Brian Lasky Platform Engineer | AI Infrastructure & Kubernetes

Kubernetes Governance · Fiscal SecOps · Multi-Cloud Resilience

Available Immediately for Remote Roles (US)

I engineer fail-closed control planes and policy-driven infrastructure on Kubernetes. I specialize in building deterministic guardrails that protect enterprise budgets and secure autonomous AI workloads at production scale.

Infrastructure-as-Code: Managed via Terraform and governed through Kubernetes admission controls.

Bridging Operational Discipline with Kubernetes Governance

Kubernetes Governance

Deploying fail-closed control planes and OPA policy-as-code to enforce structural constraints directly at the API server.

Fiscal SecOps

Implementing real-time container-level telemetry and circuit breakers to permanently neutralize AI token runaway.

Multi-Cloud Resilience

Building zero-trust, keyless active-passive topologies across GCP and AWS with keyless OIDC federation.

My engineering approach is driven by a simple operational reality: I build for environments where networks partition, upstream APIs degrade, and autonomous loops happen. This mindset is rooted in 17+ years of physical production operations and over 125 regulatory-grade incident investigations, where system uptime and deterministic safety contracts were non-negotiable.

Today, I translate that exact same incident command discipline to cloud-native platforms. Instead of relying on passive, post-billing alerts or static documentation, I focus on moving infrastructure governance directly into the Kubernetes control plane through mathematical, automated enforcement.

Through my flagship work with the Serverless Agentic Governance Controller (SAGC), I've proven that isolating blast radiuses, securing cross-cloud workloads using ephemeral Workload Identity Federation, and enforcing strict resource budgets can be built seamlessly right into the delivery pipeline.

Engineering Capabilities

☁️ Cloud Infrastructure

  • GKE Autopilot & GKE 1.27+
  • AWS ECS Fargate & Lambda
  • Hybrid/Multi-Cloud Architectures
  • Next.js & Vercel Edge

🤖 Agentic AI Governance

  • OPA/Rego Policy-as-Code
  • Fiscal SecOps & Circuit Breakers
  • Real-time Token Budgeting
  • Autonomous Remediation

🛡️ Reliability & Security

  • Incident Investigation (RCA)
  • RTO/RPO Validation
  • Keyless WIF/OIDC Auth
  • Supply Chain Security (Trivy)

🏗️ IaC & Automation

  • Terraform 1.7 (Modular)
  • GitHub Actions (Event-Driven)
  • AsyncIO Python Development
  • GitOps Patterns

Flagship Engineering Projects

Agentic Governance Controller

Zero-Trust Fiscal SecOps for Autonomous AI

GCP WIFKubernetesTerraform

Challenge

Unconstrained AI agents expose enterprises to severe 'Denial of Wallet' risks, running up unbounded token costs while relying on vulnerable static credentials.

Solution

Architected an ambient identity control plane bridging GKE and IAM, eradicating static secrets.

Impact

Mathematically bounded compute footprint to $0.00 and secured $250k+ in runaway agent budget exposure.

NorthStar Multi-Cloud DR

Active-passive resilience across AWS & GCP

TerraformOIDCZero-Trust

Challenge

Mitigating the 'Disaster Recovery Gap' and manual secret rotation.

Solution

Declarative state management with keyless Workload Identity Federation.

Impact

Targeted 0s RTO and 1s RPO without exposing static credentials.

The Tombstone Protocol

Automated Crash Forensics & Telemetry

PrometheusOpenTelemetrySRE

Challenge

Pod termination during P0 events destroys critical root-cause data.

Solution

Sever network intent via policy while preserving local memory state.

Impact

Ensured regulatory-grade forensic audits for AI hallucinations.

Architecture

Serverless Agentic Governance Controller (SAGC)

Agentic AppAutonomous LoopLLM RequestAI GatewayLiteLLM RoutingToken CountingOPA GatekeeperAdmission ControlBudget Enforcement403 Forbidden(Budget Exceeded)AllowKeyless AuthGCP WIFEphemeral TokensLLM ProviderFrontier / OSS ModelsAPI ExecutionServerless Agentic Governance Controller (SAGC)Zero-Trust Fiscal SecOps Architecture

NorthStar Multi-Cloud DR

Active-Passive Topology across AWS & GCP

GitHub ActionsOIDC / WIFTerraform CI/CDGlobal LBRoute 53Failover RoutingPrimary (GCP)GKE AutopilotActive WorkloadsCloud SQLPassive (AWS)EKS FargatePilot Light (Scaled to 0)Amazon RDSAWS DMSAsync CDC SyncMulti-Cloud Resilience & Disaster Recovery15-Min RPO / 4-Hr RTO

Primary (GCP)

GKE Autopilot handling active production traffic. Infrastructure managed via Terraform with strict OPA Gatekeeper governance.

Pilot Light (AWS)

EKS Fargate passive environment scaled to zero. Aggressively optimized to consume <5% compute cost during standard operations.

Zero-Trust Auth & CDC

Keyless deployment via GitHub Actions WIF/OIDC. State synchronization handled asynchronously via AWS DMS (Change Data Capture).