About The Position

We are looking for a DevOps Engineer to maintain our openDesk-Managed-Service in daily operations: deploying, updating, monitoring, and troubleshooting. You are comfortable with Kubernetes and familiar with the tools used to roll out openDesk: Helmfile over 35+ Helm charts, Helm-Diff, and delivery via GitLab CI. We operate openDesk tenant-separated across multiple Kubernetes clusters: each customer receives their own namespaces for applications, configuration, mail, and databases. You will operate the openDesk application layer, including deployments of components (Nubus/Keycloak, OX App Suite, Nextcloud, Collabora, Jitsi, Element/Synapse, OpenProject, XWiki), databases via the operators you manage (CNPG, MariaDB-Operator, Keycloak-Operator), and application-specific secrets via ExternalSecrets. The Platform Team provides clusters, networks, and shared components like cert-manager, external-dns, external-secrets, Flux, kube-prometheus-stack, Thanos, Loki, and OpenBao; you will use them but not operate them yourself. You work data-driven, automate recurring tasks, and consider security from the outset. As we operate a 24x7 service, on-call duty is an integral part of the role (no shift work). In an organization with 360-degree feedback, you contribute openly.

Requirements

  • Secure handling of Kubernetes in operation (workloads, networking, RBAC, storage, troubleshooting).
  • Experience with Helm; willingness and ideally experience with Helmfile and Helm-Diff.
  • Practical experience with CI-driven rollout (e.g., GitLab CI) and/or GitOps (Flux) as an operational model.
  • Experience with database operation (PostgreSQL/MariaDB), ideally via operators like CNPG/CloudNativePG or MariaDB-Operator.
  • Experience with monitoring/observability (Prometheus/Grafana ecosystem) and alerting.
  • Sound Linux knowledge and automation mentality (e.g., Ansible, scripting).
  • Willingness for on-call duty (24x7 service, no shift work).
  • German and English at business level (C1/C2) spoken and written.
  • Empirical-agile mindset and strong problem-solving skills.
  • Operational responsibility and reliability in a 24x7 context.
  • Strong communication and teamwork skills, combined with the ability for self-organization.
  • Security awareness (Security by Design, least privilege).
  • Willingness to give and receive 360-degree feedback.

Nice To Haves

  • Experience with openDesk components (Nubus/Keycloak, OX App Suite, Nextcloud, Collabora, Jitsi, Element/Synapse, OpenProject, XWiki).
  • Experience with secret management via ExternalSecrets and Vault/OpenBao.
  • Experience with Supporting Services (Redis/Memcached, Object Storage, Mail Infrastructure, ClamAV/ICAP, Coturn).
  • Experience with multi-tenant operation across multiple clusters (namespace layout, tenant isolation).
  • Certifications (e.g., CKA/CKS).
  • Experience from IT operations of a Managed Service or SaaS.
  • Willingness for knowledge transfer within the team.

Responsibilities

  • Responsible for the technical operation of the Managed Service: deploying and updating openDesk components via Helmfile/Helm-Diff through GitLab CI, including release and patch management; Supporting Services are rolled out via GitOps where possible.
  • Operate databases via team operators (CNPG for PostgreSQL, MariaDB-Operator): Backup/Restore, Point-in-Time-Recovery, Upgrades.
  • Manage application-specific secrets via ExternalSecrets against OpenBao.
  • Monitor the application: app-specific metrics, alerting rules, and work towards SLI/SLO based on kube-prometheus-stack, Thanos, and Loki.
  • Operate Supporting Services in the openDesk context (Redis/Memcached, Object Storage, Mail Infrastructure, ClamAV/ICAP, Coturn).
  • Perform troubleshooting/debugging on openDesk components and at the Kubernetes level, and document runbooks.
  • Automate operations and deployment, and work at the interface with the Platform Team.
  • Participate in on-call duty with the team for 24x7 operation.

Benefits

  • Remote-First as a lived model
  • Flexible working hours with personal responsibility
  • Exciting projects instead of routine tickets
  • Further education, certifications & knowledge exchange
  • Modern equipment & work environment
  • Attractive conditions including fair fixed salary and annual profit sharing
  • Option for a company car depending on the role
  • Transparent feedback culture & development
  • 30 days of vacation per year that do not expire
  • Additional insurance, e.g., group accident insurance
  • Team culture & shared experiences
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service