from software delivery to principal-level cloud leadership
Engineering approach
Platforms are socio-technical systems.
Good infrastructure is only half the job. I align architecture, developer experience and operations so that the whole system remains understandable as it scales.
Platform as a product
Start with the developer journey. Build paved roads, clear contracts and self-service workflows that teams choose to use.
Secure by construction
Encode least privilege, policy and supply-chain controls into the platform so the safe path is also the fast path.
Operate what you design
Make reliability, telemetry, cost and recovery first-class architecture decisions—not work deferred until production.
Selected work / open source
Working systems, not logo walls.
Public implementations that show how I think about lifecycle, operability and the trade-offs behind cloud-native platforms.
Open-source organisation
Native Cube — opens in a new tab
@native-cubeI own Native Cube, a collection of free browser tools for Kubernetes, Helm, RBAC, subnet planning and YAML/JSON, alongside reusable AWS Terraform modules.
- Catalogue
- 05 browser tools · 06 Terraform modules
- Adoption
- 200K+ combined downloads across Registry-published modules
Browser-based toolbox
05 free tools- Kubernetes Manifest Builder — opens in a new tab
- Helm Chart Builder — opens in a new tab
- Kubernetes RBAC Explorer — opens in a new tab
- Visual Subnet Calculator — opens in a new tab
- YAML & JSON Formatter — opens in a new tab
AWS Terraform modules
06 public modules- 01
terraform-aws-eksEKS clusters with managed node groups, core add-ons, access controls, control-plane logging, managed capabilities and Karpenter-ready composition outputs. — opens on GitHub in a new tab - 02
terraform-aws-eks-autoPrivate-by-default EKS Auto Mode with managed compute, load balancing, block storage, Pod Identity, access entries and rendered Kubernetes manifests. — opens on GitHub in a new tab - 03
terraform-aws-eks-node-groupEKS managed node groups with capacity controls, launch-template support, labels, taints and integrated worker-node IAM. — opens on GitHub in a new tab - 04
terraform-aws-eks-fargate-profileEKS Fargate profiles with namespace selectors, private-subnet placement and pod-execution IAM. — opens on GitHub in a new tab - 05
terraform-aws-kmsAWS KMS customer managed keys and aliases with rotation, policy, lifecycle and tagging controls. — opens on GitHub in a new tab - 06
terraform-aws-vpc-flow-logsVPC, subnet and transit-gateway flow logging with CloudWatch delivery, IAM, retention and record-format controls. — opens on GitHub in a new tab
Amazon EKS platform
marcincuber/eksA production-minded EKS implementation in Terraform, covering network foundations, add-ons, IAM, observability, cost controls and lifecycle upgrades across AWS partitions.
Flux platform delivery
marcincuber/kubernetes-fluxv2A working Flux v2 layout for EKS platform components, including ingress, DNS, secrets, policy, autoscaling, storage and cost visibility.
Argo CD patterns
marcincuber/argocdPractical Argo CD patterns for declarative application delivery, reconciliation and Kubernetes-native release management.
Kubernetes GitLab runners
marcincuber/kubernetes-gitlab-runnerConfiguration for running scalable GitLab CI workloads on Kubernetes, isolating jobs while letting the runner fleet follow demand.
mTLS Go microservices
marcincuber/k3d-ping-pong-go-apps-with-mtlsSmall Go services running on k3d with mutual TLS—a compact demonstration of service identity, encrypted traffic and local platform testing.
GitHub Actions library
marcincuber/ghaA collection of reusable GitHub Actions workflows and delivery patterns for automating repeatable engineering tasks.
Capability map
From account boundary to running workload.
I work across the platform stack and the organisational interfaces around it—deep enough to debug a pod, broad enough to set the direction.
Foundations
Cloud architecture
Multi-account AWS estates, landing zones, network boundaries and resilient multi-region design, with working knowledge of GCP and Azure.
- AWS Organizations & Control Tower
- VPC, IAM, Route 53 & CloudFront
- ECS, Fargate, Lambda, RDS & event services
Runtime
Kubernetes platforms
Production EKS architecture with controlled tenancy, capacity, upgrades and a coherent add-on lifecycle.
- EKS, GKE, Karpenter & KEDA
- Helm, operators & service mesh
- Pod security & admission policy
Delivery
Infrastructure & GitOps
Versioned, reviewable infrastructure and application delivery with small blast radii and reliable promotion.
- Terraform module engineering
- Python & Bash automation
- Argo CD, Flux CD & progressive delivery
- GitHub Actions & GitLab CI
Assurance
DevSecOps
Identity-first security, automated guardrails and software supply-chain controls embedded into delivery.
- OIDC, RBAC, ABAC, SCPs & permission boundaries
- Parameter Store, Secrets Manager & External Secrets
- Cert-manager, signing, Trivy & policy as code
Operations
SRE & observability
Telemetry and reliability practices that turn production behaviour into actionable engineering feedback.
- Prometheus, Grafana, New Relic & Datadog
- SLIs, SLOs & error budgets
- Tracing & incident learning
Leadership
Technical direction
Architecture strategy translated into standards, mentoring, pragmatic roadmaps and hands-on delivery.
- Design reviews & decision records
- Team growth & engineering standards
- FinOps, risk and stakeholder alignment
Selected outcomes
Engineering measured in change.
Representative outcomes delivered across platform engagements.
availability objectives
Resilient EKS platform patterns designed around fault isolation, observability and controlled change.
faster developer delivery
Self-service platform workflows that reduce hand-offs and shorten the path from change to production.
cloud cost reduction
FinOps guardrails, demand-aware scaling and architecture changes that treat cost as a system signal.
