Zaw Wana

Platform / Site Reliability Engineer — Kubernetes · Linux · Observability

Singapore

Download Résumé (PDF)
zaw@platform — zsh
➜~

Tools & platforms run in production

Kubernetes
Kubernetes
OpenShift
OpenShift
Docker
Docker
Helm
Helm
Terraform
Terraform
Ansible
Ansible
Jenkins
Jenkins
GitLab
GitLab
ArgoCD
ArgoCD
Git
Git
Python
Python
Bash
Bash
Java
Java
Prometheus
Prometheus
Grafana
Grafana
Elasticsearch
Elasticsearch
Kibana
Kibana
Logstash
Logstash
OpenSearch
OpenSearch
Zabbix
Zabbix
MariaDB
MariaDB
MySQL
MySQL
MongoDB
MongoDB
Redis
Redis
HashiCorp Vault
HashiCorp Vault
AWS
AWS
Azure
Azure
RHEL
RHEL
CentOS
CentOS
Rocky Linux
Rocky Linux
Ubuntu
Ubuntu
Windows Server
Windows Server
Kubernetes
Kubernetes
OpenShift
OpenShift
Docker
Docker
Helm
Helm
Terraform
Terraform
Ansible
Ansible
Jenkins
Jenkins
GitLab
GitLab
ArgoCD
ArgoCD
Git
Git
Python
Python
Bash
Bash
Java
Java
Prometheus
Prometheus
Grafana
Grafana
Elasticsearch
Elasticsearch
Kibana
Kibana
Logstash
Logstash
OpenSearch
OpenSearch
Zabbix
Zabbix
MariaDB
MariaDB
MySQL
MySQL
MongoDB
MongoDB
Redis
Redis
HashiCorp Vault
HashiCorp Vault
AWS
AWS
Azure
Azure
RHEL
RHEL
CentOS
CentOS
Rocky Linux
Rocky Linux
Ubuntu
Ubuntu
Windows Server
Windows Server

Core Technical Skills

Grouped by domain — expand a category for the full list.

Kubernetes (CKA)node lifecycleetcd healthRBACnetwork policiesresource quotasPV/PVC & storage classesOpenShift (OCP 4.x)RoutesSCCsHAProxy ingressprivate registry & image mirroringK3sIstioHelmDocker

Work Experience

Video intelligence and enterprise AI infrastructure — on-prem, government security baseline.

OpenShiftGPU-backed nodesMariaDB GaleraHAProxyELKTerraformVaultCyberArkEntra IDRHEL
  • Operate the OpenShift estate — namespaces, RBAC and SCC policy, network policies, quotas, Routes, HAProxy ingress, PV/PVC storage
  • Built and run MariaDB Galera multi-master HA — survives node loss with no failover downtime, fronted by HAProxy for routing and health checks
  • ELK monitoring across cluster, systemd, and MariaDB logs — dashboards and alerts that surface failures before users report them
  • Own the Linux layer — patching, kernel and package management, resource limits, storage mounts, sequenced to keep production up
  • Day-1 build and Day-2 ops on an enterprise AI platform running on GPU-backed nodes, plus database ownership of schema, tuning, backup and recovery
  • Provision infrastructure with Terraform — environments rebuilt from code, not reassembled by hand
  • Harden to CIS and government IM8 baselines; remediate scan findings and produce the audit evidence
  • Privileged access through CyberArk, service credentials in Vault — no long-lived secrets in configs or node images
  • Identity governance across Entra ID and on-prem LDAP — user/group lifecycle, RBAC, Azure Policy — over a mixed Linux and Windows estate
  • IPSec VPN tunnels so field devices reach internal systems without public exposure

Platform Engineering — Self-Directed

  • Two-tier homelab Kubernetes estate, continuously operated: a 3-node kubeadm cluster (Cilium CNI, MetalLB L2 load balancing, containerd) running production workloads, plus a K3s development cluster running Istio service mesh and Kyverno policy-as-code admission control ahead of promoting either to prod — both run through real upgrade, certificate-rotation, and failure scenarios
  • GitOps delivery with ArgoCD in an app-of-apps pattern — a root Application bootstraps every other workload from Git, with automated sync, pruning, and self-heal so cluster drift is reconciled rather than patched in place
  • Hosts this portfolio and internal homelab services on the platform, with ingress and TLS termination, persistent storage classes, RBAC and namespace quotas, a private image registry, and a full Prometheus/Grafana + ELK observability stack — built to enterprise patterns
  • CI/CD for this portfolio itself: GitHub Actions builds and publishes the container image to GHCR on every push to main, gated by a Trivy vulnerability scan of the image filesystem before it ships
  • HA data tier: MariaDB Galera cluster behind an evaluated proxy layer (HAProxy / MaxScale / ProxySQL), with backup, restore, and node-loss drills
  • Platform roadmap in progress: Gateway API for HTTP routing in place of classic ingress
  • Bash-based CKA exam simulator running against a disposable k3d sandbox; AWS serverless projects for SAA preparation

Certifications & Education

Certified Kubernetes Administrator (CKA)

Cloud Native Computing Foundation · ID LF-ijwzjz1ojo

↓ PDFAug 2026

BSc Computing Science (Honours)

Singapore Institute of Technology

Aug 2022 — Apr 2025

Diploma in Business Process with Systems Engineering

Temasek Polytechnic

Apr 2017 — Feb 2020