01 / Selected projects

Work that made a better path.

Platforms, tools and contributions shaped around a real constraint: remove friction, make the system safer and give engineers more leverage.

Ownership is labelled explicitly. Public code is linked; internal work is described through the problem, David's contribution and the outcome.

Selected engineering projects

04 Open source 2024–present Active

Owned · Creator and maintainer

Kubernetes SSH Router

A Kubernetes-native SSH routing service that maps managed identities to controlled exec sessions without distributing direct cluster credentials.

Constraint

Operational access needs to remain auditable and scalable without creating another static bastion configuration or handing broad kubeconfig access to users.

Contribution

  • Implemented Kubernetes exec routing with client-go and secret-backed user definitions
  • Added resource watchers, operational metrics and horizontally scalable deployment support
  • Structured the code for unit testing and predictable reconciliation behaviour

Outcome

  • Centralised access rules in Kubernetes-native resources
  • Reduced manual identity and routing configuration
  • Created an inspectable foundation for controlled operational access
  • Go
  • client-go
  • Kubernetes
  • SSH
  • Prometheus
05 Platform engineering 2017–2019 Delivered

Contributed · Infrastructure platform engineer

On-premises Kubernetes Platform

Platform engineering across on-premises and cloud Kubernetes, focused on resilience, repeatability and reducing day-two operational work.

Constraint

On-premises clusters needed cloud-like lifecycle controls while working within physical infrastructure, failure-domain and provisioning constraints.

Contribution

  • Established availability zones to improve cluster resilience
  • Developed a custom cloud controller for on-premises node provisioning
  • Automated patching, reporting and infrastructure deployment

Outcome

  • Reduced engineering time spent on recurring operational tasks
  • Improved failure-domain awareness and platform resilience
  • Brought repeatable cloud-style controls into an on-premises environment
  • Go
  • Kubernetes
  • Terraform
  • Prometheus
  • On-premises infrastructure

04 / Connect

Building a platform with similar constraints?

Let's compare notes on the technical and organisational system around it.

Start a conversation