Software Engineer · Pune, India

Akshay Rathod

I build the product, and the platform it runs on.

Ten years of it — Elixir and TypeScript on one side, the infrastructure and delivery systems underneath on the other. Lead engineer at Credibl ESG, there since it was a handful of people.

8 min CI pipeline, end to end down from 30–40
5× Faster ingestion pipeline ~14 hours → ~3
~50 Machines continuously watched a year earlier: zero
4 Products on one delivery foundation the fourth cost a fraction of the first

About

I'm a software engineer. Ten years of it, all of it building things people actually use.

Lead Software Engineer at Credibl ESG — an ESG and supply-chain traceability platform. I joined in 2018 as an early engineer at InfiniChains, the company Credibl spun out of, and I've built most layers of it since: the Elixir/Phoenix backend, the React and Next.js frontend, and eventually the infrastructure and delivery systems the rest of the team ships on.

That last part wasn't a career change. It's what happens when you've been in a codebase long enough to notice that the thing slowing everyone down isn't the code — it's the twenty minutes of CI, or the missing alert, or the deploy nobody wants to touch on a Friday. I like those problems. Nobody files a ticket for them.

What I'm good at

Writing the product. Elixir and Phoenix, TypeScript, React and Next.js, and the databases underneath. Five years of feature work before I touched infrastructure, which is the reason the platform I build is one engineers use rather than route around.

Making the loop short. CI from 30–40 minutes to 8. An end-to-end suite where there had been none. Feedback fast enough that people stay inside it.

Running it in production. Observability built from nothing across roughly fifty machines, infrastructure as code across three regions, and a deploy path with no long-lived credential anywhere in it.

Security as engineering work. Scanning as a gate rather than an audit ritual, and supply-chain controls against the package-poisoning attacks that have become routine.

Currently

Centralised logging, Kubernetes, and cost governance — and handing every system I've built to at least one other person. The measure of this kind of work isn't how much of it got built. It's how much keeps running when I'm not the one running it.

Previously

Associate Analyst at Deloitte Consulting LLP in Bengaluru — Guidewire Policy Center configuration and integrations for a US property & casualty insurer, and Node/Angular services for a telecom supply-chain client.

BCA, Indira College of Commerce & Science, University of Pune.

Elsewhere

Work

Selected engineering work. Client names are omitted deliberately; longer write-ups are linked where they exist.

CI: 40 minutes to 8

Cut the pipeline from 30–40 minutes to 8 across a 2,178-test Elixir suite. Most of it was one pathology — every test paying full production password-hashing cost — plus Postgres on tmpfs and a fix to runner allocation.

Two of the changes were correctness fixes in disguise: background jobs were being killed mid-flight by the test harness, so the suite had been fast and lying.

Read the write-up →

Elixir, GitHub Actions, PostgreSQL


Observability From Zero

There were no metrics, no alerts and no dashboards — production being down was something we learned from a customer. Built the monitoring platform end to end across the fleet: Prometheus and Grafana, blackbox uptime probes, alert routing, and a consolidated inventory so no machine runs somewhere we forgot about.

All of it defined in git and shipped through the same reviewed pipeline as product code. Each product got its own view, because a dashboard everybody owns is a dashboard nobody opens.

Read the write-up →

Prometheus, Grafana, Azure, GitOps


A Deploy Pipeline With No Password In It

One path to production for everything we run, holding no long-lived credentials. CI proves its identity with a token that lives for minutes; OpenBao validates it and returns only the secrets that job needs, which then expire.

The same path deploys a Worker at the edge and a container on a dedicated server — same review, same audit trail, same one-click rollback. Four applications now run on it.

Read the write-up →

GitHub Actions, OIDC, OpenBao, Cloudflare


Bento — Draft Zero

A product I build under Draft Zero: paste one self-contained HTML document, get a clean sandboxed URL. No build step, no hosting to configure.

It landed in a niche I hadn't planned for — AI tooling is good at producing a single HTML file and bad at editing a WordPress theme, so "generate a page and share it" had nowhere to land. Since deployed for internal use at my employer behind a Cloudflare Access perimeter, where it also hosts build artifacts.

Cloudflare Workers, Cloudflare Access, MCP


A Black Box Recorder for Containers

Container crashes were the least debuggable failure we had — the evidence died with the process, so every investigation started from zero. Wrote a watchdog that installs as a system service on every host and captures the full picture at the moment of exit, posting it to the team channel within seconds.

It immediately surfaced problems that had been happening invisibly for months: workloads killed under memory pressure mid-job, restart loops nobody had seen, and jobs that had outgrown their machines.

Read the write-up →

Go, Docker, systemd


Cloud Migration and IaC Foundation

Migrated the production estate — 38 VMs, 46 disks, AI deployments and DNS — into a new Azure subscription single-handedly, with near-zero post-migration issues.

Structured the destination from scratch rather than lifting the old mess across: a tagging taxonomy that made cost analysis possible for the first time, and a three-region topology with clean environment segregation. Used the migration to bootstrap infrastructure as code. Cost dashboards built for capacity planning turned up ~$8.4k/year of right-sizing savings as a side effect.

Azure, OpenTofu, Terragrunt, Cloudflare


Also

Security moved inside engineering. Secret, dependency, static and container scanning as CI gates — report-only first, blocking second, because a scanner that blocks on day one is a scanner everyone learns to ignore. Supply-chain controls against package poisoning: version cooldowns, blocked install scripts, locked dependencies.

