Software
Writing the thing.
- .NET / C#
- Angular
- Kafka
- JavaScript
- Python
alau.dev — online · served from a living room
Software Engineering, DevOps, AI
A DevOps engineer with five years of software engineering experience. I build cloud platforms and the pipelines that ship to them — Azure, Kubernetes, Terraform, Argo CD — and I’m now expanding into AI engineering and agent workflows.
Chapter one · NightChapter two · Day
A study inspired by my Kazakhstan roots and the software engineering years.A Chicago studio for the DevOps chapter, with a corner for AI. Both rooms are imagined, not photographs.
01About
I’m Alau Bolatov — a DevOps engineer with five years of software engineering experience and roughly three years of DevOps.
I like understanding how things fit together, from the code to the container to the machine it runs on. Most of my side projects start with a question like “what would it take to run this myself?” and end with a workflow file and a README.
My background spans .NET, Angular and Kafka on the application side, and Azure, Kubernetes, Terraform, GitHub Actions, Docker and Argo CD on the platform side. Next on the path: AI engineering and agent workflows.
When the terminal closes, the music startsIf an environment is cheap to delete, it is cheap to experiment with.
A deployment that needs a person remembering steps will eventually miss one.
Nginx, a container, a tunnel. Fewer moving parts, fewer surprises.
An estimate is labelled as an estimate. A budget alert is not a cap.
02Skills
The tools I reach for, grouped the way they work together: software that gets written, the platforms it runs on, and the AI that’s starting to help with both.
Writing the thing.
Shipping and running it.
Where I’m heading.
My sandbox repositories carry instructions for coding agents: what they may change, and what needs a plan and a person first.
The toolbox
03Projects
Two platforms I operate myself, and two small tools that live on one of them.
Azure · Terraform · GitOps
A personal Azure environment laid out like a real non-production platform: hub-and-spoke networking, a private AKS cluster, a private PostgreSQL database and GitOps delivery with Argo CD.
Homelab · Docker · Cloudflare
Nginx in Docker on Ubuntu, published through a Cloudflare Tunnel with no open ports. Every push builds a new image and ships it home.
Music · Personal
55 tracks on rotation, played through YouTube’s privacy-enhanced mode. Pick one, or let shuffle take the lead.
Python · yt-dlp · FFmpeg
A private converter on the home server. It runs as a locked-down container behind Nginx and an access key.
04Experience
One pipeline, three stages. Each one builds on the last.
Building applications with .NET and Angular, with Kafka in the mix — the code everything else exists to ship.
Infrastructure as code, CI/CD and GitOps on Azure and Kubernetes: platforms that are cheap to destroy and easy to rebuild.
Expanding into AI engineering and agent workflows, starting where I already work: delivery pipelines, infrastructure and the guardrails around them.
05Contact
The quickest way to find me is where the code lives.
01Sandbox
A personal Azure environment laid out like a real non-production platform: hub-and-spoke networking, a private Kubernetes cluster, a private database and GitOps delivery. I have full access here, so this is where new features get built and strange problems get reproduced.
Hover a repository to trace what it works with.
Reusable Terraform modules for networks, AKS, PostgreSQL, Key Vault and more. Each module is released with its own tag, such as aks1.0.0.
The hub and dev environments, split into layers with one state file each. Pull requests plan; the main branch applies.
pins module tags · runs jobs on runnerShared charts for services, namespace secrets and runners, packaged and pushed to the container registry as OCI artifacts.
consumed by deployGitOps configuration: an app-of-apps for the cluster add-ons and an ApplicationSet that turns every service folder into an app.
uses helm · deploys runner and sandbox-test-appA GitHub Actions runner image that lives inside the cluster, for jobs that need to reach private endpoints.
deployed by deploy · serves infraA small diagnostics service that checks config, secrets, the file share and the database connection end to end.
deployed by deployAll repositories are private.
The hub and dev networks are peered.
Running: one node hosts Argo CD, Traefik and the services. Requests arrive through an outbound tunnel, so nothing listens on a public IP.
A module change gets a new tag for that module only. An environment adopts it by changing one ref.
source = "…//modules/aks?ref=aks1.0.0"
Hub: foundation → security → storage. Dev: foundation → storage → computational → security. The database step runs on the in-cluster runner because PostgreSQL has no public endpoint.
push main → terraform apply, one job per layer
Charts go to the registry as OCI artifacts. The runner and test app images land in the same registry.
helm push → oci://registry/helm
The cluster API is private, so the workflow installs Argo CD from inside the cluster and sets up the tunnel. From then on, a merge to main is a deployment, and external-dns gives every new Ingress host its DNS record.
az aks command invoke → Argo CD → app-of-apps
Honest numbers. Budget alerts send email; they do not stop anything. The uptime limit is what keeps the bill small.
02Behind the scenes
This site lives on my own Ubuntu server. The homelab is where I experiment, automate and get hands-on with the systems that make software work.
Measured in your browser. Nothing is sent anywhere else.
GitHub Actions builds the static site and the converter.
Images are stored in GitHub Container Registry.
Docker Compose pulls and restarts services on Ubuntu.
A Cloudflare Tunnel connects you, with no open ports.
nginx:stable-alpine · static site · port 8080 on the LAN
python 3.13 + yt-dlp + ffmpeg · 768 MB · 1 CPU · no host port
tunnel to the edge · outbound connection only
The converter runs as a non-root user with no-new-privileges and is only reachable through Nginx.
04Off the clock
Familiar favourites and a few new directions. Pick a track or see where shuffle takes you.
The player loads only when you press play. It uses YouTube’s privacy-enhanced mode.
05Your collection, to go
Paste a YouTube video link to save its audio as an MP3 on the home server, then download it to your favourite music player.
Enter your access key to load files saved on the server.