Nikolas Gehrmann

Cloud Engineer

I build cloud platforms that stay explainable.

I design and operate cloud platforms with a focus on networking, identity, automation, security and production operations.

01

Profile

How I work

My work sits between cloud architecture and production operations. I focus particularly on the boundaries where platforms become difficult to operate: networking, identity, deployment models and troubleshooting.

I prefer infrastructure that remains observable, reproducible and understandable after the initial deployment.

02

Experience

2024—Now

Cloud Engineer

adesso as a service

Designing and operating cloud platforms primarily on Azure, with additional work across STACKIT, Kubernetes and Terraform. The role covers platform architecture, Infrastructure as Code, networking, security, deployment workflows and production troubleshooting.

Azure / StackIT / Terraform / Kubernetes

2022—2024

Penetration Tester & Security Consultant

Freelance

Conducting penetration tests and security assessments for client applications and infrastructure, covering vulnerability identification, exploitation and remediation guidance across web, network and cloud targets.

Penetration Testing / Vulnerability Assessment / Security Consulting

03

Selected Systems

Anonymized system summaries based on production engineering work.

Containerized Microservice Platform

Containerized microservice deployment across multiple isolated environments with shared platform services and declarative GitOps delivery.

Industry
Insurance
Context
Microservice workloads required a structured, environment-separated hosting model with shared platform services and reproducible deployments across isolated environments.
Role
Cloud Architecture / Infrastructure as Code / Platform Engineering
Technologies
STACKIT / Terraform / GitLab CI/CD / Argo CD
Focus
Environment separation / GitOps / Secret handling / Multi-cluster delivery / Architecture design
Outcome
Established a multi-environment deployment model with shared platform services and declarative, Git-driven delivery for all microservice workloads.

Payment Platform Security Assessment

Security audit and posture improvement for a payment platform.

Industry
Financial Services
Context
A mobile payment platform required an assessment of its existing security controls, with concrete recommendations and implementation of targeted improvements.
Role
Security Engineering / Cloud Security / Technical Assessment
Technologies
Azure / Entra ID / Defender for Cloud / Key Vault
Focus
Threat surface assessment / Identity and access review / Secret and key management / Security control hardening / Finding remediation
Outcome
Identified and remediated security gaps across identity, secret handling and platform configuration, with documented findings and applied improvements.

Hybrid Connectivity Platform

24x7 hybrid connectivity with Azure Front Door as external entry and private service paths via Site-to-Site VPN and Private Link.

Industry
Financial Services
Context
A platform required external access through Azure Front Door while keeping backend communication private between AKS workloads, managed services and on-premises systems, with explicit routing, DNS behavior and an implemented security posture.
Role
Cloud Engineering / Network Troubleshooting / Implementation
Technologies
Azure / Azure Front Door / Azure Kubernetes Service (AKS) / Private Link / Site-to-Site VPN / Hybrid Networking / Private DNS
Focus
24x7 connectivity / External ingress via Front Door / Hybrid network paths / DNS resolution / Routing / Private backend connectivity / Workload-level connectivity / Implemented security posture
Outcome
Established a resilient 24x7 connectivity model with Azure Front Door for external traffic and Private Link plus Site-to-Site VPN for private backend paths, including documented routing, DNS behavior and implemented security posture controls.

Migration into Infrastructure-as-Code

Infrastructure-as-Code migration of an existing Azure landscape into a version-controlled, reusable management model.

Industry
Manufacturing
Context
The infrastructure was built without any IaC tooling, which made it hard to maintain and expand. The goal was to migrate the existing Azure configuration into a version-controlled and reproducible management model.
Role
Migration Planning / Infrastructure as Code / Implementation / Technical Evaluation
Technologies
Terraform / Azure / GitHub Actions
Focus
Azure Landing Zones / Multi Subscription Management / State Management / Integrations / Repeatable migration
Outcome
Transferred Azure-based Infrastructure into maintainable and version-controlled configuration.
04

Capabilities

PLATFORM

  • Azure platform architecture
  • Kubernetes platforms
  • GitOps and deployment workflows
  • StackIT platform architecture

INFRASTRUCTURE

  • Terraform
  • Infrastructure as Code
  • Reusable platform modules
  • Helm
  • ArgoCD

CONNECTIVITY

  • Private networking
  • DNS and private endpoints
  • Hybrid connectivity

SECURITY

  • Cloud security baselines
  • Identity and access
  • Secure platform configuration
  • Security Consulting
  • DevSecOps and security automation

OPERATIONS

  • Troubleshooting
  • Production operations
  • Technical documentation/Technical writing
05

Principles

01

Infrastructure should remain understandable after deployment.

02

Operations are part of the architecture.

03

Automation must preserve debuggability.

04

Security controls should be explainable.

05

Documentation is part of the system.

06

Contact