An internal developer platform that cut app onboarding from days to hours
This is my own work in my day job as a DevOps engineer at a global logistics company. It isn't a BVS contract. I'm including it because it's the clearest example of what I build.
The situation
Getting an app onboarded and deployed to OpenShift took 4 to 5 days. The steps between a finished change and a running app were slow and mostly manual, and every team went through them one request at a time.
What I built
I'm the sole architect and developer of an internal developer platform that serves 5 application teams. It's a multi-service web app that puts the whole path from code to cluster in one place.
- One workflow for every deploy. A developer clicks through a window 3 times and it launches the CI/CD workflow: secret-leak checks, vulnerability scanning, application tests and the deploy to OpenShift.
- GitOps. Deploys go through Git, so what runs in the cluster matches what's in the repository.
- Self-hosted runners that start in OpenShift on demand and shut down when the build ends.
- Scan-to-fix. Every image is scanned with Trivy and signed with cosign. Developers see the results and update to the recommended versions in one step.
- Self-service secrets. Secrets are no longer passed around by hand, and teams can rotate their own.
The result
Namespace onboarding and deployment went from 4 to 5 days to hours, a cut of about 80%. The security steps run on every deploy because they're part of the workflow, not a checklist someone has to remember. I run the platform, the runners, the scanning and the signing as the sole engineer responsible for them.
What changed most wasn't any single tool. It was that a developer no longer has to know every step, or wait on someone who does. The platform knows the steps, and the developer reviews the result.
The guides behind the pieces: self-hosted runners on OpenShift, scanning images with Trivy and security gates in a CI/CD pipeline.