Rishang Bhavsar

I'm a DevOps engineer at SmartSense, building secure, self-service AWS and Azure platforms with Terraform and ArgoCD. Before that, I automated the cloud labs at KodeKloud.

My open-source infra tools have been downloaded more than 300,000 times.

rishang.yamlkubectl get engineer rishang
apiVersion: people.dev/v1
kind: PlatformEngineer
metadata:
  name: rishang-bhavsar
  labels:
    location: ahmedabad-in
    experience: 5+y
spec:
  clouds: [aws, azure]
  iac: terraform
  delivery: argocd   # gitops all the way
  certs: [cka, kcsa, terraform-003, rhce]
status:
  phase: Ready
  conditions:
  - type: InfraAsCode     status: "True"
  - type: GitOpsSynced    status: "True"
  - type: CostOptimized   status: "True"
  - type: OpenToWork      status: "True"

Experience

5+ years of DevOps, from IoT pipelines to compliance-grade AWS.

  1. DevOps Engineer

    SmartSense, GIFT City, Gandhinagar

    AWS and Azure infrastructure for clients with strict compliance needs.

    • Cut AWS cost by more than 50% by migrating from multi-tenancy to a secure single-tenant architecture aligned with SOC 2, HIPAA and ISO.
    • Put every Kubernetes resource under GitOps with ArgoCD, so every environment deploys from version control.
    • Made troubleshooting faster for developers and DevOps by connecting Claude Code to Grafana and Kubernetes through AgentGateway and MCP servers.
    • Brought hand-made AWS resources under Terraform with a scanner that generates config from live stacks.
    • Kept test accounts clean with AWS Autotagger (open source). It tags each resource with its owner and creation date, then reminds owners on Slack to delete stale PoCs.
  2. Lab DevOps Engineer

    KodeKloud, remote

    The hands-on cloud labs behind KodeKloud's DevOps courses.

    • Cut lab validation from weeks to a few hours with an automated testing framework, and used AI to generate, fix and manage lab content.
    • Gave learners real AWS accounts safely, with fine-grained role-based access per lab and an in-house cloud-nuke framework that cleans up each session.
    • Built LabUtils, so the team could see lab details and Docker image deprecation alerts in one place instead of digging through files, repos and links.
    • Built and maintained labs for AWS, Kubernetes, Terraform, GitLab, GitHub, Azure, OpenAI and Taskfile.
  3. DevOps Engineer

    TechHolding, Ahmedabad

    • Delivered client infrastructure entirely as code, with Terraform and GitOps.
    • Hardened infrastructure against penetration attacks.
  4. DevOps Engineer

    OpenXcell, Ahmedabad

    Infrastructure for fintech, crypto and banking projects.

    • Cut internal development infrastructure cost by 70%, and made it faster, on my own initiative.
    • Moved AWS authentication to OIDC federation with Keycloak and GitLab/GitHub CI/CD, and built custom AWS OIDC brokers in Python.
    • Automated the internal Kubernetes stack and client EKS clusters with Terraform.
    • Named Employee of the Month.
  5. DevOps Engineer

    ElectroMech Corporation, Ahmedabad

    • Built aws-autoscale-warmup (open source) for scheduled autoscaling.
    • Automated multi-account AWS tenant stacks with Terraform.
    • Streamed IoT device logs through Lambda into Timestream, with QuickSight dashboards, keeping cost and performance in check.

Stack and tooling

What I reach for, and what I've actually done with it.

Cloud
  • AWS
  • Azure

Compliance-grade single-tenant AWS (SOC 2, HIPAA, ISO), multi-account tenant stacks, and cost work that took bills down 50% and 70%.

Infrastructure as code
  • Terraform
  • Ansible
  • Helm

Everything starts in Terraform. I publish reusable modules and charts, and I wrote a scanner that turns click-ops AWS resources back into Terraform.

Kubernetes and GitOps
  • Kubernetes
  • EKS
  • ArgoCD
  • Docker
  • Cilium / eBPF

Every Kubernetes resource goes through ArgoCD, across every environment. I'm CKA and KCSA certified, and I've given a talk on Cilium and eBPF.

