GitOps by default
Cluster infra and tenant workloads reconciled from Git — fully auditable, no snowflakes.
The operating principle behind a global container platform: if it isn't in Git, it isn't in the cluster. OpenShift, EKS, Kyverno at the gate.
Twelve years operating platforms other teams bet their business on: clusters that heal themselves, tenants that self-service safely.
I build and run multi-tenant Kubernetes and OpenShift platforms across on-prem and AWS — ArgoCD for delivery, Kyverno for guardrails, Prometheus + Grafana + Alloy + Mimir + Loki for the truth, and a disaster-recovery plan that's been validated, not just written.
The throughline: automate the toil, secure by default, and advise the teams building on top.
Cluster infra and tenant workloads reconciled from Git — fully auditable, no snowflakes.
Kyverno policies and NetworkPolicies over runbooks. Compliance baked into the delivery path.
Consult tenant teams on OpenShift/EKS patterns, own on-call, still ship the automation myself.
Apr 2020 → present
Operate the global Red Hat OpenShift multi-tenant platform for EMEA and the Americas — two production clusters with 500+ tenant namespaces and 10,000+ running pods, plus a dedicated infra cluster (Harbor, ArgoCD, observability), in a 4–5 person team. GitOps everything with ArgoCD, enforce multi-tenant guardrails via Kyverno policy-as-code, and design CI/CD with Tekton, GitLab CI, and BuildConfigs. Built the EKS platform layer on top: Terraform + ArgoCD + Helm, Karpenter and Fargate for scale/cost, unified observability on CloudWatch + Grafana Alloy + Mimir + Loki. Own DR planning and Docs-as-Code (AsciiDoc + Antora).
Oct 2018 → Feb 2022 · part-time
Bachelor's degree completed in parallel to full-time employment at K+N. Final grade 1.2 · Thesis 1.0 — a practical, cost-efficient PostgreSQL HA architecture compared to Oracle, applied at K+N.
Jul 2014 → Mar 2020 · 5y 9m
Operated 500+ CentOS VMs across two geographically separated VMware vSphere data centres for every EMEA business unit — Contract Logistics, Road, Air, Sea Freight — managed via SaltStack and later Ansible, with Nagios monitoring and self-healing automations. Specialised in PostgreSQL HA (pgpool-II, STONITH failover, PITR) and delivered DBMOTO iSeries-to-Postgres replication + Pentaho ETL powering dashboards for Amazon, Beiersdorf, PepsiCo, Yamaha, Philip Morris, and Weber. Flagship: rolled out CLIP on-site at the Amazon Naugatuck, CT data centre.
Twelve years of commits, squashed into numbers.
Twelve years compounding across on-prem Kubernetes/OpenShift, hybrid-cloud EKS, PostgreSQL HA, and Docs-as-Code — the stack a global tenant platform is built on.
1stack:2 cloud: [aws, on-prem]3 orchestration: [openshift, kubernetes, eks, karpenter, fargate]4 delivery: [argocd, gitlab-ci, tekton, buildconfigs]5 iac: [terraform, terragrunt, ansible, awx, saltstack]6 policy: [kyverno, networkpolicies]7 observability: [prometheus, grafana, alloy, mimir, loki, cloudwatch]8 data: [postgresql-ha, pgpool-ii, dbmoto]9 storage: [netapp-trident, pure-portworx]10 docs: [asciidoc, antora, docs-as-code]
ArgoCD, GitLab CI, Tekton, OpenShift BuildConfigs, Terraform, Ansible/AWX, SaltStack
Red Hat OpenShift, Kubernetes, Amazon EKS, Karpenter, Fargate, Helm, Harbor
Prometheus, Grafana, Alloy, Mimir, Loki, CloudWatch, Kyverno, NetworkPolicies