Design networks
Architecture for service-provider and enterprise networks, from routing and peering to interconnects and traffic engineering.
BGP · MPLS · VRF · IX · PPPoEInfrastructure · Networks · Security
I design, automate and secure complex networks and platforms — from service-provider networks to Kubernetes, Anti-DDoS and eBPF.

Ilia ChernikovЧерников Илья
What I do
I work at the intersection of networking, Linux, automation and security.
Architecture for service-provider and enterprise networks, from routing and peering to interconnects and traffic engineering.
BGP · MPLS · VRF · IX · PPPoEInfrastructure services and bare-metal Kubernetes, from automated provisioning to networking, storage and application delivery.
Linux · Kubernetes · Calico · CephRepeatable configurations, infrastructure automation and controlled changes instead of manual operations and tribal knowledge.
Ansible · Puppet · Python · IaCNetwork access policies for Linux infrastructure, Host Based Firewall, traffic analysis and security controls built into the platform.
HBF · eBPF · SIEM · NetFlowDistributed Anti-DDoS systems, traffic filtering, overload diagnostics and incident response across multiple data centers.
Gatekeeper · BGP · Anti-DDoSTroubleshooting complex incidents across networks, hosts and applications using observability, telemetry and traffic analysis.
Suricata · Security Onion · GraphiteInfrastructure at scale
At scale, every change needs context, risk assessment and a clear rollback path.
Selected work
Operating and scaling a centralized Host Based Firewall platform across thousands of Linux servers: analyzing network dependencies, engineering access policies and contributing to the next generation of HBF built on eBPF.
Building and operating two production bare-metal Kubernetes clusters as part of the infrastructure team, with automated provisioning, Calico networking, Ceph storage, infrastructure workloads, monitoring and application delivery.
Deploying and operating a distributed Anti-DDoS platform across multiple data centers, automating deployment with Ansible and troubleshooting traffic anomalies, overload conditions and attacks.
Developing a regional ISP network across 26 cities, including more than 1,200 switches, configuration automation, monitoring, BRAS/PPPoE, RADIUS and IPTV infrastructure.
Integrating acquired ISP networks into a larger service-provider infrastructure through staged migration of more than 30,000 subscribers, network segments, monitoring, billing systems and carrier interconnections.
The Chaos Telekom approach
The hardest infrastructure problems rarely belong to a single layer. I build context, trace dependencies across networking, Linux, automation and security, and turn complex environments into systems that can be understood, changed safely and operated reliably.
Let’s figure it out
I can help with architecture reviews, complex troubleshooting, infrastructure automation, network security and service-provider network development.