$ whoami

Amarnath Jamale

> Senior Platform Engineer

I build the platforms other engineers build on: a Backstage developer portal, a Crossplane control plane, Flux-delivered Kubernetes runtimes, and the automation that keeps a fleet of 1000+ servers boring, compliant, and fast to ship to.

  • 0+years in infrastructure
  • 0+servers automated
  • $3.5Msaved annually via automation
  • 0×Azure certified
amar@platform: ~ (interactive, type away)

            

## 01 · about

Platform engineering is a product,
developers are the customers.

I'm a Senior Platform Engineer at CatalystOne Solutions, where I run the internal developer platform end to end: a Backstage portal with golden paths and service templates, a Crossplane control plane that turns Azure, Entra ID, and Cloudflare into self-service APIs, Flux GitOps delivery, and the Kyverno guardrails that let product teams ship without filing tickets.

Before that I spent six years at Tata Consultancy Services, embedded with DNB Bank ASA, Norway's largest bank, climbing the whole infrastructure stack: Unix/Linux operations on RHEL and Solaris, configuration management with Ansible across a 1000+ server estate, then Azure DevOps with pipelines, Bicep, and cloud migrations of on-premises workloads.

That path shaped how I work: I've carried the pager, hardened the OS, written the playbooks, and built the pipelines. The platforms I design now are opinionated where it saves teams time and flexible where it doesn't.

01 Pave the golden path. Make the right way the easy way.
02 If it's done twice by hand, it ships as code the third time.
03 Guardrails over gates. Security that shouldn't slow delivery.
04 Boring infrastructure is a feature, not a compromise.
engineer.yamlyaml
# kubectl get engineer amarnath -o yaml
apiVersion: platform.jamale.org/v1
kind: PlatformEngineer
metadata:
  name: amarnath-jamale
  labels:
    role: senior-platform-engineer
    org: catalystone-solutions
    region: oslo-norway
spec:
  focus:
    - internal-developer-platforms
    - kubernetes-runtimes
    - infrastructure-as-code
    - automation-at-scale
  tooling: [backstage, crossplane, flux, aks, ansible, terraform]
  replicas: 1  # sadly not horizontally scalable
status:
  phase: Running
  conditions:
    - type: Caffeinated
      status: "True"

## 02 · experience

Career, rendered as a pipeline.

Every stage passed. The current one is still deploying.

● runningAug 2025 → present

Senior Platform Engineer

CatalystOne Solutions AS

  • Driving the Backstage developer portal as the backbone of CatalystOne's internal developer platform: golden paths, scaffolder templates, RBAC, and a software catalog spanning a multi-region AKS fleet.
  • Building a Crossplane control plane exposing 35+ self-service platform APIs for Azure, Entra ID, and Cloudflare, provisioned by product teams through pull requests instead of tickets.
  • Delivering everything via Flux GitOps in a hub-and-spoke fleet, with Kyverno policy-as-code gates and CI validation in front of every merge.
  • Engineering a zero-static-secrets identity model: workload identity federation across GitHub OIDC, AKS, and Entra ID, backed by External Secrets Operator and Key Vault.
  • Managing GitHub itself as infrastructure as code: repositories, teams, policies, and reusable actions that codify governance, security guardrails, and delivery best practices across product teams.
BackstageCrossplaneFluxAKSKyvernoGitHub ActionsWorkload Identity
✓ succeededMay 2021 → Jul 2025

Azure DevOps Engineer

Tata Consultancy Services Ltd. · DNB Bank ASA

  • Designed and ran Azure CI/CD pipelines for continuous integration and deployment across multiple applications.
  • Streamlined infrastructure deployments with Bicep, keeping environments reproducible and reviewable.
  • Migrated on-premises workloads to Azure and standardized them behind pipelines.
  • Provided expert-level Azure administration for production cloud workloads.
AzureAzure PipelinesBicepCloud Migration
✓ succeededDec 2019 → Jul 2025

