← Back to site

Patrick de Ruiter

Senior Platform Engineer

Profile

Experienced Senior Platform Engineer with over 25 years of IT experience, specialised in cloud-native infrastructure, Kubernetes and Infrastructure as Code. Proven track record designing and implementing scalable platforms, observability solutions and security-first architectures. Expertise in transforming traditional infrastructures into modern, automated environments with focus on the HashiCorp stack, Terraform, Ansible and container orchestration.

Experience

Senior Platform Engineer · Benerail

Nov 2022Present

  • Own the platform engineering stack across a primary + DR on-prem datacenter setup, Terraform, Packer images and Ansible roles deploy identically to both sites, with Vault and observability replicated for failover. Introduced Terraform as the IaC standard. Designed and shipped a Prometheus/Grafana observability platform. Built golden-image lifecycle management with Packer. Automated VMware vSphere provisioning with Ansible + Terraform. Migrated the estate from RHEL 8 to RHEL 9 with SELinux enforcing as the platform standard. Designed an end-to-end certificate management system using Terraform, Let's Encrypt, Event Driven Ansible and HashiCorp Vault — including a custom Go module for the DNS-01 challenge. Professionalized the on-prem Kubernetes platform. Deployed Databricks on Azure with Terraform and stood up Azure ↔ on-prem VPN. Implemented Ansible Automation Platform for centralised automation, including a
  • self-hosted Ansible Galaxy-NG for distributing internal collections.
  • Designed and implemented Keycloak and Hashicorp Vault sollution for Kubernetes and portal authentication using OIDC,SAML and 2FA, that integrated with the existing IaM systems Red Hat Idm, and Microsoft Entra ID.

Proudest of: Implemented a certificate management solution that automatically generated a certificate when a VM was provisioned, stored the certificate in Hashicorp Vault, then Triggered a web hook that would execute a run-book on EDA that would run an Ansible playbook that would install and configure the Vault agent on the host so that it could automatically pull the certificate from the Vault server and deploy it on the VM. When the certificate was renewed and stored in the Vault server, the Vault agent would automatically fetch the new certificate and install it.

Senior Cloud Infrastructure Engineer · DeltaFiber

Mar 2022Oct 2022

  • Hybrid-cloud platform engineering at a multi-DC ISP — designed and implemented an Azure Kubernetes Service (AKS) platform from scratch, including all Terraform modules, federated with the existing on-prem datacenters.
  • Deployed HashiCorp Consul for service discovery and mesh spanning the hybrid estate, and design and deploy an IaM solution based on HashiCorp Vault for secrets management and Microsoft Entra ID for user group and role management across both Azure and on-prem environments.
  • Introduced Terraform as the IaC standard.

Lead CI/CD Engineer · Sanoma Learning

Apr 2020Mar 2022

  • Migrated applications from conventional stacks to Kubernetes on EKS.
  • Phased out Red Hat Satellite as the estate moved to cloud + Kubernetes.
  • Standardized RHEL AMI images, built automatically with Packer + Ansible — updating an EC2 image became a one-click redeploy.
  • Owned deployment pipelines on Jenkins and Bitbucket Pipelines.
  • Selected and implemented Datadog as the monitoring solution.
  • Embedded security and compliance procedures in CI/CD.
  • Designed Docker base images for application teams.
  • Maintained the AWS environment via CloudFormation and Terraform.

Cloud Infrastructure Engineer · CarNext

Jan 2019Apr 2020

  • Migrated CarNext out of Leaseplan AWS accounts into dedicated ones.
  • Designed and shipped the EKS cluster using Terraform + GitLab CI/CD.
  • Replaced CloudFormation with Terraform.
  • Built a CI/CD toolkit for ECS deployments, later extended for Kubernetes.
  • Implemented Kong API Gateway, OpenVPN for secure access, and templated git repositories.
  • Configured cross-account IAM roles in a multi-account AWS setup.
  • Rolled out AWS Transit Gateway to replace VPC peerings.
  • Implemented GuardDuty, Config and CloudTrail in a central audit account.

Cloud Infrastructure Engineer · TNT Digital

Apr 2018Dec 2018

  • Managed production Kubernetes clusters.
  • Upgraded and operated OTAP environments running Adobe AEM CMS for the company portal.
  • Rewrote Terraform modules for AEM EC2 instances on AWS.
  • Refactored the Ansible codebase.
  • Created and maintained Helm charts plus Docker / Docker Compose configurations.
  • Operated Jenkins servers and embedded developers into the CI/CD flow.
  • Ran a federated Prometheus + Grafana setup.
  • Scripted ETCD backup via a oneshot Kubernetes container.
  • Wired Alertmanager into Slack and PagerDuty.

