CTCHAOSTELEKOM
Available for consulting

Infrastructure · Networks · Security

From chaosto infrastructurethat works.

I design, automate and secure complex networks and platforms — from service-provider networks to Kubernetes, Anti-DDoS and eBPF.

Ilia Chernikov
01

Ilia ChernikovЧерников Илья

18+years in networks and infrastructure

What I do

Complex systems.
Clear solutions.

I work at the intersection of networking, Linux, automation and security.

01

Design networks

Architecture for service-provider and enterprise networks, from routing and peering to interconnects and traffic engineering.

BGP · MPLS · VRF · IX · PPPoE
02

Build platforms

Infrastructure services and bare-metal Kubernetes, from automated provisioning to networking, storage and application delivery.

Linux · Kubernetes · Calico · Ceph
03{ }

Automate the repetitive

Repeatable configurations, infrastructure automation and controlled changes instead of manual operations and tribal knowledge.

Ansible · Puppet · Python · IaC
04

Secure infrastructure

Network access policies for Linux infrastructure, Host Based Firewall, traffic analysis and security controls built into the platform.

HBF · eBPF · SIEM · NetFlow
05

Handle attacks

Distributed Anti-DDoS systems, traffic filtering, overload diagnostics and incident response across multiple data centers.

Gatekeeper · BGP · Anti-DDoS
06

Find the root cause

Troubleshooting complex incidents across networks, hosts and applications using observability, telemetry and traffic analysis.

Suricata · Security Onion · Graphite

Infrastructure at scale

Scale changes everything.

At scale, every change needs context, risk assessment and a clear rollback path.

18+years in infrastructure and telecom
50K+servers — production environment scale
7 DCdistributed infrastructure operations
15KLinux servers — target HBF scope
30K+subscribers migrated across ISP networks

Selected work

Not job titles.
Engineering in practice.

A

Host Based Firewall / eBPF

Operating and scaling a centralized Host Based Firewall platform across thousands of Linux servers: analyzing network dependencies, engineering access policies and contributing to the next generation of HBF built on eBPF.

~4K → ~15K serversHBF · Puppet · eBPF
B

Bare-metal Kubernetes

Building and operating two production bare-metal Kubernetes clusters as part of the infrastructure team, with automated provisioning, Calico networking, Ceph storage, infrastructure workloads, monitoring and application delivery.

2 production clustersAnsible · Calico · Ceph
C

Distributed Anti-DDoS

Deploying and operating a distributed Anti-DDoS platform across multiple data centers, automating deployment with Ansible and troubleshooting traffic anomalies, overload conditions and attacks.

Multi-DCGatekeeper · Ansible · BGP
D

ISP Network Evolution

Developing a regional ISP network across 26 cities, including more than 1,200 switches, configuration automation, monitoring, BRAS/PPPoE, RADIUS and IPTV infrastructure.

26 cities · 1.2K switchesBRAS · IPTV · Python
E

ISP Infrastructure Migration

Integrating acquired ISP networks into a larger service-provider infrastructure through staged migration of more than 30,000 subscribers, network segments, monitoring, billing systems and carrier interconnections.

30K+ subscribersNetwork · OSS/BSS · Netcracker

The Chaos Telekom approach

See the whole system
first.

The hardest infrastructure problems rarely belong to a single layer. I build context, trace dependencies across networking, Linux, automation and security, and turn complex environments into systems that can be understood, changed safely and operated reliably.

01Context before configuration
02Automation before heroics
03Observability before guesswork
04Security as a system property

Let’s figure it out

Got an infrastructure problem
without an obvious answer?

I can help with architecture reviews, complex troubleshooting, infrastructure automation, network security and service-provider network development.