Hangar

About · Senior Platform Engineer · Squamish, BC

James Fillman

I build internal developer platforms: self-service, GitOps-driven delivery on Kubernetes, with CI/CD and supply-chain security built in rather than bolted on. My career runs from web-server farms, through enterprise bare metal and VMware, to Kubernetes-native platforms, and the goal has stayed the same: less friction for the people shipping software, and more reliability, speed and cost control in how it gets to production.

jamesfillman@gmail.comLinkedInGitHub

Why Hangar

Hangar is where I put my opinions to work. It is a complete internal developer platform that I build in the open and run on a home lab of two Kubernetes clusters, one dev and one prod. Everything on this site is backed by it, and when I change my mind, the platform changes too. The principles page is the short version of what I believe; the log is how it got here.

Experience

Best Buy Canada

Platform Engineer · 2021 to 2026

Architected and led key parts of the internal developer platform on OpenShift 4, owning its GitOps strategy, CI/CD architecture and self-service tooling.

  • Defined the GitOps strategy and ArgoCD architecture that moved roughly 500 applications across 9 clusters off manual kubectl apply onto a declarative, git-driven model.
  • Replaced Sealed Secrets with External Secrets Operator, Azure Key Vault and OPA policy enforcement.
  • Built self-service onboarding (Ansible Tower, then multi-cluster ArgoCD ApplicationSets) as the platform's single path for provisioning and onboarding.
  • Authored the CI/CD v2 strategy: Tekton in place of Jenkins, with SLSA provenance and Sigstore signing, driven by PCI supply-chain requirements.
  • Embedded an automated production-readiness gate in the pipeline: image and SAST scanning, change verification, test results, provenance and signature checks.
  • Introduced progressive delivery with Argo Rollouts, and ran the Ops Community of Practice for several years.

Central 1 Credit Union

Systems Architect · 2001 to 2020

Owned the architecture and strategy for the Linux fleet and core services behind online banking and bill payments.

  • Developed a Container-as-a-Service hybrid-cloud strategy: automated OpenShift 4 installs, ArgoCD GitOps, Tekton CI/CD and OPA governance.
  • Built an automation platform around Rundeck and Chef: self-service provisioning, one-click failover, automated DDoS response and auto-remediation.
  • Architected a multi-site, highly available Splunk Enterprise platform.

Toolbox

PlatformKubernetes, OpenShift, Crossplane, Linux, Istio
CI/CD and GitOpsArgoCD, Tekton, Argo Rollouts, Jenkins, GitHub Actions, Helm, Kustomize, Ansible
Supply chain and securitySigstore, SLSA, OPA, External Secrets, Sealed Secrets
ObservabilityOpenTelemetry, Prometheus, ELK, Splunk, Dynatrace, PagerDuty
Cloud and codeAzure, AWS, Terraform · Bash, Python, JavaScript, Groovy

Away from the keyboard

I live the good life in beautiful Squamish with my dog, Riley. Most days that means climbing, trail running or hiking, and on the rest there is usually a chess game going.