Cloud architecture
Multi-region AWS, Azure and GCP designs: networking, identity, data paths, and the failure modes behind them.
DevSecOps & Cloud Infrastructure
Payments, healthcare, aviation and retail — on AWS, Azure and GCP. I design for the security audit as hard as for the outage.
20+ Years in IT infrastructure
20,000+ Servers on automated patching
~300 Services migrated, zero downtime
Approach
Multi-AZ data, multi-region clusters, restores that have actually been run — and blast radius drawn on purpose, so one compromised account cannot reach the next tenant.
Terraform provisions, Argo CD syncs, and any environment can be rebuilt from the repo without a single console click.
Dashboards, alerts and runbooks that name the cause, so the team on call doesn't need me at 3 am.
Services
Seven things, all of them hands-on.
Multi-region AWS, Azure and GCP designs: networking, identity, data paths, and the failure modes behind them.
EKS, AKS and GKE with Gateway API, Istio, KEDA and Karpenter. Multi-tenant, and boring to operate.
Terraform and Terragrunt modules with OIDC-based CI, so every environment is rebuildable from Git.
GitLab CI, GitHub Actions and Azure DevOps feeding Argo CD. Git becomes the deploy button.
Segmented subnets, private endpoints, secrets in Vault. CISA-aligned patch baselines across a whole AWS Organization, with the compliance evidence an audit asks for.
Metrics, logs and traces wired into the on-call rotation, so a 3 am page points at the cause.
Coaching for engineers moving into cloud, Kubernetes and DevOps — 15+ senior and mid-level engineers so far, taught from production rather than slides.
Architectures
Six platforms I have built, drawn the way they actually run.
Reference architectures and sector examples here are anonymized. Client names stay confidential.
Text description follows.
DNS & TLS
Route 53 public zone to an ACM cert, through CloudFront/WAF, into an API Gateway custom domain.
Compute
Lambda for edge logic, VPC Link to the internal ALB, EKS pods with IRSA, AWS Batch for async jobs.
Data
Aurora Multi-AZ, S3 for job I/O, Secrets Manager. Multi-region EKS behind private Route 53 zones.
Text description follows.
Ingress
Private AKS with Gateway API and App Gateway for Containers. HTTPRoute plus TLS.
Secrets
Key Vault CSI driver, with private endpoints from the spoke to the database and the vault.
Delivery
Azure DevOps CI/CD to Git, then Argo CD sync.
Text description follows.
Isolation
2 GCP projects, each with its own GKE cluster and regional external LB via Gateway API.
Artifacts & secrets
Artifact Registry per project. External Secrets syncs from Secret Manager.
GitOps
Argo CD per cluster. No shared global LB across projects.
Text description follows.
Flow
Git to CI to registry, then Argo CD syncs to EKS/AKS/GKE. Terraform provisions via OIDC.
Patching
Terraform and GitLab CI apply Patch Manager baselines and SSM Maintenance Windows.
Targeting
EC2 selected by tags, with compliance scans and scheduled patch runs across accounts.
Text description follows.
Delivery
GitHub Actions builds and pushes to Artifactory. Argo CD syncs Helm to GKE.
Platform
Multi-tenant SaaS on Kubernetes: API services, AI agents, read-only connectors.
Data
Secret Manager holds credentials. BigQuery is the warehouse for KPI analytics.
Text description follows.
Platform
Indra ATM core with RHEL servers for flight data and pilot comms.
Compute
RHEL provisioning and hardening, HA-ready for 24/7 aviation ops.
Network
Cisco switches and routers, multicast routing, VRF Multicast for segmented ATM domains, redundant links.
Expertise
Certifications
Alongside the certificates: Red Hat Enterprise Linux and Cisco networking in the field, on air traffic management systems.
Cloud & platform
Delivery & data
Work
Nine engagements, from air traffic control to the two products I helped start.
SaaS · co-founder
Co-founder of SQOR.ai. Multi-tenant SaaS on Kubernetes — API services, AI agents and read-only connectors, delivered by Argo CD. KPI analytics land in BigQuery.
800+KPIs
60+AI agents
Aviation · ATM
Provisioned and hardened Red Hat Enterprise Linux servers carrying flight data and pilot communications, built the Cisco switching and routing underneath them with redundant links and segmented multicast domains, and integrated the result into the Indra ATM core. Airport work, on systems that do not get a maintenance window.
Healthcare · Azure/AKS
Clinical applications on private AKS with Key Vault-backed secrets, private endpoints, audit logging and role-based access, rolled out on a staged plan so no patient data was ever exposed publicly.
5+containerized applications
120hphased deployment plan
Financial services · AWS EKS
EKS clusters across Canada and the US running payment batch workloads, with the whole estate provisioned from Terraform and Terragrunt modules rather than the console.
6+EKS clusters
13+payment batch jobs
Education · GCP/GKE
Two isolated GCP projects on current Kubernetes, moved off legacy ingress onto Gateway API without disrupting the public hosts students and staff use every day.
2dedicated GCP projects
30+public ingress hosts
Enterprise security · AWS
Patch baselines and maintenance windows across a mixed Linux and Windows estate, targeted by tags — EC2 across every account in the organization, and the servers still sitting in the company's own data centres, on the same schedule and the same reporting. Lambda turns the scans into the compliance and vulnerability reporting auditors ask for.
20,000+servers on automated patching
1,000+EC2 across multiple regions
Retail · Kubernetes
Moved roughly 300 business-critical services off Docker Swarm and onto Kubernetes without downtime — inventory, orders, payments and fulfilment kept trading throughout. The platform now runs on a small set of hardened base images and scales to zero with KEDA when the stores are closed.
~300services migrated, zero downtime
700+retail locations
22+application domains
25+container base images
Gaming & media · GCP
CI/CD for a large microservice estate on GCP. Three live titles and the Spanner-to-BigQuery data move went across without a maintenance window.
1M+monthly active users
100+microservices CI/CD
Scheduling SaaS · Visionary
Visionary and product inspirer for Calendmax, a scheduling platform that takes the back-and-forth out of finding a time. It ships under the line Schedule Smarter, Live Better.
Reference architectures and sector examples here are anonymized. Client names stay confidential.
Readiness
Six questions on the things that decide whether an outage is an inconvenience or a weekend: IaC coverage, GitOps and delivery, observability, DR and backup, secrets, and on-call maturity. Nothing leaves your browser — no account, no email, no tracking.
This check needs JavaScript to run. Nothing leaves your browser either way.
Your score
Send me your score and I'll tell you which gap to close first.
Talk it throughNothing leaves your browser — no account, no email, no tracking.
Contact
Tell me what's breaking, or what you're about to build.
Pick a time and it lands straight in my calendar — no back-and-forth about which Tuesday works.
Booking runs on Calendmax, which is my own product. Prefer to write? Use the address on the left.