Leanpub Header

Skip to main content

Thomas Zachmann

Thomas Zachmann has spent more than twenty years building systems, and the last several of them building Kubernetes platforms for organisations where security and auditability are the requirement rather than the aspiration: on-premises, on bare metal, in air-gapped networks, and in European sovereign clouds — under European regulatory and audit regimes.

His work is the hardening of container platforms and everything that has to hold up when an auditor asks: policy enforcement with Kyverno, identity and access with Keycloak, supply-chain evidence with Harbor, Trivy and Dependency Track — and secrets management with HashiCorp Vault, which he has been deploying and operating since 2017. He works in the public clouds as well, which is what makes the on-premises argument in these books a comparison rather than a preference.

He is a Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA) and Certified Kubernetes Application Developer (CKAD). Those twenty years began in software engineering — performance and systems programming at SAP in C and C++, database performance analysis at IBM, and Go since. That background is why the automation in his platforms is written rather than bought, and why his books ask you to type rather than to read.

He is based in Hamburg and works across the DACH region.