

Senior Platform / Infrastructure Engineer
Binariks is looking for a Senior Platform / Infrastructure Engineer to join our team.
Our client has a mature Kubernetes platform - clusters, networking, certificates, DNS, GitOps deployment, full observability. It works well in their existing regions. Now they need to build it again in China. The cloud providers are different ones (Alibaba Cloud, Tencent, Huawei, or the Azure China / AWS China partitions - which are run by separate local entities and are not drop-in equivalents of the global partitions). Their managed Kubernetes offerings diverge from upstream in ways you only find out by hitting them. Public container registries, Helm repositories and package indexes aren't reliably reachable, so image and dependency distribution has to be solved in-region. Certificate issuance and DNS behave differently. And data residency is a hard requirement - China-resident data stays in China.
Your responsibilities
Our client has a mature Kubernetes platform - clusters, networking, certificates, DNS, GitOps deployment, full observability. It works well in their existing regions. Now they need to build it again in China. The cloud providers are different ones (Alibaba Cloud, Tencent, Huawei, or the Azure China / AWS China partitions - which are run by separate local entities and are not drop-in equivalents of the global partitions). Their managed Kubernetes offerings diverge from upstream in ways you only find out by hitting them. Public container registries, Helm repositories and package indexes aren't reliably reachable, so image and dependency distribution has to be solved in-region. Certificate issuance and DNS behave differently. And data residency is a hard requirement - China-resident data stays in China.
Your responsibilities
- Provisioning infrastructure with a China-available cloud provider, as code
- Porting the existing Terraform modules and Argo CD deployment pipeline onto that provider
- Solving container image, package and dependency distribution inside China — mirroring registries, Helm repositories and language package indexes in-region rather than pulling from public sources at deploy time
- Setting up DNS, certificate issuance and ingress that work reliably in-region
- Working through the registration and compliance steps that are prerequisites to serving traffic
- Standing up observability and alerting for the new region, integrated with or mirroring the existing stack
- Making sure data residency holds by design, not by convention
- Candidate must demonstrate hands-on production experience. Client will screen on this.
- Kubernetes — production operational experience, not just application deployment
- CNI and cluster networking
- Ingress configuration
- RBAC
- Cluster and node upgrade paths
- PersistentVolumes and CSI drivers
- Managed Kubernetes — provisioning and operating clusters on a cloud provider's managed offering (EKS, AKS, GKE, or equivalent)
- Provisioning clusters and node pools as code
- Integrating with provider-native services: load balancers and ingress controllers, the CSI driver for provider block and file storage, and cluster DNS
- Understanding what the managed offering does not give you, and where its defaults diverge from upstream Kubernetes
- Terraform — authoring and maintaining infrastructure modules
- Certificate and DNS management — cert-manager, Let's Encrypt, DNS providers
- Significantly strengthens a candidate; gaps here are acceptable if the required skills are strong.
- Deploying applications to Kubernetes with Argo CD and a GitOps workflow
- Helm chart authoring — not just consuming published charts
- Multi-tenant and multi-region platform design and operations, including standing up a new
- China cloud providers: Alibaba Cloud, Tencent Cloud, Huawei Cloud, or the Azure China (21Vianet) / AWS China partitions
- Managed Kubernetes on those providers — ACK, TKE, CCE — and where they diverge from upstream Kubernetes
- Terraform providers for China clouds, including the Alibaba Cloud provider
- Working around restricted egress: mirroring container registries, Helm repositories and language package indexes in-region
- China data-residency and compliance: PIPL, the Cybersecurity Law, MLPS / classified protection grading, cross-border data transfer restrictions
Your Benefits
18 days of paid annual leave
10 sick leaves
Additional days off for special occasions
Medical Care
Health check-up
Play Room
IT Cluster membership
Business Trip
Tech Talks
Training & Conferences
Certification
Accounting
Corporate currency
Work From Anywhere
Sport
Internal Activities & Events
Maternity Leave Bonus
National Holidays