Christian D Wallace

Christian D Wallace

Senior Site Reliability Engineer · Chicago, IL

10 years of experience combining deep networking with modern cloud platform engineering. I operate Instructure's multi-region Kubernetes platform, powering Canvas LMS for tens of millions of learners worldwide, and I'm known for owning multi-region migrations end-to-end and building the reusable infrastructure application teams build on.

By the numbers

40
EKS clusters across 8 production AWS regions
433
Active service deployments on ArgoCD GitOps
34
Transit Gateways migrated across 9 regions with zero customer impact
60%
Bandwidth reduction via VPN split-tunneling at Trevipay
99.999%
Uptime on the AWS Transit Gateway mesh since VyOS cutover

What I’ve shipped

Internal Developer Platform at Instructure

Built "Trigger," Instructure's internal developer platform powering Canvas LMS across 40 EKS clusters in 8 AWS regions with 433 active service deployments on Akuity-managed ArgoCD GitOps, Helm/Kustomize, and Kyverno policy-as-code. Now building Trigger's next-generation deployment API on Node.js/Express and MongoDB, replacing the legacy internal PaaS it runs on.

Company-wide Zero-Trust Access Modernization

Migrated to AppGate ZTNA to replace scattered SSH keys, a legacy Teleport VPN, and the GlobalProtect client VPN, eliminating the HQ routing bottleneck. Also rolled out ArgoCD Okta SSO via SCIM and HashiCorp Vault, giving every engineer centrally managed, auditable access.

AWS Transit Gateway Mesh Migration

Architected and built Instructure's AWS Transit Gateway mesh with Terraform and Ruby, migrating off a self-hosted VyOS mesh running iBGP and OSPF with zero customer downtime. The new mesh has held five-nines uptime since cutover. Also led a fleet-wide TGW security-group referencing rollout across 34 TGWs in 9 regions, trimming thousands of CIDR-based rules.

Org-wide Security Tooling & Incident Response

Designed org-wide security tooling, including CrowdStrike CSPM, Wiz, and AWS Config StackSets. When that tooling caught an active post-compromise incident, used it to trace what changed and tuned AWS WAF rules in real time to contain the attack, then led the migration to Signal Sciences for longer-term WAF coverage.

Observability, CI/CD & IAM

Own observability and CI/CD strategy, spanning Datadog/Observe dashboards, GitHub/Gerrit for version control, and Jenkins/GitHub Actions pipelines that give every team a paved-road way to ship and debug safely. Architected network/IAM for new AWS LZA accounts end-to-end, replacing one-off account requests with a group-based access model every team onboards through.

Technical stack

Cloud / AWS
AWS Organizations · LZA · IAM Identity Center · VPC/IPAM · EKS · CloudFront
Platform
IDP · Kubernetes · ArgoCD · Akuity · Helm · Kustomize · Kyverno · Policy-as-Code · On-Call · Incident Response
IaC & CI/CD
Terraform · Terraform Cloud · Ansible · GitOps · Jenkins · GitHub Actions
Security
Zero-Trust · Okta SSO/SCIM · HashiCorp Vault · CrowdStrike CSPM · Wiz · AWS WAFv2 · Signal Sciences · AWS Config · StackSets
Networking
AWS Transit Gateway · BGP · OSPF · IPsec · Site-to-Site VPN · SD-WAN · Cisco ACI · AppGate ZTNA
Observability
Observe (OPAL) · Datadog · Prometheus · Grafana · OpenMetrics · Splunk · OpenTelemetry · CloudZero
Languages
Go · Python · Ruby · HCL · Bash · Node.js · SQL

Links