DevSecOps & Kubernetes
Build.Secure.Scale.
I'm a DevOps engineer who cares a lot about security. Day to day that means Kubernetes, CI/CD pipelines, locked down container images, Vault for secrets and policies that stop bad deploys early.
About
I've spent the last three years running Kubernetes and cloud infrastructure in production. Most of my work is taking clusters that already run, finding the gaps, fixing them and keeping them up.
- Working on production infra
- 3yrs
- Working on production infra
- Apps running at 99.9% uptime
- 30+
- Apps running at 99.9% uptime
- CI/CD pipelines with security checks
- 25+
- CI/CD pipelines with security checks
Experience
Where I've
worked.
Sep 2024 to Present
Orscope Technologies LLP
DevOps Engineer
- Kubernetes
- ArgoCD
- GitHub Actions
- Vault
- Kyverno
- Cilium
- Istio
- Karpenter
- NVIDIA MIG
CI/CD pipelines
Set up pipelines for 25+ projects using GitHub Actions and ArgoCD. Every build goes through SAST, dependency checks and image scanning, and all config sits in one central repo. Deploys now take seconds.
Kubernetes audits
Went through our live clusters one by one and fixed what wasn't ready for production: CIS Benchmark checks, tighter RBAC and proper audit logs. They now run 30+ apps at 99.9% uptime on 256GB of RAM.
Smaller, safer images
Rebuilt our container images without a shell, package manager or sudo. If someone does get code execution, there isn't much they can install or use to move around.
Secrets and policies
Moved secrets into Vault and Sealed Secrets/SOPS. Added OPA, Kyverno and Gatekeeper rules to the GitOps flow so insecure manifests get rejected before they reach production.
Networking with Cilium
Helped split a monolith into microservices on Istio, then added Cilium/eBPF network policies and runtime monitoring. Prometheus and Grafana for metrics, Karpenter, KEDA, VPA and HPA for scaling.
GPU sharing for AI
Used MIG, vGPU, time slicing and fractional GPUs so more teams could share the same cards safely, including teams running 671B and 405B parameter LLMs. Also set up KubeVirt with SR-IOV passthrough for VMs.
Jul 2023 to Aug 2024
Freelance, Remote
Software Developer
- AWS
- Terraform
- CloudFormation
- Prometheus
- Grafana
AWS setup
Built AWS environments (EC2, Fargate, ECR) with CloudFormation and kept security groups, IAM roles and load balancers on least privilege.
Terraform
Wrote Terraform for VPCs, subnets and compute across availability zones, with a disaster recovery plan and reviewed changes.
Monitoring
Set up Prometheus, Grafana and AlertManager and wired in audit logs. Incidents got picked up and fixed about 25% faster.
Projects
Things I've
built.
- 12MB RAM
Side project
Tiny Linux OS
My own stripped down Linux build. The ISO is 13MB, it runs in 12MB of RAM, and it still has SSH, FTP, Telnet, Wget and Curl.
- Linux
- Kernel
- Security
- 30% less overhead
Open source
CRI-O on Flatcar
An install script for running CRI-O on Flatcar Linux. Useful on small machines where you want a lean, locked down container runtime.
- CRI-O
- Flatcar
- Containers
Open source, PR #2256
Nextcloud entrypoint fix
Fixed the retry logic in Nextcloud's docker-entrypoint.sh so installs stop failing halfway.
- Docker
- Bash
- Nextcloud
Open source, PR #4503
LAPACK dpttrf fix
Fixed build and runtime errors in lapack/dpttrf so it compiles and returns the right results again.
- Fortran
- Numerical
- Build
Skills
What I
work with.
Security
- SAST / SCA
- Image scanning
- HashiCorp Vault
- Sealed Secrets
- SOPS
- OPA
- Kyverno
- Gatekeeper
- RBAC / IAM
- CIS Benchmarks
- Audit logging
- Cilium / eBPF
DevOps & CI/CD
- Kubernetes
- Docker
- GitHub Actions
- GitLab CI
- Jenkins
- ArgoCD
- Flux
- Terraform
- Ansible
- Helm
- Git
Cloud
- AWS
- Istio
- Envoy
- Kong
- Karpenter
- KEDA
- KubeVirt
- cert-manager
- Prometheus
- Grafana
- Jaeger
- CRDs
Languages
- Go
- Python
- Bash
- JavaScript
- Node.js
- Express
- Gin
- React
- Next.js
Blog
Notes from
the work.
All posts →Blog · 8 Oct 2026
Crash Landing in Dockerland
A crash course in Docker: containers, images, the commands you'll use every day, Dockerfiles, volumes, networking and Docker Compose.
12 min read
Blog · 20 Sept 2026
How our deploys work: GitHub Actions, ArgoCD and a few security checks
A walk through the GitOps setup I built for 25+ projects, from a push to main all the way to a running pod, and the checks that run along the way.
3 min read
Case study · 2 Aug 2026
Auditing a live Kubernetes cluster without taking it down
The checklist I follow when a cluster already runs real workloads and needs to be made production ready: CIS checks, RBAC cleanup, audit logs and network policies.
3 min read
Contact
Let's ship
something secure.
Looking for DevOps, DevSecOps or platform roles. Based in India, happy to work remote.