Skip to content
View mathewusher's full-sized avatar
  • United States

Block or report mathewusher

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mathewusher/README.md

Matthew Usher | Principal DevOps / SRE / Platform Engineer

Principal-level Linux, DevOps, SRE, and Platform Engineer with 15+ years of experience building, migrating, securing, and operating infrastructure for high-scale gaming, healthcare, telecom, and enterprise platforms.

I specialize in Hybrid and Multi-Cloud Infrastructure, Kubernetes Platforms, Infrastructure Automation, CI/CD, Observability, Zero-Trust Security, Linux Systems Engineering, and Production Operations for mission-critical systems.


Core Focus Areas

  • Platform Engineering & SRE

    • Kubernetes Platform Engineering
    • Production Reliability Engineering
    • Incident Response and On-Call Operations
    • Developer Platform Enablement
    • Infrastructure Lifecycle Management
    • Observability and Telemetry Platforms
  • Hybrid & Multi-Cloud Infrastructure

    • Physical Data Center to VMware Migration
    • VMware to AWS Migration
    • AWS to Azure Migration
    • Azure, AWS, GCP, OpenStack, vSphere, KVM/libvirt
    • Multi-Region and Geo-Redundant Infrastructure
  • Infrastructure as Code & Automation

    • Terraform, Terragrunt, Ansible, Puppet, CFEngine
    • Packer, Vagrant, Kickstart, PXE Boot, Matchbox
    • AWX / Ansible Tower, Foreman
    • GitOps and Policy-Driven Infrastructure Workflows
  • Security & Compliance

    • Zero-Trust Infrastructure Design
    • SELinux Hardening
    • IAM, RBAC, MFA, SSO, SAML, OAuth/OIDC
    • PCI and HIPAA-Aligned Infrastructure Controls
    • Audit-Ready Automation and Access Governance
  • Linux Systems Engineering

    • Deep Linux Troubleshooting
    • Kernel, Boot, Storage, Networking, and Process Diagnostics
    • Bare-Metal Provisioning
    • Filesystem, Volume, and Distributed Storage Operations

Selected Engineering Impact

  • Built and supported Kubernetes-backed infrastructure for multiple production game titles.
  • Designed and operated infrastructure supporting AAA gaming workloads and live-service platforms.
  • Led cloud migration work across physical infrastructure, VMware, AWS, and Azure.
  • Built Puppet-based infrastructure automation for hundreds of Linux servers.
  • Migrated large-scale logging workloads to Splunk Cloud while reducing legacy log server footprint.
  • Implemented security controls across code, cloud, RBAC, patching, and Linux systems with audit-focused automation.
  • Supported high-concurrency online gaming environments with strict uptime and operational requirements.
  • Developed CI/CD workflows using Jenkins, Buildkite, Bitbucket, GitHub Actions, GitLab Runners, CircleCI, Azure DevOps, Argo CD, AWX, and Ansible Tower.
  • Built and maintained observability stacks using Prometheus, Grafana, Splunk, Elasticsearch, Kibana, Loki, Graphite, InfluxDB, Cortex, Mimir, Thanos, Tempo, Jaeger, and OpenTelemetry.
  • Automated infrastructure provisioning, configuration management, reporting, compliance workflows, and operational communications across multiple cloud and virtualization platforms.

Technology Stack

Cloud Platforms

Area Technologies
Public Cloud AWS, Azure, Google Cloud Platform
Hybrid Cloud vSphere, VMware, OpenStack, KVM, libvirt
Cloud Compute EC2, Azure Virtual Machines, Google Compute Engine
Object Storage S3, Azure Blob Storage, Google Cloud Storage
CDN / Edge CloudFront, Azure Front Door, Azure CDN, Google Cloud CDN
DNS Route 53, Azure DNS, Cloud DNS, BIND, Infoblox, DNSMasq
Images AMIs, Azure Compute Gallery, Google Compute Images, Packer Images
Networking VPCs, VNets, Subnets, Security Groups, NSGs, Firewall Rules, Load Balancers, Private Endpoints
Migration Models Physical to VMware, VMware to AWS, AWS to Azure, Cloud-to-Cloud Migrations

