Pakkit.net
Contact Brandon Other role focuses

Platform & infrastructure

Brandon Donaly

Platform engineering • automation • reliability

Denver metro, Colorado · me@pakkit.net · pakkit.net/resume

Infrastructure automation, database operations, release engineering, and reliable developer environments.

Experience

Wireless Engineer III — AAA Development & Platform Automation · Charter Communications (Spectrum)

Nov 2024 – Aug 2026 · Previous role

  • Designed deployment-time configuration and secrets tooling that separates reusable policy artifacts from environment values and versioned encrypted secrets; released the deployment component with environment validation, provenance tracking, and compatibility checks while broader rollout remained in progress. (in-progress)
  • Converted runbook-driven platform deployment into 6 versioned Ansible collections with 29 tagged releases in 76 days, covering deployment, database operations, system administration, VM preparation, orchestration, and preflight checks.
  • Built the team's first collection release pipeline and test strategy, including 403 automated tests and 96 property-based tests in the earlier suite snapshot, parallel pytest execution, automatic versioning, artifact publication, and shared CI templates. Later deployment safeguards were challenged at 16 injected failure points and with 13 deliberate role mutations, checking preservation of a startable previous release.
  • Automated backup and restore end to end with scheduling, retention, verification, capacity checks, retries, and alerting, replacing an inconsistent manual process.
  • Optimized a legacy Cassandra decryption UDF, reducing development-benchmark mean latency from 12.47 ms to 0.70 ms and increasing 16-thread throughput from 635 to approximately 13,100 operations per second; scoped equivalence and round-trip compatibility checks to the tested variants.
  • Automated VM provisioning from template preparation through cloud-init self-deployment, including dual-stack IPv4/IPv6 addressing and an IPv6-only defect that had been breaking unattended provisioning. Built and verified a Rocky Linux golden template, then provisioned eight database VMs and checked unique machine identities and SSH host keys on every running guest.
  • Built repeatable IPAM import and drift-audit tooling, reconciled a 233-VM development inventory, and populated a separate integration-test inventory covering 62 VLANs, 144 subnets, and 176 addresses using hypervisor, host, and telemetry evidence.
  • Restored an internal application's login service by tracing failed database session writes to disk exhaustion caused by a cascading Redis and container-logging failure; reclaimed capacity and prepared log-rotation controls.

Founder / Principal Engineer · Duvall WiFi

Aug 2022 – Nov 2024 · Previous role

  • Founded and ran a technology and ISP services company covering network engineering, software development, hosting, cybersecurity, and managed IT. I owned customer discovery, architecture, implementation, production operations, sales, billing, and support.
  • Built a redundant multi-frequency wireless network capable of serving 160 homes with symmetric gigabit, backed by custom captive-portal and RADIUS software plus virtualized infrastructure, PKI, segmentation, monitoring, VPN connectivity, PBX/CRM integrations, and production Laravel and Spring applications.
  • Built and operated a three-host VMware vSphere/vSAN environment with data-center colocation, an air-gapped root CA, zero-trust segmentation, secure administrative workstations, SIEM monitoring, VM templates, and hub-and-spoke VPN connectivity across customer networks.
  • Operated a GenieACS TR-069/CWMP platform managing 58 MikroTik and Yealink devices through 15 presets and 15 provisions, documented its tag-driven idempotent configuration state machine, and identified security, permissions, provisioning, and device-health defects through live read-only analysis.

Technology & Growth Consultant · Pacific Northwest Plumbing

Jun 2023 – Nov 2024 · Previous role

  • Technology and growth consulting for a trades business. I brought customer acquisition cost down from roughly $150 to $5.10 and shifted 83.67% of inbound calls onto unpaid channels, working across the website, analytics, advertising, reviews, and conversion paths.
  • Delivery included a Laravel 10 production website, conversion tracking, advertising workflows, helpdesk support, and custom IP-camera security integrations.

Network & Systems Consultant · Wilderness Awareness School

Nov 2022 – Nov 2024 · Previous role

  • Designed, quoted, installed, and operated a resilient enterprise network across three forested properties using roughly 700 meters of aerial and buried cabling plus point-to-point wireless links. The design avoided the cost of an additional internet circuit and improved outage resilience.
  • Ongoing support covered routers, switches, access points, point-to-point wireless links, structured cabling, monitoring, and day-to-day technical support for staff.