Ansible Developer

Tata Consultancy Services Ltd. · DNB Bank ASA

  • Built an automation estate of 80+ projects with 300+ roles and templates managing 1000+ servers on Red Hat Ansible Automation Platform.
  • Fully automated Linux patching with compliance reporting and application orchestration, saving ~$3.5M and 20,000 engineer-hours annually.
  • Defined the RHEL 9 standard operating environment and a LEAPP in-place upgrade framework with automated remediation, re-hardening, and validation.
  • Architected compliance as code: dynamic Ansible hardening playbooks generated from OpenSCAP profiles; prototyped Event-Driven Ansible for GitOps and monitoring.
  • Automated a server decommissioning framework integrating ServiceNow, Dynatrace, Satellite, IdM, VMware, and Azure.
AnsibleAAPCIS HardeningPythonCompliance
✓ succeededFeb 2019 → Jul 2025

Unix/Linux Platform Engineer

Tata Consultancy Services Ltd. · DNB Bank ASA

  • Automated daily operations with Bash, Python, and Perl for cluster monitoring, LDAP mirroring, and access standardization, saving ~300 hours of work per month.
  • Standardized access management on OpenLDAP, OUD, and Red Hat IdM: scripted, documented, and delegated to L1 by skill level.
  • Ran PCS / VCS / Sun Cluster deployments with L3 support, filesystem and storage operations on RHEL and Solaris.
  • Built SRE SLI/SLO dashboards on Dynatrace and ServiceNow Kanban boards that kept the team ahead of SLA breaches.
RHELSolarisBashOpenLDAPIdMClustering

## 03 · now shipping

Flagship platform work.

The CatalystOne platform I'm building today, and the fleet that proved the playbook.

internal developer platform

One portal for everything

A Backstage portal unifying the software catalog, scaffolder golden paths, TechDocs, and live Kubernetes state across a multi-region AKS fleet, with Entra ID auth, fine-grained RBAC, and adoption insights to steer the roadmap.

BackstageCatalogTechDocsRBACEntra ID
platform control plane

Infrastructure as an API

A Crossplane control plane turning Azure, Entra ID, and Cloudflare into 40+ Kubernetes-native, self-service APIs: composed with functions, isolated per-subscription-per-resource-type, and requested by teams through plain pull requests.

CrossplaneXRDsComposition FunctionsAzureCloudflare
gitops fleet delivery

Git is the deploy button

Flux v2 hub-and-spoke delivery: a single platform hub remote-applies to spoke clusters over Workload Identity, with tiered reconciliation, CI policy gates on every PR, and a zero-static-secrets identity chain across GitHub OIDC, AKS, and Entra ID.

Flux v2Hub & SpokeWorkload IdentityESOKey Vault
golden paths

Paved paths, not guesswork

Scaffolder templates that stamp out production-ready Spring Boot services, React/Next frontends, and shared libraries, plus Crossplane resource requests (Key Vault, Azure RBAC, AI Foundry) with federated credentials and multitenancy wired in from commit one.

ScaffolderSpring BootReactCrossplane Templates
custom plugins

Plugins for the gaps

A suite of @catalystone Backstage modules: an Azure-resources Kubernetes ingestor, extended GitHub scaffolder actions, GitHub-environment and federated-credential automation, and Teams notifications, published through a Yarn 4 monorepo with Changesets.

TypeScriptBackstage PluginsGitHub APIMS Graph
policy as code

Guardrails, not gatekeepers

A CIS-aligned Kyverno policy suite (35 validating + 1 mutating) authored and tested with a wave-based audit-to-deny rollout, deletion-guards on critical identities and Key Vaults, and an approval gate for Entra permission grants.

KyvernoCISAdmission ControlGovernance

$ git log --oneline · past deployments

✓ shipped · 2019 → 2025 · red hat estate at dnb

1000+ servers, one control room

The full Red Hat suite run as a single automated estate: Ansible Automation Platform with 80+ projects and 300+ roles, Satellite for provisioning and content, IdM for access and DNS, and OpenShift alongside RHEL 6 to 9. Patching, hardening, and reporting fully automated, saving $3.5M a year.

Ansible Automation PlatformSatelliteIdMOpenShiftRHELEvent-Driven Ansible

## 04 · platform stack

The layers I operate.

From the developer portal down to the kernel, plus the automation that glues it together.

Developer Experience

Internal developer platforms that make the golden path the default path.

BackstageScaffolder TemplatesTechDocsGolden PathsService Catalog
BackstageKubernetesGitHub Actions

Cloud & IaC

Azure-first, everything declared in code, nothing clicked in a portal twice.

