Almost a decade moving critical systems to cloud-native environments. I treat infra as an internal product: SLOs, golden paths, measurable DX.
Today: regulated Kubernetes, end-to-end GitOps, multi-cloud (AWS · GCP · Azure), DevSecOps, AI-ready and FinOps. I build EnkiFlow and GetDecant — SaaS in production.
Two SaaS in production and two open-source repos that hold the operation together. Four active fronts.
AI-focused time tracker for builders: analyzes pages, captures context via voice or video, and syncs work across web, desktop, Chrome Extension, and VS Code.
Visit sitePremium SaaS for perfume retail: touch POS, milliliter-level inventory, per-presentation pricing, and multi-store operation with roles, transfers, and super-admin.
Visit siteLocal-first IaC repo with official Terraform, Cloudflare DNS, HCP Terraform, Vercel, Supabase, and secrets via 1Password — powering cobos.io, enkiflow, and getdecant.
View repoThis very site: single-page portfolio with operator-console aesthetic, Next.js 16, React 19, Tailwind v4, and a dev terminal that mutates the DOM live.
View repoIndustry certifications mapped to the platform work I do daily — Kubernetes, multi-cloud, IaC. A roadmap, tracked in the open.
Production cluster operations — backs the regulated EKS work I already ship.
Architect-level credential for the legacy → EKS migrations I lead.
Supply-chain, runtime, OPA/Falco — the DevSecOps angle, signed.
Multi-cloud parity for the AWS+GCP work in flight.
GPU pools, vector DBs, LLM gateways with guardrails and observability.
IDPs with golden paths, Backstage, signed service contracts.
Per-team allocation, carbon-aware scheduling, aggressive autoscaling.
mTLS, SPIFFE/SPIRE, OPA/Gatekeeper, supply-chain SLSA L3.
K8s at the edge (k3s, Karmada), CDN-as-compute, geo replication.
Rego, Cue, Kyverno — compliance is a commit.
Mapping the current system, real debt, and real constraints — not the ones in the wiki.
Platform design with SLOs, cost, security, and developer experience from day one.
Strangler fig pattern, end-to-end GitOps, observability before features.
Runbooks as code, chaos drills, monthly FinOps. The platform evolves — it doesn't freeze.
Audits, target architectures, migrations, internal platforms, FinOps. If the problem is infra and it hurts, drop me a line.