About me

I'm a DevOps Engineer based in Pune, India, with six years of building secure, scalable cloud infrastructure on AWS, Azure and Hetzner bare metal — and the Technical Account Manager who makes sure enterprise clients' SLAs are actually met. I like systems that are boring to operate because someone did the hard thinking up front.

I run Kubernetes where it earns its keep (EKS, AKS, Kops, Cluster API), keep environments identical with Infrastructure as Code (Terraform, Pulumi, Crossplane) and configuration management (Helm, Puppet), and ship through GitOps (ArgoCD, GitHub and Gitea Actions, Harness). My path started in ethical hacking, so I architect to survive an adversary: zero-trust networks with WireGuard and Netbird, Vault, Harbor, Keycloak SSO — with deep observability from Prometheus, Grafana, OpenObserve and Graylog. When the tool I need doesn't exist, I write it in Go, Python or Bash and contribute it back.

What I'm doing

  • Cloud & Kubernetes platforms

    AWS, Azure and Hetzner bare metal; EKS, AKS, Kops and Cluster API clusters running real production — currently 200+ Linux servers and 50+ Kubernetes clusters.

  • Infrastructure as Code & GitOps

    Terraform, Pulumi, Crossplane, Helm and Puppet for drift-free environments; ArgoCD with GitHub, Gitea Actions and Harness for zero-downtime releases.

  • Security & zero trust

    WireGuard and Netbird networks, Vault, Harbor with Kyverno policies, Keycloak SSO, PCI-DSS hardening — built by someone who started out as a pentester.

  • Observability & reliability

    Prometheus, Grafana, OpenObserve, Graylog, ELK and CloudWatch; highly available MongoDB and PostgreSQL; SLAs owned end to end as a Technical Account Manager.

Resume

Experience

  1. Obmondo — DevOps Engineer & Technical Account Manager

    Aug 2023 — Present · Mumbai, India (Remote)
    • Own day-to-day operations and uptime for 200+ Linux servers and 50+ production Kubernetes clusters.
    • Drove the migration from Azure AKS to self-hosted Cluster API (CAPI) on Hetzner bare metal, cutting monthly cloud cost and gaining compute.
    • Replaced Terraform state files with Crossplane: custom Compositions for Kops and AKS environments removed configuration drift and made provisioning much faster.
    • Standardised CI/CD on Gitea Actions and GitHub Actions wired into ArgoCD for zero-downtime GitOps releases; automated OS patching and configuration of the whole fleet with Puppet.
    • Deployed Harbor as an internal image proxy with Kyverno policies (no more Docker Hub rate limits, signed supply chain); rolled out Keycloak SSO globally.
    • Rebuilt monitoring on OpenObserve, Graylog, Prometheus and Grafana; stood up local LLMs on bare-metal GPU servers to power internal Mattermost bots; primary TAM for enterprise clients against strict SLAs.
  2. Tweeny Technologies — DevOps Engineer

    Jun 2021 — Jul 2022 · Pune, India (Remote)
    • Moved core services off a legacy monolith onto AWS ECS, with event-driven pieces on AWS Lambda — cheaper and more resilient.
    • Migrated CI/CD from Jenkins to Harness and GitHub Actions with reusable modules standardising deployment of 50+ microservices.
    • Built an internal Go CLI that pulls dynamic configs and API keys from HashiCorp Vault for local testing.
    • Refactored a tightly coupled Terraform codebase into clean modules, removing duplication and shrinking the blast radius of changes.
  3. Redcarpetup.com (YCombinator '15) — Lead DevOps Engineer

    Nov 2020 — May 2021 · Delhi, India (Remote)
    • Cut monthly AWS spend by ~37% (₹8 L → ₹5 L) through auditing, right-sizing, Spot Instances and auto-scaling.
    • Hardened the architecture to PCI-DSS and met NPCI / RBI guidelines, including data-localisation for sensitive financial records.
    • Laid the Terraform foundation, ran the production Kubernetes clusters and built the CI/CD pipelines from scratch.
  4. Reliance Jio — Security Engineer

    Nov 2018 — Feb 2019 · Navi Mumbai, India
    • Deployed a host-based intrusion detection system on Wazuh with custom threat-detection rules for the internal network.
    • Built a centralised SIEM pipeline on the ELK stack, feeding IDS events into real-time dashboards.

Certifications

  1. CKA — Certified Kubernetes Administrator

    The Linux Foundation · May 2026 — May 2028
  2. AWS Certified SysOps Administrator — Associate

    Amazon Web Services · Feb 2021 — Feb 2024
  3. Certified Ethical Hacker (CEH)

    EC-Council · May 2019 — May 2022
  4. Security & cloud coursework

    2019 — 2020

    Introduction to Cybersecurity (Cisco) · Cybersecurity Practices for Industrial Control Systems (U.S. Department of Homeland Security) · Web Application Penetration Testing (Pentester Academy) · Ethical Hacker (ISOEH) · Infrastructure Automation with Terraform and The Complete Kubernetes Course (Udemy).

Education

  1. Kalinga Institute of Technology — B.Tech., Computer Science

    Sep 2017 — Jun 2020 · India
  2. SRM Institute of Technology — Diploma, Electronics & Communication

    2013 — 2016 · Chennai, India
  3. Army Public School, Bathinda — 10th, CBSE

    2013 · India

Skills

  • Cloud platforms
    • AWS (EKS, ECS, Lambda, RDS)
    • Azure (AKS, Storage, Key Vault)
    • Hetzner bare metal
  • Infrastructure as Code
    • Terraform
    • Pulumi
    • Crossplane
    • Helm
    • Kustomize
    • Puppet
  • Containers & orchestration
    • Kubernetes
    • Cluster API (CAPI)
    • Kops
    • EKS
    • AKS
    • ECS
    • Docker
  • CI/CD & automation
    • ArgoCD
    • GitHub Actions
    • Gitea Actions
    • GitLab CI
    • Harness
    • Jenkins
  • Languages
    • Go
    • Python
    • Bash
  • Monitoring & logging
    • Prometheus
    • Grafana
    • OpenObserve
    • Graylog
    • OpenSearch
    • ELK
    • CloudWatch
  • Networking & security
    • WireGuard
    • Netbird
    • Vault
    • Harbor
    • Keycloak / OIDC
    • IAM
    • TLS / certificates
    • VPC, ALB/NLB
    • Wazuh
  • Version control & tooling
    • Git
    • GitHub
    • GitLab
    • Gitea
    • Artifactory

Portfolio