Observability
  • Grafana
  • Prometheus
  • Loki
  • Alloy
  • Datadog
  • New Relic
  • Langfuse
  • LangSmith

I maintain loki-stack, a one-install observability chart, and I've spoken twice on observability for AI and LLM apps.

Identity and security
  • OIDC
  • Keycloak
  • IAM
  • Zero trust

I moved AWS access to OIDC federation with Keycloak, and built aws-oidc-broker to do it without AWS SSO. Background in penetration testing.

AI for operations
  • Claude Code
  • MCP
  • AgentGateway
  • Agno
  • OpenAI
  • Langfuse
  • LanceDB

Claude Code connected to Grafana and Kubernetes through MCP servers, so developers and DevOps can troubleshoot by asking questions instead of digging. I also built agno-spec-builder, which turns YAML specs into Agno agents and workflows.

Code and data
  • Python
  • Bash
  • Go
  • Rust
  • FastAPI
  • Django
  • Node.js (basics)
  • PostgreSQL
  • Redis
  • MongoDB

Python is my default for tooling. Go when a CLI should ship as one static binary, like cu, and Rust for hterm. Bash for glue. CI/CD runs on GitHub Actions or GitLab CI.

Projects

Infrastructure and AI tools I maintain in the open. Counts update live from each registry.

230k

downloads on the Terraform Registry

terraform-aws-fargate

One module for an ECS Fargate service: the service itself, load balancer target groups and listener rules, service discovery, plus policy and scheduled autoscaling. You get it without hand-rolling the same HCL for every app.

# main.tf
module "app" {
  source  = "Rishang/fargate/aws"
  version = "1.4.3"
}

75k

PyPI downloads, 159 GitHub stars

install-release

A package manager for the tools that don't have one. Point it at a GitHub, GitLab or Codeberg repo, and it grabs the right binary for your OS, then keeps it updated. Works on Linux, macOS and WSL.

pip install -U install-release
ir get https://github.com/denoland/deno
ir upgrade

2 charts

published on Artifact Hub

helm-charts

loki-stack is a full observability stack in one install: Loki for logs, Prometheus and Alertmanager for metrics, Grafana for dashboards, and Grafana Alloy for log collection (Promtail is deprecated).

component-chart deploys any app component, from API servers to databases, from a single values.yaml. Deployments, services, ingress, autoscaling and cron jobs, without writing a chart per app.

helm repo add common-charts https://rishang.github.io/helm-charts/charts
helm install loki-stack common-charts/loki-stack -n monitoring --create-namespace
helm install api common-charts/component-chart -f values.yaml

Results

What changed, by how much, and how I did it.

Cut AWS spend by more than half at SmartSense

I moved the platform from shared multi-tenancy to a single-tenant architecture designed for SOC 2, HIPAA and ISO, with every resource defined in Terraform. Each client got isolation, and the bill still went down.

-tenancy: shared aws_cost: 100%
+tenancy: per-client aws_cost: under 50%

Took lab validation from weeks to hours at KodeKloud

Validating course labs was manual work that took weeks. I built a framework that tests and validates them automatically, then added AI to generate and fix lab content.

-lab validation: weeks, manual
+lab validation: a few hours, automated

Cut internal dev infrastructure cost 70% at OpenXcell

I took this on myself. I reworked the internal development stack so it cost far less to run, and it got faster too.

-dev_infra_cost: 100%
+dev_infra_cost: 30%, faster

Talks

Meetups and conferences around Ahmedabad and Gandhinagar.

  1. Observability for AI applications

    Cloud Native Day, IAR Gandhinagar

  2. Observability for LLMs and AI applications

    GDG Cloud Gandhinagar, Observability Meetup GIFT City

  3. Introduction to Cilium and eBPF for Kubernetes

    Cloud Native Ahmedabad x Grafana Ahmedabad

  4. Open Source Weekend

    Community speaker, Ahmedabad

Certifications

B.E. in Information Technology, Aditya Silver Oak, 2021. A few older posts on Medium.

Off the clock: photography and guitar.

Hiring for platform or DevOps?

I'm open to platform and DevOps roles, remote or with relocation. Email is the fastest way to reach me.