Portrait of Julian Kleinhans

Julian
Kleinhans

also known as kj187

Senior Platform Engineer

@ AOE Solutions GmbH

Hi, I’m Julian.

Platform Engineer by trade,
tinkerer by nature

I design and run cloud-native platforms on AWS and Kubernetes, with a focus on automation, observability and security. In my own time I build Jarvis, an open-source Alertmanager UI, and run a homelab like production.

  • Currently

    Senior Platform Engineer

    @ AOE Solutions GmbH

    My second time at AOE – I was there from 2015 to 2020 as software and cloud architect.

  • Experience

    20+

    years in software

  • Open source

    Jarvis

    Alertmanager UI for on-call teams

    Go & TypeScript
  • AWS certified

    Solutions Architect – Professional

    + 2 associate certifications

About

From building software to running the platforms it lives on.

I’m a platform engineer with 20+ years in software. I design and run cloud-native platforms on AWS and Kubernetes – with a focus on automation, observability and security.

Back in 2016 I found my passion for cloud infrastructure. Since then I’ve worked as Cloud Architect, Lead Cloud Architect and now Senior Platform Engineer at AOE.

Before that I spent over a decade building software – from PHP and TYPO3 to Go and Scala – and led an engineering team as Head of Software Engineering. That background still shapes how I build platforms: as products, written as code.

Experience

Nine roles, two decades, one direction.

From application development to cloud architecture and platform engineering.

Cloud & platform 2017 – today

  1. – today

    Senior Platform Engineer Now

    AOE Solutions GmbHRemote

  2. –

    Lead Cloud Architect

    Elmer Digital (Elmer Gruppe)Mönchengladbach · Hybrid

  3. –

    Cloud Architect / Platform Engineer

    AOE GmbHKrefeld

Software engineering 2003 – 2017

  1. –

    Senior Software Architect

    AOE GmbHKrefeld

  2. –

    Head of Software Engineering

    AIJKO GmbHKrefeld

    Headed the development team, with staff responsibility for its engineers.

    Acquired by AOE GmbH in April 2015

  3. –

    Lead Developer

    Bergisch Media GmbHHeiligenhaus

    Responsible for a large CRM system for Loewe, the TV manufacturer.

  4. –

    Software Engineer

    Marketing Factory Consulting GmbHDüsseldorf

  5. –

    Fachinformatiker Anwendungsentwicklung Apprentice

    wmdb Systems GmbHDüsseldorf

    Completed my apprenticeship as IT specialist for application development.

  6. –

    Fachinformatiker Anwendungsentwicklung Apprentice

    FS EDV Service & Beratungs GmbH

    Started my apprenticeship as IT specialist for application development.

Featured project · open source

Jarvis – an Alertmanager UI built for on‑call teams.

An open-source web frontend for Prometheus Alertmanager: interactive, realtime and self-hosted. Inspired by Karma, built for what day-to-day on-call work actually needs: acting on alerts, not just watching them.

Jarvis dashboard: alerts grouped by severity, with claims, silences and labels per cluster
Alerts grouped by severity: who claimed what, silence status and a timeline per alert.
  • Realtime

    Alerts stream in via WebSocket, no page reload.

  • Persistent history

    Full alert lifecycle in SQLite or PostgreSQL, with a grace period that stops ghost resolves.

  • Claims & comments

    Claim an alert, leave notes that survive restarts and re-fires.

  • Multi-cluster & HA

    Every cluster in one view, HA gossip groups deduplicated by fingerprint.

  • Silences with preview

    See exactly what a silence will hit before you create it. Templates and one-click Fast-Silence.

  • Single binary

    One container, Helm chart included, optional login with built-in accounts or OIDC.

How it’s built

AI writes much of the code. 20 years of engineering experience direct it. Not vibe-coded.

Every commit and CI run has to clear the same bar as hand-written code, and the scope is written down so the project stays focused.

Quality bar in CI

  • gosec
  • govulncheck
  • golangci-lint
  • pnpm audit
  • strict CSP
  • read-only container
  • OpenSSF Scorecard
  • OpenSSF Baseline

Go & TypeScriptApache-2.0SQLite / PostgreSQLHelm · OIDC

Homelab

A homelab, run like production.

My playground at home, built to the same standards I apply at work: everything as code, segmented, monitored and backed up.

How a change reaches the homelab 1. I commit a change, optionally AI agents make it for me. 2. The Git repository in Gitea is the single source of truth. 3. Gitea Actions run the pipeline: OpenTofu provisions, Ansible configures. 4. The change lands on a three-node Proxmox cluster with a Synology NAS. Prometheus, Alertmanager and Jarvis report back to me. observe · Prometheus → Alertmanager → Jarvis commit push apply Me intent & review 1 commit AI agents optional · make the change + Git repo Gitea · IaC 2 Gitea Actions Pipeline OpenTofu provision Ansible configure 3 Proxmox cluster pve-1 LXC · VM pve-2 LXC · VM pve-3 LXC · VM Synology NAS 4 How a change reaches the homelab 1. I commit a change, optionally AI agents make it for me. 2. The Git repository in Gitea is the single source of truth. 3. Gitea Actions run the pipeline: OpenTofu provisions, Ansible configures. 4. The change lands on a three-node Proxmox cluster with a Synology NAS. Prometheus, Alertmanager and Jarvis report back to me. observe · Alertmanager → Jarvis commit push Me intent & review 1 AI agents optional + Git repo Gitea 2 Gitea Actions Pipeline OpenTofu provision Ansible configure 3 pve-1 LXC · VM pve-2 LXC · VM pve-3 LXC · VM Synology NAS central storage Proxmox cluster 4
Fig. 1 — How a change reaches the homelabIllustrative · no live data
  1. 1Intent & review

    Every change starts as a commit. Nothing is clicked together by hand.

