Skip to content
View deveshr17's full-sized avatar

Block or report deveshr17

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
deveshr17/README.md

Devesh Rashinkar

Senior DevOps Engineer  |  Cloud Engineer  |  Platform Engineer
Kubernetes · GCP · AWS · Azure · DevSecOps

I build secure, scalable, observable and automated cloud platforms.

LinkedIn Email Portfolio GitHub

GCP AWS Azure Kubernetes Istio Terraform GitHub Actions Prometheus


Professional Summary

Senior DevOps / Platform Engineer with 4.5+ years of hands-on production ownership of cloud-native infrastructure. GCP is my primary platform, with additional production experience on AWS and Azure.

I design and operate the layers between application code and the cloud: multi-cluster Kubernetes (GKE, EKS, AKS), Istio and Managed Cloud Service Mesh, global HTTP(S) load balancing with Cloud Armor / WAF at the edge, and the CI/CD and infrastructure-as-code that make all of it reproducible and reviewable.

Areas of focus:

Area What I do
Cloud infrastructure Landing zones, VPC design, private connectivity, IAM boundaries, managed data services on GCP, AWS and Azure
Kubernetes platforms Cluster lifecycle, node pool strategy, autoscaling, hardened workloads, network policies, multi-cluster migrations
Infrastructure as Code Terraform modules with environment separation and remote state; Ansible for configuration management
CI/CD automation GitHub Actions and Jenkins pipelines with build, test, scan, approval and rollback stages
DevSecOps SonarCloud and Trivy as blocking gates, hardened multi-stage images, governed base images in Artifact Registry
Cloud security Cloud Armor / WAF rule design, least-privilege IAM, network segmentation, encryption, audit logging, PCI DSS-aligned baselines
Observability Prometheus, Grafana, ELK, Cloud Monitoring; SLO-backed dashboards and actionable alerting
Production reliability Incident response, root-cause analysis across Kubernetes, networking, DNS, TLS and databases; runbooks and change management
Cost optimization Rightsizing node pools, sidecars and Redis capacity; autoscaling tuning; consolidation and legacy decommissioning

Technology Stack

Category Technologies
Cloud Google Cloud Platform (primary), AWS, Microsoft Azure
Containers Docker, Kubernetes, GKE, EKS, AKS, Anthos, Cloud Run, Helm, Kustomize
Service Mesh Istio, Managed Cloud Service Mesh, Envoy, mTLS, traffic splitting, circuit breaking
Infrastructure as Code Terraform, Ansible
CI/CD GitHub Actions, Jenkins, GitLab CI, Azure DevOps, Cloud Build, GitOps workflows
Security Cloud Armor, WAF, DDoS mitigation, Trivy, SonarCloud, IAM hardening, VPC Service Controls, Secret Manager, PCI DSS baselines, DevSecOps
Observability Prometheus, Grafana, Alertmanager, ELK Stack, Nagios, Cloud Monitoring, Cloud Logging, distributed tracing, SLOs
Databases & Data Cloud SQL / MySQL, PostgreSQL, MongoDB, BigQuery, Redis Enterprise, Memorystore, RabbitMQ, Pub/Sub
Data Engineering Datastream (CDC), Airbyte, Data Fusion, Dataflow, Cloud Functions, Cloud Storage
Networking Global HTTP(S) Load Balancer, NEGs, URL Maps, Internal/External LB, Cloud CDN, Cloud DNS, Cloud NAT, Cloud VPN, Serverless VPC, Nginx, Envoy, SSL/TLS
Languages & OS Python, Bash, Groovy, YAML, Linux (RHEL, Ubuntu)

Featured Repositories

Each repository is a personal reference implementation of a pattern I use professionally. They are built and documented to production standards, but they are demonstration architectures, not the production code of any employer.

Repository Domain What it demonstrates
terraform-gcp-platform Cloud Architecture / IaC Modular Terraform landing zone: VPC, private GKE, Artifact Registry, Cloud SQL, GCS, Global HTTPS LB, Cloud Armor, WIF for CI, remote state, dev / uat / prod separation
kubernetes-production-platform Kubernetes Hardened workload baseline: probes, requests/limits, HPA, PDB, Pod Security Admission, NetworkPolicies, RBAC, Kustomize overlays and a Helm chart
github-actions-devsecops CI/CD / DevSecOps Tests, SonarCloud, Trivy, distroless multi-stage image, OIDC push to Artifact Registry, gated UAT and production GKE deploys, rollback workflow
gke-istio-platform Service Mesh Istio / Managed Cloud Service Mesh behind a Global LB with NEGs, strict mTLS, AuthorizationPolicy, canary and blue/green routing, egress control
gcp-cloud-armor-security Edge Security Cloud Armor / WAF policies as code: OWASP preconfigured rules, rate limiting, IP and geo controls, rule optimization within policy limits, security logging
kubernetes-observability-stack Observability / SRE kube-prometheus-stack, SLO recording rules with multi-window burn-rate alerts, Grafana dashboards, ELK log pipeline, alert runbooks
devsecops-vulnerability-platform Vulnerability Management Trivy image / fs / IaC scanning, CVE classification and policy gates, SBOM and cosign signing, aggregated dashboard from synthetic data, remediation workflow
cloud-cost-optimization FinOps Billing-export SQL, idle resource detectors, Kubernetes rightsizing from Prometheus data, BigQuery and storage optimization, Redis capacity planning, safe cleanup automation
cloud-data-platform Data Platform MySQL and MongoDB to BigQuery via Datastream CDC and Airbyte, GCS landing, dedupe and SCD2 SQL, reconciliation tooling, backfill and cutover runbook

Reading order for a quick review: terraform-gcp-platform for how I structure infrastructure, github-actions-devsecops for how I ship, gke-istio-platform and gcp-cloud-armor-security for how I handle traffic and security, and kubernetes-observability-stack for how I keep it running.


