GKE Platform Architect — Canada
I’m Amit Malhotra, a Principal GKE Platform Architect based in Toronto, working with mid-market and enterprise teams across Canada.
If your engineering team is running — or planning to run — production workloads on Google Kubernetes Engine, I design, build, and harden the platform layer that makes GKE reliable, secure, and operable at scale.
What I Do as a GKE Platform Architect
GKE is not a managed service you turn on and forget. The cluster configuration, node pool design, network topology, security controls, autoscaling model, and observability stack all require deliberate architectural decisions. Getting them wrong early creates platform debt that compounds fast.
I work with Canadian engineering teams on:
Cluster architecture and design. Multi-zone and regional cluster topology, node pool segmentation by workload type, private cluster configuration, and network design — Hub-and-Spoke VPC, VPC-native networking, and Network Policy enforcement.
GKE security hardening. Workload Identity Federation to eliminate static service account keys, Binary Authorization to enforce signed image policies, OPA/Gatekeeper for policy-as-code, distroless base images, and secrets injection via the Secret Manager CSI Driver. I’ve hardened GKE clusters for regulated clients including Tangerine Bank and Telus Health.
Platform engineering and IDP. Standardised app templates, self-hosted GitHub Actions runners on GKE via ARC, Terraform module structure, and the internal developer platform layer that lets your engineering team deploy to GKE without becoming GKE experts themselves.
Autoscaling and reliability. Horizontal Pod Autoscaler, Vertical Pod Autoscaler, cluster autoscaler configuration, PodDisruptionBudgets, health probe design, and multi-zone failover — the reliability layer that keeps GKE operational under real production load.
Observability. Datadog or Google Cloud Operations integration, custom SLIs and SLOs, GKE-specific alerting, and log aggregation that gives your SRE or on-call team actionable signals.
My approach follows the SCALE Framework — Security by Design, Cloud-Native, Automation/IaC, Lifecycle Ops, and Elastic Scalability. Every GKE platform I design is evaluated against all five dimensions, not just the workload requirements in front of us today.
Fractional or Full Engagement — Your Choice
I work with mid-market and enterprise teams in two models:
Fractional GKE Architect. Ongoing architectural oversight without a full-time hire. I embed into your team on a part-time basis — reviewing platform decisions, unblocking engineers, and owning the GKE architecture roadmap. Typically 2–3 days per week.
Project engagement. Scoped work with a defined deliverable — a hardened GKE platform, a migration to GKE, a security remediation, or a full platform engineering buildout. Fixed scope, clear outcome.
Both models give you direct access to a Principal Architect. No account managers, no junior engineers, no handoffs.
Why Canadian Teams Work With Me
I’m based in Toronto and work exclusively with North American clients. I understand Canadian data residency requirements (PIPEDA, provincial health privacy legislation), the compliance landscape for regulated industries, and the practical reality of building GCP platforms for Canadian enterprise and mid-market companies.
Named clients include Tangerine Bank, Telus Health, Loblaws, and RBC. More about my background and approach →
Book a Free GCP Architecture Review Explore Platform Engineering Services