  2. +Optional: agents

    AI agents can make the change for me, using shared context files and my own Homelab MCP.

  3. 2Single source of truth

    Gitea holds the OpenTofu modules, Ansible roles and app configs.

  4. 3Pipeline

    Gitea Actions deploy: OpenTofu provisions LXC containers and VMs, Ansible configures them.

  5. 4Run & observe

    Three Proxmox nodes run every app. Prometheus and Alertmanager report back, alerts land in Jarvis.

At a glance what runs on it

Service map · every app in its own LXC container or VMbuilt by me
  • 3Proxmox nodes
  • 4VLANs
  • 62Shelly devices
  • 2×DNS with failover

Smart home7

  • Home Assistant
  • Frigate NVR
  • MQTT
  • Node-RED
  • 62 × Shelly
  • Smart-meter Pi
  • Kiosk dashboards

Frigate analyses the cameras locally. A Raspberry Pi in the basement reads the power meter through an IR read head and the water meter by radio.

Apps7

  • Immich
  • Paperless-ngx
  • Vaultwarden
  • Planka
  • n8n
  • Homer
  • own apps

Homer is the start page; the apps keep their data in PostgreSQL and TimescaleDB.

Observability8

  • Prometheus
  • Exporters
  • Alertmanager
  • Jarvis
  • Grafana
  • Loki
  • PatchMon
  • healthchecks.io

Alerts land in Jarvis; healthchecks.io watches the watchers.

Delivery & tooling7

  • OpenTofu
  • Ansible
  • Gitea
  • Gitea Actions
  • Image registry
  • Homelab MCP
  • UniFi MCP

OpenTofu provisions, Ansible configures, Gitea Actions deploy. Claude Code, Copilot and Codex share the same context files and use both MCPs as tools.

Edge & identity5

  • Traefik
  • Keycloak
  • Pocket-ID
  • Blocky DNS ×2
  • Keepalived

Traefik is the reverse proxy, SSO runs on Keycloak and Pocket-ID, DNS fails over via Keepalived.

Data & backups4

  • PostgreSQL
  • TimescaleDB
  • Restic
  • Hyper Backup offsite

Restic to the NAS, Hyper Backup offsite to the cloud. Home Assistant and Immich also back themselves up.

Compute & storage · 3-node Proxmox cluster

  • pve-1Lenovo ThinkCentre
  • pve-2Lenovo ThinkCentre
  • pve-3Lenovo ThinkCentre
  • SynologyNAS · central storage
  • K8scluster for experiments
  • Raspberry Pismart meter

Network · UniFi · 4 VLANs

  • TrustedVLAN
  • UntrustedVLAN
  • IoTVLAN
  • GuestVLAN

Skills

The stack, and the paper trail.

Cloud & platform

  • AWS
  • Kubernetes
  • Docker / OCI
  • Helm
  • Traefik
  • Proxmox
  • Cloud-native architecture
  • Platform engineering

IaC & delivery

  • Terraform / OpenTofu
  • Terragrunt
  • Ansible
  • GitLab / GitLab CI
  • Gitea Actions
  • Argo CD
  • GitOps
  • CI/CD pipelines

Observability & logging

  • Prometheus
  • Grafana
  • Alertmanager
  • Loki
  • Elasticsearch
  • Logstash
  • Kibana
  • Fluentd
  • Filebeat

Security

  • IT security & compliance
  • Security operations
  • SSO / OIDC
  • Network segmentation

Programming

  • Go
  • Python
  • Bash
  • TypeScript
  • Node.js
  • Scala earlier
  • PHP earlier

Ways of working

  • DevOps
  • Scrum
  • Kanban
  • German native
  • English

Certifications

Amazon Web Services

Security & more

  • Introduction to Cyber Security

    TryHackMe

    2024

  • Cybersecurity Foundation for IT Professionals

    Ripka Technologies

    2023

  • Certified TYPO3 Integrator

    TYPO3 Association

    2009

Off the clock

Life outside the terminal.

Family, games, a new instrument and a toolbox – the things that keep me busy when the laptop is closed.

  • Dad of three girls

    Three daughters – at home I’m happily outnumbered.

  • PC gamer

    When there’s time left, I like to play games on my PC.

  • Learning the piano New

    In September 2026 I bought a Casio CDP-S110 and started from zero – no musical background at all.

  • DIY at home

    I love working with my hands and do almost everything around the house myself.

Contact

Let’s talk platforms.

Cloud-native platforms, observability, homelab setups or Jarvis: I’m happy to exchange ideas. The quickest way to reach me is a message on LinkedIn or Xing.