GitOps & agentic platform engineering. I build systems that deploy, secure, and heal themselves.
From nuclear-missile technician to self-taught cloud engineer. Argo CD, Kargo, Kyverno, Terraform, and a self-built production cluster this very site runs on.
Two decades of high-stakes technical work, then I bet on myself and started over.
I walked away from nearly twenty years in audio-visual engineering to be present for my daughter,
and taught myself cloud engineering from nothing in nine months. In five years I’ve gone from
junior to running production platforms end to end. I don’t just work hard at this. I love it.
2000 – 2004
U.S. Air Force · Nuclear Missile Technician
Maintained Minuteman III missile silos: solid rocket boosters, guidance systems, propulsion, and warheads. Held a Top Secret clearance.
Everything ran on checklists, two-person integrity, and verification. Nothing moved on a hunch and nothing shipped unverified.
It taught me that in high-consequence systems the process is the product. That has never left me.
2004 – 2021
Live-Event AV · up to Technical Director
Nearly two decades engineering audio for churches, corporate events, and touring entertainment, working up to Technical Director.
Live events have no retakes. You design the system, you test it, and when something breaks you fix it while a full room watches. Two decades of that builds a specific kind of calm.
Then COVID crashed the industry, my daughter was eight, and I had an epiphany: I wouldn’t miss the next eight years.
2021 – Present
Tensure Consulting · Jr → Cloud Engineer
Nine months of self-taught study, day and night, landed my first DevOps role. From there: Junior DevOps, Associate, and Mid-Level Cloud Engineer.
Today I operate Argo CD GitOps control planes, write Terraform and Kyverno policy-as-code, and build agentic infrastructure that automates platform operations.
Same instinct as the silo and the sound board: build it so it holds, then prove it.
"My only regret is that I didn’t find this 20 years ago, but my track record shows I’m a fast
learner, self-motivated, and I’ll never stop improving."
Live Homelab
This site runs on hardware I built and operate myself.
Not a metaphor. The page you're reading is served from an 8-node Proxmox + Ceph cluster in my home,
GitOps-managed with Argo CD. These numbers are pulled live from the cluster (read-only) and refresh on load.
—
Argo CD apps healthy
GitOps-managed
—
Cluster nodes
Proxmox + K3s
—
Running pods
across namespaces
—
Ceph raw storage
hyperconverged
—
Ceph utilization
3× replication
—
Longest node uptime
and counting
Fetching live cluster status…
Selected Work
Real systems, in production, built end to end.
A mix of anonymized client platform work and systems I've designed, built, and operate myself.
Every card has a short audio walkthrough. Filter by the tech that matters to you.
Homelab Private Cloud
Personal · 8 nodes
An 8-node hyperconverged cluster running live production workloads
Designed and operate an 8-node Proxmox + Ceph cluster (~56 TiB) hosting an HA K3s Kubernetes cluster. Everything is GitOps-managed with Argo CD (app-of-apps), Helm, and Traefik, exposed via Cloudflare Tunnels. This very site runs on it.
ProxmoxCephK3sArgo CDHelmKubernetes
GKE GitOps Control Plane
Client work · GCP
A production Kubernetes platform, fully GitOps-managed
Operate a production GKE cluster managed end to end by Argo CD: ApplicationSets and app-of-apps driving 30+ platform addons with automated sync and self-heal, progressive delivery with Kargo, Helm value overlays, and self-service infrastructure via Crossplane.
Argo CDKargoGKECrossplaneHelmKubernetes
GCP Secure Landing Zone
Client work · GCP
An enterprise cloud foundation for a private-equity client
Delivered an 8-stage Terraform landing zone: org policy, centralized IAM, Security Command Center, logging and cost controls, base and restricted Shared VPCs, Cloud NAT, and Cloud Armor, with keyless CI via Workload Identity Federation. Client details omitted.
TerraformGCPSecurityGKE
Aegis
Personal · DV-CRM
A purpose-built, survivor-led CRM for domestic-violence non-profits
A TypeScript end-to-end CRM (Hono + tRPC + Drizzle) on Postgres with row-level security, pgcrypto PII encryption, and an append-only audit log. Deployed on K3s via Argo CD with a Postgres-native job queue and a scheduled media pipeline. Compliance-honest by design.
TypeScriptPostgresArgo CDKubernetesRLS
FilterParent
Personal · Public beta
Safety-critical AI communication filtering, in public beta
A FastAPI + async Postgres + Redis backend on K3s with queue workers, integrating Twilio (A2P 10DLC), Claude, Whisper, and Stripe. Scaled by migrating shared audio storage from RWO to RWX CephFS, with application-layer encryption for sensitive content.
