Mark Marryatt

Platform Engineer · Gauteng, South Africa · 10+ years

Infrastructure, Kubernetes and cloud foundations for multi-tenant SaaS.

Across on-premises networks and public cloud, I build the foundations multi-tenant SaaS runs on: GCP and Azure, Kubernetes and Helm, infrastructure as code and CI/CD, observable and secure by default.

Experience

Platform Engineer

CloudSmiths2025-2026

GCP / GKE / Kubernetes / Helm / Terraform / Terragrunt / GitHub Actions / Workload Identity / NetworkPolicy / Cloud SQL / Private Service Connect / RabbitMQ / Secret Manager / Security / SaaS / Multi-tenancy / CI/CD / Gateway API

Moved into a platform-focused role building the foundation for Objective as a public-facing SaaS product.

Created the platform-as-a-service layer that allowed internal product teams to deploy, secure and operate tenant environments on GCP with a repeatable path from CI to production.

  • Built reusable Terraform and Terragrunt modules for tenant provisioning, including GCP projects, restricted Kubernetes namespaces, Workload Identity, Cloud SQL IAM databases with pgvector, generated Secret Manager keys and RabbitMQ vhosts/users.
  • Used Terragrunt to keep infrastructure DRY across preprod and multi-region SaaS environments, making SDLC redeployments repeatable while managing multiple GKE clusters.
  • Provisioned regional platform foundations including VPC subnetting, Cloud NAT, Private Service Connect, private Cloud SQL DNS, Gateway API load balancers, certificate maps and TLS policy.
  • Maintained the Helm chart and environment configuration used to deploy tenant-facing applications, including routing, identity, secrets and operational defaults.
  • Improved CI workflows across Objective Foundation so builds, releases and deployments became more predictable for a product serving external customers.
  • Implemented default-deny tenant NetworkPolicies with explicit egress for DNS, GKE metadata, RabbitMQ, document conversion and Cloud SQL over Private Service Connect.

Azure / Databricks / Terraform / env0 / Airflow / Adverity / Django / Kubernetes / CI/CD / SaaS / Deep Learning

Moved internally into Dentsu's Data Refinery team, supporting a SaaS marketing application where deep learning was applied to performance metrics.

Worked across ingestion, orchestration, processing services and deployment paths inside the wider company SaaS platform.

  • Supported Adverity deployments for metrics ingestion, Airflow workflows for processing and custom Django applications for processing logic.
  • Contributed to the overarching Dentsu CI platform used to build, test and deploy application services.
  • Designed and maintained Terraform modules for Azure infrastructure, most notably architecting private-network Databricks deployments and data-source connectivity.
  • Used env0 to manage infrastructure deployments and make environment changes more repeatable.

Kubernetes / Helm / Terraform / Brigade.sh CI / Azure / PostgreSQL / Hashicorp Vault / Istio / K6 / Grafana / Prometheus / InfluxDB

During this period I was directly outsourced to Dentsu, the fifth largest advertising agency network in the world, working in a small team responsible for the upkeep of data engineering business functions.

Became the go-to point for operational knowledge, as well as a key part in design discussions which paved our roadmap.

  • Built and maintained Terraform modules used company-wide.
  • Wrote Brigade CI pipeline functions in Javascript to build containers, publish Helm charts, run tests and deploy applications on Kubernetes.
  • Used K6 to load test web applications and RESTful APIs, pushing metrics to InfluxDB and visualising them in Grafana.
  • Worked extensively with Azure resources including AKS, Key Vault, Container Registry, SQL Server, PostgreSQL, Frontdoor, Application Gateway, DNS, Active Directory, Virtual Machine Scale Sets, Storage Accounts and Log Analytics.

Network Systems Engineer

Reflex Solutions2020-2021

RADIUS / Ansible / DroneCI / Terraform / Elastic Stack / Docker / Kubernetes / VXLAN

Designed and implemented systems to be used company-wide with the DevOps mindset from the onset, commissioning a Kubernetes cluster to serve AWX, Gitea, DroneCI, Netbox, a Wiki, and other supporting applications. Many time-consuming operations were automated in pipelines by combining DroneCI and Gitea.

