DevOps Engineer Needed for Kubernetes/K3s Production Deployment of Full-Stack AI Real Estate Platform -- 2
Budget: $250 – $750 USD
We are looking for a senior DevOps engineer with strong experience in Kubernetes, Docker, CI/CD, Helm, Linux VPS deployment, production security, and cloud migration planning.
We have a full-stack real estate platform. The project includes multiple services: Next.js website, React dashboard, Node.js/Express backend, dashboard backend/proxy, Python FastAPI AI services, MongoDB, Redis, ChromaDB, and integrations with Supabase, Firebase, Cloudinary, SMTP, and LLM providers.
The initial deployment will be on a VPS server with:
12 vCPU
32 GB RAM
1 TB disk
AMD64 Linux
Public IPv4
Single-node Kubernetes using K3s
Self-hosted MongoDB on VPS storage
After around two months of production traffic, we plan to migrate to AWS if the metrics justify it.
What we need
We already have internal architecture and deployment documentation prepared. Your job will be to review the codebase and documentation, validate the current implementation, and implement a production-ready deployment path.
Main responsibilities:
Review the current Dockerfiles, GitHub Actions, Helm templates, environment variables, and deployment documentation.
Set up single-node K3s on the VPS.
Install and configure ingress-nginx, cert-manager, metrics-server, and basic monitoring.
Configure secure firewall rules, SSH key-only access, and restricted Kubernetes API access.
Normalize or refactor existing Helm charts for KSA-only production deployment.
Add proper Helm values files for VPS/KSA deployment.
Deploy all services to Kubernetes with correct resource limits, probes, secrets, config maps, and internal service URLs.
Deploy MongoDB as a StatefulSet with persistent storage.
Deploy Redis as an internal cache.
Configure ChromaDB persistence for the chatbot service.
Configure TLS certificates through cert-manager.
Update GitHub Actions CI/CD to use immutable image tags and production approval gates.
Ensure secrets are handled safely using Kubernetes Secrets and GitHub Actions secrets.
Set up MongoDB backup and restore process using offsite storage.
Add clear rollback commands and production runbooks.
Perform smoke testing for website, dashboard, backend APIs, AI services, uploads, notifications, and database connectivity.
Prepare handover notes for ongoing operations.
Important security requirements
The freelancer must sign an NDA before accessing the repository, server, documentation, or credentials.
Real environment variables and secrets must never be committed to Git.
Any exposed or previously shared credentials must be rotated before production launch.
Secrets must be stored only in GitHub Actions secrets, Kubernetes Secrets, or another approved secure secret manager.
The freelancer must be careful when handling Supabase, Firebase, Cloudinary, MongoDB, SMTP, AI/LLM provider keys, Docker registry credentials, SSH keys, and deployment credentials.
MongoDB, Redis, and AI internal services must not be publicly exposed.
Production access must be limited and documented.
Required experience
Please apply only if you have strong experience with:
Kubernetes and K3s
Helm charts
Docker multi-service deployments
GitHub Actions CI/CD
Linux server hardening
ingress-nginx
cert-manager / Let’s Encrypt
MongoDB StatefulSets and backups
Redis
Node.js and Python service deployment
FastAPI and Express deployment experience
Secret management
Production rollback and incident handling
AWS migration planning, preferably EKS/ECR/Route53/ACM/CloudWatch
Deliverables
Production-ready K3s setup on the VPS.
Updated Helm values/templates for KSA-only deployment.
Working deployment of all services.
Secure environment and secret configuration.
TLS-enabled public routes.
Working CI/CD deployment flow.
MongoDB backup and restore procedure.
Monitoring and operational checklist.
Rollback procedure.
Final handover documentation.
Please include in your proposal:
Similar Kubernetes/K3s production deployments you have done.
Your experience with Helm and GitHub Actions.
Your approach to secret management.
Estimated timeline.
Any security checklist you normally follow before production launch.
We have a full-stack real estate platform. The project includes multiple services: Next.js website, React dashboard, Node.js/Express backend, dashboard backend/proxy, Python FastAPI AI services, MongoDB, Redis, ChromaDB, and integrations with Supabase, Firebase, Cloudinary, SMTP, and LLM providers.
The initial deployment will be on a VPS server with:
12 vCPU
32 GB RAM
1 TB disk
AMD64 Linux
Public IPv4
Single-node Kubernetes using K3s
Self-hosted MongoDB on VPS storage
After around two months of production traffic, we plan to migrate to AWS if the metrics justify it.
What we need
We already have internal architecture and deployment documentation prepared. Your job will be to review the codebase and documentation, validate the current implementation, and implement a production-ready deployment path.
Main responsibilities:
Review the current Dockerfiles, GitHub Actions, Helm templates, environment variables, and deployment documentation.
Set up single-node K3s on the VPS.
Install and configure ingress-nginx, cert-manager, metrics-server, and basic monitoring.
Configure secure firewall rules, SSH key-only access, and restricted Kubernetes API access.
Normalize or refactor existing Helm charts for KSA-only production deployment.
Add proper Helm values files for VPS/KSA deployment.
Deploy all services to Kubernetes with correct resource limits, probes, secrets, config maps, and internal service URLs.
Deploy MongoDB as a StatefulSet with persistent storage.
Deploy Redis as an internal cache.
Configure ChromaDB persistence for the chatbot service.
Configure TLS certificates through cert-manager.
Update GitHub Actions CI/CD to use immutable image tags and production approval gates.
Ensure secrets are handled safely using Kubernetes Secrets and GitHub Actions secrets.
Set up MongoDB backup and restore process using offsite storage.
Add clear rollback commands and production runbooks.
Perform smoke testing for website, dashboard, backend APIs, AI services, uploads, notifications, and database connectivity.
Prepare handover notes for ongoing operations.
Important security requirements
The freelancer must sign an NDA before accessing the repository, server, documentation, or credentials.
Real environment variables and secrets must never be committed to Git.
Any exposed or previously shared credentials must be rotated before production launch.
Secrets must be stored only in GitHub Actions secrets, Kubernetes Secrets, or another approved secure secret manager.
The freelancer must be careful when handling Supabase, Firebase, Cloudinary, MongoDB, SMTP, AI/LLM provider keys, Docker registry credentials, SSH keys, and deployment credentials.
MongoDB, Redis, and AI internal services must not be publicly exposed.
Production access must be limited and documented.
Required experience
Please apply only if you have strong experience with:
Kubernetes and K3s
Helm charts
Docker multi-service deployments
GitHub Actions CI/CD
Linux server hardening
ingress-nginx
cert-manager / Let’s Encrypt
MongoDB StatefulSets and backups
Redis
Node.js and Python service deployment
FastAPI and Express deployment experience
Secret management
Production rollback and incident handling
AWS migration planning, preferably EKS/ECR/Route53/ACM/CloudWatch
Deliverables
Production-ready K3s setup on the VPS.
Updated Helm values/templates for KSA-only deployment.
Working deployment of all services.
Secure environment and secret configuration.
TLS-enabled public routes.
Working CI/CD deployment flow.
MongoDB backup and restore procedure.
Monitoring and operational checklist.
Rollback procedure.
Final handover documentation.
Please include in your proposal:
Similar Kubernetes/K3s production deployments you have done.
Your experience with Helm and GitHub Actions.
Your approach to secret management.
Estimated timeline.
Any security checklist you normally follow before production launch.