FastAPIClaudeWhisperTwilioCephFS
Cloud Infrastructure Modernization
Client work · GCP
Consolidating messaging and going GitOps across GKE environments
Migrated RabbitMQ off a dedicated standalone cluster into the existing GKE application clusters, removing a whole tier of infrastructure. Deployments moved to FluxCD with Kustomize overlays per environment, and Private Service Connect behind internal load balancers gave other GCP projects private access to RabbitMQ with no public endpoints, and without redesigning the network into a Shared VPC.
GKEFluxCDKustomizeRabbitMQGCPKubernetesGitOps
RabbitMQ Sleep / Wake Automation
Client work · GCP
Nightly shutdown and morning restore, fully automated
A reusable GitHub Action that pauses Flux reconciliation, scales RabbitMQ StatefulSets down for the night, then restores them and resumes reconciliation each morning across multiple GKE environments, reporting to Slack either way. One action covers both operations through a job-type input, replacing duplicated workflows and the manual steps they needed.
On-prem SQL Server to Azure SQL, provisioned entirely in Terraform
Migrated an on-premises SQL Server estate to Azure SQL Database with Azure Database Migration Service, and built everything underneath it in Terraform: VNets and subnets, NSGs, private endpoints with private DNS, managed identities and RBAC, and Entra ID authentication. Reviewed compute tiers and reserved-instance savings to right-size the result.
AzureTerraformAzure SQLEntra IDSecurity
AWS RDS Terraform Platform
Client work · AWS
T-shirt sizing that lets app teams ship databases safely
A two-repo Terraform platform: a core module encoding enterprise security and AWS standards, and a thin application-facing repo teams actually touch. Pick a size (small, medium, large) and an environment, and the module derives backup retention, storage, monitoring, encryption, maintenance windows, and Multi-AZ, with per-setting overrides when a team needs one. A single codebase covers PostgreSQL, MySQL, and Oracle.
TerraformAWSRDSIaCPlatform
AWS DBaaS Secrets Rotation
Client work · AWS
Hardened database credential rotation at enterprise scale
Hardened the secrets-rotation platform for an enterprise financial-services database-as-a-service across RDS and Aurora (five engines), with engine-aware endpoint routing, an S3 race-condition fix, and Terraform native test suites. Client details omitted.
AWSTerraformAuroraRDS
Freedom Automations
Personal · Multi-tenant
A multi-tenant automation platform on Kubernetes
Each customer is an isolated namespace provisioned by a reusable Helm chart (queue-mode n8n, CloudNativePG HA, cache, quotas, NetworkPolicy). A content-hash-triggered Argo CD pipeline auto-deploys workflows; a custom image bakes in a 97% PDF-compression step.
HelmArgo CDCloudNativePGn8nGitOps
Centralized Identity Platform
Client work · Identity
Single sign-on across cloud and SaaS
Deployed Authentik and Keycloak on GKE as a centralized identity broker, integrating AWS IAM Identity Center via SAML and SCIM, with platform secrets managed by External Secrets Operator and Google Secret Manager.
AuthentikSAMLGKESecurity
DriveForge
Personal · MIT
Open-source drive-refurbishment appliance
A FastAPI + asyncio appliance automating NIST 800-88 secure erase across a multi-node fleet with mDNS auto-discovery. A dual-ISO GitHub Actions release pipeline ships two Debian Live images per tag, backed by 793 unit tests plus real-hardware integration tests.
PythonFastAPIGitHub ActionsDebianOpen Source
FFN Case Analyzer
Personal · AI / RAG
RAG-powered document pattern analysis
A FastAPI + Qdrant retrieval-augmented service using Claude and OpenAI embeddings to detect patterns across private document corpora. Containerized and deployed to K3s alongside the rest of the platform.
RAGQdrantClaudeFastAPI
Fortified Freedom Website
Personal · Production
The public home of a domestic-violence protection non-profit
A hardened static site delivered through the same GitOps pipeline as the rest of the platform: custom nginx image built in CI, deployed by a self-registered Argo CD Application, exposed via Cloudflare Tunnel with edge TLS.
nginxArgo CDCloudflareCI/CD
Kirk
Personal · Local AI
A fully local AI voice assistant + knowledge base
A self-hosted voice pipeline (wake-word to Whisper to agent to ElevenLabs TTS) with a RAG knowledge base over a personal vault (Ollama embeddings to Qdrant), exposed via CLI, HTTP, and a Model Context Protocol server.
OllamaWhisperQdrantMCPRAG
Recommendations
If you hand JT a problem, he will solve it.
