Platform leadership · DevSecOps · Multi-tenant systems
Hi, I’m Viswaroop — I design identity and platform systems that let organizations scale without slowing teams or breaking security.
I design identity-aware platforms using Kubernetes, GitOps, and open-source identity platforms so teams can move quickly without sacrificing security.
What I build
Systems I lead
Platform engineering
GitOps-first multi-cloud platform
ArgoCD + Kustomize + Helm to normalize app delivery across EKS/GKE, with golden paths for networking, secrets, and observability.
- Promotion pipelines that align blast radius with risk
- Tenant-aware namespaces, quotas, and policy as code
- Operational readiness baked into templates (logging/SLOs)
Reliability & operations
Guardrails that keep teams moving
SLOs, incident learnings, and paved-road patterns so platform changes ship fast without whiplash for security or compliance.
- Runbooks and dashboards owned with product teams
- Pre-flight checks for identity, policy, and secrets
- Cost/reliability tradeoffs documented with decision records
Identity & tenancy
Replacing AWS Cognito with open-source IAM
ORY Hydra/Kratos/Keto, token flows tuned for tenant isolation, auditable governance, and predictable onboarding for every new app.
- Auth boundaries that survive org growth and audits
- Revocation, rotation, and SSO flows modeled up front
- Cost/lock-in tradeoffs made explicit for stakeholders
Case studies I’m writing up
GitOps repo design beyond 5 teams
ArgoCD app-of-apps vs. tenant-per-repo, promotion lanes, and minimizing blast radius.
EKS/GKE platform hardening
Golden path for networking, secrets, TLS, and SSO across clouds—without slowing delivery.
Replacing Cognito with ORY
Context, constraints, and why open-source IAM beat managed services for multi-tenant growth.
Want the deep dives? Ask for the drafts or check back soon.
Latest writing (9)
- Ingress vs Gateway API on GKE: What Actually Changes in Production
- Observability on AWS at Scale: Six Years of Lessons from OpenSearch, EKS, and Production Reality
- Books I Plan to Read in 2026
- Books I Read in 2025
- Identity Platforms Fail at the Frontend Boundary (Part 2: When Identity Becomes a Platform Problem)
- The AI Coding Stack Is Splitting: IDE-Native vs CLI-First
- Argo CD vs Flux in Production: Insights from Running Both at Scale
- Welcome — Blog is live