An internal developer platform that cut app onboarding from days to hours

By Brian Gomes, Owner and Principal Engineer. Published .

This is my own work in my day job as a DevOps engineer at a global logistics company. It isn't a BVS contract. I'm including it because it's the clearest example of what I build.

The situation

Getting an app onboarded and deployed to OpenShift took 4 to 5 days. The steps between a finished change and a running app were slow and mostly manual, and every team went through them one request at a time.

What I built

I'm the sole architect and developer of an internal developer platform that serves 5 application teams. It's a multi-service web app that puts the whole path from code to cluster in one place.

  • One workflow for every deploy. A developer clicks through a window 3 times and it launches the CI/CD workflow: secret-leak checks, vulnerability scanning, application tests and the deploy to OpenShift.
  • GitOps. Deploys go through Git, so what runs in the cluster matches what's in the repository.
  • Self-hosted runners that start in OpenShift on demand and shut down when the build ends.
  • Scan-to-fix. Every image is scanned with Trivy and signed with cosign. Developers see the results and update to the recommended versions in one step.
  • Self-service secrets. Secrets are no longer passed around by hand, and teams can rotate their own.

The result

Namespace onboarding and deployment went from 4 to 5 days to hours, a cut of about 80%. The security steps run on every deploy because they're part of the workflow, not a checklist someone has to remember. I run the platform, the runners, the scanning and the signing as the sole engineer responsible for them.

What changed most wasn't any single tool. It was that a developer no longer has to know every step, or wait on someone who does. The platform knows the steps, and the developer reviews the result.

The guides behind the pieces: self-hosted runners on OpenShift, scanning images with Trivy and security gates in a CI/CD pipeline.