Professional Experience

Senior DevOps Engineer — CheQ, Bangalore  (Feb 2025 – Present)

Architected and own the production GCP platform spanning multi-cluster GKE, Cloud Run, Cloud SQL, BigQuery, Memorystore, VPC and Artifact Registry for PCI, lending and core application workloads serving 500K+ users. Led cross-cluster workload migrations with zero data loss and no customer-facing downtime, designed the Global HTTP(S) Load Balancer topology using NEGs and URL maps, operate Istio / Managed Cloud Service Mesh in production, own Cloud Armor / WAF policy design and DDoS mitigation, and run the GitHub Actions and Jenkins DevSecOps pipelines with SonarCloud and Trivy as blocking gates. Administer Cloud SQL / MySQL and Redis Enterprise HA, maintain a PCI DSS-compliant security baseline, and act as technical lead for reliability, observability, security and compliance initiatives.

DevOps Engineer — MoreYeahs IT Technologies, Indore  (Oct 2020 – Jan 2025)

Built fintech cloud infrastructure from scratch on GCP with a multi-cluster GKE, multi-project topology, and operated GCP and Azure estates for fintech, healthcare, e-commerce and B2B SaaS workloads. Managed production GKE, AKS and EKS clusters with Anthos and Istio (mTLS, canary and blue/green releases), consolidated fragmented Azure DevOps pipelines into a unified multi-tenant delivery pipeline, and built CI/CD with GitHub Actions, Jenkins and Cloud Build. Orchestrated TB-scale MySQL and MongoDB to BigQuery migration and CDC synchronization using Datastream, Data Fusion, Dataflow, Airbyte and Cloud Storage, and implemented observability with Prometheus, Grafana, ELK and Nagios. Grew the cloud engineering team from 2 to 15 engineers, led a DevOps squad of 3, and introduced organization-wide standards for pipelines, IaC, branching and change management.


Certifications

  • Google Cloud Certified — Professional Cloud Architect
  • Google Cloud Certified — Professional Cloud Security Engineer
  • Microsoft Certified — Azure Administrator Associate (AZ-104)
  • Microsoft Certified — Azure Fundamentals (AZ-900)

Education

  • Master of Computer Applications (MCA) — Rajiv Gandhi Proudyogiki Vishwavidyalaya, Indore (2019 – 2021)
  • Bachelor of Computer Applications (BCA) — Devi Ahilya Vishwavidyalaya, Indore (2015 – 2018)

GitHub Activity

GitHub statistics Most used languages


How I Work

  • Infrastructure is code. Every environment is reproducible from a versioned, peer-reviewed repository. No console changes in production.
  • Secure by default. Least-privilege IAM, private networking, encryption in transit and at rest, and security scanning as a blocking gate rather than a report.
  • Observability before scale. SLOs, dashboards and actionable alerts ship with the service, not after the first incident.
  • Rollback is a feature. Every deployment path has a tested, documented way back.
  • Cost is an engineering metric. Rightsizing, autoscaling and consolidation are part of platform ownership.

Professional experience above reflects my actual career. Repositories are personal reference implementations and labs; none contain employer code, credentials or infrastructure details.

Popular repositories Loading

  1. deveshr17 deveshr17 Public

    Profile README

  2. kubernetes-production-platform kubernetes-production-platform Public

    Production-grade Kubernetes platform baseline: hardened workloads, autoscaling, PDBs, network policies, RBAC, Kustomize overlays and Helm packaging.

    Shell

  3. terraform-gcp-platform terraform-gcp-platform Public

    Modular Terraform for a production GCP landing zone: VPC, private GKE, Artifact Registry, Cloud SQL, Cloud Storage, Global HTTPS LB and Cloud Armor with dev/uat/prod separation and remote state.

    HCL

  4. github-actions-devsecops github-actions-devsecops Public

    End-to-end DevSecOps pipeline on GitHub Actions: tests, SonarCloud, Trivy, distroless multi-stage image, OIDC push to Artifact Registry, gated UAT/production GKE deploys and rollback.

    JavaScript

  5. gke-istio-platform gke-istio-platform Public

    GKE service mesh reference platform: Istio / Managed Cloud Service Mesh behind a Global HTTPS LB and Cloud Armor, strict mTLS, AuthorizationPolicy, canary and blue/green routing, egress control.

    Shell

  6. gcp-cloud-armor-security gcp-cloud-armor-security Public

    Cloud Armor / WAF edge security as code: OWASP preconfigured rules, rate limiting, IP and geo controls, rule optimization within policy limits, and security logging and alerting.

    HCL