
Just Eat Takeaway.com
Enschede, Netherlands
Platform Engineer
September 2024 - Present
Built and operationalized a Go service that traces AWS network paths across VPC route tables, Transit Gateways, Cloud WAN, and accounts, reducing typical 30–60-minute manual investigations to minutes.
Led root-cause analysis of a production EKS CPU-saturation incident, tracing the interaction between workload rightsizing, Kubernetes requests, HPA behavior, and .NET thread-pool exhaustion. Worked with the vendor and designed a reusable rightsizing policy for latency-sensitive workloads.
Implemented Kyverno Chainsaw end-to-end tests for a shared Helm application chart used to deploy into EKS, running on every PR and gating chart publication. Validated upgrades, canary progression, HTTP connectivity, workload health, and rollback across prior patch, minor, and major versions, catching multiple regressions before release, including selector-label changes that could break API endpoints.
Investigated Karpenter consolidation and node churn across production EKS clusters, turning findings on disruption blockers, pod disruption budgets, topology spread, disruption windows, and instance selection into tracked platform improvements.
Automated Kubernetes quota risk analysis across 200+ namespaces and six environments, warning 45+ teams about quotas that could block HPA scaling before a peak-traffic change freeze.
Built a repeatable disaster-recovery dependency discovery workflow using C4/Structurizr modeling, repository analysis, and AWS cost data across 200+ components. Reused the tooling to map six applications in less than a day.
Evaluated EKS Auto Mode for 10+ clusters and 1,000+ workloads. Validated networking and load-balancer migration paths, identified EBS migration and controller-coexistence blockers plus a 10–12% compute-cost increase, and recommended a no-go based on reliability, effort, and cost.
Extended Backstage with custom TypeScript actions to automate EKS workload onboarding, service metadata updates, traceability, and documentation.
Hardened progressive delivery by improving Argo Rollouts observability, fixing Helm rollback edge cases, and validating KEDA autoscaling behavior to support safer releases and clearer operational signals.
Automated migration of all in-use gp2 EBS-backed Kubernetes storage to gp3, including scale-down, persistent-volume recreation, and recovery flows. Completed the migration with minimal downtime and zero data loss, then prevented new workloads from using gp2.
Built Python checks to validate ingress hosts and ACM certificates in Helmfile/Terragrunt workflows, preventing broken TLS and load-balancer reconciliation issues before deployment.
Reduced non-actionable PagerDuty alerts and investigated Prometheus, Alertmanager, and Datadog failure modes to improve on-call signal quality and platform operability.
Contributed to platform security and governance through Kubernetes RBAC access-model proposals, EKS risk assessments, and DNS validation improvements.



