About me
Sysadmin by day,
cluster wrangler
by night.
I work at ICS (Masaryk University) doing user support and infrastructure, managing Windows + Linux servers, AD, and M365. Previously at Air Bank.
Outside work hours: homelab Kubernetes, GitOps with Flux, SOPS-encrypted secrets, and whatever breaks next in my k3s cluster. Working toward the CKA and a DevOps role.
Daily driver: Arch Linux + Sway. Proud dad of 4-years old. Married way above myself. Bitcoin enjoyer. Tech books addict. AI enthusiast.
Kubernetes
k3s + Flux GitOps
Linux
Arch / Sway daily
SOPS + AGE
GitOps secrets
Cloudflare
Tunnels + DNS
Windows
AD, GPO, SCCM
Proxmox
Homelab VMs
Career timeline
Now
CKA Certification
Self-directed · Homelab
Building a k3s cluster managed with Flux GitOps. Deploying real apps like
Audiobookshelf, Mealie, Homarr, Blogs. I am simply learning through real breakage.
Studying Kubernetes internals for the CKA exam.
Present
IT Support & Sysadmin
ICS · Masaryk University, Brno
Dual role covering end-user support and infrastructure admin.
Managing Windows/Linux servers via Proxmox, RDP, SSH.
Microsoft stack: AD, GPO, DHCP, Configuration Manager, M365.
Previous
End User Support Sysadmin
Air Bank, a.s.
Banking environment, tight security requirements. Honed support and
systems discipline. First real exposure to the gap between
"it works on my machine" and production.
Earlier
Linux & Virtualization
Geetoo
Where the Linux obsession started. Virtualization, servers,
and the slow realization that this is the kind of work I want to do forever.
Latest posts
Featured · Kubernetes
SOPS + AGE in a Flux GitOps cluster: the parts nobody explains
Getting secrets management right in a GitOps workflow took me days of debugging.
Here's everything from key generation, to Kustomize integration,
to the exact reason your decryption silently fails when you expect it to work.
🔐
Homelab
Fixing a CrashLoopBackOff the hard way (PVC edition)
Mealie kept dying. The culprit was a PersistentVolume with a Retain policy
holding stale data. Here's the reset procedure I wish I found on Google.
Linux
Half of the year on Arch Linux with Sway as my only desktop
No GNOME, no KDE. Just Sway, a config file, and occasional frustration
with PipeWire audio. Would I go back? Absolutely not.
DevOps
Helm vs. Kustomize: what I got wrong for months
Helm is a package manager and one-shot applier, not a controller.
Kustomize is a patcher. Both have a place. Here's how I finally made
it click after confusing them for way too long.
Networking
Cloudflare tunnels as a poor man's VPN for self-hosted apps
No open ports. No public IP headaches. Just cloudflared in a pod
and your app on the internet in 15 minutes. Setup, pitfalls, and the credentials.json story.
What is API
An API (Application Programming Interface) is a standardized way for software systems to communicate.
One system requests data or an action, and another system responds, without exposing its internal workings. APIs are fundamental to modern software because they allow applications, services, and platforms to work together reliably and at scale.
APIs make it possible to connect independent systems, reuse existing functionality instead of rebuilding it, and grow complex platforms without tightly coupling all components. Most everyday digital experiences rely on APIs, even if users never see them directly.