Skip to content

Currently DevOps Engineer @ Emumba

Annas Ali

Senior DevOps Engineer

AWS Certified DevOps Professional

I build GitOps platforms, infrastructure as code and delivery pipelines that let product teams ship safely at scale.

Lahore, Pakistan

Résumé (PDF)

About

I build the platforms other engineers ship on. Right now that means running GitOps delivery for a 35+ microservice AI system across 50+ Amazon EKS clusters: ArgoCD ApplicationSets, Helm golden paths, Vault-backed secrets and pre-merge quality gates.

Before that I spent four years on AWS delivery at TCP Software and TkXel, working on blue/green releases, ECS and EKS, Jenkins at scale and multi-region Terraform. Outside work I run a hybrid on-prem lab (Proxmox, Active Directory, WatchGuard, IPsec DR tunnels and Cloudflare Zero Trust) to keep my networking and identity skills sharp.

EKS clusters under GitOps
50+
microservices delivered
35+
years in DevOps
5+
faster CI/CD at TCP
40%

Experience

  1. Dec 2025 – Present

    DevOps Engineer · Emumba

    Remote

    • Own the delivery platform for a 35+ microservice enterprise AI system, governing application lifecycle across 50+ AWS EKS clusters through an ArgoCD ApplicationSet GitOps control plane with per-cluster configuration isolation and controlled override patterns for incident response.
    • Drove shift-left practices by authoring Helm chart templates as a golden path for service teams, with a per-environment override model via GitOps config repositories.
    • Established GitHub Actions pre-merge quality gates, surfacing integration failures before they reach cluster environments.
    + 3 more
    • Architected a dual-region (GDC/RDC) deployment topology with regional ApplicationSets, authenticated gRPC ingress for cross-cluster traffic and network-level egress controls.
    • Codified Jenkins delivery pipelines (deploy/upgrade/destroy) with regional parameterization, replacing ad-hoc runbooks with version-controlled pipeline code.
    • Designed centralized secret management using HashiCorp Vault with ArgoCD Vault Plugin, enforcing per-cluster secret isolation with zero credentials in source control.
    • EKS
    • ArgoCD
    • ApplicationSets
    • Helm
    • HashiCorp Vault
    • GitHub Actions
    • Jenkins
    • gRPC
  2. Sep 2023 – Dec 2025

    Senior DevOps Engineer · TCP Software

    Lahore

    • Automated infrastructure and application delivery using Terraform, Jenkins, and AWS CodeBuild.
    • Implemented Blue/Green deployment strategies on AWS for risk-free application updates.
    • Streamlined containerized deployments on Amazon ECS to improve scalability and management.
    + 3 more
    • Optimized CI/CD performance by 40% through a Jenkins controller/agent architecture on EC2 and Fargate.
    • Monitored application and infrastructure performance with New Relic to resolve critical issues.
    • Optimized MSSQL (RDS/EC2) health through automated backups, indexing strategies, and partitioning.
    • Terraform
    • Jenkins
    • CodeBuild
    • ECS
    • Fargate
    • New Relic
    • MSSQL
  3. Jul 2021 – Aug 2023

    DevOps Engineer · TkXel

    Lahore

    • Managed AWS services (EC2, S3, RDS, DynamoDB, Lambda) and containerized Node, Next.js, Angular, Flask, PHP and Laravel applications with Docker.
    • Implemented Terraform IaC for multi-region deployments and environment migrations.
    • Designed CI/CD pipelines using Jenkins, GitHub Actions, GitLab CI/CD, and AWS CodePipeline.
    + 3 more
    • Managed Kubernetes clusters and standardized add-ons (Datadog, ALB Controller, Autoscaler) with Helm; implemented GitOps with ArgoCD and Terraform Cloud.
    • Managed MySQL, PostgreSQL and DynamoDB databases, including user management, migrations and multi-region replicas.
    • Configured monitoring and alerting with CloudWatch, Datadog, New Relic and Opsgenie.
    • AWS
    • Docker
    • Kubernetes
    • Terraform
    • ArgoCD
    • GitLab CI
    • Datadog
View full résumé

Projects

  • Emumba · Dec 2025 – present

    Multi-cluster GitOps delivery platform

    One ArgoCD ApplicationSet control plane shipping a 35+ microservice AI system to 50+ EKS clusters across two regions, with zero credentials in Git.

