Cloud Engineer Available for cloud and platform roles
MERATE, ITALY

Federico Baldan

I run production cloud infrastructure, mainly on AWS. Earlier roles covered GCP, Azure, and Oracle Cloud. Day to day, I work with Terraform, Kubernetes, CI/CD, and the LGTM stack: Grafana, Loki, Tempo, and Mimir.

FOCUS · RELIABILITY
What I do

Cloud Engineering

AGE
23 years old
TECH
IaC · Kubernetes · Observability
EQF 5
Cloud & Data Security SpecialistITS Angelo Rizzoli

About me.

I'm a Cloud Engineer based in Merate, Italy, currently working at Satispay 🦄.

At Satispay, I work on the infrastructure behind the payments platform, where every change needs clear reviews, observability, and a rollback path.

Before that, at NEEN, I worked on client cloud environments across several providers, keeping provisioning, workloads, and monitoring consistent from project to project.

I like infrastructure that is fully defined in code, easy to review, and simple to rebuild when a team needs a clean start.

Observability

"You can't buy observability. You have to build it."

Charity Majors · Honeycomb
Provisioning
~45 min
From a manual multi-day setup to a single Terraform pipeline run.
Incident triage
<30 min
Logs, metrics, traces, dashboards, and alerts consolidated in Grafana.
Associate Degree
100/100
ITS Angelo Rizzoli, Cloud & Data Security Specialist, EQF Level 5.

Where I've worked
in production.

Cloud and platform roles where the work touched infrastructure, releases, monitoring, and the checks around each change.

Apr 2026— Present
Satispay
Milan, Italy

Cloud Engineer Fintech

  • Platform team: Work with the team behind a high-volume Italian payments platform, focusing on AWS infrastructure and internal tooling.
  • AWS infra: Keep production running across AWS, hands on with ECS, Kubernetes, Lambda, RDS, SQS, and SNS, shipping changes through established deployment patterns.
  • Terraform: Ship production IaC through plan review, approvals, and controlled applies.
Jul 2024— Apr 2026
NEEN S.p.A.
Milan, Italy

Cloud Engineer & Monitoring Team Lead Consulting

  • Multi-cloud: Built reusable modules for client projects across AWS, GCP, Azure, and OCI.
  • Puppet: Maintained Puppet code on the central master. New servers enrolled automatically and converged to the right baseline.
  • LGTM: Operated the LGTM platform with dedicated client tenants managed through IaC. Logs, metrics, and traces in one place.
  • GitLab CI/CD: Added security and quality gates ahead of each reviewed infrastructure apply.
  • Kubernetes: Supported client workloads, cluster configuration, scaling policies, and rolling deployments.
Nov 2023— Jul 2024
CODERIT s.r.l.
Milan, Italy

Cloud Engineer Consulting

  • Terraform (GCP): Provisioned and maintained dev, test, and prod environments as code: modules, remote state, and per-environment variable configuration.
  • GCP services: Compute Engine, Cloud Storage, Cloud SQL, and VPC. Reviewed service configuration and cost impact for each architecture change.
  • Cloud Build: Built automated pipelines from source to each environment, replacing manual release steps with a reviewable process.
  • GKE: Managed cluster configuration and delivered Kustomize overlay-based rollouts per environment through the CI pipeline.
  • Delivery: Owned infrastructure and release changes end-to-end, from scoping through production cutover.

Projects I've built.

INGRESSCF Tunnel EDGE ROUTINGTraefik RUNTIMEDocker PRIVATE VPNWireGuard
Personal · 2025 · Present

Self-hosted
homelab

Homelab I use to host services I rely on: Home Assistant, Vaultwarden, Umami, Immich, Radicale, Node-RED, Changedetection, and a few internal tools. Public services sit behind Cloudflare Tunnel and Traefik, admin access goes through WireGuard, and the host handles DNS, updates, filtering, and alerts.
Ingress
CF Tunnel brings traffic in without exposing any ports. Traefik picks it up and routes to the right container by hostname.
Private access
WireGuard for remote access to admin interfaces. Technitium handles local name resolution and split DNS.
Host controls
CrowdSec filters bad IPs before requests reach the app. Health checks and alerts are delivered via Telegram.
Docker ComposeTraefikCloudflare TunnelCrowdSecWireGuardTechnitium DNSWatchtowerLinux
STACKGrafana LGTM MIGRATIONZabbix → Grafana COLLECTORSAlloy SCOPEPublic cloud
Production · 2024 · 2025

