Marcus Wiederstein
Administrator, DevOps
Experience
Administrator, DevOps
KZVB
- Planned and implemented new network infrastructure (VLAN, LACP, DMZ, structured cabling)
- Migrated from VMware to KVM using Oracle Linux Virtualization Manager (OLVM), including CPU pinning
- Hardened the entire environment using SELinux (KVM hosts, container hosts, database servers)
- Configured and operated the virtualization platform with OLVM and Ansible-based provisioning
- Containerized and redeployed critical services: WordPress, Jenkins, PostgreSQL, MariaDB, Subversion with Apache + AD integration
- Developed Ansible playbooks for automated deployment and configuration management
- Integrated Foreman for repository and security management in the DMZ
- Produced technical documentation in Markdown; organized in Bookstack
- Coordinated with external vendors (e.g. HPE) for hardware installation and setup
- Delivered all contributions documented and reproducible in Markdown
DevOps Engineer / IT Consultant / System Administrator
Decathlon mode project
- Operated and improved a complex production environment (Ansible, Docker, Kubernetes, Git)
- Administered PostgreSQL and Oracle database instances
- Analyzed and maintained virtualization and storage infrastructure (vSphere, HPE 3PAR, Multipath)
- Delivered onboarding and technical training for internal administrators (Ansible, Kubernetes, CI/CD)
- Created technical documentation and ensured knowledge transfer
- Integrated Linux servers with Active Directory domain using SSSD
- Maintained Docker container environments and KVM-based virtual machines
- Refactored and extended Bash and Python scripts
- Corrected and enhanced existing Ansible playbooks
- Conducted workshops and introduced ChatGPT/Gemini for prompt engineering
DevOps Engineer / Linux Specialist / Database Migration
MLP
- Supported design and operation of Kubernetes clusters (deployment, Helm, monitoring)
- Managed containerized applications (logging, secrets, persistent volumes, registry integration)
- Migrated live Oracle databases to PostgreSQL using Altova MapForce, Python, and pgloader
- Set up a highly available PostgreSQL environment with streaming replication and VIP failover
- Developed automation scripts for data migration and verification (Python, Bash)
- Administered mixed Linux platforms (SLES, Ubuntu, RHEL)
DevOps, Linux Administrator
Univention Corporate Server project
- Designed and implemented a Samba-compatible Active Directory domain with Univention Corporate Server
- Integrated UCS into existing Linux and Windows environments
- Developed automation scripts in Python for user provisioning, ACLs, and backups
- Documented the domain architecture and created handover procedures
- Provided consulting on LDAP/Kerberos-based application integration
Administrator, XSD Designer, Data Analyst
Rheinmetall
- Designed and documented complex XML/XSD target structures
- Created reusable and configurable mapping templates in Altova MapForce
- Implemented multi-stage mappings: Oracle → XML → JSON
- Automated mapping processes via MapForce scripts and job scheduling
- Integrated schema validation and test datasets
- Optimized performance for large data volumes and repeated runs
IT Project Manager, System Administrator
Own data center
- Planned, set up, and operated a fully self-hosted data center with fibre uplink and static IPs
- Virtualized using KVM (virsh) and Ceph block storage with multipath connectivity
- Deployed and operated a Kubernetes platform for containerized services
- Dockerized core services: Bookstack, Nextcloud, OpenProject, Mailcow
- Built firewall and VPN infrastructure with OPNsense and WireGuard
- Integrated Samba-based Active Directory domain with Kerberos and SSSD for Linux systems
- Implemented browser-based training system via Apache Guacamole (snapshots, file transfer)
- Rebuilt and migrated company websites with WordPress into private infrastructure
- Used AI tools (ChatGPT/Gemini) for documentation, automation, and operational support
- Maintained stable, high-performance infrastructure with 24/7 availability
- Created scalable training platform with isolated, resettable DevOps/Kubernetes/Linux labs
Summary
I support companies in building digital infrastructures that are self-determined, maintainable, and future-proof – based entirely on open-source technologies and independent of proprietary ecosystems. I place strong emphasis on knowledge transfer through structured documentation and hands-on training.
I take a holistic view of IT – from the network layer to container platforms to stable applications.
For refining language, exploring edge cases, and reflecting on architectural choices, I occasionally use supportive tools like ChatGPT and Gemini – for structure, phrasing, best-practice input, and sometimes a bit of emotional support during long working phases. All decisions, content, and technical solutions, however, are based entirely on my own expertise and experience.
Skills
- Linux Administration: Debian, Ubuntu, Rhel, Oracle Linux; Systemd, Lvm, Crontab, Shell, Ssh, Journalctl
- Infrastructure, Networking & Security: Vlan, Trunking, Fibre Channel, Lacp, Multipath, Ceph (Block Storage)
- Firewall/vpn: Opnsense, Flexiwan, Openwrt, Wireguard
- Security: Selinux, Apparmor, Clamav, Rspamd, Tls Certificates, Ssh Hardening, Network Hardening, Kerberos, Openscap
- Ldap/authentication: Samba Ad, Sssd, Pam, Winbind, Kerberos, Apache Modules (Mod Authnz Ldap, Mod Auth Kerb)
- Openstack (Core Services): Nova, Neutron, Keystone, Ceph, Cinder (Ceph Backend), Horizon
- Monitoring: Prometheus, Grafana, Snmp-based Hardware Monitoring
- Hardware/hosting: Raspberry Pi, Disk Enclosures, Fibre Channel, Self-hosting Setups
- Virtualization: Proxmox Ve, Kvm With Virsh, Oracle Linux Virtualization Manager (Olvm)
- Kubernetes: Kubespray (Provisioning With Ansible), Cluster Setup, Deployment, Helm, Kustomize, Gitops, Opa/gatekeeper, Secrets, Volumes, Rbac, Kubevirt, Longhorn
- Containerization: Docker, Docker Compose
- Openstack (Integration): Ansible, Heat (Orchestration), Magnum (Kubernetes On Openstack), Automation
- Automation & Scripting: Ansible, Bash, Git, Python, Php
- Databases (Postgresql): Administration, Security, High Availability, Performance Tuning, Monitoring, Ci/cd, Migration, Operation On Docker, Kubernetes And On-premise, Backup & Recovery (Including Pitr), Clustering, Replication
- Databases (Mariadb/mysql): Security, Monitoring, Ci/cd Integration, Docker/kubernetes Integration, Performance Tuning
- Migration & Mapping: Altova Mapforce, Talend Open Studio
- Server Software: Apache2, Nginx, Mailcow, Wordpress, Ha Cluster, Apache Guacamole, Samba
- Self-hosted Tools: Bookstack, Nextcloud, Opentalk, Openproject, Git, Freeswitch, Espro Crm, Matrix/element
- Diy And Infrastructure Projects: Raspberry Pi-based Home Servers, Network Test Environments, Backup Servers
- Training & Lab Environments: Virtual Lab Setups With Kvm, Browser-based Access Via Apache Guacamole, Use Of Ansible, Kubernetes And Git
- Ai & Documentation: Chatgpt/gemini Prompt Engineering, Markdown-based Workflows, Bookstack Knowledge Systems
Languages
Education
Ruhr University Bochum
Electrical Engineering & Computer Science · Bochum, Germany
Similar Freelancers
Discover other experts with similar qualifications and experience