Infrastructure engineer · Kubernetes, multi-cloud routing & resilience, Go · Orange County, California
Fifteen-plus years deploying, routing and keeping distributed platforms healthy across clouds — most recently as the deployment and escalation engineer for the largest HashiCorp and Wiz accounts. Still hands-on daily on a mixed ARM64/x86-64 cluster at home.
Infrastructure Engineer · Kubernetes deployments & rollouts · Multi-cloud routing & resilience · Go / Python
Infrastructure engineer with 15+ years deploying, routing and keeping distributed platforms healthy across clouds. Before the field I was the customer: at Creative Artists Agency I shipped Go and Python services onto Kubernetes across AWS and GCP and ran a Consul service mesh spanning AWS, GCP and VMware; at Dell EMC I wrote Go services for OpenShift and a Python data-protection extension for OpenStack.
Since 2021 I've been the deployment and escalation engineer for HashiCorp's and Wiz's largest accounts: production rollouts, cross-datacenter replication and DR topologies, and "why is this cluster unhappy" calls on Vault, Consul, Nomad and Kubernetes in Fortune 100 estates. Still hands-on daily on a mixed ARM64/x86-64 kubeadm cluster: Cilium BGP and Gateway API routing, GitOps rollouts, and the observability to see what broke.
Deployment pipelines and rollouts. GitOps (Flux) and Helm rollouts of Cilium, cert-manager and GitLab with rollout failures root-caused; a phased node-upgrade operator with SSH retry and reboot detection; Jenkins and GitLab CI (SAST / DAST) pipelines; a series of Terraform modules I developed as field SME cut typical Wiz onboarding for Globals & Majors from 16 weeks to 4.
Request routing, load balancing, traffic management. Cilium BGP Control Plane v2 peering, LB-IPAM address pools and Gateway API HTTPRoutes (the Kubernetes API itself served behind a Cilium Gateway); Consul service mesh spanning AWS, GCP and VMware; Boundary multi-hop PKI worker architectures.
Multi-cloud and cross-datacenter resilience. Vault Enterprise disaster-recovery and performance-replication topologies for regulated customers; platforms deployed across AWS, GCP, Azure and Kubernetes; Consul → Raft and ZooKeeper → Raft storage migrations for Vault.
Heterogeneous fleet. Mixed ARM64 (Raspberry Pi 5) / x86-64 (NUC) cluster; root-caused ARM64/amd64 scheduling failures (jemalloc page size) and per-architecture placement.
Observability-driven tuning. Prometheus / Loki / Grafana pipelines fed by Terraform-emitted metrics; Hubble flow observability; Grafana + Loki packaging (grafana2go).
Languages. Go (production services at CAA, Dell EMC and LoginID; a Vault / OpenBao secrets-engine plugin), Python (Dell EMC OpenStack extension, CAA services, metrics scraper), HCL, Bash.
kubeadm, CRI-O, Cilium (BGP control plane, LB-IPAM, Gateway API, Hubble), Flux GitOps, Helm, cert-manager, External Secrets, OpenShift, AKS; managed Kubernetes across AWS / GCP / Azure
AWS, GCP, Azure, OpenStack, VMware · Vault (Enterprise replication / DR, KMIP, PKI, plugin development), Consul (service mesh), Nomad, Terraform (modules, provider generation, CDKTF), Boundary
Prometheus, Grafana, Loki / Promtail, Hubble · GitLab CI (SAST / DAST), Jenkins, Ansible + Molecule, Packer, Vagrant
Go, Python, HCL, Bash, Rego, TypeScript (CDKTF) · PostgreSQL, CockroachDB, Redis, MinIO / S3
Wiz, OPA / Rego policy-as-code, PKI / mTLS, SSO / OIDC / LDAP / Okta, SIEM integration
k8s-vanilla — cluster operations, routing and rollouts · github.com/markchristopherwest/k8s-vanilla
Raspberry Pi 5 + NUC kubeadm cluster: CRI-O, Cilium CNI with BGP peering to the home gateway, LB-IPAM pools, Gateway API HTTPRoutes, Flux GitOps, cert-manager (Let's Encrypt DNS-01 wildcard, Hubble mTLS), TLS 1.3 on etcd, self-hosted GitLab 19 on external PostgreSQL / Redis / MinIO. Wrote the bash operator (Linux and macOS bash 3.2) that upgrades node OSes in phases with per-run reports. Root-caused a Cilium 1.20 DaemonSet rollout stalled by a dead CRI-O socket, Helm server-side-apply ownership conflicts on cert-manager CRDs, a CRI-O upgrade repository move, and a firmware-update loop driven by GitHub API rate limits.
openbao-plugin-secrets-graphql — Go · github.com/markchristopherwest
Vault / OpenBao secrets engine for GraphQL APIs: credential lifecycle, GraphQL-over-HTTP protocol implementation, OpenBao SDK migration, generated Terraform provider, test suite; companion graphql-server-go and graphql-client-go.
