Hanna Marusych

Platform Engineer · AWS · Kubernetes · Terraform

I build the platforms other engineers ship on.

Platform Engineer with nearly 6 years building and operating AWS and Kubernetes platforms for high-scale consumer and B2B products. At Egencia I run the Kubernetes platform behind 50 services across 3 engineering teams — Terraform modules and OIDC-federated pipelines in place of hand-run, per-environment work.

I also build the agentic tooling on top of it: Claude Code skills and MCP integrations that platform and product engineers use day to day.

What I run

50 services, 3 teams

The Kubernetes platform behind Egencia's services — EKS, Terraform modules, and the delivery path onto them.

Self-service paths

OIDC-federated pipelines, GitOps delivery, and routing that brings up its own load balancer, DNS record, and TLS certificate.

Agentic tooling

Claude Code skills and MCP integrations that take over the manual review passes — PRs, logs, rollouts, Terraform plans.

Infrastructure should make the safe path the easy path.

Experience

Building infrastructure that has to work.

Nearly 6 years building and operating AWS and Kubernetes platforms for high-scale consumer and B2B products — delivery paths, Terraform modules, routing, observability, and the agentic tooling on top.

Nov 2023 — Present

Chicago, IL

Egencia — American Express Global Business Travel

DevOps Engineer, Platform Engineering

Run the Kubernetes platform behind 50 services across 3 engineering teams — Terraform modules and OIDC-federated pipelines in place of hand-run, per-environment work.

  • Own the delivery path for 8 of the platform's 50 services and the 6 developers behind them: one GitHub Actions → ECR → ArgoCD → EKS flow in place of manual per-environment deploys, now shipping daily production releases.
  • Swapped hardcoded AWS credentials in CI/CD for Terraform-managed OIDC roles — no more long-lived keys sitting in pipelines.
  • Built self-service routing for application teams: a Kubernetes route declaration automatically brings up the load balancer, Route 53 record, and TLS certificate (Gateway API, ExternalDNS, cert-manager).
  • Unified fragmented per-team checks into one Prometheus, Grafana, and Alertmanager stack — alerting on certificate expiry and node pressure before they reach customers, and replacing cross-team Slack threads with one Grafana panel on-call works from.
  • Automated first-pass PR review across 30 repositories with a Claude Code GitHub Action that reads each pull request against its Jira ticket and flags requirement gaps and exposed secrets.
  • Migrated 4 ML model-serving workloads from AWS SageMaker to Amazon EKS as part of the platform team, cutting monthly compute cost for the highest-traffic inference workload 66%.
AWSEKSTerraformArgoCDGitHub ActionsGateway APIPrometheusClaude Code

Sep 2020 — Oct 2023

Remote

FanDuel

Cloud Engineer

Cloud engineer on the AWS and Kubernetes platform behind FanDuel's betting product, through NFL-season traffic peaks and the move onto reusable Terraform modules.

  • Scaled Kubernetes workloads for NFL season peaks: historical traffic analysis, load tests on the critical paths, and node groups pre-scaled for 3–5× traffic spikes.
  • Ran the AWS platform behind the betting product — 6 accounts, 12 Kubernetes clusters — and moved its provisioning onto reusable Terraform modules for node groups, IAM/IRSA, networking, and CloudFront, shared across development and staging.
  • Provisioned additional Amazon Redshift clusters with Terraform on a producer/consumer data-sharing pattern, monitored for query queue time and concurrency.
  • Built the provisioning path for live sports video channels behind the betting product, turning manual requests into self-service configuration — 4 live channels online in 3 weeks.
AWSKubernetesTerraformIAM/IRSACloudFrontRedshift

I'm most interested in the problems where infrastructure, developer experience, reliability, and security overlap.

AI-Assisted Engineering

Agentic tooling on top of the platform.

Four Claude Code skills built and run in day-to-day platform work, each taking over a manual review pass.

01

PR requirements review

Reads each pull request against its Jira ticket and flags missing requirements and exposed secrets before merge — replaces the first manual pass.