Cloud Specialist · TripleIT

Feb 2018Mar 2018

  • Short engagement: designed and built a multi-tier web application framework.
  • Translated customer requirements into technical design and produced the LLD from the HLD.

Senior Linux Infrastructure Specialist · SSC-I Dienst Justitiële Inrichtingen

Jan 2017Dec 2017

  • Deployed and managed RHEL systems via Red Hat Satellite 6.
  • Automated VM deployments to VMware vSphere via Satellite.
  • Automated operations using Ansible and Puppet.
  • Migrated RHEL 5/6 systems to RHEL 7.
  • Introduced GitFlow for structured version control.

Senior Unix Infrastructure Specialist · Tele2

Jun 2016Dec 2016

  • Operated a heterogeneous fleet (Red Hat, CentOS, Debian, Ubuntu, Solaris, HP-UX) across two active/active datacenters.
  • Deployed DTAP environments for application development.
  • Wrote and extended Puppet modules.
  • Managed and configured DNS infrastructure (BIND, PowerDNS, Unbound).

Senior Linux Infrastructure Consultant · Nationale Nederlanden Investment Partners

Mar 2014Jun 2016

  • Owned Linux infrastructure across two active/active datacenters.
  • Upgraded all RHEL 5 nodes to RHEL 6.
  • Designed and implemented CFEngine for configuration management, including Operational Security Guidelines (OSG) policy.
  • Enabled SELinux in enforcing mode across the entire fleet and authored / modified targeted-policy modules so every service (Tomcat, Tibco, Apache, the in-house Java apps) ran cleanly without permissive fallback.
  • Automated VM provisioning.
  • Replaced an end-of-life Red Hat Satellite with Pulp for update and package management.
  • Introduced Git for version control of infrastructure code.
  • Designed and implemented a master-master replicated MySQL platform as a standardized building block, spanning both DCs.
  • Insourced a complete multi-tier OTAP application landscape for pension insurances.
  • Designed the Linux infrastructure for the main website and the Financial API.
  • Designed a central authn/authz platform on FreeIPA.

Senior Linux Infrastructure Consultant · Global Collect Services

Jan 2013Dec 2013

  • Built infrastructure across two active/active datacenters.
  • Stood up a private vCloud from the ground up for test, development and staging.
  • Designed a fully automated Kickstart environment for VM deployment (including OS hardening) and a parallel one for ESXi node deployment.
  • Enabled SELinux in enforcing mode fleet-wide and authored / modified the targeted-policy modules so every running service complied, no permissive escapes.
  • Implemented CFEngine 3 for configuration management.
  • Implemented an Iam platform based on Red Hat Idm, and used Microsoft Active Directory as a federation source, so that the complete authentication and authorisation process could be centralized.
  • Designed monitoring + trending solution based on Nagios and Cacti.
  • Tuned RHEL vms and VMware platform for performance.

Senior Linux Infrastructure Consultant · Ministerie van Economische Zaken, Landbouw en Innovatie

Apr 2012Dec 2012

  • Built greenfield Linux infrastructure on Red Hat Enterprise Linux for the ministry.
  • Designed monitoring on Nagios, implemented Puppet for configuration management (with custom modules where the Forge fell short), and built HA failover with Pacemaker + Corosync.
  • Operated multi-tier web stacks on jBoss + PostgreSQL clusters.
  • Owned patch + security management and incident response.
  • Stack: RHEL, jBoss, PostgreSQL, Puppet, Cobbler, NetApp, NetBackup.

Senior Unix Consultant · KPN Hosting Services

Jul 2011Jan 2012

  • Operated and configured RHEL and Solaris systems at scale within KPN's hosting business.
  • Monitored services with Nagios + Cacti, ran multi-tier web stacks on Tomcat / jBoss, managed Varnish caching and Memcached, MS SQL and MySQL.
  • Daily change/incident management.

Senior Unix Beheerder · Vancis B.V.

