I build and run Kubernetes platforms β the identity, the network edge, the secrets, the access path, the observability β and I try to make each one boring enough that nobody has to think about it at 3 a.m.
- 8+ years in infrastructure β systems engineering at ISPs and telecoms from 2016, DevOps / platform engineering since 2022.
- Kubernetes end to end β Amazon EKS in the cloud and RKE2 / Rancher on-prem, from cluster lifecycle and networking (CNI, ingress, Istio, mTLS) down to workload RBAC. CNCF Kubestronaut: CKA Β· CKAD Β· CKS Β· KCNA Β· KCSA, plus ICA and RHCSA.
- Security and identity as a specialty β zero-trust access (HashiCorp Boundary), secrets management and dynamic credentials (Vault, HCP), SSO and federation (Okta, Keycloak, OIDC), API edge (Kong). Designed and built an Okta β Boundary β Vault β EKS access path with no standing credentials.
- Production operations β observability with Prometheus, Grafana, ELK and Datadog; Kafka primary β DR switchover runbook; Linux hardening and OS imaging on Red Hat.
- Infrastructure as code and delivery β Terraform, Packer, Ansible; GitHub Actions and Jenkins; GitOps. Immutable images, OIDC-authenticated pipelines, no static cloud keys.
- Communicates the work β long-form technical writing, hand-drawn architecture diagrams, moderator of a 1,000+ member IT community in Dubai.
Everything here is my own work β hundreds of hours of drawing, designing, building and breaking. That is the part AI cannot do.
| Project | One line | Design principles |
|---|---|---|
| Zero-Trust Kubernetes Access | Okta β Boundary β Vault β private EKS: no kubeconfig, 15-minute credentials, self-scaling workers | zero trust Β· PAM Β· secrets management Β· least privilege Β· CI/CD with OIDC |
| EKS auth: OIDC + IAM β RBAC | Keycloak and IAM as two identity paths into one cluster, both scoped by RBAC | identity federation Β· authN / authZ separation Β· RBAC |
| HCP Vault cluster | Managed Vault with HVN peering and auth methods, built with Terraform | secrets management Β· private connectivity Β· IaC |
| AWS SSM access patterns | Private EC2 access with no SSH keys, three network designs, Packer images | zero inbound Β· private endpoints Β· immutable images |
| Keycloak SSO federation gateway | Identity federation behind an nginx/njs API gateway | SSO Β· edge authentication Β· API gateway |
| Kong API gateway architecture | Kong with Keycloak OIDC enforced at the edge | API gateway Β· OIDC at the edge |
| Istio Ambient Mesh deep dive | Sidecarless mesh: ztunnel, waypoints, mTLS and policy | service mesh Β· mTLS Β· L4/L7 policy |
| Rancher RKE2 Β· Kafka DR switchover | On-prem cluster lifecycle and a primary β DR runbook | on-prem platform Β· disaster recovery |
All of it, with diagrams: kst-devops.com/#portfolio Β· all repositories
All five CNCF Kubernetes certifications β Kubestronaut β plus Istio Certified Associate and RHCSA. Every badge above links to its verification.
Approach β fundamentals first, tools second. Tools change every year; the workflows underneath them β how identity is proven, how a packet reaches a private API, how a credential is minted and expires β do not. I learn the fundamentals so I can extend across workflows, not memorise one vendor's tool. I do not automate what I cannot explain. Each platform starts in the console, click by click, until I can draw the whole thing from memory β and only a design I can draw is one I let become Terraform. The drawing is the design; the code is the output.
An interview is forty minutes, maybe an hour. I always walk out wishing there had been more time. There is so much I would love to walk you through, and so little of it fits into one conversation.
So rather than spend those minutes saying I am hardworking, passionate and flexible, I would love you to see it for yourself. Those words are easy to say. I would much rather hand you something you can actually look at.
I have left the work somewhere you can take your time with it. Projects has the diagrams and the notes from things I actually built and broke. The Blog has the long write-ups, including the parts where I got it wrong and had to go back and understand it again.
There is only one thing I can really guarantee you. Whatever I take on, I put my heart into it. I think that shows in the work far more honestly than it ever could in a sentence about myself β so please have a look. I hope you can feel it.
Long-form, including the parts I got wrong first:
- What is HashiCorp Boundary? A beginner's guide
- Who actually carries the packets? Boundary workers
- A network with no way out β Boundary multi-hop on AWS
- The private worker β Boundary egress on Azure
- Your own front door β Boundary ingress on GCP
- Boundary and Microsoft Entra ID
- Keycloak SSO and identity federation
| Dubai IT Community | Moderator since 2022 |
| Dubai Directory MM | Organizer β 1,000+ members, 30 businesses Β· Facebook Β· Android app |

