Skip to main content

Daniel-Adrian Gherasim

Full Stack & DevOps EngineerIași, Romania

Software engineer across Java applications, Kubernetes platforms, and security compliance.

4+ years of production work at MIND CTI and BeeNear, from React and Java/Spring Boot products to AKS delivery pipelines.

Current role
Software Engineer at BeeNear
Application stack
Java, Spring Boot, Quarkus, React, Angular
Delivery stack
Kubernetes on Azure, Helm, ArgoCD, Azure DevOps

Experience

Product engineering at MIND CTI; application, delivery, and compliance work at BeeNear.

BeeNear

Aug 2025 — PresentIași, Romania

Jul 2026 — Present

Software Engineer (NIS2 compliance)

Migrating an existing application to meet NIS2 cybersecurity requirements by refactoring its application code.

  • Scope: refactoring the application code of an existing application, at code level
  • Working in Java on WildFly with Hibernate

Java, WildFly, Hibernate

Dec 2025 — Jun 2026

DevOps Engineer

Designed, automated, and operated cloud-native platforms on Azure and Kubernetes, and owned production on-call.

  • Reduced overall infrastructure costs by approximately 50%: optimized AKS capacity, chose more appropriate database tiers for non-production environments, cut unnecessary logging consumption, and made sure build VMs ran only when required
  • Reduced the startup time of several microservices from approximately five minutes to a few seconds
  • Significantly reduced out-of-memory incidents by optimizing JVM configuration, Kubernetes resource requests and limits, and health probes
  • Was the primary engineer for the production on-call function: handled production alerts, investigated incidents, restored service, and made improvements to prevent recurring issues
  • Reduced public exposure with layered defences: Azure Front Door, WAF, Private Link, internal load balancers, Kubernetes Network Policies, and secrets managed with Azure Key Vault and External Secrets
  • Ran GitOps deployments across multiple clusters with Argo CD and Helm
  • Built observability with Prometheus, Grafana, Loki, and Alertmanager, with Alertmanager integrated with PagerDuty and Slack for incident notification and escalation

Azure, AKS, Docker, Kubernetes, Helm, ArgoCD, Azure DevOps, Prometheus, Grafana, Loki, Alertmanager, PagerDuty, Azure Front Door, WAF, Private Link, External Secrets

Aug 2025 — Dec 2025

Full Stack Developer

Worked across Angular applications, Spring Boot microservices, and the Kubernetes workloads that run them.

Connected application code with how it is deployed and operated.

  • Developed features across Angular applications and Spring Boot microservices
  • Upgraded Java and Spring Boot following semantic versioning to keep backward compatibility
  • Troubleshot production issues across applications and microservices
  • Tuned Kubernetes workloads: resource limits and liveness/readiness probes

Angular, Spring Boot, Java, Kubernetes, RabbitMQ, Azure Storage Accounts, REST APIs, MongoDB

MIND CTI

Iași, Romania

Mar 2022 — Aug 2025

Software Engineer

Built and maintained web, mobile, and backend systems for product delivery.

Over three years of product delivery across frontend, backend, and authentication.

  • Played an important role in migrating an application platform from on-premises to Kubernetes: containerized the services, created Helm charts and environment-specific configurations, and migrated incrementally, service by service
  • Developed a self-care microservice end to end, across the full stack
  • Developed dynamic web applications using ReactJS and Redux with Java/Spring Boot backends
  • Built a cross-platform mobile app using React Native for iOS and Android
  • Designed REST APIs and implemented authentication with OAuth, Keycloak, and Microsoft Identity
  • Developed Quarkus-based microservices with Java 17, Hibernate ORM, and Docker
  • Maintained automated tests using Vitest (frontend) and Mockito (backend)
  • Worked with Oracle, PostgreSQL, and MariaDB databases

React, Redux, React Native, Java, Spring Boot, Quarkus, Docker, Kubernetes, Helm, Keycloak, PostgreSQL

Projects

Personal projects: an automated delivery platform for microservices, and a Kubernetes homelab on Proxmox.

Cloud-Native Microservices Platform with Automated Delivery

Personal project: DevOps and full-stack implementation

A small e-commerce backend (three Quarkus services and a Next.js frontend) delivered to Kubernetes through a signed, GitOps-driven pipeline. Infrastructure is written for AWS, Azure and GCP.

Problem

Ship the services to Kubernetes with recreatable infrastructure, scanned and signed images, and no credentials in Git.

Solution

Terraform builds the cloud foundation and hands over to Argo CD, which owns everything after. Reusable GitHub Actions workflows test, scan, sign and verify each image, then open a pull request that promotes it.

Outcome

A push to main reaches dev through an auto-merged pull request, while staging and prod need approval. The infrastructure is written for AWS, Azure and GCP, with Azure as the cloud deployed so far.

Architecture
  1. 1Terraform: network, managed Kubernetes, registry, PostgreSQL and secrets per cloud
  2. 2GitHub Actions: CodeQL, gitleaks, Trivy, SBOM, keyless cosign signing
  3. 3Argo CD: app-of-apps and an ApplicationSet per service and environment
  4. 4Istio ambient mesh with mTLS, Gateway API ingress, External Secrets

Terraform, Kubernetes, Argo CD, GitHub Actions, Helm, Quarkus, Istio, cosign, Trivy, Azure

View repository

Kubernetes Homelab on Proxmox

Personal project: design, automation and operation

A production-style Kubernetes platform on a single Proxmox host, defined in Git and rebuilt from it. A hands-on way to work with cluster internals, networking, GitOps and security.

Problem

The cluster had to be rebuildable from Git alone, safe on a home network, and every design choice explainable.

Solution

OpenTofu creates the VMs, Ansible bootstraps kubeadm, and Argo CD reconciles everything else from Git. Each significant choice is an ADR listing the alternatives considered.

Outcome

A three-node cluster was torn down and rebuilt from Git, with all 12 Argo CD applications healthy afterwards. Where it is heading: management over VPN only, off-host backups (a target, not yet done), Kyverno policies, SOPS and age secrets, an observability stack and automated recovery tests.

Architecture
  1. 1OpenTofu and Ansible provision the VMs and bootstrap upstream kubeadm
  2. 2Argo CD reconciles the platform from Git (app-of-apps, self-heal)
  3. 3Cilium with default-deny policies; Istio Gateway API with strict mTLS
  4. 4Remote access through a Tailscale gateway, not port forwarding

Proxmox VE, OpenTofu, Ansible, Kubernetes, kubeadm, Cilium, Istio, Argo CD, Prometheus, Tailscale

View repository

Skills

Frontend, backend, databases, DevOps, cloud, identity, and observability tools used across recent work.

Frontend Engineering

React, Angular, Next.js, React Native, Redux, TypeScript

Backend Engineering

Java, Spring Boot, Quarkus, JBoss, WildFly, Hibernate ORM, REST APIs

Cloud & DevOps

Azure, AKS, Docker, Kubernetes, Helm, Terraform, ArgoCD, Azure DevOps, GitHub Actions

Data Layer

MongoDB, PostgreSQL, Oracle, MariaDB

Security & Identity

Keycloak, Azure Key Vault, External Secrets, OAuth, Microsoft Identity

Observability

Prometheus, Grafana, Loki

Education

2023 — 2025

Master's degree, Distributed Systems and Web Technologies

Gheorghe Asachi Technical University of Iași

2019 — 2023

Bachelor's degree, Computer Engineering

Ștefan cel Mare University of Suceava

Contact

For Full Stack, Backend, Cloud, Platform, or security-focused software roles.

Email is the best way to reach me.

contact@danielgherasim.com

Iași, Romania