Feb 2010Mar 2011

  • Designed, installed and operated RHEL, Debian, Solaris and AIX systems for hosting customers across two datacenters.
  • Redesigned and upgraded the VMware ESX 3.5 cluster to vSphere 4.
  • Designed a new CFEngine 3 configuration management framework, managed Postfix / Exim mail platforms with anti-spam/anti-virus, EMC Clarion storage, Cisco ASA + Fortigate firewalls, PostgreSQL clusters, PowerDNS + BIND, NFS + Samba file servers, Tivoli Storage Manager backups, Linux LVS for failover and load balancing.

Senior Unix Beheerder · EspritXB Managed Hosting

Feb 2009Feb 2010

  • ISP-grade Linux + Solaris operations for managed hosting.
  • Designed and shipped a new mail platform on Postfix + Amavisd + PolicyD + Spamassassin.
  • Operated 2×12 clustered VMware ESX servers with HP Left Hand virtual SAN, Tomcat / jBoss / Glassfish application servers, Netvault backup against 40 TB of storage, Linux LVS for failover.
  • Tuned the kernel and TCP/IP stacks on Linux and Solaris.
  • Designed a CFEngine configuration management framework.
  • Operated Confluence + Jira + CVS/SVN, and Tridion CMS.

Linux Consultant · Tweede Kamer der Staten-Generaal

Jul 2008Feb 2009

  • Linux consultancy for the Dutch House of Representatives.
  • Upgraded the Red Hat Enterprise Linux estate and kept the public websites — tweedekamer.nl, eerstekamer.nl, derdekamer.nl — plus the intranet running.
  • Implemented a central authentication platform on OpenLDAP + Kerberos + Samba, set up the backup environment, owned Unix-side security across the fleet, monitored all systems and designed new capabilities.
  • Stack: RHEL, Tridion CMS, Apache, PHP, MySQL, OpenLDAP, Kerberos, Samba, Oracle 10.

Linux Consultant · KPMG Meijburg & Co

Mar 2008Jul 2008

  • Short engagement at the tax-advisory practice.
  • Built a SAN environment on NetApp Filers, implemented GFS Cluster File System, designed data collection for performance metrics and wrote shell-based intelligent monitoring scripts.
  • Analysed performance of the existing Oracle platform and advised on the upgrade.
  • Stack: RHEL, Windows 2003, VMware, Oracle, GFS, NetApp, ITIL.

Linux Consultant · Ministerie van Verkeer en Waterstaat

Nov 2007Feb 2008

  • Linux consultancy on the Capgemini outsourcing of ~14,000 workplaces for Rijkswaterstaat.
  • Inventoried the in-use applications and wrote the transition strategy for the "Basishosting" application cluster — the portal underpinning every other web app — moving operations from RWS to Capgemini.
  • Stack: RHEL, SUSE Linux, Apache, ITIL, Prince2.

Unix System Specialist · @Home

Dec 2006Oct 2007

  • ISP operations at scale — ~600 Ubuntu/Debian servers and ~160 Sun Solaris servers.
  • Designed and operated network + system monitoring (Cacti, SNMP, RRDTool), managed Veritas NetBackup with a Sun L100 tape robot and a NetApp VTL, ran DNS, mail, news, LDAP, NTP and web infrastructure.
  • Patch + security management across the fleet, Oracle 10g and MySQL administration.

Unix Systeem Beheerder · Nedstat B.V.

Feb 2004Nov 2006

  • Unix systems engineering for the Sitestat web-analytics ASP platform on Solaris, RHEL, Debian, FreeBSD and OpenBSD.
  • Designed and operated the SMTP stack (Postfix + DSPAM) with virus + spam filtering, an OpenLDAP authentication infrastructure, redundant MySQL database servers, Apache for the Sitestat ASP, NFS + Samba storage on a SAN, and a Nagios + MRTG + RRD monitoring platform.
  • VPN infrastructure, DNS infrastructure, security tooling (Nmap, Nessus, Snort), Cisco PIX firewalls + load balancers + switches.
  • Wrote scaling advisories for customers running Sitestat on-premise.

Unix Systeem Beheerder · Backbone Consultancy and Services

Jun 2003Dec 2003

  • Datacenter Unix administration.
  • Operated a wireless mesh routing network, designed and managed RHEL / Mandrake / SUSE Linux servers and firewalls, MySQL, Apache, and PPTP VPN servers on Linux / FreeBSD / OpenBSD.
  • Patch, change and security management.