Cameron Holtfour years alongside JT at Tensure
“
I had the pleasure of working alongside JT at Tensure for just over four years, and I can say without hesitation that he's one of the most capable and genuinely enjoyable people I've ever worked with. He has a rare gift: give him a problem or an idea, and he'll dive in headfirst, learning it inside and out until he's mastered it. That relentless curiosity means he's constantly expanding what he can do, and the team always benefits from it.
What sets JT apart is the combination of raw intelligence and approachability. He's sharp, but he's also down to earth and easy to talk to, the kind of person who makes hard problems feel solvable and collaboration feel effortless. Lately he's channeled that drive into AI and infrastructure, building systems that do remarkable amounts of work for him. But the tools are only half the story; it's the context and judgment behind them that make the difference, and that's something he brings in spades.
Simply put, if you hand JT a problem, he will solve it. I recommend him wholeheartedly for any role he sets his sights on, and any team would be lucky to have him.
“
JT and I worked together on a client project and had won the client's trust when establishing their monitoring stack. Along the way, he also won my trust as I didn't need to manage his work beyond your typical PR review. He's advanced rapidly in a short time and is really making strides in this new career.
“
JT is a highly motivated engineer that picks up new technologies quickly. He's a tinkerer at heart and has a true passion for this line of work that will take him very far. IAC, Kubernetes, AI, Cloud, Hybrid, On Prem. Wherever you place him, he will excel!
“
I had the pleasure of working alongside JT at Tensure for just over four years, and I can say without hesitation that he's one of the most capable and genuinely enjoyable people I've ever worked with. He has a rare gift: give him a problem or an idea, and he'll dive in headfirst, learning it inside and out until he's mastered it. That relentless curiosity means he's constantly expanding what he can do, and the team always benefits from it.
What sets JT apart is the combination of raw intelligence and approachability. He's sharp, but he's also down to earth and easy to talk to, the kind of person who makes hard problems feel solvable and collaboration feel effortless. Lately he's channeled that drive into AI and infrastructure, building systems that do remarkable amounts of work for him. But the tools are only half the story; it's the context and judgment behind them that make the difference, and that's something he brings in spades.
Simply put, if you hand JT a problem, he will solve it. I recommend him wholeheartedly for any role he sets his sights on, and any team would be lucky to have him.
“
JT and I worked together on a client project and had won the client's trust when establishing their monitoring stack. Along the way, he also won my trust as I didn't need to manage his work beyond your typical PR review. He's advanced rapidly in a short time and is really making strides in this new career.
“
JT is a highly motivated engineer that picks up new technologies quickly. He's a tinkerer at heart and has a true passion for this line of work that will take him very far. IAC, Kubernetes, AI, Cloud, Hybrid, On Prem. Wherever you place him, he will excel!
Recommendations written on LinkedIn. Hover to pause, click any card to read it in full.
Slack high-fivesShout-outs from five years in Tensure's #highfives channel.
1 / 4
I watched you in a month go from "I am trying out learning to be DevOps" to accomplishing many technical tasks you've never done before. DevOps / System Administration is obviously coming naturally to you. You're gonna kill it.
NathanLead DevSecOps Manager+++++
Went from working in project management last year to handling his own Friday Triage as a DevOps engineer at Chord. He even fixed an issue that popped up while the rest of the team was on vacation. I am proud of you, man.
MallerieProject Supervisor+++++
Reading through the Chord SOC 2 Type 2 audit work, his stuff is INSANELY DETAILED, to the point where he gives deep explanations of his evidence with plenty of screenshots to back it up. You are much better at this than you think.
NathanLead DevSecOps Manager++++++
Rocking an awesome complex Terraform demo.
JamesCloud Architect++++
Awesome work at Roark. And a cool Helm and GitOps bridge demo.
JoeCloud Practice Director++
Fantastic job! The Pindrop leadership team had genuinely glowing remarks about your performances. Well done!
FrankPresident of Sales++++
Huge shoutout for the work on the Pindrop project over the last 5 months. Glowing remarks from Pindrop in our closeout meeting.
AntonioProject Manager++++
For all your hard work at Synchrony. The Product Owner shared his appreciation for the demos and willingness to assist in Agile planning for the upcoming PI.
AntonioProject Manager+++
For closing out Roark strong. I think CSAT is going to be through the roof on this one. It sounds like they're interested in being a repeat customer.
JoeCloud Practice Director+++
Amazing and informative demo on T-shirt sizing! Great work!
Michael+++++
For your time figuring out a solution and learning the knowledge as you go to get it accomplished.