02

Log diagnostics

Collects the relevant logs, groups repeating errors, ties them to a deployment or workload, and proposes what to check next.

03

Kubernetes triage

Reads pod events, deployment status, and resource errors to explain a failed rollout, in place of hand-assembled kubectl context.

04

Terraform plan review

Checks plans for unexpected IAM, networking, and security changes, flags drift, and surfaces violations before apply — replaces reading large plans by eye.

Scoped by repository-level CLAUDE.md conventions carrying the team's Terraform and delivery standards, MCP integrations for infrastructure context, and AWS Bedrock for analysis workloads.

Selected Work

Projects that show how I work.

A few examples of infrastructure, platform engineering, and cloud migration work. The goal is not just to list technologies, but to show the problems I solve with them.

01

EKS Cluster Migration — CloudFormation → Terraform

Migrated a team's live EKS cluster from a hand-created CloudFormation stack to Terraform with no meaningful downtime. Ran both clusters in parallel while validating networking, IAM, Kubernetes RBAC, ingress, monitoring, and CI/CD, then cut over application by application. Modernized to an IPv6-primary design with worker nodes in private subnets, removing per-node public IPv4s and the associated public-networking cost (verified before/after in AWS Cost Explorer).

TerraformAWSEKSKubernetesIPv6GitHub Actions
02

RouteBox — Cloud-Native Microservices Platform

A production-style logistics platform built as independent services on AWS: a customer-facing Shipments API (the authoritative shipment lifecycle), a carrier webhook ingestion service that validates and deduplicates events from UPS/FedEx/DHL/USPS, an OR-Tools route-optimization worker that runs as a scalable background process, and an internal ops console. All AWS infrastructure is provisioned with modular Terraform using environment separation and automated remote state — the focus is service decomposition and infrastructure-as-code, not a single monolith.

TerraformAWSMicroservicesDockerREST APIsCI/CD
03

Product Review System — 3-Tier App on AWS

A 3-tier web application on AWS where users add products and leave reviews: an Nginx-served frontend, a Python/Flask REST API, and a MySQL database. Containerized with Docker and designed for high availability and scalability, it demonstrates clean 3-tier separation, containerization, and cloud deployment end to end.

AWSDockerPythonFlaskMySQLNginx

Technical Stack

Tools I use in production.

A practical stack built around cloud infrastructure, Kubernetes, automation, security, observability, and AI-assisted engineering.

Cloud & Infrastructure

AWSEKSECREC2ECSS3RDSLambdaVPCIAMCloudFrontRoute 53ACMCloudTrailLinuxNetworkingDNSLoad balancing

Kubernetes & Platform

KubernetesEKSHelmArgoCDFluxCDGitOpsAWS Load Balancer ControllerGateway APIExternalDNScert-managerKarpenterKEDAKyvernoVeleroVault

Infrastructure as Code & Delivery

TerraformCloudFormationGitHub ActionsGitLab CI/CDOIDC federationInfrastructure automation

Observability

PrometheusGrafanaAlertmanagerOpenTelemetryElasticsearch/KibanaEFKCloudWatchPagerDuty

Security & Access

IAMIRSAKubernetes RBACZero TrustSecrets managementAWS Secrets Manager

AI-Assisted Engineering

Claude CodeCLAUDE.mdCustom skillsMCP integrationsAWS BedrockContext engineeringAI-assisted code review

Programming

PythonBashSQL

I care less about collecting tools and more about understanding how they behave in production — how infrastructure is provisioned, secured, deployed, observed, and recovered.

Education

Academic Background

Bachelor's Degree in Management of Organizations

National Aviation University

Kyiv, Ukraine

Certifications

Professional Certifications

AWS Certified Solutions Architect – Associate

Certified Kubernetes Application Developer (CKAD)

HashiCorp Certified: Terraform Associate

Contact

Let's build something reliable.

I'm open to Platform Engineering, DevOps, Cloud Engineering, and other infrastructure-focused roles.

If you're working on Kubernetes platforms, delivery paths, infrastructure automation, or agentic tooling for engineering teams, I'd be happy to connect.