I build Kubernetes platforms that stay boring in production.
Platform/DevOps Engineer in Dubai. 9+ years across Telecoms, FinTech, Healthcare and ISP — turning architectural standards into repeatable, well-documented automation.
Grab my CV
One page of what I actually do — Kubernetes platforms, service mesh, GitOps and the automation around them. PDF, updated August 2026.
CNCF Kubestronaut
Elite CNCF status earned by passing all five core Kubernetes certifications — CKA, CKAD, CKS, KCNA and KCSA. Fewer than a thousand engineers worldwide hold it.
Verify on CNCF →Experience
DevOps Engineer
- Design and operate production Kubernetes platforms on EKS and RKE2 for regulated fintech and telecom workloads.
- Run Istio service mesh in production — mTLS between services, ingress/egress policy, and an ambient mesh evaluation.
- Built GitOps delivery with Jenkins, GitHub Actions and Kustomize so environment promotion is a merge, not a ticket.
- Standardised secrets on HashiCorp Vault and HCP, with Keycloak as the OIDC issuer behind Kong API Gateway.
- Engineered the observability stack — Prometheus, Grafana and ELK with Fleet and APM agents across clusters.
- Own Kafka reliability including documented primary ↔ DR switchover procedures.
- Automate AWS infrastructure with Terraform, Ansible and Packer — SSM, S3, KMS and cross-account IAM.
System Engineer
- Built and maintained private cloud infrastructure on VMware ESXi supporting telecom and fintech services.
- Introduced containerisation with Docker and early Kubernetes workloads to replace bare-metal deployments.
- Automated repetitive provisioning with Ansible and Bash, cutting manual build steps for new environments.
- Ran monitoring and alerting with Zabbix and the ELK stack across the server estate.
- Hardened Linux images and managed OS lifecycle for production hosts.
System Engineer
- Operated ISP network and Linux server infrastructure serving broadband subscribers.
- Deployed LibreNMS and Zabbix for network-wide visibility and faster fault isolation.
- Handled escalated incidents across routing, DNS and service availability.
System Support Engineer
- Deployed and supported healthcare systems on client sites as part of an SI team.
- Managed Windows and Linux servers, backups and user access for hospital deployments.
Junior System Administrator
- Where it started — Linux administration, networking fundamentals and daily operations.
- Wrote the first shell scripts that made me realise automation was the actual job.
Education
Bachelor of Computing In progress
BA (English)
Certifications
Kubestronaut progress
Every badge below is clickable and independently verifiable.
Skills & technologies
Grouped by what they actually do, not by vendor.
Kubernetes & orchestration
Service mesh & networking
Infrastructure as code
CI/CD & GitOps
Cloud platforms
Observability & monitoring
Security & identity
Data & messaging
Linux & containers
Programming & scripting
Portfolio & diagrams
Documented research, architecture diagrams and hands-on implementations. Filter by domain, then tap a topic.
Blog
Long-form deep dives — the kind of write-up I wish I had found when I was building the thing. Filter by topic; each post is tagged with how deep it goes.
Who actually carries the packets? Boundary workers across AWS, Azure and GCP
I built the same thing three times — one private VM, reachable over SSH with no key on my laptop — in three clouds, with three different data paths. One line of worker config decides which path you get, and almost nothing written down says so plainly.
Deep dive · Identity & accessBoundary and Microsoft Entra ID: single sign-on was the easy half
I wired HashiCorp Boundary to Entra ID so engineers could reach a private VM with their corporate login and no SSH key anywhere. Authentication worked the same afternoon. Then I logged in successfully and could see absolutely nothing — plus what the bastion-and-keys pattern actually costs, and where this goes next.
Deep dive · AuthenticationKeycloak SSO and identity federation behind an nginx/njs API gateway
Can an application own 100% of its login UI while an identity provider still owns 100% of the credentials? I built the thing to find out, and traced every request to see what actually happens — seven auth flows end to end.
About me
➜ whoami Kyaw Sithu — Platform/DevOps Engineer, Dubai UAE ➜
I would rather show you
An interview is forty minutes, maybe an hour. I always walk out wishing there had been more time. There is so much I would love to walk you through, and so little of it fits into one conversation.
So rather than spend those minutes saying I am hardworking, passionate and flexible, I would love you to see it for yourself. Those words are easy to say. I would much rather hand you something you can actually look at.
I have left the work somewhere you can take your time with it. Projects has the diagrams and the notes from things I actually built and broke. The Blog has the long write-ups, including the parts where I got it wrong and had to go back and understand it again.
There is only one thing I can really guarantee you. Whatever I take on, I put my heart into it. I think that shows in the work far more honestly than it ever could in a sentence about myself, so please have a look. I hope you can feel it.
Beyond work
Built and run independently — giving back to the Myanmar expat community in Dubai.
Dubai IT Community
Active moderator in a Dubai-based IT professionals group, contributing knowledge and community support. Since 2022 the Myanmar IT community in Dubai has grown a lot — members are connecting, finding jobs and building careers. A small but meaningful impact on people's lives in a foreign country.
Join the groupDubai Directory MM
A community platform and business directory for the Myanmar community in Dubai — connecting expats with local businesses, job resources and community support. Designed, built and operated as a personal initiative outside of work.
Say hello
I am looking for Platform Engineer, DevOps or Cloud-Native work. I am in Dubai and happy to stay here, and equally happy to talk about Singapore or anywhere else that makes sense.
The work I enjoy most is the platform underneath other people's work. Kubernetes that nobody has to think about, pipelines where promotion is a merge, and access that is tied to who someone is rather than what they happen to hold. If that is the kind of problem on your desk, I would like to hear about it.
Recruiters and hiring managers are very welcome. So is anyone who read something here, disagreed with it, and wants to tell me why.
Email me, or say hi on LinkedIn
No form to fill in — either of these reaches me directly, and I read every message. Tell me about the team and the stack, and I will come back to you.