Available for contract & consulting
I build cloud platforms and carry the pager for them.
Fourteen years of AWS, Kubernetes, Terraform, and CI/CD, most of it on call. The platform I run today peaks above 200 million requests a day. When a team needs a senior owner on an infrastructure problem for a while, that's the work I take.
200M+
requests/day at peak on the platform I run now
~$4M/yr
cloud spend held flat while traffic grew
$350K/yr
saved moving one transcode fleet to Spot
14+ yrs
building and running production infrastructure
What I take on
all services →platform
Cloud platform architecture
Full AWS environment builds and rebuilds: VPC, EKS, ECS, MSK, RDS Aurora. Done under live production load, documented on the way out.
kubernetes
Kubernetes and EKS operations
ArgoCD, Helm, Karpenter, KEDA. Cluster upgrades, ECS-to-EKS migrations, and node fleets sized for the workload instead of the worst case.
delivery
Terraform and CI/CD at scale
Hundreds of resources migrated off CloudFormation. Pipelines on GitHub Actions with OIDC role assumption, a plan on every PR, and no stored keys.
cost
Cloud cost engineering
A $500K AWS bill cut to $200K. $350K a year moved to Spot. Attribution first, then the savings, then the controls that keep them.
ai ops
AI ops and readiness
I run Claude Code against a live platform of 50+ microservices, behind a create-only gate and a production-safety review that clear before any apply. The harder part is making that speed safe for a whole team, and that's a platform problem before it's a model problem:
Identity & access
Least-privilege IAM with short-lived, scoped roles and OIDC instead of stored keys, so no human or agent holds standing production access.
Isolated environments
Separate accounts and hard blast-radius boundaries, so a wrong move in dev has no path to prod.
Ephemeral dev & test
Environments that spin up per branch and tear down after, so a fast team tests against real infrastructure without accumulating drift or idle cost.
Articles
all articles →-
AWS built a deploy mode for AI agents. Build the gates first.
CloudFormation's new express mode is made for agents: up to 4x faster, rollback off by default. What that says about where IaC is going in 2026.
-
Agent governance can't wait for the standards
NIST's AI RMF, ISO 42001, and the EU AI Act were all written before tool-calling agents, and the CSA says its own standards land through 2027. Build now.
-
Your AI agents are sharing an API key
In a 900-respondent survey, 45.6% of organizations authenticate agent-to-agent traffic with shared API keys. The identity work that has to precede autonomy.
Have a platform problem that needs an owner?
Contract and consulting engagements, remote from Colorado. Anything from a short assessment to a multi-quarter build.