Technical writing
Field notes from operating cloud-native systems.
Runbooks, upgrade journeys and explanations shaped by the failure modes engineers meet in real environments.
Amazon EKS Upgrade Journey: From 1.35 to 1.36- Haru — opens on Medium in a new tab
Amazon EKS 1.35-> 1.36: an evidence-driven upgrade journey through Kubernetes “Haru.
Read articleHow to Run Argo CD on Minikube: A Practical Local GitOps Tutorial — opens on Medium in a new tab
Learn how to run ArgoCD on Minikube and build a local GitOps workflow using Kubernetes, GitHub, and Kustomize.
Read articleMacOS Tahoe 26- creating admin users using DSCL cli — opens on Medium in a new tab
A practical guide to creating admin users using the DSCL command-line interface in macOS Tahoe 26.
Read articleAmazon EKS upgrade journey from 1.34 to 1.35 — opens on Medium in a new tab
A practical control-plane upgrade runbook for the Timbernetes release, with the compatibility checks and sequencing that matter in production.
Read articleWhat happens when you delete a Kubernetes CRD? — opens on Medium in a new tab
Why deleting a definition also deletes its custom resources, and how that failure mode affects common platform operators.
Read articleECR pull-through cache and cross-Region replication — opens on Medium in a new tab
A Terraform-based design for resilient, low-latency image pulls, including a safe approach to backfilling existing repositories.
Read articleWhy a headless service returns NXDOMAIN on EKS — opens on Medium in a new tab
A debugging guide to StatefulSet DNS, readiness and headless services, ending in a copy-ready production runbook.
Read articleProduction-ready InfluxDB on Amazon Timestream — opens on Medium in a new tab
The available deployment choices for Timestream for InfluxDB, expressed as a repeatable Terraform implementation.
Read articleKubernetes-based GitHub Actions runners with Flux — opens on Medium in a new tab
A working pattern for self-hosted Actions runners on EKS using Flux and Actions Runner Controller.
Read articleCareer journey
From software engineer to technical leader.
A progression from product software into the design and operation of enterprise cloud platforms.
Open the full CV2026 — present
Lead Cloud Native Developer
CurrentCapgemini
Combining hands-on engineering and technical leadership to build resilient, modern cloud-native systems for large-scale client environments.
2022 — 2026
Principal Cloud Engineer · DevOps Technical Lead
Dare
Set platform direction and led hands-on delivery for a secure multi-region EKS trading platform using Terraform and Flux, improving latency by 30%. Standardised Control Tower provisioning, policy-as-code and FinOps, cutting account setup time by 70% and targeted RDS/Redis costs by at least 50%.
2021 — 2022
DevOps Technical Lead
Limejump
Led platform and SRE practices for energy optimisation systems, introducing structured on-call, runbooks and blameless postmortems. Standardised delivery with EKS, CircleCI, Flux, Vault and Terraform Cloud/Sentinel, while migrating Airflow v1 to managed Airflow v2.
2019 — 2021
Lead DevOps Engineer
uMotif
Progressed from Senior to Lead DevOps Engineer while building regulated multi-region platforms across Ireland, North Virginia and Beijing. Delivered EKS/ECS foundations, reusable Terraform modules, GitLab CI security gates, identity integration and regional data-residency controls for clinical applications.
2018 — 2019
Cloud DevOps Engineer
News UK
Rolled out production EKS platforms with Helm and Flux, standardising DNS, secrets and observability with New Relic and Datadog. Reduced compute costs by approximately 49% through autoscaling, Spot capacity and Kubecost-guided rightsizing.
2016 — 2018
Software Engineer
The Times
Developed Node.js and Express APIs plus Docker delivery pipelines for a high-traffic digital news product. Built AWS serverless workflows with Lambda, API Gateway and DynamoDB, supported by TeamCity, Datadog and ELK telemetry.
Education & credentials
Credentials, not just claims.
Formal study
Education
2012 — 2016
MEng (Master of Engineering), Computer Science
University College London
Four-year integrated master’s degree with Upper Second-Class Honours, including research in security, data visualisation, transport-network optimisation and a Python modal-logic theorem solver.
Before UCL
A Levels & BTEC National Diploma
South Cheshire College
IT, Mathematics, Further Mathematics and an Extended Project Qualification.
Professional development
Certifications
- Claude Certified Developer - FoundationsAnthropic · AI
- AWS Certified CloudOps Engineer — AssociateAmazon Web Services · Cloud
- AWS Certified Solutions Architect — AssociateAmazon Web Services · Cloud
- AWS Certified AI PractitionerAmazon Web Services · Cloud
- HashiCorp Certified: Terraform AssociateHashiCorp · Infrastructure as Code
- GitHub AdministrationGitHub · Developer platform
- GitHub FoundationsGitHub · Developer platform
- GitLab Certified AssociateGitLab · Developer platform
- New Relic Certified Performance ProNew Relic · Observability
- Prefect Associate CertificationPrefect · Data orchestration
- Akamai DevOps ProfessionalAkamai · Edge & delivery
- Akamai Bot Manager AdvancedAkamai · Edge & delivery
AWS Community Builder
Contributing practical cloud-native knowledge to the wider AWS community.
New Relic FutureStack speaker
Shared the operational story behind News UK’s production move to Amazon EKS.
Published EKS case study
Co-authored the News UK and New Relic story on Kubernetes infrastructure monitoring.
Let’s compare notes
Architecture challenge, platform problem or open-source idea?
The best conversations usually begin with a system diagram and one stubborn constraint.
Open source with purpose
Two journeys, one shared future.
Your contribution helps my daughter pursue higher education and helps me continue creating thoughtful, accessible open-source tools—free for everyone to use.