Platform engineering · cloud infrastructure · data
Joshua Brewer
I build systems that engineers can depend on.
Platform Engineer focused on cloud infrastructure, automation, observability, security, and
data-driven systems. Currently expanding that foundation through an M.S. in Management
Information Systems at Texas A&M University.
Select a milestone for the engineering context behind it.
2018 · Foundation
Systems & infrastructure
Enterprise systems, security, automation, and operations established the habit of
understanding how the whole environment behaves—not just one component.
View the full timeline as text
2018 · Systems & infrastructure
Enterprise systems, security, automation, and operations established the habit of
understanding how the whole environment behaves—not just one component.
2022 · AWS & Kubernetes
Supporting enterprise container environments sharpened a methodical approach to Kubernetes
troubleshooting, networking, scaling, upgrades, and documentation.
2023 · Platform engineering
The focus moved from resolving individual operational problems to building reliable,
repeatable foundations that help engineering teams deliver.
2026 · Texas A&M MS MIS
Data analytics, warehousing, mining, Python, and SQL extend the platform lens: operational
signals can become inputs to better technical and organizational decisions.
Now · Platform + data engineering
The current direction combines reliable infrastructure with operational data and information
systems thinking—better context for better engineering decisions.
Explore my engineering environment
A sanitized, fictional platform model built from the real open-source stack I operate day to
day. Select a layer to see what it does, why it exists, the relevant technologies, and where
this connects to my own experience.
View the architecture diagram as text
Cloud — AWS
Cloud infrastructure creates a resilient foundation for applications and operations.
Technologies: AWS · Terraform · IAM. Experience: operates AWS infrastructure in production
as a Platform Engineer, architecting EKS, VPC, RDS, S3, and IAM with Terraform across four
promotion environments, and previously supported enterprise AWS container environments
directly as a Cloud Support Engineer.
Packaging & delivery — Zarf, Helm, GitLab CI/CD
Applications are packaged as versioned bundles so the same artifact can be validated once
and promoted safely through every environment, including disconnected ones. Technologies:
Zarf · Helm · GitLab CI/CD. Experience: contributed CLI enhancements directly to Zarf
(public PRs #3568 and #3579), an open-source Kubernetes packaging tool built for air-gapped
deployments, and builds Helm-based bundles delivered through CI/CD pipelines.
Orchestration — EKS / Kubernetes
Container orchestration and the platform foundation for repeatable workload delivery.
Technologies: EKS · Cluster Autoscaler. Experience: manages full lifecycle operations for
production EKS clusters, including zero-downtime control-plane upgrades and automated node
scaling with Cluster Autoscaler.
Ingress — Istio
A controlled entry point that routes traffic, terminates TLS, and makes services
discoverable. Technologies: Istio · Ingress Gateway · TLS. Experience: configures Istio
ingress gateways and load-balancing for production Kubernetes workloads, and previously
diagnosed ingress and routing issues across enterprise clusters as a Cloud Support Engineer.
Identity
Centralized authentication lets every application and every tenant trust the same source of
truth instead of managing its own users. Technologies: Keycloak · OIDC · SAML. Experience:
designed Keycloak-driven, OIDC-based identity mapping for a multi-tenant observability
platform, and mentored teammates on AWS IAM Roles Anywhere CAC trust-anchor configuration.
Services
Application workloads are operated through clear interfaces, resource boundaries, and
observable behavior. Technologies: Kubernetes · CI/CD · GitOps. Experience: operates
production services delivered through GitOps and CI/CD pipelines as part of a live platform
engineering role.
Policy & admission
Guardrails enforced at admission time catch misconfiguration before it reaches running
workloads, instead of relying on after-the-fact audits. Technologies: Pepr · OPA/Rego.
Experience: migrated OPA/Rego policy validation into the platform's default
infrastructure-as-code stack and shipped JSON schema validation for air-gapped Kubernetes
runners, enforcing tagging and configuration contracts across every component.
Worker capacity
Compute capacity is planned and scaled so workloads have a reliable place to run.
Technologies: Autoscaling · Cluster Autoscaler · Multi-AZ. Experience: diagnosed capacity
and autoscaling issues professionally, including the kind of node-capacity exhaustion
modeled in this site's Incident Simulator.
Runtime security
Continuous scanning and runtime threat detection catch what static checks miss, once
workloads are actually running. Technologies: Falco · NeuVector. Experience: integrated
Falco runtime threat detection and NeuVector continuous container scanning into a hardened
platform baseline aligned to NIST SP 800-53 and CIS benchmarks.
Observability
Metrics, logs, and dashboards help engineers move from symptoms to evidence. Technologies:
Grafana · Loki · Vector · Prometheus · Splunk. Experience: designed and shipped a
multi-tenant observability architecture on Grafana, Loki, and Vector for 13+ vendor teams,
migrated Grafana configuration to Terraform for drift detection, and feeds centralized
Splunk through Vector pipelines.
Interested in what platform reliability and data-driven engineering could look like on your
team?