Selected engineering work

Systems I've built.
Decisions you can inspect.

Four independent projects covering streaming, Kubernetes operations, infrastructure and delivery. Each case study documents my implementation, the tradeoffs and the evidence behind the result.

Independent engineering portfolioScope & provenance

Every architecture, measurement and demonstration shown here comes from my own project environments. No former-employer source code, configuration, customer information, infrastructure inventory, budgets or production metrics are presented.

Flagship case study

Kafka Streaming Platform

I built a sensor-event pipeline with Python services, a three-node Kafka KRaft cluster and PostgreSQL on Kubernetes. Application logic, stateful infrastructure and the ordered Argo CD rollout are managed separately.

Objective
Ingest, process and expose IoT-style sensor events reliably.
Ownership
Architecture, containerization, Kubernetes runtime and GitOps rollout.
Evidence
Replication factor 3, minimum ISR 2, persistent storage and sync waves 0-5.
Read case study

Platform operations

EKS Platform Tools

I built an EKS operational layer with workload-aware provisioning, shared observability and scoped CI runners. A 22-day Cost Explorer report records 100% Spot usage in this project environment.

Decision
Express capacity policy and limits in Karpenter.
Evidence
NodePool configuration, runtime inventory and tagged spend.
KarpenterPrometheusGrafanaGitLab Runner
Read case study

Infrastructure automation

EKS Terraform Infrastructure

I defined the networking, identity and cluster boundaries as separate Terraform responsibilities: three availability zones, private IPv6 workers, seven service endpoints and controlled scaling.

Decision
Keep private service access explicit in the VPC design.
Evidence
Module boundaries, source inventory and deployment order.
TerraformEKSIPv6AWS
Read case study

Live delivery infrastructure

This portfolio is also a deployed system.

Terraform manages a Route 53 and CloudFront delivery path backed by a private S3 origin. Deployment, cache invalidation, origin isolation, TLS and cost controls are documented as operational evidence.

View the AWS delivery case study
Origin
Private S3 through OAC
Edge
CloudFront + managed WAF
DNS
Route 53 A and AAAA aliases
Guard
Budget alerts + automated spend protection

AI-assisted product and engineering workflows

FitBack Coach and controlled agent-assisted delivery are presented separately from the cloud infrastructure case studies.

Explore AI Workflows