Rafael Orman

Software engineer in Vienna, at FireStart since 2023

  • Backend & DevOps
  • Homelabber
MORE

About

I am a software engineer in Vienna. At FireStart I work on the backend and the infrastructure underneath it — Go and C# services, Kubernetes, and the delivery and observability that decide whether a release is a non-event. Before that I spent two summers on reinforcement learning at enliteAI, which is why the AI work on the platform did not feel like a detour when it arrived.

The other half happens at home, on several used HPE servers that I rebuild on purpose. Most of what I know got its first run there. It is a good place to be wrong about a design before being wrong gets expensive, and it is where the tools listed below stopped being names and became things I have had to debug at least once.

Work

FireStart

since Feb 2023

Software Engineer — Backend & DevOps · Vienna

  • Core engineer on the platform since it was empty: a no-code workflow engine for business-process modelling (BPMN 2.0) with its own form modeller, now in front of more than 10,000 users, built by a cross-functional team of five.
  • Own the backend architecture — Go, C#, gRPC, GraphQL, Kubernetes, PostgreSQL, MongoDB — including the service boundaries, APIs and data models everything else has to live with.
  • Built the integration bridges that connect the existing on-premise product to the cloud platform.
  • Currently integrating the platform into the ecosystem of FTAPI, a leading secure data-exchange platform in the German-speaking region.
  • Drove the cloud migration: core infrastructure off a US hyperscaler, which cut hosting cost and made data governance and GDPR a much shorter conversation.
  • Moved delivery from ArgoCD to FluxCD with a real dev/staging/production promotion path, so releases got smaller and the surprises got rarer.
  • Instrumented the backend with OpenTelemetry and Grafana, so questions about production can be answered with data instead of guesses.
  • Integrated LLM-powered features into the production platform, and work AI-first day to day with agentic coding tools.
  • Backend team lead for about six months: code review, sprint planning, 1:1s, onboarding and mentoring.

S&T AG (S&T Group)

Jul 2021

ITSM Intern · Vienna, remote

  • A Microsoft Teams chatbot in C# for enterprise communication, wired into internal APIs and a Python framework for intelligent agents, as part of a diploma project.

enliteAI

Summers 2019 & 2020

Machine Learning Intern · Vienna

  • Self-learning systems in Python within a team of nine, training jobs run on a Kubernetes cluster, and the reinforcement learning competition held at NeurIPS 2020.

Stack

Languages

  • Go
  • C#
  • Python
  • TypeScript

Services & APIs

  • Microservices
  • gRPC
  • GraphQL
  • REST

Data

  • PostgreSQL
  • MongoDB
  • Kafka

Platform & delivery

  • Kubernetes
  • Docker
  • FluxCD
  • ArgoCD
  • GitHub Actions

Observability

  • OpenTelemetry
  • Grafana

AI

  • LLM integration
  • Agentic development

The lab

Hardware & virtualisation

Several used HPE servers running Incus. The instances on top are described with OpenTofu and stacked with Terramate, so the lab can be torn down and rebuilt from the repository.

Networking

OPNsense at the edge and MikroTik further in, both configured from Ansible playbooks rather than by hand in a web UI.

Identity

Authentik as the single sign-on provider in front of everything that can be persuaded to speak OIDC.

Secrets

OpenBao as the secret store, with credential rotation driven by its own playbooks instead of a calendar reminder.

Ingress

Traefik as the single entry point, routing to the container workloads and handling certificates for them.

Continuous deployment

doco-cd watches the repository and rolls out Docker Compose stacks when they change, which keeps the lab honest about what is actually deployed.

Observability

Grafana for dashboards, fed by a collector that gathers metrics from the hosts and the services running on them.

Registry

A Zot OCI registry as the local source of truth for images, with Oras pushing non-image artifacts alongside them.

Build pipelines

Jenkins handles the jobs that need to run on a schedule or on a push, and reports back into the same stack.

The part guests notice

Immich for photos, Jellyfin for media and Open WebUI for running models locally — the workloads that justify the rest of it.

Stack

Infrastructure as code

  • OpenTofu
  • Terramate
  • Terraform
  • Ansible
  • Mise

Virtualisation & containers

  • Incus
  • Proxmox VE
  • Docker
  • Docker Compose
  • OCI / Oras
  • Zot

Networking

  • OPNsense
  • MikroTik RouterOS
  • Traefik

Identity & secrets

  • Authentik
  • ZITADEL
  • OpenBao
  • HashiCorp Vault

Delivery & observability

  • doco-cd
  • Jenkins
  • Grafana

Open source

A year of it, and the handful of patches worth pointing at.

4,821 contributions in the last yearLessMore
SepOctNovDecJanFebMarAprMayJunJulAug
MonWedFri

31 August 2025 to 4 September 2026.

More of it, including the parts that are only interesting to me, is on GitHub.

Contact

In Vienna, Austria. Email is the surest way to reach me; the other two work as well.