Open to new opportunities

Hi, I'm Tushar.
DevOps Engineer

I design and automate cloud platforms on AWS, Azure and GCP: secure hub-and-spoke networks, private Kubernetes, and pipelines that build a full environment in one click.

2+years full-time DevOps
3clouds: AWS, Azure, GCP
40+Terraform modules built
15+Helm releases in production
60%faster environment provisioning

Brief history

Mechanical engineer turned DevOps engineer

I like infrastructure that's boring to operate: secure by default, rebuilt by code, and identical in every environment.

I work at Ksolves India in Noida, where I build and run the platform layer for client products: networks, Kubernetes clusters, secrets, observability and the pipelines that create them. The design I've built most is hub-and-spoke, which I've implemented on all three major clouds with Terraform.

Before that I set up Docker Swarm, GitLab CI and Vault for a startup, and before that I studied mechanical engineering, which is where my habit of drawing a system before building it comes from.

  • Multi-cloud (AWS, Azure, GCP)
  • Infrastructure as Code
  • Private Kubernetes platforms
  • Zero static credentials
  • Secure CI/CD pipelines
  • Observability end to end
Know more on LinkedIn

What I do

Areas of expertise

Transit Gateway · VNet peering · PSC

Cloud networking

Hub-and-spoke on AWS, Azure and GCP: shared gateway, WAF, CDN and NAT in the hub, private spokes for Kubernetes and databases. Workloads have no direct internet exposure.

Terraform · Ansible · Helm

Infrastructure as Code

40+ Terraform modules and one blueprint reused across three clouds. Environment provisioning is 60% faster and every change goes through code review.

Azure DevOps · GitLab CI · GitHub Actions

CI/CD automation

A 3-stage pipeline (hub → self-hosted agent → spoke) that builds a full environment with no manual steps, and build → test → deploy pipelines for 3 product squads.

EKS · GKE · AKS · Istio · Docker

Kubernetes & containers

15+ Helm releases on private EKS and GKE with Istio and HPA. Earlier, 8 microservices on Docker Swarm with zero-downtime deploys; dev setup went from 2 days to under 2 hours.

Vault · Workload Identity · Trivy · Gitleaks

Security & secrets

Removed long-lived cloud keys with Workload Identity Federation, moved secrets into Vault with TTL rotation, and added Trivy, Gitleaks and SonarQube gates to delivery pipelines.

Prometheus · Grafana · OpenTelemetry

Observability & cost

Metrics, dashboards and distributed tracing with Prometheus, Grafana, Jaeger and OpenTelemetry, plus scheduled off-hours shutdown to cut non-production spend.

The journey

Experience & education

  1. Oct 2024 – Present

    DevOps Engineer · Ksolves India Limited

    Noida

    • Designed hub-and-spoke platforms on AWS, GCP and Azure from one Terraform blueprint
    • Built one-click environment provisioning in Azure DevOps
    • Run private EKS/GKE clusters with Istio, Vault and security-gated delivery
  2. Feb – Jun 2024

    DevOps Engineer · BUOPSO Pvt Ltd

    Noida

    • Ran microservices on Docker Swarm with zero-downtime rolling updates
    • Set up GitLab CI/CD and HashiCorp Vault for the engineering team
  3. 2024

    B.Tech, Mechanical Engineering

    Ganga Institute of Technology & Management (MDU)

  4. 2019

    Diploma, Mechanical Engineering

    Pusa Institute of Technology (BTE)

Selected work

Projects I've built

AWS · Terraform

Hub-and-spoke with centralized egress

Spokes have no internet gateway. All traffic goes through Transit Gateway to Network Firewall and NAT in the hub, with a domain allowlist. Private EKS with IRSA, deployed by GitHub Actions over OIDC.

  • Transit Gateway
  • Network Firewall
  • EKS
  • IRSA
View on GitHub →

Azure · Terraform

Private AKS behind Azure Firewall

AKS egress forced through the hub firewall with user-defined routes. Local accounts disabled, Entra ID RBAC, workload identity, and Key Vault reachable only over a private endpoint.

  • AKS
  • Azure Firewall
  • Key Vault
  • Cilium
View on GitHub →

GCP · Terraform

Apigee X in front of private GKE

Public APIs through Apigee with no VPC peering and no proxy VMs. The spokes connect only through Private Service Connect. Cloud Armor WAF, deny-by-default egress, keyless CI via Workload Identity Federation.

  • Apigee X
  • PSC
  • GKE
  • Cloud Armor
View on GitHub →

AWS · AI agent

Deployment failure RCA agent

An AI agent built on Claude that diagnoses failed ECS/Fargate deployments from CloudWatch logs, explains the root cause in plain English and proposes a fix. Fixes run only after human approval, under a tightly scoped IAM role, with a full audit trail in RDS. Average time to resolve went from ~45 minutes to under 10.

  • ECS/Fargate
  • CloudWatch
  • CodePipeline
  • RDS
Internal project, code not public

Tricks of the trade

Tools I work with

  • AWSCloud
  • AzureCloud
  • Google CloudCloud
  • TerraformIaC
  • AnsibleIaC
  • KubernetesContainers
  • HelmContainers
  • DockerContainers
  • IstioService mesh
  • NGINX IngressContainers
  • Azure DevOpsCI/CD
  • GitHub ActionsCI/CD
  • GitLab CICI/CD
  • JenkinsCI/CD
  • Argo CDGitOps
  • VaultSecrets
  • SonarQubeCode quality
  • TrivyImage scanning
  • GitleaksSecret scanning
  • PrometheusMetrics
  • GrafanaDashboards
  • OpenTelemetryTracing
  • BashScripting
  • PythonScripting
  • LinuxOS
  • GitVersion control

Let's build something reliable.

I'm open to DevOps, platform and cloud infrastructure roles. The quickest way to reach me is email. I usually reply within a day.