Terraform → Prometheus / Loki / Grafana — observability from provider data
Modules that query a security platform's Terraform provider on a schedule (CrowdStrike Falcon, Prisma Cloud), emit JSON reports, and feed Promtail / Loki / Prometheus and Grafana dashboards to track post-sales consumption and churn inside a customer tenant; Python scraper, docker-compose packaging.
Ontele — serving pipeline in Go · github.com/ontele/ontele
Open-source (Apache-2.0) media server: HLS transcoding pipeline, HDHomeRun DVR with commercial skip, embedded web UI, zero-dependency Go.
HashiCorp reference implementations · github.com/markchristopherwest
vault-operator-migrate (Consul → Raft, ZooKeeper → Raft), vault-k8s-external-secrets, vault-replication, vault-ldap, vault-gitlab-jwt, vault-mfa-pingid, vault-puppet (PKI), boundary-session-recording, terraform-ckx, terraform-tls-automagically, cdktf-demo, grafana2go.
University of San Francisco — Psychology, undergraduate studies
The PDF version has everything on these cards in two pages:
Each link opens in a new tab and tries to leave this one in front. ⌘-click (Ctrl-click) if your browser insists on switching.
LinkedIn linkedin.com/in/markchristopherwest — career, posts, the professional record
GitHub github.com/markchristopherwest — open source, homelab, reference implementations
Email: markchristopherwest@gmail.com
I've spent almost twenty years on the infrastructure side of software. The last seven have been the ones that matter here: platform engineering with Go, Python and Kubernetes across AWS and GCP, then the field roles at HashiCorp and Wiz.
At HashiCorp I was a Solutions Architect for global and enterprise accounts, doing pre- and post-sales for Vault, Consul, Nomad, Terraform and Boundary. My specialties were Vault Enterprise replication, disaster recovery and KMIP, plus Boundary. I ran nearly everything through Terraform and rarely touched the UI.
Today I'm an L5 Technical Solutions Consultant at Wiz, which became part of Google in 2026. I act as the field subject-matter expert for large deployments and wrote the Terraform modules that cut customer onboarding from sixteen weeks to four.
Off the clock I maintain a mixed ARM64/x86-64 Kubernetes homelab and write open-source tools: a media server, a Vault / OpenBao secrets engine, and the automation that keeps the cluster alive. I care about self-hosted, open infrastructure that you can read all the way down.
Studied psychology at the University of San Francisco.
The last seven years, one card per employer, newest first. Use ▶ to page through, or jump straight to one:
Mar 2025 – present · Senior Technical Solutions Consultant
Oct 2021 – Feb 2025 · Consultant → Senior Consultant
Jun – Oct 2021 · Site Reliability Engineer
to 2021 · Senior Software Engineer
Earlier platform work (OpenStack, OpenShift, Windows infrastructure) is summarized on the card.
Irvine, CA · Mar 2025 – present
Senior Technical Solutions Consultant, Google Cloud (Jun 2026 – present; Wiz acquired March 2026)
Senior Advanced Delivery Architect, Wiz (Mar 2025 – May 2026)
San Francisco, CA · Oct 2021 – Feb 2025
Senior Consultant (May 2023 – Feb 2025) · Consultant (Oct 2021 – May 2023)
San Mateo, CA · Jun 2021 – Oct 2021 · Site Reliability Engineer
Senior Software Engineer (pre-HashiCorp)
Open source, mostly Go, mostly built to run on the homelab. Apache-2.0 unless the repo says otherwise.
Ontele — media server: HLS transcoding, HDHomeRun DVR, commercial skip, embedded web UI, zero Go dependencies. v2 is a Rust rewrite aimed squarely at replacing Plex. github.com/ontele/ontele
openbao-plugin-secrets-graphql — a Vault / OpenBao secrets engine for GraphQL APIs, with companion graphql-server-go and graphql-client-go and a generated Terraform provider.
k8s-vanilla — the automation behind the homelab: kubeadm, CRI-O, Cilium, Flux, cert-manager, OS upgrade phases, reboot detection, Markdown run reports. Bash that also runs on macOS's 3.2. github.com/markchristopherwest/k8s-vanilla
HashiCorp reference implementations — vault-operator-migrate, vault-k8s-external-secrets, vault-replication, vault-ldap, vault-gitlab-jwt, vault-mfa-pingid, vault-puppet, boundary-session-recording, terraform-ckx, cdktf-demo, grafana2go.
terraform-tls-automagically, golang-actorname, python-actorname — smaller tools and libraries.
Everything else: github.com/markchristopherwest
A mixed ARM64/x86-64 Kubernetes cluster: Raspberry Pi 5 nodes plus an Intel NUC, with real BGP to the router.