Kubernetes & Container Platforms

Area Technologies
Kubernetes Platforms Kubernetes, K8s, AKS, EKS, GKE, vSphere Kubernetes Service, Rancher, OpenShift, K3s, Minikube
Local / Private Kubernetes Typhoon Kubernetes on libvirt/KVM, KVM-Backed Clusters, Lab Clusters
GitOps Argo CD, Flux
Packaging & Deployment Helm, Kustomize, Kubernetes Manifests
Workloads Deployments, StatefulSets, ReplicaSets, DaemonSets, Services, Pods, Jobs, CronJobs
Scheduling Affinity, Anti-Affinity, Taints, Tolerations, Node Selectors
Storage PersistentVolumes, PersistentVolumeClaims, StorageClasses, Volumes, Dynamic Volume Provisioning, vSphere Volume Provider
Networking Services, Ingress, Egress Controls, Cloud Load Balancers, Ingress Controllers
Ingress / Edge Nginx Ingress, HAProxy Ingress, Contour, Voyager, Istio Ingress Gateways
Service Mesh Istio
CNI / Pod Networking Calico, Flannel, Canal, Weave Net
Virtualization on Kubernetes KubeVirt
Container Runtimes containerd, CRI-O, runc, crun
Container Tooling Docker, Podman, Buildah, Skopeo
Image Management Harbor, Red Hat UBI, Scratch Images, Custom Base Images
Security Falco, Rootless Containers, Runtime Security Controls

Infrastructure as Code & Configuration Management

Area Technologies
Provisioning Ansible, Terraform, Terragrunt, Packer, Vagrant
Configuration Management Ansible, AWX, Ansible Tower, Puppet, CFEngine, Foreman
Bare Metal Automation Kickstart, PXE Boot, TFTP, DHCP, Matchbox, cloud-init
Ansible Ecosystem Playbooks, Roles, Collections, Inventories, Dynamic Inventory, Ansible Galaxy, Ansible Vault
Policy / State GitOps Workflows, Desired-State Automation, Idempotent Configuration Design

CI/CD, Release Engineering & Build Systems

Area Technologies
CI/CD Platforms GitHub Actions, GitLab CI, GitLab Runners, Jenkins, Buildkite, Bitbucket, CircleCI, Azure DevOps, Tekton
GitOps / Deployment Argo CD, Flux, Helm, Kustomize
Automation Platforms AWX, Ansible Tower
Source Control Git, GitHub, GitLab, Bitbucket, SVN
Build Tooling Make, CMake, CPack, RPM Spec Files, fpm, RPM Packaging, Source Builds
Repositories RPM Repositories, Artifact Repositories, Package Lifecycle Management
Release Automation CI/CD Pipelines, Deployment Automation, Artifact Promotion

Linux Systems Engineering

Area Technologies
Operating Systems RHEL, CentOS, Fedora, Rocky Linux, Ubuntu, CoreOS, openSUSE
Init / Boot systemd, GRUB, EFI, Bootloaders
Kernel / Isolation Namespaces, Cgroups, chroot, Capabilities, seccomp, eBPF
Kernel Diagnostics dmesg, lsmod, slabinfo, kdump
Hardware / Platform Inspection dmidecode, lspci, lsblk
Process / Runtime Debugging strace, ltrace, ptrace, lsof, fuser, ldd
Performance Tools top, htop, sysstat, iostat, vmstat, ethtool
Filesystems ext3, ext4, XFS, Btrfs
Filesystem Repair fsck
Storage LVM, RAID, SMART, Block Devices, Partitioning, Backup, Replication
Distributed / Shared Storage GlusterFS, NFS, SMB
Security SELinux, ACLs, File Permissions, LUKS, polkit
Troubleshooting osquery, sysdig, dd, journalctl, System Logs

Virtualization & Local Infrastructure

Area Technologies
Virtualization VMware vSphere, VMware Workstation, KVM, libvirt, VirtualBox
Containers / OS Virtualization LXC, Containerized Linux Environments
VM Automation Vagrant, Packer, Cloud Images, Golden Images
Private Cloud OpenStack, Typhoon, libvirt-backed Kubernetes Labs
Enterprise Features vMotion, Resource Pools, Templates, Image Pipelines

Networking & Traffic Management

Area Technologies
Core Networking TCP/IP, VLANs, Routing, Switching, VLSM, OSPF, BGP, HSRP, VXLAN
Addressing / Discovery ARP, DNS, DHCP
Load Balancing HAProxy, Nginx, Traefik, F5, Cloud Load Balancers
Web / Reverse Proxy Nginx, Apache, HAProxy, Traefik
Firewalls firewalld, iptables, NAT, VPNs, Cisco ASA
DNS / DHCP BIND, DNSMasq, Infoblox, DHCP, TFTP
Diagnostics tcpdump, netstat, ss, netcat, nmap, iftop, Wireshark, ethtool

