Secure, resilient cloud platforms that let teams ship with confidence.
I build the infrastructure, delivery pipelines, and event-driven systems behind high-stakes products — on AWS and Kubernetes, with security designed in from the start.
What I Do
Platform Engineering & DevOps
Golden-path tooling, CI/CD pipelines, and infrastructure as code on AWS and Kubernetes. I build the internal platforms that make engineering teams faster and happier.
Cloud Security
Least-privilege IAM, OIDC-based auth, PII-safe data handling, and supply-chain auditing. Security that ships as reusable guardrails, not gate reviews.
Event-Driven Architecture
Decoupling monoliths using Outbox patterns and reliable messaging. Systems that survive network partitions, handle spikes gracefully, and process every message exactly once.
Resilient Payment Infrastructure
Ledgers, reconciliation pipelines, and wallet systems. Built with deep observability and idempotent patterns so you never worry about double-spending or lost transactions.
Ditto
Ephemeral database copies with real schema, real data shape, and no shared state
A Go CLI and shared-host service that gives every developer and CI job a throwaway copy of production-shaped data — with PII scrubbing baked into the dump, OIDC-secured access, and SDKs for Go, Ruby, and TypeScript.
What it solves:
- -PII scrubbing at dump time — real production data never reaches laptops or CI logs
- -Warm copy pool: fresh database copies in seconds, not minutes
- -OIDC or token auth for shared team hosts
- -Ships via Homebrew, deb/rpm/apk, and Go install
Why it matters: Seeding staging environments with production dumps is how customer data ends up on laptops. Ditto makes the safe path the fast path — scrubbed, disposable, and provisioned in seconds.
Writing Highlights
Idempotency Without the Round-Trip
Why every distributed system needs idempotent handlers, and how to implement them without hitting the database on every message.
The Transactional Outbox Pattern
Avoiding dual-write disasters in microservices. Includes Rails implementation patterns you can ship today.
Making On-Call Sustainable
Runbooks, SLO-based alerting, blameless postmortems. How to transform on-call from dreaded to manageable.
Let's build something reliable.
I'm not job-hunting — but I'm always glad to talk platform engineering, cloud security, and open source. I read every message and respond within 48 hours.