Skip to content
View rosaliei's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report rosaliei

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
rosaliei/README.md

Kyaw Sithu - Platform / DevOps Engineer - Kubernetes platforms that stay boring in production - kst-devops.com

kst-devops.com LinkedIn Email Credly Repositories

I build and run Kubernetes platforms β€” the identity, the network edge, the secrets, the access path, the observability β€” and I try to make each one boring enough that nobody has to think about it at 3 a.m.

At a glance

  • 8+ years in infrastructure β€” systems engineering at ISPs and telecoms from 2016, DevOps / platform engineering since 2022.
  • Kubernetes end to end β€” Amazon EKS in the cloud and RKE2 / Rancher on-prem, from cluster lifecycle and networking (CNI, ingress, Istio, mTLS) down to workload RBAC. CNCF Kubestronaut: CKA Β· CKAD Β· CKS Β· KCNA Β· KCSA, plus ICA and RHCSA.
  • Security and identity as a specialty β€” zero-trust access (HashiCorp Boundary), secrets management and dynamic credentials (Vault, HCP), SSO and federation (Okta, Keycloak, OIDC), API edge (Kong). Designed and built an Okta β†’ Boundary β†’ Vault β†’ EKS access path with no standing credentials.
  • Production operations β€” observability with Prometheus, Grafana, ELK and Datadog; Kafka primary ↔ DR switchover runbook; Linux hardening and OS imaging on Red Hat.
  • Infrastructure as code and delivery β€” Terraform, Packer, Ansible; GitHub Actions and Jenkins; GitOps. Immutable images, OIDC-authenticated pipelines, no static cloud keys.
  • Communicates the work β€” long-form technical writing, hand-drawn architecture diagrams, moderator of a 1,000+ member IT community in Dubai.

Everything here is my own work β€” hundreds of hours of drawing, designing, building and breaking. That is the part AI cannot do.

Projects

Project One line Design principles
Zero-Trust Kubernetes Access Okta β†’ Boundary β†’ Vault β†’ private EKS: no kubeconfig, 15-minute credentials, self-scaling workers zero trust Β· PAM Β· secrets management Β· least privilege Β· CI/CD with OIDC
EKS auth: OIDC + IAM β†’ RBAC Keycloak and IAM as two identity paths into one cluster, both scoped by RBAC identity federation Β· authN / authZ separation Β· RBAC
HCP Vault cluster Managed Vault with HVN peering and auth methods, built with Terraform secrets management Β· private connectivity Β· IaC
AWS SSM access patterns Private EC2 access with no SSH keys, three network designs, Packer images zero inbound Β· private endpoints Β· immutable images
Keycloak SSO federation gateway Identity federation behind an nginx/njs API gateway SSO Β· edge authentication Β· API gateway
Kong API gateway architecture Kong with Keycloak OIDC enforced at the edge API gateway Β· OIDC at the edge
Istio Ambient Mesh deep dive Sidecarless mesh: ztunnel, waypoints, mTLS and policy service mesh Β· mTLS Β· L4/L7 policy
Rancher RKE2 Β· Kafka DR switchover On-prem cluster lifecycle and a primary ↔ DR runbook on-prem platform Β· disaster recovery

All of it, with diagrams: kst-devops.com/#portfolio Β· all repositories

Certifications

CNCF Kubestronaut CKA CKAD CKS KCNA KCSA ICA RHCSA

All five CNCF Kubernetes certifications β€” Kubestronaut β€” plus Istio Certified Associate and RHCSA. Every badge above links to its verification.

How I think

Approach β€” fundamentals first, tools second. Tools change every year; the workflows underneath them β€” how identity is proven, how a packet reaches a private API, how a credential is minted and expires β€” do not. I learn the fundamentals so I can extend across workflows, not memorise one vendor's tool. I do not automate what I cannot explain. Each platform starts in the console, click by click, until I can draw the whole thing from memory β€” and only a design I can draw is one I let become Terraform. The drawing is the design; the code is the output.

I would rather show you

An interview is forty minutes, maybe an hour. I always walk out wishing there had been more time. There is so much I would love to walk you through, and so little of it fits into one conversation.

So rather than spend those minutes saying I am hardworking, passionate and flexible, I would love you to see it for yourself. Those words are easy to say. I would much rather hand you something you can actually look at.

I have left the work somewhere you can take your time with it. Projects has the diagrams and the notes from things I actually built and broke. The Blog has the long write-ups, including the parts where I got it wrong and had to go back and understand it again.

There is only one thing I can really guarantee you. Whatever I take on, I put my heart into it. I think that shows in the work far more honestly than it ever could in a sentence about myself β€” so please have a look. I hope you can feel it.

Writing

Long-form, including the parts I got wrong first:

Stack

Kubernetes & orchestration Kubernetes Amazon EKS RKE2 Rancher Helm Kustomize
Service mesh & networking Istio Consul NGINX CNI Ingress/Egress mTLS
Infrastructure as code Terraform Ansible Packer Helm charts Manifests
CI/CD & GitOps GitHub Actions Jenkins GitOps Gitea Bitbucket
Cloud platforms AWS Huawei Cloud HCP Hybrid cloud VMware ESXi
Security & identity Vault Boundary Keycloak Okta OIDC Kong
Observability & monitoring Prometheus Grafana ELK Datadog Zabbix LibreNMS
Data & messaging Kafka Kafka Connect
Linux & containers Linux Red Hat Docker Security hardening OS imaging
Programming & scripting Python Bash Shell

Community

Dubai IT Community Moderator since 2022
Dubai Directory MM Organizer β€” 1,000+ members, 30 businesses Β· Facebook Β· Android app

Pinned Loading

  1. ambient-mesh-deepdive ambient-mesh-deepdive Public

    Istio Ambient Mesh β€” sidecarless service mesh deep dive

    1

  2. aws-ssm-patterns aws-ssm-patterns Public

    AWS SSM Session Manager β€” private EC2 access three ways: VPC endpoints, NAT gateway, S3/KMS + Packer (Terraform)

    HCL 1

  3. eks-auth-oidc-iam eks-auth-oidc-iam Public

    EKS authentication & authorization: Keycloak OIDC issuer + IAM roles mapping to Kubernetes RBAC (Terraform)

    HCL 1

  4. keycloak-sso-federation-gateway keycloak-sso-federation-gateway Public

    Keycloak SSO + identity federation behind an nginx/njs API gateway

    JavaScript 1

  5. kong-api-gateway-architecture kong-api-gateway-architecture Public

    Kong API Gateway β€” Kong + Keycloak OIDC architecture research

    CoffeeScript 1