DevOps Engineer at ABLY · Seoul, Korea
I work on Kubernetes, AI agent infrastructure and the data platform.
When an open-source tool breaks in production, I read the source and fix it upstream.
# $ kubectl get engineer sehwan-kim -o yaml
apiVersion: kimsehwan96.com/v1
kind: Engineer
metadata:
name: sehwan-kim # 김세환
labels:
nickname: hayden
role: devops-engineer
company: ably
location: seoul
spec:
experience: 6y+ # since 2020.03
career: [ingkle, lendit, nrise, ably] # SWE → DevOps → SRE → DevOps
focus:
platform: [kubernetes, eks, karpenter, istio, argo-cd, terraform]
ai-infra: [mcp-gateway, a2a, agent-platform]
data-platform: [trino, apache-ranger, starrocks, spark-on-emr]
shippedUpstreamIn: [python, typescript, javascript, java, go, rust]
maintains: [pyjosa] # Korean particle (은/는, 이/가) library on PyPI
education: Tech University of Korea · Electronic Engineering (Embedded Systems)
status:
phase: Running
conditions:
- type: FixesItUpstream
status: "True"
- type: WritesItDown
status: "True"
message: https://www.kimsehwan96.comMost of my contributions start from a real problem, usually something that broke in production or docs that didn't match the code. I dig into the source, file an issue with the root cause, and send the fix.
49 merged pull requests · 24 upstream projects
🛰️ One MCP gateway for the whole company
Every engineer's agent reaches internal tools through a single gateway, with team RBAC and OAuth token delegation.
📝 흩어진 MCP를 게이트웨이 하나로 모아 전사 공통 인프라로 만들기까지 (ABLY tech blog) · 사내 단일 MCP Gateway 도입기
- IBM/mcp-context-forge: IdP-issued token verification via JWKS (#3715), tool execution for team viewers (#3882), OAuth authorization for non-owners (#3935), A2A protocol version selector (#4761) and a run of OAuth/UI fixes
- agentgateway: RFC 8414 discovery for path-based issuers (#1206)
- n8n: MCP OAuth
audnow matches the advertised resource (#30055)
🔐 Per-user access control on Trino
Apache Ranger policies, with users and groups synced from Google Workspace Secure LDAP.
📝 Trino 에 접근제어 붙이기 1편 · 2편
- apache/ranger: groups removed from LDAP get hidden (RANGER-5461), membership changes reach the plugins (RANGER-5463), delta sync can be turned off for LDAP servers without
uSNChanged(RANGER-5466) - getredash/redash: Trino user impersonation, so queries run as the signed-in user (#7605)
☸️ An HA on-prem Kubernetes design
Control plane, etcd and kubeadm internals.
📝 etcd 의 snapshot 과 WAL · kube-apiserver 와 etcd 통신
- kubernetes-sigs/kubespray: the reset playbook now fully removes the etcd systemd units (#10902)
- kubernetes/kubernetes: corrected the kubeadm control-plane join comment for external-etcd HA (#124920)
- etcd-io/website: storage and recovery guide fixes (#827, #833)
| Area | Projects · merged PRs |
|---|---|
| 🤖 AI & agent infra | IBM/mcp-context-forge 11 · BerriAI/litellm 3 · a2aproject/A2A 1 · agentgateway/agentgateway 1 · kagent-dev/kagent 1 · n8n-io/n8n 1 |
| 📊 Data platform | apache/ranger 3 · apache/superset 2 · getredash/redash 2 · influxdata/docs-v2 1 · plotly/plotly.js 1 · trinodb/trino-gateway 1 |
| ☸️ Kubernetes & cloud native | aws-samples/custom-scheduler-eks 3 · kubernetes-sigs/kubespray 3 · etcd-io/website 2 · open-feature/open-feature-operator 2 · aws/amazon-vpc-cni-k8s 1 · kubernetes/kubernetes 1 |
| ☁️ Cloud, IaC & CI/CD | awslabs/amazon-documentdb-tools 4 · aws-iot-builder-tools/aws-greengrass-provisioner 1 · hashicorp/vault 1 · jenkinsci/jenkins 1 · serverless/serverless-python-requirements 1 · terraform-aws-modules/terraform-aws-eks 1 |
merged PRs per year
2021 ███ 3
2022 █ 1
2023 ██ 2
2024 ████████████ 13
2025 ████ 4
2026 ████████████████████████ 26
All 49 merged pull requests
- Trino 에 접근제어 붙이기 : Google Workspace Secure LDAP 을 Ranger 에 연결하기 2026-08-11
- Trino 에 접근제어 붙이기 : Apache Ranger 는 무엇이고 어떻게 동작하는가 2026-08-02
- 간헐적인 502 는 어디서 오는가? (feat: NLB draining 과 istio 의 terminationDrainDuration) 2026-07-25
- 사내 단일 MCP Gateway 도입기 (feat: IBM mcp-context-forge) 2026-07-19
- ECR Pull-Through Cache 적용기(feat: Docker Rate Limit 을 피해서) 2025-02-27
More on kimsehwan96.com, where I write (in Korean) about Kubernetes internals, Istio, etcd, AWS and MCP/AI infrastructure.




