Devops Engineer
We are looking for an infrastructure specialist to own the Zimbra platform, the SSO layer (Keycloak), and the surrounding network plumbing — DNS, TLS, reverse proxy, and Docker services.
Experience: 3–5 years
Employment Type: Full-time
Location: Sahibabad
Reports To: Engineering Manager / CTO
About the Role
We run a Zimbra Collaboration Suite (FOSS) deployment integrated with an in-house Document & Data Management System (DDMS) through single sign-on, zimlets, and a reverse-proxied service mesh. We are looking for an infrastructure specialist to own the Zimbra platform, the SSO layer (Keycloak), and the surrounding network plumbing — DNS, TLS, reverse proxy, and Docker services. You will work alongside a separate application development team: they build the zimlets and DDMS application; you make the platform they run on reliable, secure, and reproducible.
Key Responsibilities
· Administer Zimbra 10.x (FOSS): mailboxd, zmprov, zmcontrol, domain configuration, preauth keys, virtual/public service hostnames, class-of-service, and account provisioning.
· Deploy and manage zimlets delivered by the development team — zmzimletctl deployment, cache flushes, service restarts, and post-deploy health verification.
· Own the SSO layer: Keycloak realm and client administration, OIDC configuration, group and role management, LDAP user federation against Zimbra's directory, and Zimbra preauth-based seamless login.
· Manage the network path end to end: internal DNS / hosts resolution, TLS certificates and private CA trust, Caddy (or Nginx) reverse proxy configuration, CORS and Content-Security-Policy headers for cross-origin iframe embedding.
· Operate the supporting Docker Compose stack — Keycloak, PostgreSQL, MongoDB, Collabora Online — including upgrades, volumes/backups, and container networking (host-gateway, port mappings).
· Administer Linux VMs: SSH key lifecycle and hardening, sudoers policy for delegated commands, firewall/port management, service monitoring, and log analysis (mailbox.log, proxy and container logs).
· Automate operations with Bash and PowerShell — deployment scripts, environment resets, smoke tests — and keep runbooks and integration documentation current.
· Manage mail flow and deliverability: SMTP relay configuration, DNS records (MX, SPF, DKIM, DMARC), and troubleshooting message delivery issues.
· Diagnose issues across the full chain — browser, proxy, Keycloak, Zimbra — including certificate errors, token/preauth failures, redirect loops, and WOPI callback connectivity.
Required Skills & Experience
· 3+ years in Linux system administration, with at least 2 years administering a production mail platform — Zimbra strongly preferred (Postfix/Exchange/Carbonio considered).
· Working knowledge of Zimbra internals: zmprov, zimlet deployment, preauth, LDAP directory, proxy/mailbox architecture.
· Strong networking fundamentals: TCP/IP, DNS, TLS/PKI (including private CAs), reverse proxies, NAT/firewalls.
Posted August 3, 2026