
SSK
Infrastructure Automation Expert
Building fault-tolerant systems at scale with Temporal & PostgreSQL. DevOps & Infrastructure Engineer passionate about workflow automation, PostgreSQL HA, and intelligent systems.
Technical Arsenal
The tools, languages, and frameworks I use to bring ideas to life.
Work Experience
DevOps Engineer • Feb 2026 - Present
- ▹Built and operate a production PostgreSQL 17 primary-replica HA cluster with async WAL streaming replication across three machines, automated failover runbooks, zero-data-loss backup/restore, and fleet-wide multi-tenant data retention via dblink and pg_cron.
- ▹Built an Ansible automation platform running in containerized Execution Environments (ansible-builder/ansible-navigator) with a custom-built AWX deployment, Vault-encrypted secrets, and playbooks for server bootstrap, GitHub provisioning, Elastic Agent rollout, and patch governance.
- ▹Deployed and maintain a custom Dockerized Apache Superset analytics platform with Hive Metastore/Trino integration, Celery background workers, and an MCP server enabling AI assistant access to dashboards.
DevOps Intern • Jun 2025 - Jan 2026
- ▹Built "run", a schema-driven CLI (Ink/Pastel/TypeScript) for provisioning and maintaining Ubuntu dev servers with dependency-aware package installs, dry-run planning, and self-update, adopted fleet-wide via Ansible.
- ▹Built the monitoring stack for a Temporal + PostgreSQL deployment: Prometheus scraping PostgreSQL exporter metrics remotely from a separate replica host, visualized in Grafana with alerting.
GitHub Overview
Featured Projects
Most Recent Posts
Running AWX on Docker Compose: A Stand-Alone Alternative to Kubernetes
AWX's official deployment assumes Kubernetes — but what if your org isn't ready for K8s? This guide walks through building a custom AWX Docker image, crafting the Docker Compose configuration, and running 14 job templates with 7 schedules on a single host, complete with ansible-vault credential injection and the AWX-as-code approach.
Controlled Linux Patch Management: From Supply Chain Risk to Fleet-Isolated Package Delivery
Every server downloading directly from public repos is a supply chain risk — amplified by AI-powered malware targeting Linux infrastructure. After unattended-upgrades auto-rebooted a prod server multiple times, I created a controlled patch management system: fleet-isolated Aptly mirror, immutable snapshots, SQL-gated dev→staging→prod promotion, and a PostgreSQL governance database with Grafana dashboards for fleet-wide CVE visibility.
Systemd in Production: Service Management Beyond the Basics
How I use systemd for production services — writing good unit files, managing services day-to-day, logging with journald, and hardening for security. Practical patterns from real deployments.
Get in Touch
If you have any inquiries, please feel free to reach out. You can contact me via email at
sauravchp2@gmail.com