Context & constraints
At BrainGu, I lead engineering for Kubernetes platforms supporting regulated, multi-tenant workloads across EKS and bare-metal environments. The work brings together application needs, access controls, and platform operations.
My contribution
I developed a Kubernetes operator covering tenant onboarding, RBAC, network policy, secrets management, and upgrade safety gates.
Alongside the operator, I developed Crossplane-based platform capabilities and a self-service infrastructure catalog using OpenTofu and Terragrunt.
I work with developers, security engineers, product teams, and customers to turn recurring requirements into reusable APIs and deployment patterns.
Engineering focus
- Tenant lifecycle
- Bring onboarding, access, network policy, and secrets into platform lifecycle automation.
- Upgrade readiness
- Include safety gates in the lifecycle of platforms that already support running workloads.
- Self-service interfaces
- Express recurring infrastructure needs as reusable capabilities that developers can provision.