CI/CD Automation & Service Integration

Job ID: 39856943

Budget: $750 – $1,500 CAD

Freelancer Devops
BE SURE TO READ THE ENTIRE REQUIREMENTS
Be sure to ADD 'd4VoPS7' TO YOUR BID OR IT WILL BE CNSIDERED SPAM, IGNORED AND REMOVED.

Role Overview

We’re looking for a Senior DevOps Engineer who can design, build, and operate a complete automated sub-site provisioning and infrastructure orchestration system — not just CI/CD or deployment.

This role covers end-to-end automation: from GitHub Actions triggering → Cloudflare DNS → Let’s Encrypt TLS issuance → Nginx configuration → firewall policy updates → internal service registration → database and API integration → CI/CD pipelines.

You will own the automation pipeline from the public edge to internal service layer, including all integrations, security, and rollback logic.

Core Responsibilities

Design and implement full-stack automation for sub-site provisioning:
Trigger from GitHub Actions / Webhook / API call
Connect to Cloudflare API to create DNS records and SSL/TLS policies
Automate Let’s Encrypt certificate issuance and renewal
Dynamically generate Nginx reverse-proxy configurations (with templating and zero-downtime reloads)
Call firewall APIs (cloud or on-prem) to open or close ports securely
Call internal service APIs to register new sub-sites and environments (service registry, internal DB, auth system, API gateway, etc.)
Manage internal resource allocation (DB schema cloning, bucket creation, tenant registration, etc.)
Maintain and secure GitHub self-hosted runners, manage scaling, tokens, network segmentation, and isolation.
Build and maintain CI/CD pipelines across environments (staging → production).
Integrate with managed services (databases, message queues, object storage, load balancers).
Write automation logic and service connectors in Python, Go, or Bash.
Implement monitoring, alerting, and auto-rollback for failed provisioning flows.
Ensure secure communication between internal services (token exchange, TLS mutual auth, etc.).
Implement infrastructure as code (Terraform/Ansible) for all systems.

Required Experience

5–10+ years in DevOps / CloudOps / Infrastructure Engineering
Strong background in both infrastructure and software integration
Proven experience building automation pipelines that call internal/external APIs (REST, gRPC, GraphQL)

Deep understanding of:
GitHub Actions (composite/reusable workflows)
GitHub self-hosted runners (deployment, isolation, scaling)
Cloudflare API & DNS automation
Let’s Encrypt / ACME protocols (HTTP & DNS challenges)
Nginx dynamic configuration and reload
Firewall / security group automation via API
Linux system administration, networking, routing, iptables/nftables
Scripting & tooling:
Python / Go / Bash (must be able to write production-grade scripts)
Terraform, Ansible, or Pulumi
Git & GitHub REST API
Knowledge of containerization and virtualization (Docker, Podman, LXC, KVM).
Familiar with internal system APIs, service registry, database provisioning, auth token management, CI/CD security.

Nice to Have

Experience in multi-tenant SaaS systems (auto tenant setup & isolation)
Integration with Kubernetes, Helm, or Nomad for on-demand deployments
Familiar with internal microservice orchestration (service discovery, API gateway, config center)
Has worked with internal approval / workflow systems (e.g., ticket-driven or API-driven provisioning)
Knowledge of Zero Trust, audit logging, internal PKI, or RBAC enforcement

This is a long term position for a qualified candidate.