Ansible Developer for Infrastructure Automation and root encryption

Job ID: 39823047

Budget: $250 – $750 CAD

## Project Overview

We need an experienced Ansible developer to complete infrastructure automation for an AlmaLinux cluster (bootstrap + production servers) featuring:
- Full-disk LUKS encryption with remote unlock and OpenBao key management
- HashiCorp stack integration (OpenBao/Vault, Consul, Nomad)
- Zero-trust security with mTLS throughout
- KMIP-based auto-unseal for secrets management

**Timeline:** Not urgent - 2 weeks to 1 month
**Environment:** Cloud/VPS servers only (no physical access)
**Support:** Direct collaboration with our team
**Existing Work:** Some templates and modules already started
**About Us:** We're a very small business that prioritizes enterprise-grade security, proving that company size doesn't dictate security standards

## Scope of Work

### Core Components to Build (13 Ansible Roles):
1. **LUKS Encryption System**
- Detection and automated encryption process
- Custom initramfs with SSH for remote unlock
- Detached header management
- Bootstrap to production key transition

2. **HashiCorp Stack Deployment**
- OpenBao (Vault fork) in HA Raft mode
- Consul service mesh with mTLS
- Nomad orchestration platform
- Complete PKI/certificate rotation/logs

3. **KMIP Integration**
- External KMS auto-unseal configuration for openBao
- mTLS certificate authentication
- Manual unseal fallback procedures

## Technical Requirements

**Essential Skills:**
- Ansible experience with complex roles/collections
- Deep Linux knowledge (boot process, initramfs, dracut)
- LUKS encryption including detached headers
- Some HashiCorp stack experience (Vault/OpenBao, Consul, Nomad)
- KMIP protocol and KMS integration
- PKI/certificate management (Ed25519)
- Bash scripting for automation

**Preferred:**
- AlmaLinux/RHEL experience
- Zero-trust architecture implementation
- Log aggregation (Loki/Promtail)
- Security compliance knowledge

## Key Constraints
- Software-only encryption (no hardware security modules)
- Remote-only administration
- Limited KMS/KMIP availability
- Must support both automated and manual recovery procedures

## Deliverables

1. **Complete Ansible Collection**
- All roles fully tested and idempotent (luks_initramfs, openbao_server, consul_client, etc)
- Well-commented code explaining complex logic and design decisions
- Integration with existing Terraform workflow

2. **Documentation**
- Deployment workflow and procedures

3. **Tested Solution**
- All components working end-to-end
- Supports both fresh installs and incremental deployment
- Ready for production deployment

**AI Usage Policy:** We ask that AI usage be disclosed. AI tools can assist with boilerplate code and documentation, but core logic and architecture decisions must be human-authored. Please specify which parts utilized AI assistance in your deliverables. We are a carbon-neutral small business and disclosure helps us accurately calculate and offset the environmental impact of AI compute usage.

*Potential for ongoing maintenance work.*

More details upon requests.
AI Disclosure: AI was used to help enhance this project description