CamContent Strategist++++++
Appreciate you jumping in and continuing to grow and impress!
FrankPresident of Sales+++++
Getting a great public shoutout in standup this morning from the project sponsor.
John++++
Shoutout for knocking it out of the park with the client!
MallerieProject Supervisor+++++++++++
For completing the final migration on a Friday night for 4C for Children. They worked after hours to get it done.
AntonioProject Manager++++
Shout out to JT for continuing to crush Data Studio for Canary reporting!
Kevin++++++
Thankful to have such an amazing team that knows how to impress our clients. You guys make my job 10x easier.
AntonioProject Manager++
Beat me to it John! Great work JT. Truly representing what it means to be a part of Tensure!
AntonioProject Manager+++
For referring me to Tensure, and always watching my journey as a programmer, and as a person.
Josiah++
For the DevOps coffee chats!
DavidPrincipal DevOps Engineer+
For bringing some awesome production value to our townhalls!
Dan++++++
For always making our Town Hall meetings rock!
Karen+++
4C wrapped up and the client told us: Tensure really listened and understood our needs. Timeline estimates were extremely on-point and we are so happy with the end product.
Dan++
Thanks JT for getting me addicted to yet ANOTHER game. I'm getting too old for this.
CamContent Strategist++
Recommendation
The Toolkit
Depth across the platform stack.
GitOps & Delivery
Argo CDKargoCrossplaneHelmKyverno
Kubernetes
GKEK3sCloudNativePGcert-managerTraefik
Cloud
GCPAWSCloud RunCloud SQLIAM Identity Center
Infra as Code / CI
TerraformGitHub ActionsCloud BuildJenkinsRenovate
Platform & Storage
ProxmoxCephZFSPrometheusGrafana
Agentic AI
ClaudeMCPRAGQdrantWhisper
Ask About My Work
Curious about something specific? Just ask.
This assistant answers questions about my experience and projects, grounded in my own notes.
It's powered by Claude and, fittingly, runs on the cluster it's telling you about.
Hi! I'm JT's assistant. Ask me anything about his experience, projects, or availability.
Work With Me
Let's build something that runs itself.
Open to full-time roles and contract engagements. If you need GitOps, Kubernetes, or agentic
platform work done right, I'd love to talk.
AvailabilityFull-time & contract
Contract rateFrom $200/hr
LocationGermantown, WI · Remote
Code samplesAvailable on request
Download Resume
Which version?
Grab the tight one-pager, the full extended resume, or both.
Cloud and platform engineer focused on GitOps delivery and platform automation. I design and operate Argo CD-driven Kubernetes platforms with Kargo progressive delivery and Kyverno policy-as-code, provision everything through Terraform, and build agentic AI infrastructure that automates platform operations. Seeking a senior platform / cloud engineering role where deep GitOps and automation expertise drives reliability and velocity.
Professional Experience
Cloud / Platform Engineer | Tensure Consulting
2021 - Present
Progressed Jr. DevOps → Associate → Mid-Level Cloud Engineer
Operate an Argo CD GitOps control plane for a production GKE cluster: ApplicationSets + app-of-apps managing 30+ addons with automated sync and self-heal; adapted the open-source GitOps-bridge pattern from AWS/EKS to GKE.
Automated progressive delivery with Kargo (Warehouse → Stage → Promotion pipelines), continuously updating platform components and applications from Git.
Authored policy-as-code with Kyverno (validation, mutation, and generation): security baselines, injected security contexts, and auto-generated LimitRange + NetworkPolicy per namespace.
Built and maintain Terraform IaC on GCP: 20+ project stacks and an enterprise Secure Landing Zone (Shared VPC, Cloud NAT, Cloud Armor, CIS org policies) with keyless Workload Identity Federation CI/CD.
Drive IaC CI/CD with GitHub Actions and Google Cloud Build: path-based Terraform plan/apply, keyless Workload Identity Federation, and native .tftest.hcl test suites across 20+ stacks.
Codified GCP security guardrails: CIS Foundation Benchmark org policies in Terraform, Security Command Center, and nightly automated posture scans.
Enabled self-service infrastructure with Crossplane, letting developers request cloud resources through the Kubernetes API.
Built agentic AI infrastructure: Model Context Protocol (MCP) servers exposing Kubernetes / Argo CD, GitHub, and Slack operations as LLM-callable tools, plus a Claude-driven daily platform-audit pipeline.
In progress (independent R&D): building in-cluster agentic operators: LLM-driven Kubernetes controllers for log monitoring, error mediation, and automated self-healing.
Additional experience examples available on request.