AzureCrossplaneTerraformBicepGitHub as CodeAWSGoogle Cloud
Microsoft AzureCrossplaneTerraformAmazon Web ServicesGoogle Cloud

Containers & Orchestration

Kubernetes runtimes operated as products, with GitOps as the delivery contract.

AKSKubernetesFlux GitOpsHelmIstioOpenShiftDockerPodman
KubernetesFlux CDHelmIstioRed Hat OpenShiftDockerPodman

CI/CD & Automation

Pipelines and event-driven automation at fleet scale: 1000+ nodes, zero snowflakes.

GitHub ActionsAzure PipelinesAnsibleEvent-Driven AnsibleJenkins
GitHub ActionsAzure DevOpsAnsibleJenkins

Security & Governance

Guardrails as code: policy admits, identity federates, secrets never sit in git.

KyvernoWorkload IdentityExternal SecretsKey VaultOIDC FederationCIS Baselines
KyvernoAzure Key Vault

Observability

If it isn't measured, it isn't operated. Metrics, traces, and mesh telemetry.

PrometheusGrafanaMimirJaegerKialiAzure MonitorLog Analytics
PrometheusGrafanaJaeger

Systems & Identity

The unglamorous foundation: hardened OS builds, clustering, and access done right.

RHEL 6–9SolarisSatelliteIdM / OpenLDAPPacemakerVCSCIS Benchmarks
Red Hat Enterprise LinuxLinux
λ

Languages & Glue

Whatever the layer speaks, from kernel scripts to portal plugins.

PythonBashYAMLPowerShellJavaScriptPerlJinja2
PythonGoBashJavaScript

## 05 · credentials

Verified, not vibes.

## 06 · automation

Playbooks that ran a bank.

A slice of the 80+ projects and 300+ roles I built on Red Hat Ansible Automation Platform across DNB's 1000+ server estate. Each one replaced a runbook with code.

Fleet-wide RHEL patching

End-to-end OS patching: Satellite content promotion, ServiceNow change requests, application failover to passive nodes, and day-0 errata within a day, across the estate. The backbone of the ~$3.5M/year savings.

AnsibleSatelliteServiceNowInsights

RHEL 9 SOE & LEAPP upgrades

Standard operating environment via image-builder and kickstart, plus a report-driven LEAPP in-place major-upgrade framework with dynamic remediation, re-hardening, and validation — no redeploy, no app migration.

AnsibleSatelliteimage-builderLEAPP

CIS hardening as code

Dynamic Ansible playbooks generated from OpenSCAP profiles: deploy the CIS benchmark, refresh rules without internet access, scan periodically, and apply only the rules a client approves.

AnsibleOpenSCAPCIS

Config as Code: Satellite & AAP

Extract, version, and restore the full configuration of Red Hat Satellite and Ansible Automation Platform as code — repos, content views, job templates, inventories, RBAC — for reproducible, recoverable control planes.

AnsibleSatelliteAAP

Event-driven decommissioning

A ServiceNow-triggered, approval-gated teardown built on Event-Driven Ansible: removes hosts from Satellite, IdM, and Azure, then publishes a released-capacity report.

Event-Driven AnsibleServiceNowIdMAzure

Automated access provisioning

Azure tags and Satellite params drive Red Hat IdM: user groups, host groups, HBAC, and sudo rules created or extended automatically as each server lands — access without tickets.

AnsibleRed Hat IdMAzure

Secured-app deployments

Pipeline-built servers that deploy and configure CyberArk PSMP/PTA, Dynatrace, and Autosys at build time, with on-the-fly upgrades and full-infra redeploys.

AnsibleCyberArkDynatraceAzure DevOps

Compliance & capacity reporting

Self-publishing HTML dashboards: weekly patch/CVE compliance and non-reporting hosts from Satellite, Solaris capacity and hardware health, and pre-prod server-handover validation.

AnsibleSatelliteSolarisHTML5

# and ~40 more: SOSReport auto-upload, pre/post-change checks, disaster-recovery drills, LVM standardization, support-case digests…

## 07 · contact

Let's build a platform.

Talking shop about developer platforms, Kubernetes, or automation? My inbox reconciles faster than my clusters. Based in Oslo, Norway.

$ mail -s "reach out" amar@jamale.org