GKE Platform Architect — USA
I’m Amit Malhotra, a Principal GKE Platform Architect working with mid-market and enterprise engineering teams across the United States.
If your team is building or scaling production workloads on Google Kubernetes Engine, I provide the platform architecture expertise to do it right — secure, observable, Terraform-managed, and built to survive enterprise security reviews.
What I Do as a GKE Platform Architect
Production GKE requires deliberate architectural decisions across cluster design, security, networking, autoscaling, and observability. Teams that treat GKE as a black box accumulate platform debt that surfaces at the worst possible moment — a security review, a scaling incident, or an audit.
I work with US engineering teams on:
Cluster architecture and design. Regional cluster topology, node pool design by workload profile, private cluster configuration, VPC-native networking, and Network Policy enforcement from day one.
GKE security hardening. Workload Identity Federation, Binary Authorization, OPA/Gatekeeper policy enforcement, distroless containers, and Secret Manager CSI Driver for secrets injection. The full defense-in-depth stack, implemented as code.
Platform engineering. Standardised GKE deployment templates, self-hosted GitHub Actions runners via ARC, Terraform module structure, and an internal developer platform layer that abstracts GKE complexity from application teams.
Autoscaling and reliability. HPA, VPA, cluster autoscaler, PodDisruptionBudgets, multi-zone failover, and health probe design — the reliability architecture that keeps clusters operational under real production load.
Observability. Datadog or Google Cloud Operations, GKE-specific alerting, custom SLOs, and log aggregation that gives your on-call team clear, actionable signals.
My approach follows the SCALE Framework — Security by Design, Cloud-Native, Automation/IaC, Lifecycle Ops, and Elastic Scalability. Every GKE platform I design is evaluated against all five dimensions, not just the immediate workload brief.
Fractional or Full Engagement — Your Choice
Fractional GKE Architect. Part-time embedded architectural oversight — I own the GKE platform roadmap, review decisions, and unblock engineers without the cost or lead time of a full-time senior hire. Typically 2–3 days per week.
Project engagement. Scoped deliverable — a new GKE platform build, security hardening, migration, or platform engineering programme. Fixed scope, defined outcome, direct Principal Architect involvement throughout.
No sales layer, no junior engineers, no handoffs.
Why USA Teams Work With Me
I work exclusively with North American clients and understand the compliance and security requirements that US enterprise and mid-market companies face — SOC 2, HIPAA, PCI, and enterprise security review processes that GKE platforms need to pass.
Named clients include Tangerine Bank, Telus Health, Loblaws, RBC, and Ford.
Book a Free GCP Architecture Review Explore Platform Engineering Services