from software delivery to principal-level cloud leadership
Engineering approach
Platforms are socio-technical systems.
Good infrastructure is only half the job. I align architecture, developer experience and operations so that the whole system remains understandable as it scales.
Platform as a product
Start with the developer journey. Build paved roads, clear contracts and self-service workflows that teams choose to use.
Secure by construction
Encode least privilege, policy and supply-chain controls into the platform so the safe path is also the fast path.
Operate what you design
Make reliability, telemetry, cost and recovery first-class architecture decisions—not work deferred until production.
Selected work / open source
Working systems, not logo walls.
Public implementations that show how I think about lifecycle, operability and the trade-offs behind cloud-native platforms.
Amazon EKS platform
marcincuber/eksA production-minded EKS implementation in Terraform, covering network foundations, add-ons, IAM, observability, cost controls and lifecycle upgrades across AWS partitions.
Flux platform delivery
marcincuber/kubernetes-fluxv2A working Flux v2 layout for EKS platform components, including ingress, DNS, secrets, policy, autoscaling, storage and cost visibility.
Argo CD patterns
marcincuber/argocdPractical Argo CD patterns for declarative application delivery, reconciliation and Kubernetes-native release management.
Kubernetes GitLab runners
marcincuber/kubernetes-gitlab-runnerConfiguration for running scalable GitLab CI workloads on Kubernetes, isolating jobs while letting the runner fleet follow demand.
mTLS Go microservices
marcincuber/k3d-ping-pong-go-apps-with-mtlsSmall Go services running on k3d with mutual TLS—a compact demonstration of service identity, encrypted traffic and local platform testing.
GitHub Actions library
marcincuber/ghaA collection of reusable GitHub Actions workflows and delivery patterns for automating repeatable engineering tasks.
Capability map
From account boundary to running workload.
I work across the platform stack and the organisational interfaces around it—deep enough to debug a pod, broad enough to set the direction.
Foundations
Cloud architecture
Multi-account AWS estates, landing zones, network boundaries and resilient multi-region design.
- AWS Organizations & Control Tower
- VPC, IAM, Route 53 & CloudFront
- ECS, Lambda, RDS & event services
Runtime
Kubernetes platforms
Production EKS architecture with controlled tenancy, capacity, upgrades and a coherent add-on lifecycle.
- EKS, Karpenter & KEDA
- Helm, operators & service mesh
- Pod security & admission policy
Delivery
Infrastructure & GitOps
Versioned, reviewable infrastructure and application delivery with small blast radii and reliable promotion.
- Terraform module engineering
- Bash automation
- Argo CD, Flux CD & progressive delivery
- GitHub Actions & GitLab CI
Assurance
DevSecOps
Identity-first security, automated guardrails and software supply-chain controls embedded into delivery.
- OIDC, ABAC, SCPs & permission boundaries
- Vault, Secrets Manager & External Secrets
- SBOM, signing, Trivy & policy as code
Operations
SRE & observability
Telemetry and reliability practices that turn production behaviour into actionable engineering feedback.
- Prometheus, Grafana & New Relic
- SLIs, SLOs & error budgets
- OpenSearch, tracing & incident learning
Leadership
Technical direction
Architecture strategy translated into standards, mentoring, pragmatic roadmaps and hands-on delivery.
- Design reviews & decision records
- Team growth & engineering standards
- FinOps, risk and stakeholder alignment
Selected outcomes
Engineering measured in change.
Representative outcomes delivered across platform engagements.
availability objectives
Resilient EKS platform patterns designed around fault isolation, observability and controlled change.
faster developer delivery
Self-service platform workflows that reduce hand-offs and shorten the path from change to production.
cloud cost reduction
FinOps guardrails, demand-aware scaling and architecture changes that treat cost as a system signal.
Technical writing
Field notes from operating cloud-native systems.
Runbooks, upgrade journeys and explanations shaped by the failure modes engineers meet in real environments.
MacOS Tahoe 26- creating admin users using DSCL cli — opens on Medium in a new tab
A practical guide to creating admin users using the DSCL command-line interface in macOS Tahoe 26.