    • EKS
    • Argo CD
    • ApplicationSets
    • Helm
    • Vault
    • GitHub Actions
    • Jenkins

    Read case study

  • Personal lab

    Hybrid on-prem infrastructure & secure remote access lab

    Proxmox cluster, Active Directory and a WatchGuard perimeter, linked to AWS over IPsec with automatic DR failover. Legacy client VPN replaced by Cloudflare Zero Trust.

    • Proxmox
    • Active Directory
    • WatchGuard
    • IPsec VPN
    • Cloudflare Zero Trust
    • Terraform
    • Ansible

    Read case study

  • CI/CD platform

    Serverless Jenkins on AWS Fargate

    A Jenkins controller and on-demand Docker build agents on ECS Fargate, built with Terraform, with no build servers to patch.

    • Jenkins
    • ECS Fargate
    • Terraform
    • EFS
    • CloudWatch
    • AWS Backup

    Read case study

  • Access management

    Temporary Elevated Access Management (AWS TEAM)

    Just-in-time, time-bound admin access across AWS accounts, with Okta identity, approval workflows, MFA and full session auditing.

    • AWS TEAM
    • IAM Identity Center
    • Okta
    • CloudTrail
    • CloudWatch

    Read case study

More projects

  • Kubernetes infrastructure deployment standardization

    • Provisioned Amazon EKS clusters with Terraform and standardized application delivery with Helm and Argo CD.
    • Integrated Pod/Node autoscalers and Istio service mesh for scaling, security policy and observability.
    • Integrated Datadog, ELK Stack and StackRox for logging, monitoring and security.
    • EKS
    • Terraform
    • Helm
    • Argo CD
    • Istio
    • Datadog
    • StackRox
  • Cross-account AWS Glue data pipeline

    • Deployed a secure cross-account data pipeline with Terraform, using S3 (Parquet), Glue Crawlers and Glue ETL jobs.
    • Enforced least-privilege cross-account IAM policies for access control and compliance.
    • Terraform
    • S3
    • AWS Glue
    • IAM

Skills

Cloud (AWS)
EC2 · S3 · RDS · DynamoDB · Lambda · API Gateway · SNS · SQS · Glue · EKS · ECS
Containers & GitOps
Docker · Kubernetes · Helm · Argo CD · ApplicationSets
IaC & Scripting
Terraform · Terraform Cloud · CloudFormation · Ansible · Python · Bash · PowerShell
CI/CD
Jenkins · GitHub Actions · GitLab CI/CD · AWS CodePipeline · Bitbucket Pipelines
Security & Secrets
HashiCorp Vault · AWS WAF · IAM · GuardDuty · KMS · Secrets Manager · Orca
Monitoring
Datadog · New Relic · CloudWatch · ELK · Opsgenie · Splunk On-Call
Networking & VPN
DNS · VLANs · AWS VPC · Load Balancers · Transit Gateway · VPC Peering · IPsec Site-to-Site & DR VPN
Firewall & Zero Trust
WatchGuard Firebox (BOVPN, Mobile VPN) · Cloudflare Zero Trust (WARP, Tunnel, Access, Gateway)
On-Prem & Virtualization
Proxmox VE · Proxmox Backup Server · ZFS · Windows Server · Linux
Identity & Access
Active Directory (AD DS, DNS, GPO) · RADIUS/NPS · IAM Identity Center · Okta
Databases & Web
MSSQL · MySQL · PostgreSQL · DynamoDB · Redshift · Nginx · Apache · IIS
DNS Hosting
Route 53 · Cloudflare · GoDaddy

Certifications

Education

B.Sc. in Computer Engineering

Ghulam Ishaq Khan Institute (GIKI)

Sep 2017 – May 2021

Languages

  • English: Professional
  • Urdu: Native