Selected engineering projects
01 Upstream open source 2020–present Maintained upstream
Owned · Substantial contributor
Version Checker
Contributions to Jetstack's Kubernetes controller for observing container image versions across public and private registries.
Constraint
Registry behaviour, authentication and version semantics vary considerably, making reliable upgrade visibility harder than a simple tag comparison.
Contribution
- Expanded registry support across Docker Hub, GHCR, GCR, ECR, ACR and self-hosted registries
- Hardened semantic-version handling, caching and error paths
- Added focused controller and client tests around real registry behaviour
Outcome
- Broadened the environments in which teams could use a single version-observation workflow
- Improved confidence in registry integrations through repeatable automated tests
- Turned cloud-specific edge cases into maintainable upstream behaviour
- Go
- Kubernetes
- Container registries
- AWS
- Azure
- GCP
02 Internal platform 2021–2025 Delivered
Led · Architect and hands-on builder
Ephemeral Training Platform
A Kubernetes-based workshop platform designed to make repeatable technical training easier to prepare, deliver and reset.
Constraint
Technical workshops were slowed by environment preparation, inconsistent attendee access and the operational burden of rebuilding shared systems.
Contribution
- Architected internal and external training environments on Kubernetes
- Automated recurring preparation and delivery work
- Designed the platform around a consistent attendee experience
Outcome
- Reduced toil across repeated course deliveries
- Improved consistency for instructors and attendees
- Replaced one-off setup work with a reusable platform capability
- Kubernetes
- Go
- Argo Workflows
- RBAC
- GitOps
03 Developer platform 2014–2017 Delivered
Built · Software engineer and platform contributor
WH Cloud
An internal platform and containerised infrastructure product that changed environment delivery from a ticket-led process into a repeatable workflow.
Constraint
Teams waited three to six weeks for environments, with delivery crossing development, infrastructure, networking, security and approval boundaries.
Contribution
- Built software and automation around on-premises infrastructure and container orchestration
- Helped turn network and security workflows into visible, repeatable platform capabilities
- Led proofs of concept across Kubernetes, Mesos/Marathon and Docker Swarm
Outcome
- Reduced environment delivery from 3–6 weeks to 1–2 hours
- Helped teams move from infrastructure requests towards self-service platform workflows
- Made cross-team constraints visible enough to automate safely
- Ruby
- VMware vSphere
- Mesos
- Marathon
- Docker
- Kubernetes
04 Open source 2024–present Active
Owned · Creator and maintainer
Kubernetes SSH Router
A Kubernetes-native SSH routing service that maps managed identities to controlled exec sessions without distributing direct cluster credentials.
Constraint
Operational access needs to remain auditable and scalable without creating another static bastion configuration or handing broad kubeconfig access to users.
Contribution
- Implemented Kubernetes exec routing with client-go and secret-backed user definitions
- Added resource watchers, operational metrics and horizontally scalable deployment support
- Structured the code for unit testing and predictable reconciliation behaviour
Outcome
- Centralised access rules in Kubernetes-native resources
- Reduced manual identity and routing configuration
- Created an inspectable foundation for controlled operational access
- Go
- client-go
- Kubernetes
- SSH
- Prometheus
05 Platform engineering 2017–2019 Delivered
Contributed · Infrastructure platform engineer
On-premises Kubernetes Platform
Platform engineering across on-premises and cloud Kubernetes, focused on resilience, repeatability and reducing day-two operational work.
Constraint
On-premises clusters needed cloud-like lifecycle controls while working within physical infrastructure, failure-domain and provisioning constraints.
Contribution
- Established availability zones to improve cluster resilience
- Developed a custom cloud controller for on-premises node provisioning
- Automated patching, reporting and infrastructure deployment
Outcome
- Reduced engineering time spent on recurring operational tasks
- Improved failure-domain awareness and platform resilience
- Brought repeatable cloud-style controls into an on-premises environment
- Go
- Kubernetes
- Terraform
- Prometheus
- On-premises infrastructure