Belhadj Kessas
EN FR

Infrastructure that rebuilds itself from Git.

I'm Belhadj Kessas, a DevOps engineer. At Montpellier Méditerranée Métropole I run the Kubernetes platforms behind more than 100,000 IoT sensors: four clusters on our own servers, every layer declared in Git. I now take on consulting work too — GitOps, Kubernetes, observability and IoT — for teams who want that same control over their infrastructure.

Remote first, with on-site days when the project needs them. French and English.

infra-repo / main a1f3c9e scale api to 3 replicas 7be2104 add loki retention 0c9d4e1 bump cilium to 1.16 5d61a0b bootstrap prod cluster Argo CD Synced OutOfSync prod cluster node-1 node-2 node-3 3 nodes · RKE2 · Cilium infra-repo / main a1f3c9e scale api to 3 replicas 7be2104 add loki retention Argo CD Synced OutOfSync prod cluster node-1 node-2 node-3
What a git push does on the platforms I run: Argo CD compares the repository with the cluster, then brings every node back to what Git declares.

What I can do for you

Each piece of work has a written scope and ends with a handover, so your team can carry on without me.

  • Platform audit

    An outside review of your Kubernetes setup: security basics, backups, deployments, alerting, upgrades and costs. You get a prioritised report and a plan your team can follow.

    About a week, over 3 weeks
  • GitOps setup

    Your clusters' state moves into Git with Argo CD or Flux: structured repositories, promotion between environments, drift detection and a tested rollback.

    3 to 6 weeks
  • Observability

    Prometheus, Grafana and Loki, or Mimir when several teams share it. Alerts that fire when things degrade, before your users notice.

    2 to 4 weeks
  • Kubernetes on your own servers

    Clusters built on bare metal, Proxmox or vSphere, provisioned from code — or workloads moved off a managed cloud when owning the hardware makes more sense.

    Scoped per project
  • IoT and LoRaWAN platforms

    ChirpStack on Kubernetes, gateways, MQTT and time-series pipelines, device provisioning at fleet scale. The stack I run for 100,000+ sensors.

    3 to 8 weeks

Ways to work together

Project
A fixed price for a written scope, delivered in milestones.
Monthly support
A few days a month for upgrades, fixes and architecture questions.
Reinforcement
A named Kubernetes expert on an IT firm's client project.

Digital sovereignty

Know where your data lives and which laws apply to it, and keep the freedom to change providers.

For companies and public bodies alike: data protection rules, pricing changes and vendor decisions all matter less when you own your stack.

  • Dependency map and plan

    What relies on outside providers, and a plan ranked by risk and effort.

  • Infrastructure you control

    Kubernetes on your own servers or with a provider in your jurisdiction, managed from Git.

  • Open-source building blocks

    Linux, Proxmox, PostgreSQL, Keycloak, Grafana — handed over to your team.

Already done at Montpellier Méditerranée Métropole. See the platform

The platform I run in Montpellier

Montpellier Méditerranée Métropole runs one of France's largest municipal IoT networks — air quality, water and energy metering, waste, street lighting and mobility — for a metropolitan area of 500,000 people. I moved the platform from containers on rented VMs to Kubernetes clusters on the Métropole's own infrastructure, open source from the kernel up and driven entirely from Git.

100,000+
IoT sensors in production
4
Kubernetes clusters, all managed from Git
0
manual steps to build a complete cluster
1 min
from a silent gateway to an alert
100,000+ sensors LoRaWAN gateways Kubernetes clusters

Four clusters, one repository

Production
RKE2 on VMware vSphere. Every service the city relies on.
Pre-production
RKE2 on Proxmox. Identical, so every change proves itself here first.
Monitoring
A dedicated three-node cluster that watches the other two.
GPU lab
NVIDIA Jetson Orin nodes for computer-vision inference at the edge.

A git push starts a self-hosted runner that calls the hypervisor API, then OpenTofu and Ansible build the machines, RKE2 starts the cluster, and Argo CD installs everything else. Destroy a cluster, push again, and you get the same one back.

Monitoring that outlives what it watches

Metrics and logs from production and pre-production flow into Mimir and Loki on their own cluster, stored on Ceph, split into isolated tenants, with a single Grafana on top. Losing a cluster never means losing sight of it.

One minute, not days

  1. A LoRaWAN gateway goes silent after a power failure.
  2. The alert fires as soon as the gateway stops answering, before any sensor data goes missing.
  3. A technician is on site, the fault is fixed, the data gap never matters.

How a project runs

  1. We talk

    A first call about your setup and what's getting in the way. It's free, and you get my notes in writing afterwards.

  2. I send a written scope

    What I'll deliver, in which order, and at what price. No open-ended billing.

  3. I deliver in your Git

    Every change is a commit in your repositories, reviewed with your team, and the project ends with documentation and a handover session.

Open-source tools only: no licences, no proprietary agents, no lock-in — to a vendor or to me.

Tools I use every day

CKA (Certified Kubernetes Administrator) in progress, 2026.

Kubernetes
RKE2, Rancher, k3s, Cilium, MetalLB, Rook-Ceph, Envoy Gateway, Helm
GitOps & IaC
Argo CD, GitLab CI, GitHub Actions, OpenTofu, Terraform, Ansible
Observability
Prometheus, Grafana, Loki, Mimir, Alloy, Alertmanager, Zabbix
Infrastructure
Linux, Proxmox, VMware vSphere, Cloudflare
IoT
ChirpStack v4, LoRaWAN, MQTT, NVIDIA Jetson
Code
Python, Bash, Rust, SQL

Questions

Do you work remotely?

Mostly, yes. Everything can be done remotely, and I come on site for a few days when the project needs it — a kickoff, a workshop, an installation.

Who do you usually work with?

Teams that run Kubernetes without a dedicated platform team, organisations that want to keep their infrastructure in-house, and IT firms that need a named Kubernetes expert on a client project.

Do you work with AWS, GCP or Azure?

Yes. EKS, GKE, AKS or your own servers: the work is the same — GitOps, access control, network policies, observability, upgrades. I adapt to where your clusters already run.

What do we keep at the end?

Everything: the code in your Git, the documentation, the runbooks. The goal is that your team runs it without me.

How is the price set?

A fixed price for a written scope on projects, a monthly fee for support, time spent with a cap for reinforcement. You get a quote after the first call.

On my own time

OpenHertz

A free platform to learn radio with a real receiver: plug in a $30 SDR and decode live FM and aircraft signals right in the browser. Built with Rust and TypeScript, bilingual.

openhertz.org

My own cluster

My personal projects run on a small K3s cluster the same way I would set up yours: tested in CI, images pinned by commit, deployed by Argo CD, secrets sealed, every pod with limits.

Tell me about your infrastructure.

Where it runs, how you deploy, what's getting in the way. I answer every message, in French or English.

contact@belhadj.dev

LinkedIn GitHub