PLATFORM-MINDED SOFTWARE ENGINEER · JAPAN
Harumi Morikawa
Platform / Backend Engineer
Enterprise Java applications, Camunda workflow systems and a self-managed Kubernetes platform — built, deployed and operated end to end.
I turn fragmented applications, infrastructure and operational knowledge into systems that are easier to run, debug and change.
- BUILD
- Product systems
- OPERATE
- Self-hosted Kubernetes
- INVESTIGATE
- Incidents and evidence
harumi.uk · self-hosted · 3 public apps · 6 systems running privately
03What I bring
- 01
Operate real systems
I work beyond feature delivery — deployment, observability, incident investigation and recovery are part of the system.
- 02
Connect application and infrastructure
I trace problems across Java, Camunda, Kafka, Kubernetes, Envoy, GitOps and identity boundaries.
- 03
Turn incidents into knowledge
I document assumptions, evidence, rejected fixes and decisions so that failures become reusable engineering knowledge.
04Selected systems
01
MakeUp
Solo developer & operatorA relationship app for any close pair where each feature publishes to the same Kafka topic, and persistence, SSE and Web Push all happen in one flow.
Spring Boot · Next.js · Kafka · PostgreSQL
Read the write-up →02
Camunda 8.8 operations
OperatorTasklist182 requests / 88 connections
commonHttpProtocolOptions.maxRequestsPerConnection: 1問題は、追加した「修正」だった。
The fix was the problem.
Evidence over guesswork.The full Camunda 8 stack behind a single OIDC domain. Envoy measurements identified — and retired — a connection setting that was making latency worse.
Camunda 8.8 · Zeebe · Keycloak · Envoy
Read the write-up →03
Home Kubernetes platform
Platform ownerSynced は、必ずしもデプロイ完了ではない。Synced is not always deployed.
Seven services on two bare-metal nodes behind one gateway, now fronted by a single console for health, resources and docs. Every deploy goes through the same two-stage GitOps pipeline.
Kubernetes · ArgoCD · GitLab CI · Cloudflare
Read the write-up →04
Harumi Platform
Solo developer & operatorRole: get,list on pods · namespace-scoped, no secrets退役は、削除ではない。
Retire the surface, not the data.
3 ops surfaces → 1 console, zero downtime.Three admin tools retired into one console. The rule for retiring any of them: port what it does first, then re-home whatever infrastructure was quietly living in its namespace, then delete.
Next.js · Kubernetes RBAC · ArgoCD · Go
Read the write-up →05NOTES
Incident Method
Problems that took time to isolate, and the evidence behind each decision.
- An opacity animation was trapping the fixed elementsModal hiddenraise z-indexinspect paint orderremove opacity stacking context
- chroot /host was not the live nodeNode mount missingtrust chroot /hostinspect namespacesdelegate through host systemd
- 697 connections for 778 requestsExternal access slowforce new connectionsinspect Envoy statsremove speculative fix
- A hand-signed token was correctly rejectedNo live ArgoCD datahand-sign a token, skip the passwordinspect the "revoked" checkreset password, use the real endpoint
- The PVC was never actually the blockerWorkload rebalance stalledassume storage pins the nodeinspect a workload already running cross-nodemove three services onto the other node
06CURRENT / 2026
Platform reliability
AI-assisted document processing
Operational writing
07ABOUT
Based in Japan
中文 · 日本語 · English
Platform / Backend Engineer
Verify the source of truth.
Remove, don’t layer.
Ship, listen, revert honestly.