Independent DevOps / Platform Engineer · Kubernetes • Terraform • GitOps • IDP • Observability • DevSecOps
I help growing engineering teams ship faster with self-service internal developer platforms, GitOps delivery, and policy-driven governance — and I build AI SRE agents that detect, remediate, and commit fixes back through GitOps.
🟢 Open to: freelance / contract engagements and full-time Platform / SRE / DevOps roles.
- Internal Developer Platforms (IDP): Backstage + Terraform golden paths for self-service provisioning
- GitOps Delivery: ArgoCD + Kubernetes rollout patterns with reliable rollbacks
- AIOps / SRE Automation: an agent I built that triages incidents, proposes remediations behind safety gates, and opens GitOps PRs
- Cloud Governance & FinOps Guardrails: Cloud Custodian (Aegis) policies to prevent cost spikes
- DevSecOps: CI/CD security gates (SAST, IaC scan, image scan, SBOM, DAST)
- Observability: Prometheus + Grafana + Loki + OpenTelemetry dashboards & alerting
- Cognee — Contributor. Landed the native Langfuse ↔ OpenTelemetry observability integration: an ergonomic config surface plus a custom span processor that maps Cognee's spans to OTel‑GenAI semantic conventions (LLM calls render as proper Generations). → my commits in
main - LikeC4 — Merged PR. Added missing test coverage for the
$excludepredicate in deployment views. → PR #2576
- Reduced S3 provisioning by 82% (45m → 8m) using golden-path templates — OPSIE
- Reduced VPC setup by 80% (60m → 12m) with standardized infra workflows — OPSIE
- Cut cloud-spend remediation from 4–24 hours → < 2 minutes with policy-as-code automation — Aegis
- Built a secure Azure pipeline with 32m 52s commit-to-deployment, fixing 2 critical CVEs — Zero-Trust
OPSIE — Internal Developer Platform · infra Backstage + Terraform + ArgoCD golden paths for self-service infra provisioning, with catalog entries auto-registered by the pipeline.
Aegis — Governance + Observability · governance Policy-as-code guardrails (Cloud Custodian, OIDC keyless) to stop runaway resources, plus an AI SRE agent that remediates incidents and commits fixes via GitOps — instrumented end-to-end with SigNoz / OpenTelemetry.
Zero-Trust DevSecOps Pipeline (Azure + AKS) Multi-stage pipeline: secret scan → IaC scan → image scan → SBOM → DAST → gated deploy, with Key Vault CSI secret injection.
Cloud: OCI, GCP (GKE), Azure (AKS / Azure DevOps), AWS Platform: Kubernetes, Docker, Helm, ArgoCD, Backstage IaC: Terraform, Cloud Custodian CI/CD: GitHub Actions, Azure Pipelines, GitLab CI, Jenkins Observability: Prometheus, Grafana, Loki, OpenTelemetry, SigNoz, Alertmanager Security: Trivy, Checkov, Gitleaks, OWASP ZAP, OPA Gatekeeper Scripting: Python, Bash
- Email: shashwat.pratap94550@gmail.com
- LinkedIn: shashwat-pratap-singh
- GitHub: @Shrinet82


