Summary
I build and run the platform that development teams ship on. Seven years of hands-on work with Kubernetes and cloud-native infrastructure, currently leading the DevOps function at Easygenerator.
Day to day that means multi-cluster EKS strategy, Helm charts for around 85 microservices, Terraform for everything underneath, GitOps delivery, and an observability stack that tells us what broke before a customer does. I care most about the unglamorous part: production staying up, and the people deploying to it not having to think about me.
Work
-
Easygenerator
Senior Platform Engineer & DevOps Team Lead — Dubai, UAE
Jan 2022 Present
Own the Kubernetes platform end to end and lead the DevOps team that runs it.
- Lead the DevOps team — platform strategy, mentoring engineers, and working alongside development teams to improve production stability, availability, and reliability.
- Architect and operate multi-cluster EKS environments using Karpenter for dynamic node scaling, Flux CD for GitOps delivery, and Bottlerocket OS for a hardened, minimal node base.
- Write and maintain Helm charts for roughly 85 microservices, improving templating consistency, environment parity, and developer self-service.
- Manage all infrastructure as code in Terraform with modular, reusable structures; migrated the state backend from Terraform Cloud to Scalr and added pre-commit hooks (TFLint, terraform-docs).
- Deployed the Grafana LGTM stack — Prometheus, Loki, Tempo, and Mimir — cutting mean time to resolution and moving alerting from reactive to proactive.
- Halved CI/CD build times across GitHub Actions and Octopus Deploy, folded in security scanning with SonarCloud and Trivy, and manage self-hosted Linux runners.
- Integrated Cloudflare across the estate: Workers, TLS certificate management, WAF policy, and DNS. Evaluated ECDSA P-256 against P-384 for certificate security.
- Reduced cloud cost by about $220k a year (30%) through rightsizing, Savings Plans, Reserved Instances, and lifecycle rules across three AWS accounts.
- Contributed to ISO 27001:2022 and SOC 2 Type II compliance, and support ongoing audits and CI/CD security hardening.
- Hardened cluster security with Kubernetes RBAC and network policies, and migrated from legacy IRSA to Pod Identity Associations via IAM Access Entries.
- Built a dedicated staging environment with full AWS account segregation, its own EKS/Karpenter/Bottlerocket cluster, Cloudflare integration, and isolated pipelines.
- Wrote and tested disaster recovery strategy under a Business Continuity Plan, bringing RPO and RTO inside SLA.
-
Integra Technologies
DevOps Engineer — Dubai, UAE
Jan 2019 Dec 2021
Migrated enterprise workloads to AWS and automated the infrastructure underneath them.
- Migrated enterprise workloads to AWS following Well-Architected principles, running pre-migration assessments and resolving encryption blockers.
- Automated infrastructure deployment with Terraform and Ansible; containerised workloads on ECS, Fargate, and EKS.
- Designed and tuned CI/CD pipelines on AWS CodePipeline and CodeDeploy, with custom CloudWatch metrics and dashboards for performance monitoring.
- Improved application security using HashiCorp Vault, least-privilege IAM policy, and encryption best practice.
- Cut data transfer cost and latency with CDN, and used Cost Explorer to optimise billing across client accounts.
- Re-architected applications onto auto-scaling groups and load balancers with monitoring, on Debian-based EC2.
Skills
What I reach for, grouped by the layer of the stack it sits in.
- Kubernetes
- Multi-cluster operations Helm authoring Karpenter Flux CD ArgoCD Bottlerocket
- Infrastructure as code
- Terraform (modular, Scalr) OpenTofu AWS CDK CloudFormation Ansible
- Cloud
- AWS EKS ECS EC2 S3 RDS Lambda Bedrock
- CI/CD
- GitHub Actions GitLab CI Octopus Deploy CodePipeline CodeDeploy Flux CD ArgoCD
- Observability
- Prometheus Grafana Loki Tempo Mimir ELK CloudWatch
- Networking and CDN
- Cloudflare Workers WAF DNS TLS Nginx CloudFront
- Security
- HashiCorp Vault Kubernetes RBAC Network policies SonarCloud Trivy AWS Security Hub
- Linux and languages
- Debian/Ubuntu RHEL/AL2 Bottlerocket Go Python Bash TypeScript
Certifications
All three Kubernetes certifications, plus both AWS professionals and the HashiCorp pair.
- CKA Certified Kubernetes Administrator
- CKAD Certified Kubernetes Application Developer
- CKS Certified Kubernetes Security Specialist
- SAP AWS Solutions Architect Professional
- DOP AWS DevOps Engineer Professional
- TFA HashiCorp Terraform Associate
- VA HashiCorp Vault Associate
Background
Education
BSc Computer Engineering
2014 – 2018
Recognition
- AWS Migration Game Day winner, 2020 and 2021
- AWS JAM winner at KubeCon, 2022
- Bronze medal for academic excellence
What I'm working towards
- Kubestronaut certification
- Go API development
- AWS Security Specialty
- KubeCon Europe 2026, Amsterdam
Get in touch
Happy to talk about platform work, Kubernetes at scale, or bringing a cloud bill back down.
- Based in Dubai, UAE
Reach me through whichever channel we already share, or through the introduction that brought you here.
Ahmed Qazi, 2026. Built with Astro, served from Cloudflare's edge.