  • Implemented a Wiki of my own volition that became the de facto system used to store technical documentation.
  • Used Terraform to provision the underlying network for VMWare Hypervisors and the Virtual Machines that ran on them, removing daily toil for Cloud engineers and eliminating common manual mistakes.
  • Played a critical role in setting up VMWare NSX-T and vCloud Director, enabling the company to sell a PaaS solution to clients.

Enterprise Team Lead

Reflex Solutions2018-2020

MPLS / L3VPN / L2VPN / Linux / BGP / Firewalls / ISIS / DNS

Focused on upskilling my team as much as possible by orchestrating and leading multiple training sessions. Created complimentary virtual labs to test their knowledge and explain complex concepts.

As I transitioned to the Team Lead role, I picked up the support for multiple linux servers which had not been maintained since my arrival.

  • Supported core routing and switching infrastructure in data centers across South Africa, including individual travel for maintenance windows when needed.
  • Managed new APN onboarding, configured RADIUS for SIM card AAA, and worked directly with MSSQL stored procedures, queries and performance tuning.
  • Implemented a highly-available Elastic cluster with 9 nodes and 6 terabytes of distributed storage - more in the projects section below.
  • Containerised the FreeRADIUS implementation used to provide, limit and bill internet access for hundreds of devices - more in the projects section below.
  • Implemented Huawei's CloudCampus software-defined networking solution by drawing on a strong understanding of its underlying components.
  • Produced detailed documentation that made the full implementation path clear and reusable.

Network Engineer

Reflex Solutions2017-2018

MPLS / BGP / Firewalls / FTTx / QoS

Quickly moved into the Reflex team as my skills were aligned with Reflex's offerings.

  • Completed site installations, going onsite to install routers and switches in LAN environments.
  • Configured layer 2 and 3 last-mile connectivity on both PE and CE routers.
  • Completed thorough network audits with in-depth evaluations, documenting large campuses with hundreds of devices and different connectivity mediums.

Support Engineer

Jasco Electronics Holdings Limited2016-2017

Routing & Switching / Firewalls / VMWare ESXi / Fabric Connect / SPB-M / Active Directory / Linux / Windows Server / IP PABX / QoS

Completed a total rip and replace of all networking equipment, implementing Avaya's flagship Fabric Connect protocol. ISIS adjacencies were formed on all access switches to achieve Shortest Path Bridging via mac-in-mac encapsulation.

Supported all IT infrastructure in Jasco group, gaining exposure to a wide range of technologies and a practical understanding of what makes for good user experience.

Network Intern

Avaya2015-2016

Routing & Switching / Fabric Connect / SPB-M / IP PABX

Learned networking and voice solution deployment methods as well as how to support customers in different environments.

Earned multiple entry-level certifications during my internship.

Selected Projects

CloudSmiths

AI SaaS Platform Foundation

Helped pioneer Objective Foundation in 2023, building an AI harness before the patterns around agentic SaaS products had settled.

The platform grew into a multi-tenant SaaS application that combines reusable AI workflows, tenant-aware execution, controlled deployment paths and security boundaries suitable for public customer environments.

Focused on the platform layer that made this repeatable: infrastructure as code, tenant provisioning, CI/CD, Kubernetes deployment, identity, secrets, database access and operational guardrails.

Enterprise Microsoft Fabric DataOps Platform

Designed a repeatable Microsoft Fabric deployment model for a regulated data environment using Atmos and Terraform.

Provisioned and managed Azure/Fabric foundations including resource groups, Key Vault, Entra applications, Fabric capacities, domains, workspaces, lakehouses, SQL databases, Git integration, role assignments and shareable cloud connections.

Helped shape a governed lakehouse architecture with Bronze, Silver and Gold layers, source ingestion from systems such as M-Files, BambooHR and ClickUp, semantic models, Power BI reporting and Row-Level Security preserved through workspace separation.

Built the deployment approach around OIDC-authenticated GitHub Actions, environment-specific stacks, validation, drift detection and Fabric Git Integration so dev and prod data environments could be managed predictably.