Because a cluster that has to survive a Pi rebooting mid-upgrade teaches more than a cloud account ever will. This site is one of the Helm charts.
My first computer was an Apple IIc — the little cream-colored one with the handle, a 65C02 running at one megahertz, and a 5¼-inch drive built right into the side. It had no hard disk and no idea it needed one.
There was a disk I played more than any game: a program whose entire purpose was to play a sonata — Beethoven's Moonlight Sonata, as I remember it — through the one-bit speaker. A single square-wave voice, note by note, and I'd sit and let the whole thing run while the drive light stayed dark. It was the first time a machine did something beautiful for no reason.
The other thing it did was BASIC. Type ], then 10 PRINT "HELLO", 20 GOTO 10, RUN, and the screen was yours. I filled disks with programs that drew lo-res shapes, asked questions, and beeped. Nobody had told me this was "programming"; it was just what the computer was for.
At school it was Logo: a turtle on the screen that only went where you told it, in the order you told it. FORWARD 50 RIGHT 90, four times, and you had a square — and a first lesson in why the computer does exactly what you said instead of what you meant.
A shout-out to my favorite computer science teacher, Jeanne Robb, who taught that class. She never married and lived on her own, but she assured a room full of us — with a straight face — that her heart belonged to Mel Gibson. She gave a lot of kids their first square, and she gave me the whole road.
My best friend's house had a Macintosh Plus. Nine-inch black-and-white screen, a mouse, a desktop with icons you could drag — the machine this whole site is dressed up as. We spent afternoons in front of it playing Where in the World Is Carmen Sandiego?, flipping through the World Almanac that came in the box to work out which country has a currency called the kwacha, and losing her anyway.
My parents could afford exactly one Apple, and it was the II. The Macintosh cost more than our car had any right to, so for a few years the closest I got to a Mac was riding my bike to it. That is also why I know the Apple IIc's BASIC prompt better than I know MacPaint: you learn the machine you have.
I did get a Macintosh eventually. It took a while. HyperCard was on it, and I built stacks that did nothing useful and everything I wanted. If you're reading this on the message box (⌘M), you'll understand.
My first internet connection was Pacific Bell dial-up: a 28.8 modem, a phone line nobody else could use, and the handshake screech that still means "online" to a certain generation.
The computer on the other end of the modem was a Compaq Presario, not a Mac. Loyalty lost to plumbing: the Mac's networking stack at the time (MacTCP, then the early Open Transport releases) was flaky enough that getting PPP to stay up was a project in itself, while the Presario just dialed. Windows 95 was king — it felt like '97 by the time we got it — and for a short while Netscape Navigator was the entire web, with a throbbing N in the corner to prove you were connected.
That Presario is where I learned that the interesting part of a computer is the part that talks to other computers. Everything since — service meshes, BGP peering, a Gateway in front of a Kubernetes API — is the same handshake, faster.
Everything on this site is my own opinion and my own work. Nothing here represents the views, positions or policies of my employer (Google Cloud, formerly Wiz) or of any past employer. I speak for myself.
This site is a single static file with no advertising and no third-party trackers. Two Google services can be involved: Google Fonts, from which the pixel typeface is loaded, and Google Analytics 4 for anonymous usage statistics — analytics is currently off on this copy of the site. When analytics is on it records which cards are viewed and which buttons and links are used, with ad features and Google Signals disabled; it is not loaded at all if your browser sends Global Privacy Control or Do Not Track. Google's privacy policy applies to those requests. The host that serves the page keeps ordinary access logs (IP address, user agent, time) for operational purposes.
Links to LinkedIn, GitHub and other sites take you to services with their own policies. The résumé PDF contains my contact details; please use them for professional purposes only.
The site's code is MIT-licensed; the writing and the résumé are © Mark Christopher West and may be quoted with attribution. Provided as-is, without warranty. Customer and employer names appear only as public, factual statements of where I worked; no confidential information is published here.
Questions: markchristopherwest@gmail.com
Open source and self-hosting. If I use it every day, I'd like to be able to read it, build it and run it myself. Most of my projects start as "why am I paying for this?"
Homelab engineering. Real networking (BGP, Gateway API), real failure modes (ARM/amd64 mismatches, dead CRI-O sockets, firmware loops), real fixes.
Media. Transcoding pipelines, DVR, and the plumbing under a good living-room stream.
Secrets and identity. Vault, LDAP, PKI, passwordless auth — the plumbing under every login.
Retro computing. This site is a HyperCard stack because HyperCard got a lot right: cards, buttons, fields, and a message box you could talk to. Try ⌘M.
Best reached by email or LinkedIn. Recruiters: the Résumé cards are current and there's a PDF.
Views here are my own, not my employer's.
Every card has a URL: add #cardname to the address, e.g. #projects.