Senior platform and site reliability engineer. I design, build and operate production infrastructure at scale — bare-metal Kubernetes, GPU clusters, hybrid networking, internal developer platforms. From low-level systems to developer tooling: I own the full stack.
Built an internal Kubernetes operator for declarative management of Keycloak clients, scopes, and AD group mappings — modernising a legacy non-HA Keycloak onto CloudNativePG, Keycloak Operator, Envoy Gateway, and Kerberos/SPNEGO integration.
Python-based golden image pipeline replacing Packer for internal image builds.
Dockerized AnyConnect VPN client with automated OTP support, multi-arch images, and CI/CD publishing to three container registries.
Specialisms: Bare-metal Kubernetes, Developer Platforms, Networking, PKI, Identity, Observability
Platform & Infra: Kubernetes, Docker, Helm, ArgoCD, Envoy Gateway, Linux, Nix, AWS, Azure, VMware
Automation & CI/CD: Terraform, Ansible, Packer, GitLab CI, GitHub Actions, Jenkins, TeamCity
Networking & Observability: Cilium, Vault, Prometheus, OpenTelemetry, Grafana, ClickHouse, S3, PostgreSQL, Kafka
Languages: Python, Go, Rust