Technical Consultant · Beyond Grey Skies, LLC

Mar 2016 – Jun 2021 · Earlier chapter

  • Supported enterprise networks, data-center fabric, Linux and Windows servers, intrusion monitoring, and emergency technical operations, working across pfSense, VyOS, MikroTik RouterOS, and Cisco IOS.

Independent projects

Identity Platform Engineering · Independent project

2026 · Independent project

  • Deployed an Authentik identity platform using Ansible, Docker Compose, declarative Blueprints, and Terraform-managed Cloudflare Access, with OIDC group claims for application authorization.
  • Verified signed identity tokens, allow/deny behavior, group-removal revocation, deactivated-user denial, and configuration reapplication through 20 infrastructure checks and a ten-check identity suite.
  • Validated idempotent deployment and unattended reboot recovery, and preserved existing access policies during additive application migration.

Private Cloud & Homelab Platform Engineering · Independent project

Ongoing · Ongoing

  • Operate a three-host vSphere/vCenter environment inventorying 149 VMs (86 running), 469 allocated vCPUs, roughly 686 GiB of allocated RAM, eight datastores, and 45 networks across Linux, Windows, RHEL, Debian, FreeBSD, and network-appliance workloads.
  • Built repeatable VM provisioning and golden-template workflows spanning cloud-init guestinfo, clone customization, LVM growth, Docker bootstrap, network and IP validation, sysprep, smoke tests, and reusable Ansible and CLI automation.
  • Performed read-only isolation and hypervisor-risk analysis across the workload, management, vMotion, and vSAN planes, validating layer-2 protections and blocked routing while identifying patch-level exposure to guest-to-host escape vulnerabilities and a high-blast-radius shared-storage design. (analysis)

Embedded, Mobile & Signal Engineering · Independent project

2021 – 2023 · Earlier project

  • Built and deployed nine networked ESP8266 devices in C++, each reporting into a self-hosted MQTT broker or SNMP poller so the readings landed in the same monitoring stack as the rest of the network rather than in a vendor cloud application.
  • Instrumented an off-grid solar installation with three-channel high-side current and voltage sensing, applying per-channel shunt calibration offsets and deriving panel wattage and PoE draw so battery behaviour could be trended over time instead of guessed at.
  • Built a charging-cable thermal monitor that reads the handle's NTC thermistors through an external analog-to-digital converter, linearizing against a measured reference voltage and divider resistance, with a local display and an asynchronous web server for remote reads.

Skills demonstrated here

  • Ansible
  • Ansible Collections
  • Jinja2
  • Apache Cassandra 4.1 / 5.0
  • User-defined functions
  • RADIUS
  • GitLab CI
  • Artifact provenance
  • Docker
  • Docker Compose
  • Vulnerability management
  • Mutual TLS / X.509
  • VMware vSphere / vCenter
  • VM templating
  • cloud-init
  • IPv4/IPv6 dual-stack
  • Rocky Linux
  • Python
  • Java 23 / Spring Boot
  • PHP / Laravel
  • Behavioural-parity testing
  • Root-cause analysis
  • Property-based testing
  • Authentik
  • OIDC / OAuth 2.x
  • Cloudflare Access / Workers
  • Terraform / OpenTofu
  • MikroTik RouterOS
  • VMware vSAN
  • GenieACS / TR-069
  • pfSense
  • VyOS
  • Cisco IOS
  • Guest customization / sysprep
  • MariaDB / MySQL
  • Redis
  • pytest
  • Fault injection
  • Incident response & postmortems
  • Rollback engineering
  • SOPS / age
  • phpIPAM / inventory reconciliation
  • Mutation testing
  • Performance benchmarking
  • MQTT
  • Embedded C++ / Arduino
  • ESP8266
  • I²C / SPI
  • ADC & sensor calibration
  • SNMP

Certifications

CompTIA A+ · CompTIA Network+ · CompTIA Security+ · CompTIA Server+ · Microsoft MTA: Mobility and Device Fundamentals