Platform Engineering · Cloud · DevSecOps
Shravan Kumar Yadav
I engineer the systems behind reliable software delivery.
Cloud infrastructure, platform engineering, Kubernetes, delivery automation, and DevSecOps — built to hold up in production, not just in a demo.
Technology Ecosystem
Technologies I use across production cloud, platform, delivery, security, and observability systems.
Cloud Platforms
- AWS
- Azure
Containers & Orchestration
- Kubernetes
- EKS
- ECS
- Docker
Infrastructure as Code
- Terraform
- CloudFormation
- Ansible
CI/CD & Delivery
- GitHub Actions
- GitLab CI
- Jenkins
- AWS CodePipeline
Observability
- Prometheus
- Grafana
- Datadog
- ELK
- CloudWatch
Systems & Scripting
- Linux
- Bash
- Python
- Nginx
Security & Secrets
- Vault
About
Engineering experience shaped by different business realities.
I'm a Cloud & Platform Engineer with 8+ years of experience building, operating, and modernizing production infrastructure across financial services, lending technology, payments, insurance, EdTech, consumer products, and data platforms.
My work sits underneath business-critical software — cloud infrastructure, Kubernetes platforms, infrastructure automation, CI/CD, security controls, observability, reliability, and production operations.
Industry exposure
Financial Services
Banking · Cards · Mortgage · Lending
Insurance
EdTech
Consumer Products
Data & Analytics Platforms
Product context
Credit cards · Mortgage & secured lending · Personal & unsecured lending · Loan origination · Customer-facing digital products · Internal enterprise applications · Data platforms
Featured Engineering Stories
How the engineering decision actually got made.
Based on real production engineering work. Sensitive implementation details have been omitted or generalized.
0103
Identity & Access Modernization
Certificate-only access Identity-driven, policy-scoped access
01 / 05Existing State
Access relied on certificates alone.
Client
VPN Endpoint
02 / 05Constraint
A certificate proves possession of a device — not who someone is, or what they should be allowed to reach.
Client
VPN Endpoint
No identity context
03 / 05Engineering Decision
Move to federated identity (SAML) with MFA and persona-based access policy — deciding deliberately not to replace the working certificate path outright, but to migrate it under control.
Client
Identity Provider
SAML + MFA
VPN Endpoint
Existing certificate path — unchanged
04 / 05Controlled Migration
The certificate-based path stayed live while the identity-driven path was rolled out in parallel — access moved over deliberately, not all at once.
Client
Identity Provider
SAML + MFA
Access Policy
VPN Endpoint
Existing certificate path — phased out during rollout
Terraform — defines and manages the access policy as code
05 / 05Changed State
Access is now identity-driven, MFA-enforced, and defined as infrastructure — the certificate-only path has been retired.
Client
Identity Provider
SAML + MFA
Access Policy
VPN Endpoint
Terraform — defines and manages the access policy as code
01 / 05Existing State
Client
VPN Endpoint
Selected Engineering Work
A sample of the engineering problems this covers.
Delivery Engineering
Jenkins → GitHub Actions delivery modernization
Moved Lambda delivery off a legacy Jenkins pipeline onto GitHub Actions, reducing hand-maintained pipeline logic.
JenkinsGitHub Actions
DevSecOps
Container registry scanning and promotion gates
Added vulnerability scanning and promotion gates to the container registry, so known-vulnerable images can't reach production undetected.
Unscanned promotionScanned + gated promotion
Cloud Infrastructure
EC2 access modernization
Introduced IAM-controlled EC2 access through AWS Systems Manager Session Manager, reducing reliance on SSH keys and traditional network-based administrative access.
SSH keys · network accessIAM-controlled Session Manager
Platform Engineering
Elastic Beanstalk → ECS platform migration
Migrated an application platform off Elastic Beanstalk onto ECS for finer-grained control over deployment and scaling.
Elastic BeanstalkECS
Kubernetes & Containers
EKS/Kubernetes operational modernization
Modernized a Kubernetes/EKS environment's operational practices — from workload configuration to cluster lifecycle.
EKS · Kubernetes
Infrastructure Automation
Terraform platform and module engineering
Built reusable Terraform modules to standardize how infrastructure gets provisioned across environments.
Terraform · Reusable modules
Expertise
Engineering domains across cloud, platform, and delivery.
Cloud Infrastructure
Designing and operating infrastructure on AWS and Azure — networking, compute, and storage.
Platform Engineering
Building the internal platforms and tooling that let engineering teams ship safely and consistently.
Kubernetes & Containers
Running containerized workloads in production, from cluster design to day-two operations.
Infrastructure Automation
Infrastructure defined, versioned, and managed as code rather than configured by hand.
Delivery Engineering / CI/CD
Designing delivery pipelines that catch problems before production does.
DevSecOps
Building security into the delivery path rather than bolting it on afterward.
Reliability / Observability
Making systems observable enough that "it's up" and "it's healthy" mean the same thing.
Contact
Have a cloud or platform engineering problem worth discussing?
A straightforward way to start a conversation — no forms, no pressure.