Andy Suderman
andy@suderman.dev
linkedin.com/in/sudermanjr
github.com/sudermanjr
CTO and cloud-native leader with a decade of building, operating, and securing
Kubernetes platforms across AWS, GCP, and Azure. I grew from hands-on SRE and
systems engineering into technical leadership. Running multi-client managed
Kubernetes operations, setting company-wide technical strategy, and owning
security architecture and SOC 2 compliance.
I create and maintain widely used open source Kubernetes tools (including
Goldilocks and Pluto), serve as a CNCF Ambassador and co-chair of the Policy
Working Group, and speak regularly at KubeCon on policy, platform security, and
operational excellence. I connect deep infrastructure expertise to business
outcomes: growing engineering leaders, turning open source into market presence,
and making the tradeoffs that keep platforms reliable, secure, and cost-effective.
Chief Technology Officer
Fairwinds, Remote
April 2022–Present
- Oversaw ~12 mid-to-large scale engineering projects and an organization of up to
30 engineers; delivered quarterly technical updates to the board and executives
- Maintained company open source projects including
Polaris (3.3k+ stars),
Goldilocks (3.3k+ stars),
Pluto (2.5k+ stars), and
RBAC Manager (1.6k+ stars)
- Served as security officer and security architect
- Grew the open source community into a source of sales leads and established the
company as Kubernetes experts
- Led SOC 2 compliance program, shortening enterprise sales cycles. Maintained through 3 years of audits.
- Managed the technical leadership team, growing and enabling new leaders
CTO Advisor
Maybe Don't, AI
June 2025–December 2025
- Advised on technical strategy, architecture, and product direction for an agentic AI
platform focused on policy enforcement, observability, and audit logging
- Built the initial proof of concept that demonstrated policy enforcement and
observability for agentic AI workflows
CTO Advisor
Fluincy, Denver CO
March 2022–January 2026
- Advised on technical strategy, architecture, and engineering practices for a
sales enablement and partner ecosystem platform
- Built and maintained the initial product
Director, R&D and Technology
Fairwinds, Remote
April 2021–April 2022
- Managed a team of SREs responsible for maintaining highly-available Kubernetes infrastructure
across many clients with 24x7 support
- Participated in hiring engineering management that produced a high-performing
SRE team
- Managed the engineering manager for the SRE Operations team responsible for
routine maintenance of client Kubernetes infrastructure
Principal Engineer
Fairwinds, Remote
October 2020–April 2021
- Participated in strategic technological discussions in the absence of a CTO
- Continued evaluation of the impact of new technologies on business outcomes
Lead Research and Development Engineer
Fairwinds, Remote
October 2019–October 2020
- Explored new technologies relevant to the business and evaluated them for
potential use or partnership
- Developed and maintained open source projects to secure company recognition in the Kubernetes landscape
- Continued to serve as a lead technical resource for the engineering department
- Participated in a council to guide the technical direction of the company in a rapidly
changing Kubernetes and CNCF landscape
Lead Site Reliability Engineer
ReactiveOps/Fairwinds, Remote
March 2019–October 2019
All of the same responsibilities of the SRE role, plus:
- Participated in a council to guide the technical direction of the company
- Developed and maintained internal tooling and processes to assist the SRE team
- Developed and maintained open source projects
Site Reliability Engineer
ReactiveOps/Fairwinds, Remote
May 2018–March 2019
- Maintained several customer infrastructures running in Kubernetes with 24x7
support and high availability
- Assisted clients in migrating to Kubernetes in order to accelerate their business goals
- Advised clients on best practices regarding CI/CD, security, and general
operations in Kubernetes in order to ensure smooth transition to Cloud Native technologies
Site Reliability Engineer
ReadyTalk, Denver CO
May 2017–May 2018
- Developed and implemented Kubernetes for internal services
- Assisted in the architecture of services running in Kubernetes
- Developed metrics and alerting for Kubernetes clusters
- Led the design and deployment of a global WebRTC audio gateway in Kubernetes
Systems Administrator
ReadyTalk, Denver CO
June 2016–May 2017
- Responsible for Linux systems running development, staging, and production
infrastructure that supported all business operations
- Maintained and improved Puppet/Foreman infrastructure to ensure consistent configuration
and reliability in business-critical infrastructure
- Maintained and improved Nagios/PagerDuty infrastructure
Systems Administrator
Dairy Engineering Company, Arvada CO
June 2016–May 2017
- Managed all elements of IT infrastructure from desktops to servers
ensuring smooth operations day-to-day
- Maintained proprietary database application that backed all company
operations
- Performed software deployments and automated many IT tasks
- Implemented and migrated to an open source email solution, enabling the company
to save money and have reliable communications
- Designed and wrote new website using MVC architecture in order to enhance company
brand and showcase used equipment listings
Open Source and Community
- Creator and primary developer of Goldilocks
(3.3k+ GitHub stars), an open source tool for recommending Kubernetes requests and limits
- Co-author and maintainer of Pluto (2.6k+ stars),
a CLI for discovering deprecated and removed Kubernetes API versions
- Maintainer of additional Fairwinds open source projects including
Polaris (3.4k+ stars) and
RBAC Manager (1.7k+ stars)
- CNCF Ambassador since 2024 and co-chair of the CNCF Policy Working Group
Public Speaking
Skills
- Leadership: technical strategy, engineering management, hiring and developing
leaders, open source community building, cross-functional stakeholder alignment
- Languages: Go, Python, Bash, YAML, JSON/CEL
- AWS: EKS, EC2, EBS, S3, VPC, Route 53, IAM, ELB/ALB, CloudWatch, ECR
- GCP: GKE, Compute Engine, Persistent Disk, Cloud Storage, VPC, Cloud DNS,
IAM, Cloud Load Balancing, Cloud Monitoring, Artifact Registry
- Azure: AKS, Virtual Machines, Managed Disks, Blob Storage, Virtual Network,
Azure DNS, Entra ID / RBAC, Load Balancer, Azure Monitor, Container Registry
- Kubernetes: cluster architecture, upgrades, addons, RBAC, networking (Ingress /
Gateway API), autoscaling (HPA, VPA, cluster autoscaler, KEDA), Helm, operators
- Infrastructure as Code: Terraform, Pulumi, Helm, cloud-init, configuration
management (Puppet)
- CI/CD: GitHub Actions, CircleCI, GitOps patterns, release automation
- Platform engineering: managed Kubernetes-as-a-Service, multi-cluster operations,
developer platforms, self-service infrastructure
- Security and policy: Policy-as-Code, admission control, Pod Security, supply-chain
and configuration hardening, SOC 2 program ownership
- Observability: Prometheus, Grafana, Alertmanager, Datadog, metrics, logging,
tracing, alerting, and incident response
- Reliability and operations: SRE practices, 24x7 support models, Linux systems
administration, on-call and operational excellence
- Cost and efficiency: FinOps, rightsizing, capacity planning, cloud cost visibility
BS Engineering, Mechanical Specialty
Colorado School of Mines, Golden, CO