I build tools that help engineering teams see what's changing in their infrastructure β before drift, misconfigurations, or silent regressions reach production.
My work sits at the intersection of Kubernetes, cloud security, and developer experience. I turn invisible infrastructure problems into things you can inspect, reason about, and fix with confidence.
I write about these topics on my blog β covering platform engineering, Helm workflows, cloud security, and the tools I build. You can subscribe via RSS.
|
Go Β· Next.js Β· Helm SDK Β· β 4 Understand potentially disruptive Helm chart changes before deployment. Surfaces availability, rollout risk, and security changes in Helm chart upgrades with a risk assessment engine.
|
React Β· Monaco Β· Dagre Β· β 3 Interactive editor and visualizer for GitHub Actions workflows. Write, validate, and visualize CI/CD workflows with a real-time graph of job dependencies.
|
|
TypeScript Β· Stream Deck SDK See your unread GitHub notification count on a physical button.
|
Shell Β· macOS Keychain Β· β 1 Generate MFA codes from the terminal while keeping seeds in macOS Keychain.
|
|
Go Scan directories recursively to audit Terraform versions across a multi-project codebase. |
PHP Β· Laravel Β· β 1 Drop-in Laravel database driver that fetches credentials from AWS Secrets Manager at runtime with built-in caching. |
I write about platform engineering, Kubernetes tooling, and cloud security at dcotelo.dev. Topics include Helm workflows, infrastructure risk, CI/CD patterns, and the thinking behind the tools I build.
Expand full stack details
| Area | Technologies |
|---|---|
| Languages | Go, TypeScript, Python, Bash, PHP |
| Cloud | AWS (EKS, IAM, VPC, DynamoDB, ALB/NLB, Route53, KMS, S3, CDK, Secrets Manager) |
| Kubernetes | EKS, EKS Auto Mode, Karpenter, Helm, Kustomize |
| GitOps / CI | ArgoCD, GitHub Actions, OIDC-based auth |
| IaC | Terraform, Terraform Cloud, AWS CDK |
| Frontend | Next.js, React, Monaco Editor |
| Observability | Datadog, Grafana, SLOs |
| Containers | Docker, Docker Compose |
| Storage | PostgreSQL, DynamoDB, S3 |
| Security | IAM least privilege, CodeQL, OpenSSF Scorecard, OIDC |
|
|
Security is an architecture problem, not a checklist.
The best platforms fade into the background. If your platform requires a tutorial every sprint, it's not a platform β it's a tax.
Clear ownership beats perfect tooling. When something breaks at 3 a.m., the answer to "who owns this?" should be obvious.
Decision support, not enforcement. Surface what's changing and why it matters. Enable informed team decisions β don't impose judgment.




