Enterprise scale. Indie execution. Fully shipped.

Eight-plus years in platform and DevOps engineering, currently leading Kubernetes infrastructure at a Fortune 50 company on a fleet in the thousands of clusters. Deployment engines, fleet-wide configuration, the identity model that decides who can deploy and who can read a secret, and Vault underneath both. That is the day job.

Then I go home and ship finished products.

That combination is the reason to hire me. Most engineers who operate at this scale have never shipped a product end to end. Most people who ship products have never run a fleet. You get one person who does both, which means no bench, no handoffs, and no discovery phase spent explaining your own stack back to you.

Nothing I build asks you to trust it. Single binary where possible, local by default, your data stays yours, and the output is something you can verify yourself.

Engagements

Fixed scope, fixed price, no hourly billing. You know the number before we start.

Platform Assessment

3 days · $4,500

The cheap way to find out whether the expensive thing is worth doing.

  • A working read of your platform: tenancy model, quota and namespace governance, secret distribution, and where the blast radius actually is
  • A written, prioritized list of what will hurt you and roughly when
  • A scoped plan if a larger engagement makes sense
  • Credited in full against an audit or migration booked within 60 days

Platform Blast Radius Audit

2 weeks · $12,000

One tenant should never be able to take down the other nine hundred.

  • Namespace and quota governance review against how your teams actually deploy
  • Tenant isolation assessment: what one workload can reach, exhaust, or starve
  • Failure domain mapping, including the dependencies nobody drew on the diagram
  • Written findings with prioritized remediation, ordered by blast radius and not by how interesting the fix is

Vault Migration Sprint

4 to 6 weeks · from $30,000

Secrets sprawl is a quiet problem right up until it is the only problem.

  • Full secrets inventory and a migration plan that survives contact with your release process
  • Dynamic secrets and lease handling, so credentials stop outliving the people who used them
  • Policy, path, and auth method design built from your org structure rather than a template
  • Runbooks and a handoff session, because your team owns this when I leave

Price scales with fleet size and the number of consuming systems. The assessment above prices it exactly.

Proof

I would rather show you working software than a list of technologies.

LoomSeal is an open format for tamper-evident evidence: a specification, two independent verifiers written in different languages from that spec, thirty-three conformance vectors that both must pass, and a browser build that runs offline. There is a signed bundle on the site you can download and verify on your own machine without an account, without contacting me, and without trusting anything I say about it. Try to break it. That is the point.

SwitchTender is an automation controller that replaces AWX in a single binary with no cluster, seven execution tools, SSO and RBAC in the free tier, and a tamper-evident hash chain over every run.

Also shipped and running: whodar, Skerry, and Skua. The source for the KordLoom work is at github.com/kordloom.

Not linked here because the repositories are temporarily unavailable, but happy to walk through any of them: a programmatic SOPS library and CLI in Go with backends for age, AWS KMS, GCP KMS, Vault Transit, Azure Key Vault, and PGP; multi-cluster Kubernetes drift detection that uses the fleet as its own baseline; and a JWT library with a controller, admission webhook, JWKS publishing, and key rotation.

Who this is not for

  • Teams who want a body to fill a seat for six months. These are scoped engagements with an end date.
  • Anyone who needs a vendor name on the invoice more than they need the problem fixed.
  • Greenfield builds. I am most useful where something already exists, already has users, and already hurts.

Start

Email [email protected] with what is breaking, or what you are afraid will break. A short reply beats a long form.

Work is contracted and invoiced through KordLoom LLC, Austin, Texas.