About · Senior Platform Engineer · Squamish, BC
James Fillman
I build internal developer platforms: self-service, GitOps-driven delivery on Kubernetes, with CI/CD and supply-chain security built in rather than bolted on. My career runs from web-server farms, through enterprise bare metal and VMware, to Kubernetes-native platforms, and the goal has stayed the same: less friction for the people shipping software, and more reliability, speed and cost control in how it gets to production.
Why Hangar
Hangar is where I put my opinions to work. It is a complete internal developer platform that I build in the open and run on a home lab of two Kubernetes clusters, one dev and one prod. Everything on this site is backed by it, and when I change my mind, the platform changes too. The principles page is the short version of what I believe; the log is how it got here.
Experience
Best Buy Canada
Platform Engineer · 2021 to 2026Architected and led key parts of the internal developer platform on OpenShift 4, owning its GitOps strategy, CI/CD architecture and self-service tooling.
- Defined the GitOps strategy and ArgoCD architecture that moved roughly 500 applications across 9 clusters off manual
kubectl applyonto a declarative, git-driven model. - Replaced Sealed Secrets with External Secrets Operator, Azure Key Vault and OPA policy enforcement.
- Built self-service onboarding (Ansible Tower, then multi-cluster ArgoCD ApplicationSets) as the platform's single path for provisioning and onboarding.
- Authored the CI/CD v2 strategy: Tekton in place of Jenkins, with SLSA provenance and Sigstore signing, driven by PCI supply-chain requirements.
- Embedded an automated production-readiness gate in the pipeline: image and SAST scanning, change verification, test results, provenance and signature checks.
- Introduced progressive delivery with Argo Rollouts, and ran the Ops Community of Practice for several years.
Central 1 Credit Union
Systems Architect · 2001 to 2020Owned the architecture and strategy for the Linux fleet and core services behind online banking and bill payments.
- Developed a Container-as-a-Service hybrid-cloud strategy: automated OpenShift 4 installs, ArgoCD GitOps, Tekton CI/CD and OPA governance.
- Built an automation platform around Rundeck and Chef: self-service provisioning, one-click failover, automated DDoS response and auto-remediation.
- Architected a multi-site, highly available Splunk Enterprise platform.
Toolbox
| Platform | Kubernetes, OpenShift, Crossplane, Linux, Istio |
|---|---|
| CI/CD and GitOps | ArgoCD, Tekton, Argo Rollouts, Jenkins, GitHub Actions, Helm, Kustomize, Ansible |
| Supply chain and security | Sigstore, SLSA, OPA, External Secrets, Sealed Secrets |
| Observability | OpenTelemetry, Prometheus, ELK, Splunk, Dynatrace, PagerDuty |
| Cloud and code | Azure, AWS, Terraform · Bash, Python, JavaScript, Groovy |
Away from the keyboard
I live the good life in beautiful Squamish with my dog, Riley. Most days that means climbing, trail running or hiking, and on the rest there is usually a chess game going.