Windows–Unix Systeem Beheerder · Bourse Du Vin International

Nov 2001May 2003

  • Retail multi-OS operations across NL, Belgium and France.
  • Managed Windows NT 4 / 2000 / XP servers + workstations, Mac OS 9 and OS X workstations + servers, Solaris database servers, MS SQL and MySQL.
  • Designed DHCP / DNS / WINS, an OpenBSD-based network monitoring stack (Nagios + MRTG + RRD), Veritas / ArcServe / ufsdump backups, Sendmail on DG-UX, networking (routers, switches, frame-relay, ISDN). 3rd-line support for Solaris + Windows + VPN, remote operations across three countries.

Unix Systeem Beheerder · Getronics Network Services

Jun 2001Nov 2001

  • Unix administration on Solaris, Linux, FreeBSD and OpenBSD systems.
  • Kernel and TCP/IP stack tuning.
  • Daily admin, software installation, user/group management.
  • HP OpenView NNM + Nagios for monitoring.
  • Firewall installation and management across Checkpoint FW-1, Cisco PIX, iptables, IPF and PF.
  • Operated mail (Sendmail / Qmail-LDAP / Postfix), web (Apache / iPlanet), LDAP (OpenLDAP / iPlanet Directory Server) and DNS.
  • Change/incident management via Aplix helpdesk; monthly customer reporting + advisories.

3rd-line Helpdeskmedewerker · Freeler

Jun 2000May 2001

  • 3rd-line helpdesk at the ISP — resolved technical incidents via phone, email, fax and IRC.
  • Escalated systemic incidents to systems administration, maintained the customer database, identified recurring problem patterns and engineered solutions.
  • Stack: Solaris, FreeBSD, Linux, Qmail, Roxen, Oracle.

Medewerker Technische Dienst · Computer Point Almere

Oct 1999Apr 2000

  • Technical-services role at a computer retailer — troubleshooting hardware and software on Windows, Linux and Mac.
  • Installed and configured computers and networking gear (Windows NT 4, Mac OS, Linux).
  • Advised customers on hardware/software configurations, assembled and upgraded computers, supported sales and procurement.

Skills

Core: Kubernetes (8y) · Container image authoring (multi-stage builds, minimal base, CI/CD-driven) (9y) · VM → container migration (on-prem + cloud: Docker, K8s, EKS, AKS, ECS, ACI) (8y) · Terraform (8y) · Ansible (10y) · Linux (RHEL / CentOS / Debian / Ubuntu) (25y) · Multi-DC active/active design (12y) · Packer (7y) · HashiCorp Vault (6y) · HashiCorp Consul (4y) · GitLab CI/CD (6y) · Flux CD (3y) · Prometheus + Grafana + Alertmanager (7y) · Go (4y) · Python (12y) · Bash (25y) · VMware vSphere (15y) · AWS (EKS, IaM, Transit Gateway, GuardDuty) (7y) · Azure (AKS, Databricks, VPN to on-prem) (4y) · PostgreSQL + CloudNativePG (6y) · Traefik (5y) · Cert-manager + Let's Encrypt (5y) · External-DNS (4y) · External-Secrets Operator (3y) · Event Driven Ansible (EDA) (3y) · Ansible Galaxy-NG (private hosting) (3y) · Kustomize (4y) · BIND / DNS (15y) · Loki (3y) · Argo CD (2y) · Apache HTTP Server (22y) · HAProxy (8y) · Postfix / SMTP platforms (20y) · FreeIPA / Red Hat IdM (10y) · Pacemaker / Corosync / DRBD (10y) · LVS + Keepalived (10y) · SELinux (policy authoring + fleet enforcement) (10y)

Working knowledge: Docker Swarm · Jenkins · Bitbucket Pipelines · CloudFormation · Puppet · CFEngine · OpenLDAP + Kerberos · Longhorn · MinIO · Datadog · Helm · Keycloak · Kong API Gateway · Adobe AEM operations · Solaris / HP-UX · IBM WebSphere · Elasticsearch · Sealed Secrets · Tomcat / jBoss / Glassfish · MariaDB / Percona / MySQL · MongoDB · iptables / nftables · Nagios / Cacti / SNMP · Red Hat Satellite / Spacewalk / Pulp · Enterprise storage (NetApp / EMC / HP 3Par / Dell Compellent / Huawei OceanStor) · F5 BIG-IP / A10 load balancers · Cisco ASA / Checkpoint FW1 / PIX · OpenSCAP / CIS hardening · Snort / Nessus / IDS tooling · OpenBSD / FreeBSD · VMware vSphere / vCloud Director

Languages

  • DutchNative
  • SpanishBasic
  • GermanBasic
  • EnglishFluent