Read articleAmazon EKS upgrade journey from 1.34 to 1.35 — opens on Medium in a new tab
A practical control-plane upgrade runbook for the Timbernetes release, with the compatibility checks and sequencing that matter in production.
Read articleWhat happens when you delete a Kubernetes CRD? — opens on Medium in a new tab
Why deleting a definition also deletes its custom resources, and how that failure mode affects common platform operators.
Read articleECR pull-through cache and cross-Region replication — opens on Medium in a new tab
A Terraform-based design for resilient, low-latency image pulls, including a safe approach to backfilling existing repositories.
Read articleWhy a headless service returns NXDOMAIN on EKS — opens on Medium in a new tab
A debugging guide to StatefulSet DNS, readiness and headless services, ending in a copy-ready production runbook.
Read articleProduction-ready InfluxDB on Amazon Timestream — opens on Medium in a new tab
The available deployment choices for Timestream for InfluxDB, expressed as a repeatable Terraform implementation.
Read articleKubernetes-based GitHub Actions runners with Flux — opens on Medium in a new tab
A working pattern for self-hosted Actions runners on EKS using Flux and Actions Runner Controller.
Read articleCareer journey
Software foundations. Platform depth. Technical leadership.
A progression from product software into the design and operation of enterprise cloud platforms.
Open the full CV2026 — present
Lead Cloud Native Developer
CurrentCapgemini
Combining hands-on engineering and technical leadership to build resilient, modern cloud-native systems for large-scale client environments.
2022 — 2026
Principal Cloud Engineer · DevOps Technical Lead
Dare
Led cloud-native engineering and platform direction, with an emphasis on secure AWS foundations, developer experience and high-quality operational practices.
Earlier chapter
DevOps Technical Lead
Limejump
Grew platform capability and helped establish enterprise AWS organisation and governance patterns.
Earlier chapter
Lead DevOps Engineer
uMotif
Led cloud infrastructure across multiple regions for a product operating in a regulated environment.
Earlier chapter
Cloud DevOps Engineer
News UK
Architected the organisation’s Amazon EKS environment and helped move production workloads from self-managed Kubernetes to a managed platform.
Career foundation
Software Engineer
The Times
Built software for a high-traffic digital news product before moving deeper into infrastructure and platform engineering.
Education & credentials
Deep foundations, continuous learning.
Formal study
Education
2012 — 2016
MEng (Master of Engineering), Computer Science
University College London
Four-year integrated master’s degree, including research in security, data visualisation and transport-network optimisation.
Before UCL
A Levels & BTEC National Diploma
South Cheshire College
IT, Mathematics, Further Mathematics and an Extended Project Qualification.
Professional development
Certifications
- AWS Certified CloudOps Engineer— AssociateAmazon Web Services · Cloud
- AWS Certified Solutions Architect— AssociateAmazon Web Services · Cloud
- AWS Certified AI PractitionerAmazon Web Services · Cloud
- HashiCorp Certified: Terraform AssociateHashiCorp · Infrastructure as Code
- GitHub AdministrationGitHub · Developer platform
- GitHub FoundationsGitHub · Developer platform
- GitLab Certified AssociateGitLab · Developer platform
- Prefect Associate CertificationPrefect · Data orchestration
- Akamai DevOps ProfessionalAkamai · Edge & delivery
- Akamai Bot Manager AdvancedAkamai · Edge & delivery
AWS Community Builder
Contributing practical cloud-native knowledge to the wider AWS community.
New Relic FutureStack speaker
Shared the operational story behind News UK’s production move to Amazon EKS.
Published EKS case study
Co-authored the News UK and New Relic story on Kubernetes infrastructure monitoring.
The site is a system too
Python in the build path. Zero JavaScript in the critical path.
This portfolio is generated from validated structured content by a typed, dependency-free Python build. GitHub Actions tests it, fingerprints the assets and publishes only the immutable static output.
Inspect the source- 01profile.jsonsingle content source
- 02Pythonvalidate + render
- 03CI checkstest + inspect links
- 04Pagesstatic deploy
Let’s compare notes
Architecture challenge, platform problem or open-source idea?
The best conversations usually begin with a system diagram and one stubborn constraint.