Platform Engineer @ MinIO · Kubernetes & High-Perf Infra
Mountain View, Bay Area
Working on MinIO's Kubernetes Operator: maintainer/contributor since 2022.
Key bits I've shipped or fixed:
- Operator STS: Kubernetes native IAM authentication https://github.com/minio/operator/blob/master/docs/STS.md
- CVE-2025-32963 fix: audience scoping for STS (Security Token Service) tokens to block replays
- Spread-zone config for HA Pod placement & erasure coding resiliency SpreadZone
- Guides for EKS exposure, Helm, Prometheus, OpenShift compat
Helm charts work:
- Contributed to Helm charts helm for core MinIO products.
- Involved in enterprise/AIStor Operator charts (licensed: aistor-objectstore-operator, aistor-keymanager-operator, etc.) for advanced features like key management and volumemanager
Also managed publishing and certification:
- AWS Marketplace publisher/manager for MinIO AIStor (easier EKS/subscription-based installs)
- OpenShift OperatorHub certified operators (via Red Hat OLM/Marketplace) for hybrid/OpenShift-native deployments
Also run MinIO's internal multi-cloud R&D setups (AWS-heavy) and datacenter labs:
IaC (Terraform/CloudFormation for clouds, pure K8s for DC), high-speed fabrics (100–400Gbps), physical hands-on (cabling, installs), monitoring (Prometheus/Grafana dashboards for visibility), outage RCA, troubleshooting across envs, secrets management (Keycloak realms, KES policies, CA certs).
Pinned:
- minio/operator — Kubernetes Operator for MinIO clusters (features, Helm, releases, security)
- minio/docs — Official MinIO documentation
Some old public examples of identity + monitoring setups just for fun:
- minio-operator-keycloak: Operator Console SSO with Keycloak (Cert-Manager, realm config, CA secret sharing)
- minio-tenant-keycloak: Tenant-level SSO / OIDC with Keycloak
- keycloak-deployment: Declarative Keycloak on K8s (Operator + CRD + Postgres)
- minio-kes-prometheus: MinIO tenant with KES + Prometheus scraper (ServiceMonitors, automated TLS via Cert-Manager, Vault AppRole for secrets)
If you're digging into MinIO/K8s/storage infra, Keycloak SSO patterns, KES monitoring, Helm for operators, or Marketplace/OperatorHub certifications, feel free to ping.
Thanks for looking.



