Joel Freeman

Projects

Things I've built at work, as a founder and on my own time.

AWork
4 projects

Work

Platform and infrastructure I designed and shipped at Starboard and MetService.

Fig. 01Starboard · 2025 - now

Kubernetes platform

I built the platform, wrote the service contract every service ships through, and moved all 38 production services onto it with zero downtime. Deploys went from hours or days to five minutes, self-service, with one-click rollback.

  • GKE
  • Argo CD
  • Kargo
  • Kyverno
  • OPA
  • Helm
  • Envoy Gateway
  • Terraform
  • GCP PAM

Service contractAbout ten lines per service drive its deployment, secrets, network policy, gateway routes and alerts, with no platform ticket.

The platform runs on five GKE clusters, about 600 vCPUs. A highly available Argo CD reconciles every cluster from Git, so what runs is always what was reviewed. Kargo promotes signed releases through dev, staging and production, and a Kyverno policy stops automatic promotion into production. Twenty OPA policies check placement and every GitOps change before merge. CI renders each change once, runs nine validation stages and posts one verdict, with a diff of what will change on each cluster. Traffic enters through an API gateway on Envoy Gateway, and Terraform builds the Google Cloud foundation underneath. Terraform went from two laptops with admin credentials to about 36 reviewed changes a week: each stack applies through Workload Identity Federation to a least-privilege identity, production changes wait for a named approver, and the tooling blocks an apply if the approved commit is no longer current. Nobody holds standing production access either. Access runs through GCP Privileged Access Manager with 87 tiered entitlements, a CLI that requests and approves access in seconds, and automation that keeps on-call permissions in line with the rotation, and it passed a NIST 800-171 customer audit. Then I moved production onto it. I turned 22 stalled pull requests into a staged rollout: merge every config dormant, enable one service at a time, snapshot each step for rollback and prove each cutover with a render-versus-live diff tool. All 38 services moved with no code freeze and nine days early, and 50 bespoke CI workflows were retired. The ingestion service, undeployable for four years, cut over in ten minutes. More than 15 engineers now ship through it, and a teammate onboarded 12 services unaided.

Service contract

One service definition of about ten lines, on a three-chart Helm family, replaces a platform ticket. It drives:

  • Deployment
  • Secrets from Secret Manager
  • Network policy
  • Gateway routes
  • Alerts
Fig. 02Starboard · 2025 - 2026

Alerts that can fire

Four monitors were reporting healthy while broken. Now CI catches that.

  • Grafana
  • eBPF
  • Alerting

Service-owned monitoring across five clusters on Grafana Cloud, with eBPF tracing and no code changes. A CI check renders every alert rule against live metrics and fails the pull request's check when a rule is broken or could never fire.

Fig. 03Starboard · 2026

Agent-written validation plans

In an evaluation on nine real changes, unaided agents wrote a usable validation plan for one. With an adversary agent reviewing each plan, all nine were usable.

  • Claude Code
  • Agents
  • Evaluation
Read the write-up

A workflow that lets coding agents plan and check infrastructure changes while a person does every merge, apply and promotion. An adversary agent tests each plan against deliberately broken changes. It shipped as seven skills and four evaluation suites.

Fig. 04MetService · 2024 - 2025

Aviation weather pipeline

Replaced legacy APIs with a pipeline that turns aviation weather data into GeoJSON.

  • AWS
  • TypeScript
  • Data pipelines

Designed and built in TypeScript on Lambda, S3, SQS and SNS for the Aviation Resiliency Project, with missing-data alerting so it couldn't look healthy while files never arrived.

BProduct
1 project

Product

A commercial product I co-founded and build as its sole engineer.

Fig. 05313 Management · Co-founder · 2026 - now

Atlas

A commercial product for music festivals that I co-founded. Atlas brings a festival's ticket sales, its app and what happens on site into one place. I'm the sole engineer, so I built the platform and the mobile app and run both in production.

  • Next.js
  • Prisma
  • Postgres
  • Expo
  • React Native
  • Vercel Workflows
Visit site

AtlasAtlas keeps one record per event, artist and attendee, so each person is known across every event and the app: spend, returning, home city and music taste.

Atlas APIOne Next.js app on Vercel serves the back office and the REST API, keeps staff and attendee sign-in apart, and checks every caller before it reads any data.

Map

Atlas joins ticketing history, artist interest, app engagement and on-site behaviour into one profile per attendee, so a festival can see who its best customers are, which artists they came for and how they move around the site. On-site analytics show movement, time spent and where crowds build through the day. Its first paying customer is Sub180's Rolling Meadows festival, with about 10,000 attendees. I built it as one TypeScript monorepo: the back office and REST API on Next.js, Prisma and Postgres, and the attendee app for iOS and Android in Expo and React Native. Lineup changes reach the app only as verified releases, and push notifications go out through Vercel Workflows.

CPersonal
5 projects

Personal

Smaller things I've built on my own time.

Fig. 06Side project · 2026

what

One place for every agent session I have running across Claude Code and Codex, and every promise I made in Slack or a meeting.

  • Electron
  • TypeScript
  • SQLite
  • Claude Code
  • Codex

whatA local daemon keeps everything in one SQLite archive on my machine and works out where each session is at.

Map

A desktop app and CLI that pulls in my agent history, works out where each session is at, and builds a view of each day: what needs me, an overview, and a section for each piece of work. Everything stays on my machine in a local SQLite archive, and the sources are never changed. Search, a week view, the work still open in each project and Ask, which answers with citations, all read from the same archive.

Fig. 07freeman.gg · 2026

This site

My site and writing, with a terminal you can type into.

  • Next.js
  • TypeScript
  • Motion

Built with Next.js and Motion. Posts are MDX files in the repo, so there's no CMS to look after.

Fig. 08GitHub · 2023

GitHub OIDC for Terraform

A Terraform module that lets GitHub Actions authenticate to AWS or Azure.

  • Terraform
  • AWS
  • Azure
View on GitHub

Creates the resources GitHub Actions needs to sign in to AWS or Azure with short-lived tokens.

Fig. 09GitHub · 2023

URL shortener

A URL shortener written in Go.

A small Go service for shortening links.

Fig. 10GitHub · 2021

Pritunl VPN image

Ansible roles and Packer configuration that install and configure Pritunl.

  • Ansible
  • Packer
View on GitHub

Builds a machine image with Packer and configures the Pritunl VPN server on it with Ansible.