Cloud Platform Engineer · FinOps · Calgary, Canada 🇨🇦 ·
I make cost, security, and reliability enforceable — not aspirational.
My work sits where platform engineering, FinOps, and governance meet: guardrails that fail closed, evidence that survives an audit, and automation that takes humans out of the critical path.
🚀 Currently shipping → cloud-finops-agent — tiered, fail-closed cost validation with production canaries and SARIF findings. Read why →
Principles I build by
| Principle | Why it holds |
|---|---|
| Policy engines over runbooks | SCPs and Kyverno enforce; documents get forgotten |
| Fail closed or it isn't safety | If the system can't verify, it stops — no silent pass |
| Document why-not, not just how | Rejected options are what stop repeated mistakes |
| Evidence over assertion | A claim without a check is a hope, not a control |
🏢 150+ AWS accounts — Control Tower + AFT, policy-gated vending, cost attribution from day one.
☸ Kubernetes at scale — Multi-tenant EKS with Karpenter, Kyverno guardrails, per-namespace budgets.
💰 $500K+/yr savings — RI/SP coverage, Graviton, gp2→gp3, storage lifecycle — each with a proof step.
🛡️ Org-wide security — IAM Identity Center, SCPs, GuardDuty + Security Hub + Config across all accounts.
⚙️ Fail-closed automation — SARIF findings, OIDC-scoped access, production canaries.
|
Tiered validation — math, metrics, production canary. SARIF findings. Fail-closed. OIDC.
|
Self-service account lifecycle. Policy-gated. Step Functions. Audit trail.
|
|
🏭 aws-aft-account-factory-blueprint Secure, cost-attributed account vending. Control Tower + AFT.
|
☸️ eks-cost-governance-toolkit Kyverno guardrails + budgeted namespaces. Multi-tenant EKS cost governance.
|
| Piece | Theme | |
|---|---|---|
| 📡 | Why Sandbox Benchmarks Don't Validate What They Claim | FinOps · Validation |
| 📐 | The Agent Is Not the Control Plane | Security · Architecture |
| 📐 | Tiered Validation Model | Systems Design |