DevOps Engineer · Cloud Native & AIOps Infrastructure automation, GitOps, and AI-assisted operations. Kubernetes · GitOps · Multi-cloud · AIOps.
- 🔧 Experience: Kubernetes (EKS/GKE/ACK), Argo CD, Helm, Istio, Terraform; GCP/AWS/Aliyun; Prometheus/Grafana
- 🎯 Current focus: CNCF cloud-native platforms (GitOps, service mesh) and AI-driven AIOps / FinOps workflows
- 📝 Blog: yakir.top
| Secret | Used by | Minimum access |
|---|---|---|
GH_TOKEN |
Sync | Fine-grained or classic PAT: list/clone owned (personal) repos. Org public repos in SYNC_ORGS are listed with GITHUB_TOKEN and cloned without this PAT, because org policies can reject fine-grained PATs whose lifetime exceeds 366 days. |
METRICS_TOKEN |
Metrics (optional) | Classic PAT only (repo scope). Metrics uses GitHub GraphQL, which rejects fine-grained tokens. If unset, falls back to GITHUB_TOKEN (current-repo stats only). |
GITLAB_TOKEN |
Sync | api scope (create/update projects + git push). Personal GitLab username should match the GitHub login. Org repos are created under the matching GitLab group (already created). |
GITEE_TOKEN |
Sync | Private token with repo create/push. Personal Gitee username should match the GitHub login. Org repos are created under the matching Gitee org (already created). |
Sync copies GitHub owner/name 1:1 to GitLab and Gitee. Personal private repos are included; organization repos in SYNC_ORGS are public-only.
SVG artifacts are published to the output branch (not main). Metrics and snake share an output-branch concurrency group so they do not overwrite each other.




