S Dishan Samuel
Systems, DevOps and Data Engineer
Hands-on experience in Linux infrastructure, cloud-native architecture, and low-level tooling.
Skills
Orchestration & Cloud
- › Kubernetes (K3s)
- › Docker
- › Podman
- › AWS
- › Cloudflare Zero Trust
Infrastructure & Automation
- › Terraform
- › Ansible
- › Prometheus
- › Grafana
- › CI/CD Pipelines
- › Git
Systems & Networking
- › Linux (Fedora & RHEL)
- › BASH
- › systemd
- › tmux
- › WireGuard
- › TCP/IP
- › SSH
Programming & Backend
- › Go (Golang)
- › Python
- › JavaScript
- › Next.js
- › REST APIs
- › PostgreSQL
- › MySQL
Experience
Software Engineering Intern
experience letter- Developed core Go microservices for a peer-to-peer platform prototype, implementing concurrent data processing using goroutines and channels.
- Managed secure containerized deployment contexts, optimizing resource allocation for distributed backend services.
Projects
-
01
KubeMCP — In-Cluster Kubernetes Incident Diagnostics via MCPKubernetes · Go · PythonAutonomous in-cluster Kubernetes diagnostic system resolving production incidents without ingress exposure or broad developer RBAC. Deploys as an isolated Pod running Anthropic Claude via the Model Context Protocol (MCP) over an outbound Slack WebSocket to inspect client-go telemetry and Prometheus metrics.
system architecture & pipeline- Zero-Ingress Network Model: Slack integration operates entirely on Socket Mode over an outbound WebSocket (wss://), exposing zero public endpoints, ingress controllers, or listening webhooks
- Process-Level IPC over stdio: Python runner (Slack Bolt + Anthropic Claude) spawns compiled Go MCP binary as child process communicating via JSON-RPC over stdin/stdout with no listening ports (SSRF-immune)
- Direct Telemetry Ingestion: Go binary queries K8s control plane via client-go (deployments, pods, logs, events) and internal Prometheus via safe, parameterized PromQL templates
- Cluster Hardening: Constrained by egress-only NetworkPolicy (CoreDNS:53, K8s API:443, Prometheus:9090) with multi-stage scratch builds via initContainer mounts to eliminate build toolchains from runtime
env_stack: -
02
zombie-cli — Cross-Plane Cloud Waste Remediation EngineAWS · Go · GitHub APITackles cloud waste and FinOps alert fatigue by correlating AWS compute utilization with GitHub branch and PR lifecycles. Identifies abandoned GPU instances and SageMaker endpoints with verified cross-plane evidence and executes a 5-stage graduated safety protocol.
system architecture & pipeline- Audit (Dry-Run): Read-only cross-plane evaluation correlating low AWS compute utilization with merged PRs and deleted Git branches
- Attribution & Alert: Attributes abandoned resources to real creators via CloudTrail event logs and dispatches Slack notifications
- Grace Window: Resource owners can request an operational freeze, approve teardown, or whitelist the asset via Slack
- Reversible Stop: Stops compute instances first to halt billing immediately while preserving disk state and model artifacts intact
- Snapshot & Purge: Takes automated point-in-time EBS and SageMaker model snapshots prior to final resource termination
env_stack: -
03
High-Availability Bare-Metal Server & Custom CI/CD PipelinePodman · Nginx · systemdEngineered a lightweight CI/CD pipeline using custom webhooks and native Podman containers to build and serve a React SPA. Deployed an observability stack (Prometheus, Grafana) and a self-hosted ntfy instance for push telemetry.
system architecture & pipeline- Git push → custom webhook → deploy script pulls main over a scoped deploy key
- Multi-stage container build (Node builder → Nginx runtime) via native Podman
- Rootless container lifecycle managed by a systemd --user unit
- Prometheus scrapes host & service metrics; Grafana dashboards for visibility
- Self-hosted ntfy pushes start / success / failure telemetry with log tails
env_stack: -
04
System-Event Gateway & Observability PipelineGo · LinuxDeveloped a high-throughput observability gateway in Go to parse system logs at 2,000+ lines per second.
system architecture & pipeline- Ingests raw system log streams from the Linux host
- Concurrent Go parsing pipeline normalises events into structured records
- Forwards parsed events downstream for observability and alerting
env_stack: -
05
ManSycGo · Bash · systemdEngineered a lightweight Linux process management utility, reducing manual intervention time by 60%.
system architecture & pipeline- Go core for process supervision and state inspection
- Bash glue for host-level automation tasks
- Native integration with systemd units for lifecycle control
env_stack: -
06
Shadow BrowseGo · DockerBuilt a sandboxed virtual execution environment utilizing isolated Docker containers.
system architecture & pipeline- Go control plane provisions an ephemeral container per session
- Isolated Docker runtime separates untrusted execution from the host
- Containers are torn down after use to leave no residual state
env_stack: -
07
Agri VoiceJavaScript · Twilio · AssemblyAIEngineered an offline, call-based AI voice assistant utilizing edge-processing.
system architecture & pipeline- Inbound voice calls handled through Twilio — no smartphone or data plan required
- Speech transcribed with AssemblyAI and routed to the assistant logic
- Edge-processing keeps the interaction loop usable over plain phone lines
env_stack:
Credentials
Certifications
- Introduction to Linux (LFS101) Linux Foundationview credential image
Achievements
- Published Research IEEE ICAECT2026
- 2nd Place XENITH 2025 TerminalX Hackathon2025
- 1st & 2nd Place Techfusion2025
Education
Dayananda Sagar Academy of Technology and Management
Bachelor of Technology: Computer Science