Security, Identity & Compliance

Area Technologies
Identity IAM, Entra ID / Azure AD, LDAP, SAML, OAuth2, OIDC
Access Control RBAC, MFA, SSO, Least Privilege, Service Principals, PIM
Linux Security SELinux, ACLs, Cgroups, chroot, polkit, SSH Hardening
Security Tooling Wazuh, Falco, Audit Tooling, Vulnerability Remediation Workflows
Compliance PCI, HIPAA, STIG-Aligned Hardening, Audit Evidence Automation
Application Security TLS/SSL, HSTS, CSP, CSRF Protections, Secure Headers

Observability, Logging & Telemetry

Area Technologies
Metrics Prometheus, Alertmanager, Grafana, Graphite, InfluxDB, Netdata
Long-Term Metrics / Scale-Out Cortex, Mimir, Thanos
Logging Splunk Cloud, Elasticsearch, Logstash, Kibana, Loki, Heka
Tracing Jaeger, Grafana Tempo, OpenTelemetry
Alerting PagerDuty, Alertmanager, Bosun, Nagios
Dashboards Grafana Dashboards, Kibana Dashboards, Superset, Tableau
Operations 24x7 On-Call, Incident Response, SLA/SLO-Focused Operations

Databases, Data Platforms & Caching

Area Technologies
Relational Databases PostgreSQL, MySQL, MariaDB, Azure SQL
NoSQL / Document Stores CouchDB
Caching Redis, Memcached
Data Movement Azure Data Factory, ETL Workflows
Scaling Patterns Read Replicas, Backup/Restore, Replication, Restricted Network Access

Programming, Scripting, APIs & Templating

Area Technologies
Languages Python, Go, Bash, Ruby, JavaScript, HTML
Shell / CLI Bash Scripting, Linux CLI Automation, Operational Tooling
Static Sites Hugo, Static Website Generation
Templating Jinja2, Go Templates, Golang Templating, Hugo Templating, ERB, Email Templating
Data Formats YAML, JSON, TOML, INI
API Tooling REST APIs, Swagger / OpenAPI, Postman
Automation Patterns CLI Tooling, Bots, ChatOps, Event-Driven Workflows, Report Generation via Automation

Collaboration, Documentation & Delivery

Area Technologies
Project Tracking Jira, Trello, ClickUp, Azure DevOps, Kanban Boards, Jira Automation
Documentation Confluence, Notion, Technical Design Docs, Functional Design Docs
Diagrams Mermaid, UML, Flowcharts, Network Diagrams, Visio
Collaboration Slack, Mattermost, Microsoft Teams, Cisco Webex, ChatOps Bots
Engineering Process SDLC, TDD, DevOps, DevSecOps, Platform Engineering

Current Interests

  • Multi-Cloud Infrastructure Automation
  • Kubernetes Platform Engineering
  • GitOps-Driven Operations
  • Local-First AI Agent Workflows
  • Security-Focused Infrastructure as Code
  • Self-Hosted Developer Platforms
  • Reliable, Repeatable Infrastructure Patterns

Popular repositories Loading

  1. golang-self-healer golang-self-healer Public

    Golang library for configuration management / self healing

  2. clirescue clirescue Public

    Forked from GoBootcamp/clirescue

    Someone started a CLI tool in Go to consumer a web API, however the project isn't going so well, can you help?

    Go

  3. voyager voyager Public

    Forked from voyagermesh/voyager

    ✈️️ Secure HAProxy Ingress Controller for Kubernetes

    Go

  4. musherpiARnoApp musherpiARnoApp Public

    C++

  5. Unity-MRMotifs Unity-MRMotifs Public

    Forked from oculus-samples/Unity-MRMotifs

    The developer community is beginning to show the world why Mixed Reality can be special. Developers come up with new mechanics that show why MR will be the best way to engage Quest users. MR Motifs…

    C#

  6. Unity-FirstHand Unity-FirstHand Public

    Forked from oculus-samples/Unity-FirstHand

    Oculus Interaction SDK showcase demonstrating the use of Interaction SDK in Unity with hand tracking. This project contains the interactions used in the "First Hand" demo available on App Lab. The …

    C#