Zaw Wana
Platform / Site Reliability Engineer — Kubernetes · Linux · Observability
Singapore
zaw@platform — zsh
➜~
Tools & platforms run in production
Core Technical Skills
Grouped by domain — expand a category for the full list.
Kubernetes (CKA)node lifecycleetcd healthRBACnetwork policiesresource quotasPV/PVC & storage classesOpenShift (OCP 4.x)RoutesSCCsHAProxy ingressprivate registry & image mirroringK3sIstioHelmDocker
Work Experience
Video intelligence and enterprise AI infrastructure — on-prem, government security baseline.
OpenShiftGPU-backed nodesMariaDB GaleraHAProxyELKTerraformVaultCyberArkEntra IDRHEL
- Operate the OpenShift estate — namespaces, RBAC and SCC policy, network policies, quotas, Routes, HAProxy ingress, PV/PVC storage
- Built and run MariaDB Galera multi-master HA — survives node loss with no failover downtime, fronted by HAProxy for routing and health checks
- ELK monitoring across cluster, systemd, and MariaDB logs — dashboards and alerts that surface failures before users report them
- Own the Linux layer — patching, kernel and package management, resource limits, storage mounts, sequenced to keep production up
- Day-1 build and Day-2 ops on an enterprise AI platform running on GPU-backed nodes, plus database ownership of schema, tuning, backup and recovery
- Provision infrastructure with Terraform — environments rebuilt from code, not reassembled by hand
- Harden to CIS and government IM8 baselines; remediate scan findings and produce the audit evidence
- Privileged access through CyberArk, service credentials in Vault — no long-lived secrets in configs or node images
- Identity governance across Entra ID and on-prem LDAP — user/group lifecycle, RBAC, Azure Policy — over a mixed Linux and Windows estate
- IPSec VPN tunnels so field devices reach internal systems without public exposure
Platform Engineering — Self-Directed
- Two-tier homelab Kubernetes estate, continuously operated: a 3-node kubeadm cluster (Cilium CNI, MetalLB L2 load balancing, containerd) running production workloads, plus a K3s development cluster running Istio service mesh and Kyverno policy-as-code admission control ahead of promoting either to prod — both run through real upgrade, certificate-rotation, and failure scenarios
- GitOps delivery with ArgoCD in an app-of-apps pattern — a root Application bootstraps every other workload from Git, with automated sync, pruning, and self-heal so cluster drift is reconciled rather than patched in place
- Hosts this portfolio and internal homelab services on the platform, with ingress and TLS termination, persistent storage classes, RBAC and namespace quotas, a private image registry, and a full Prometheus/Grafana + ELK observability stack — built to enterprise patterns
- CI/CD for this portfolio itself: GitHub Actions builds and publishes the container image to GHCR on every push to main, gated by a Trivy vulnerability scan of the image filesystem before it ships
- HA data tier: MariaDB Galera cluster behind an evaluated proxy layer (HAProxy / MaxScale / ProxySQL), with backup, restore, and node-loss drills
- Platform roadmap in progress: Gateway API for HTTP routing in place of classic ingress
- Bash-based CKA exam simulator running against a disposable k3d sandbox; AWS serverless projects for SAA preparation
Certifications & Education
Certified Kubernetes Administrator (CKA)
Cloud Native Computing Foundation · ID LF-ijwzjz1ojo
BSc Computing Science (Honours)
Singapore Institute of Technology
Diploma in Business Process with Systems Engineering
Temasek Polytechnic