Dentsu

Containerisation of a monolith

Before I joined, the DevOps team struggled with slow and faulty deployments of a third-party, monolithic Java application onto virtual machine scale-sets.

Messy and imperative CloudInit scripts were used to unreliably stand up environments that required manual intervention to get to an operational state.

Redefined the process entirely, configuring CI to securely pull artifacts, build container images, test and publish helm charts and finally use terraform to stand up an instance of the application on Kubernetes in mere minutes.

Load-testing

Pioneered the usage of K6 as a load-testing tool, testing RESTful APIs as well as direct browser interactions. To quickly find resource sweet spots, the CICD pipeline created multiple ephemeral environments with different resource settings and tests would automatically be run against each.

Created highly informative dashboards from this data, linking commits, environments and resources to each test.

People gradually started following my methodologies in this area when they were able to see the value it provided.

Reflex Solutions

Automation Stack Implementation

Commissioned multiple systems to achieve a scalable automation solution.

Ansible AWX pulled playbooks and references to dynamic inventory sources from a Gitea repository, the dynamic inventory was enriched by device specific variables stored in Netbox.

The playbooks mostly automated router and firewall management. Configuration backup playbooks wrote device configuration to a dedicated Git repository, achieving version control and a level of insight not previously attainable.

Wrote these playbooks to be vendor-agnostic, using variables from Netbox to run the correct steps.

Other playbooks included the configuration of TACACS (Authentication/Authorization), standardizing ACLs and ensuring security practices are implemented.

Detailed dashboard were automatically created for each client, this information assisted greatly in reducing MTTR by making it possible to correlate events across devices, with information that would previously have been a painstaking ordeal to retrieve.

This implementation got me recognized as employee of the month - which was the third time during my time at Reflex.

Elastic Stack Redesign

This project saw a complete overhaul of the Elastic Stack in place, resulting in jumping multiple major releases from 2.3 to 7.10.

This included racking the physical equipment, creating virtual machines, installing the OSes, configuring RAID, cabling, networking, load balancing, security, logstash pipelines, index management, visualisations, dashboards and everything else in between.

Carefully planned the implementation of every node, automating a secure installation process.

Spinning up a new node and adding it to the cluster took only a few short minutes.

Different indexing and sharding strategies were tested by implementing Index Lifecycle Management, until the most effective combination was found.

This allowed for much more valuable alerts to be created, using in-depth KQL queries to output specific information to webhooks.

Logstash pipelines took the most development - enriching the raw data that came in to be much more useful.

The outcome was a secure and multi-tenanted platform thats employees and customers alike could access to view insights.

RADIUS Redesign

A FreeRADIUS implementation already existed at Reflex Solutions when I joined.

Took ownership of upgrading it to a new major version.

Containerized the application and ran it in production with Docker.

This project stemmed from the creation of an internal RADIUS frontend being built which led to me working closely in conjunction with our internal development team.

Throughout the process, we highly customized our RADIUS deployment. Created and troubleshot new SQL scripts to achieve our desired outcome.

MPLS Decommissioning

Planned, scripted and executed the seamless decommissioning and replacement of core infrastructure in different regions.

These changes were applied flawlessly in minutes after weeks of meticulous planning and preparation.

Network Device Management redesign

Implemented AAA from the ground up, utilizing TACACS for Authentication and Authorization, and the Elastic Stack for Accounting.

All device logs were parsed using in-depth grok patterns and data enrichments, allowing for the creation of meaningful visualizations, providing holistic views into operational and security performance with the ability to drill down into specifics.

A large part of the redesign was separating core infrastructure into distinct management zones, enabling the application of fine-grained security policies to segments of the network at scale.

Certifications

Education

Elasticsearch Engineer 1 & 2

Elastic Institute

The ins and outs of administering a high-scale Elasticsearch cluster. Creating complex search queries to visualize static and time-series datasets.

2019

High School

Sutherland

2009-2013

Hobbies & Interests

Home Automation · Self-hosting · Music