Brian Lasky Platform Engineer | AI Infrastructure & Kubernetes
Kubernetes Governance · Fiscal SecOps · Multi-Cloud Resilience
Available Immediately for Remote Roles (US)
I engineer fail-closed control planes and policy-driven infrastructure on Kubernetes. I specialize in building deterministic guardrails that protect enterprise budgets and secure autonomous AI workloads at production scale.
Infrastructure-as-Code: Managed via Terraform and governed through Kubernetes admission controls.
Bridging Operational Discipline with Kubernetes Governance
Kubernetes Governance
Deploying fail-closed control planes and OPA policy-as-code to enforce structural constraints directly at the API server.
Fiscal SecOps
Implementing real-time container-level telemetry and circuit breakers to permanently neutralize AI token runaway.
Multi-Cloud Resilience
Building zero-trust, keyless active-passive topologies across GCP and AWS with keyless OIDC federation.
My engineering approach is driven by a simple operational reality: I build for environments where networks partition, upstream APIs degrade, and autonomous loops happen. This mindset is rooted in 17+ years of physical production operations and over 125 regulatory-grade incident investigations, where system uptime and deterministic safety contracts were non-negotiable.
Today, I translate that exact same incident command discipline to cloud-native platforms. Instead of relying on passive, post-billing alerts or static documentation, I focus on moving infrastructure governance directly into the Kubernetes control plane through mathematical, automated enforcement.
Through my flagship work with the Serverless Agentic Governance Controller (SAGC), I've proven that isolating blast radiuses, securing cross-cloud workloads using ephemeral Workload Identity Federation, and enforcing strict resource budgets can be built seamlessly right into the delivery pipeline.
Engineering Capabilities
☁️ Cloud Infrastructure
- ✓GKE Autopilot & GKE 1.27+
- ✓AWS ECS Fargate & Lambda
- ✓Hybrid/Multi-Cloud Architectures
- ✓Next.js & Vercel Edge
🤖 Agentic AI Governance
- ✓OPA/Rego Policy-as-Code
- ✓Fiscal SecOps & Circuit Breakers
- ✓Real-time Token Budgeting
- ✓Autonomous Remediation
🛡️ Reliability & Security
- ✓Incident Investigation (RCA)
- ✓RTO/RPO Validation
- ✓Keyless WIF/OIDC Auth
- ✓Supply Chain Security (Trivy)
🏗️ IaC & Automation
- ✓Terraform 1.7 (Modular)
- ✓GitHub Actions (Event-Driven)
- ✓AsyncIO Python Development
- ✓GitOps Patterns
Flagship Engineering Projects
Agentic Governance Controller
Zero-Trust Fiscal SecOps for Autonomous AI
Challenge
Unconstrained AI agents expose enterprises to severe 'Denial of Wallet' risks, running up unbounded token costs while relying on vulnerable static credentials.
Solution
Architected an ambient identity control plane bridging GKE and IAM, eradicating static secrets.
Impact
Mathematically bounded compute footprint to $0.00 and secured $250k+ in runaway agent budget exposure.
NorthStar Multi-Cloud DR
Active-passive resilience across AWS & GCP
Challenge
Mitigating the 'Disaster Recovery Gap' and manual secret rotation.
Solution
Declarative state management with keyless Workload Identity Federation.
Impact
Targeted 0s RTO and 1s RPO without exposing static credentials.
The Tombstone Protocol
Automated Crash Forensics & Telemetry
Challenge
Pod termination during P0 events destroys critical root-cause data.
Solution
Sever network intent via policy while preserving local memory state.
Impact
Ensured regulatory-grade forensic audits for AI hallucinations.
Architecture
Serverless Agentic Governance Controller (SAGC)
NorthStar Multi-Cloud DR
Active-Passive Topology across AWS & GCP
Primary (GCP)
GKE Autopilot handling active production traffic. Infrastructure managed via Terraform with strict OPA Gatekeeper governance.
Pilot Light (AWS)
EKS Fargate passive environment scaled to zero. Aggressively optimized to consume <5% compute cost during standard operations.
Zero-Trust Auth & CDC
Keyless deployment via GitHub Actions WIF/OIDC. State synchronization handled asynchronously via AWS DMS (Change Data Capture).