An end-to-end test suite, finally. A years-open gap. Not a script somebody runs occasionally but a system with its own dashboard, running on every merge and again nightly on ephemeral infrastructure, with flakiness tracked over time.

Shipping to production without an engineer. A Cloudflare Worker in front of the marketing domain routes bespoke pages from git while everything else passes through to the WordPress origin. A team that doesn't write code now ships to the real site, reviewed and revertible, with no engineer in the loop.

Ingestion pipeline, 5× faster. Cut a production data pipeline from ~14 hours to ~3 by profiling and restructuring query patterns and the MySQL configuration behind them.

Federated SSO for enterprise customers. Single sign-on between our platform and a Big Four consultancy's identity infrastructure. Difficult structurally rather than protocol-wise: a split frontend/backend deployment meant the standard flows didn't apply, so it needed a custom token exchange that leaked nothing at any boundary.

Frontend architecture. Set the layout, theming, state and component conventions the team still builds on, then codified them so they get applied without supervision.

How the scope grew

  1. 2016
    Deloitte Consulting LLP Guidewire for a US insurer; Node and Angular for a telecom supply chain.
  2. 2018
    Early engineer — InfiniChains → Credibl Blockchain-backed cotton traceability. Product code, end to end.
  3. 2021
    Frontend architecture & platform modernisation Set the conventions the team still builds on. Started owning deploys.
  4. 2023
    Lead Software Engineer Cloud migration, infrastructure as code, three-region topology.
  5. 2026
    Platform, delivery & security Observability from zero, CI at 8 minutes, secretless deploys, security inside engineering — and handing all of it to more than one person.

Résumé

Software engineer, ~10 years. Product first, then the infrastructure and delivery systems underneath it — which is most of why the platform work lands.

Experience

Lead Software Engineer · Credibl ESG

Jun 2023 – Present · Pune, India

Technical lead across platform, delivery and security for an ESG and supply-chain traceability product suite.

  • Built the company's observability platform from nothing — Prometheus, Grafana, uptime probes, alerting and per-product dashboards across a ~50-machine fleet, fully GitOps-managed.
  • Cut CI from 30–40 minutes to 8 (−78%) across a 2,178-test Elixir suite; the test step alone went from 20.5 to 3.5 minutes.
  • Designed a secretless delivery pipeline — short-lived OIDC tokens exchanged with OpenBao for scoped, expiring secrets. One reviewed path deploys Cloudflare Workers, containers and every environment behind them. Four applications now run on it.
  • Moved security ownership into engineering: SAST, DAST, secret, dependency and container scanning as CI gates, plus supply-chain controls (version cooldowns, blocked install scripts, locked dependencies). Ran an internal source-level audit alongside an external penetration test; all findings remediated with regression tests added in three languages.
  • Shipped a continuously running end-to-end test suite — a years-open gap — on ephemeral infrastructure, with pass rate and flakiness tracked over time.
  • Migrated the entire production estate (38 VMs, 46 disks, AI deployments, DNS) to a new Azure subscription single-handedly, restructuring it into a tagged, three-region topology and bootstrapping IaC with OpenTofu and Terragrunt.
  • Wrote a container watchdog that captures full diagnostics at the moment of exit and posts them to the team channel, turning the least debuggable class of failure into the most.
  • Led security assessments and questionnaires for 40+ enterprise customers.

Full Stack Developer · Credibl ESG

Nov 2018 – Jun 2023 · Pune, India

Early engineer on the product, originally at InfiniChains, which Credibl spun out of.

  • Built core product across the Elixir/Phoenix backend and the React/Next.js frontend, from the blockchain-backed cotton traceability origins through to the current ESG platform.
  • Established the frontend architecture — layout, theming, state management and component conventions — later codified so the team applies it without supervision.
  • Led the platform's modernisation: Elixir/Phoenix version migration, a full Bootstrap-to-Tailwind replacement, and major feature work shipped in parallel across multiple deployment forks.
  • Cut a production ingestion pipeline from ~14 hours to ~3 by restructuring query patterns and MySQL configuration.
  • Took on increasing ownership of infrastructure, deployment and DevOps over time.

Associate Analyst · Deloitte Consulting LLP

Nov 2016 – Nov 2018 · Bengaluru, India

  • Configured and extended Guidewire Policy Center — data model, screens and integration services — for a US property & casualty insurance client.
  • Built Node/Express/MongoDB services and Angular dashboards for a telecom supply-chain client, integrated with Ethereum-based ledgers (Quorum, Parity).

Side Work

Draft Zero · draftzero.xyz

Bento — paste one self-contained HTML document, get a sandboxed shareable link. Cloudflare Workers, private pastes, token-scoped ownership, MCP integration. Deployed for internal use at my employer behind a Cloudflare Access perimeter, where it also hosts build artifacts.


Education

BCA · Indira College of Commerce & Science

University of Pune · 2016


Skills

Languages & Frameworks: Elixir / Phoenix, TypeScript, JavaScript, Node.js, Next.js, React, Go, SQL

Data: PostgreSQL, MySQL, MongoDB

Platform & Infrastructure: Azure, Cloudflare (Workers, Access), OpenTofu, Terragrunt, Ansible, Docker, systemd, Kubernetes (in progress)

Observability: Prometheus, Grafana, Blackbox Exporter, alerting & SLO design, Sentry, PostHog

Delivery & Security: GitHub Actions, OIDC federation, OpenBao, SAST/DAST, secret & dependency scanning, supply-chain hardening, SSO / OIDC / SAML

Practices: Infrastructure as Code, GitOps, DevSecOps, AI-assisted development