Grafana monitoring
automation platform

At NEEN I worked on a shared Grafana platform for public cloud clients. The problem was the repeated manual setup: dashboards, alert rules, cloud alarms, and agents had to be recreated too often. I helped turn that into reusable templates, one on-call path for provider alarms and Grafana rules, and the first phase of the Zabbix migration with automated Alloy deployment.
Grafana
Built reusable alert and dashboard templates with shared panels, thresholds, and labels.
Cloud alarms
Normalized AWS and Azure alarms into the same alerting pipeline as Grafana rules.
Migration
Started the Zabbix-to-Grafana cutover and automated Alloy agent deployment across accounts.
Grafana Grafana Alloy Zabbix Cutover Alert Rules Dashboards Prometheus Terraform On-call Routing

My daily
stack.

Tools I use for real infrastructure work: provisioning, deployment, observability, configuration, and day-two operations.

CORE

Terraform

IaC
My main IaC tool. I use modules, plan review, and CI checks to keep provisioning repeatable across cloud providers.

Kubernetes

Container orchestration
Cluster workload operations with Helm charts, Kustomize overlays, rolling releases, health checks, and day-to-day troubleshooting.

Grafana / LGTM

Observability stack
Loki for logs, Mimir for metrics, Tempo for traces, Grafana for dashboards and alerting.
CORE

Multi-cloud

GCP · AWS · Azure · OCI
Certified on OCI, AWS, and Azure, with hands-on work across all four providers: IAM, networking, compute, storage, and service operations.

CI/CD

Pipelines & automation
Infrastructure changes go through static checks, plan review, approval, and apply instead of manual release steps.

Docker

Containers
Containerized workloads in production and CI. Multi-stage builds, image hardening, and private registry workflows.

Puppet

Config management
Declarative configuration management with pinned modules. Enforces desired state across long-running Linux VMs.

Linux

Systems · Debian / RHEL
Daily Linux operations across Debian-based systems, with some RHEL exposure. System hardening, systemd units, logs, and Bash automation.

Git

Version control · Review
Source of truth for code, configs, and infrastructure. Branch-based changes, peer review, and clean history before anything reaches production.
$_ Live · terraform apply branch: production · region: eu-west-1
~/infra/app · terraform apply -var-file=prod.tfvars live

Cloud credentials.

Current certifications across OCI, AWS, Azure, and GitHub, with the cloud fundamentals covered on the main providers.

Oracle Cloud Infrastructure3 certifications
  • Certified Multicloud Architect ProfessionalOct 2025
  • Certified Architect AssociateOct 2025
  • Certified Foundations AssociateSep 2025
Microsoft Azure4 certifications
  • Azure Administrator Associate (AZ-104)Jul 2023
  • Azure Data Fundamentals (DP-900)Jun 2023
  • Security, Compliance & Identity (SC-900)Jun 2023
  • Azure Fundamentals (AZ-900)May 2023
Amazon Web Services1 certification
  • Certified Cloud PractitionerNov 2024
GitHub1 certification
  • GitHub FoundationsNov 2024

Outside work
hours.

Away from work, I'm usually on the R3, running local routes, reading and taking notes, or changing something in the home rack.

✦ Outside the terminal ✦
Yamaha R3 · Road focus
Yamaha Motor logo
Motorcycle
Early rides on the R3, before the roads fill up. It's the cleanest way I know to get away from alerts, dashboards, and screens for a while.
Yamaha R3 Weekends
Trail · Merate
Active · Trails
Running
Mostly steady trail runs, with 5km or more when there's enough time before work.
5km+ Trails
Unova · Starters
Snivy Oshawott Tepig

Every great journey starts
with a small choice

Pokémon · TCG Collector
Pokémon
I collect more than I play: booster boxes, sleeved holos, graded cards, and binders that keep getting new pages.
Base Set Holo
Reading
Reading · Books
Reading
Most evenings end with a book or a long article. Technical reading keeps me sharp; fiction is what I pick up when I need to switch off.
Books Notes