Matt Hainley

Matt Hainley

Infrastructure & DevOps

I build infrastructure that doesn't break, and I document it so the next person doesn't have to guess. Over a decade across state government, higher education, and private industry — networks, identity, cloud, and the automation that holds it all together.

DevOps Engineer at the Iowa County Engineers Association Service Bureau

Experience

2025 – Present

DevOps Engineer

Iowa County Engineers Association Service Bureau

Sole engineer for the Bureau's infrastructure, from the rack up. Costed vendor quotes against a custom build, then designed, racked, and cabled a hyper-converged Proxmox cluster — Ceph, software-defined networking, BGP into Cilium — and migrated the entire Hyper-V estate onto it, running old and new networks side by side throughout. Replaced a Kubernetes platform fifteen major versions behind with an automated Cluster API, Talos, Cilium, and Argo CD stack, with secrets and key rotation through 1Password. Migrated hMail to Microsoft 365 and Exchange with DKIM, DMARC, and SPF, retiring the managed security provider in favor of Defender and Intune.

2021 – 2025

Cloud & Infrastructure Lead

Iowa Health and Human Services·Iowa Department of Management

Led a team of four through a 10x expansion of the state's AWS footprint, owning security posture, cost management, and networking. Worked with HHS stakeholders and the AWS account team to scope and stand up a data lake over HHS databases, delivering it and its Quicksight dashboards through GitHub Actions. Architected and staged the replacement of aging Cisco and Hyper-V infrastructure with Nutanix and Palo Alto, migrating every VM with effectively no user downtime. When Iowa consolidated IT under the Department of Management in 2024, represented HHS in the statewide stakeholder and Gartner sessions that shaped the new structure, and served on the committees selecting the State's management platforms and its primary identity provider.

2017 – 2021

Cloud Network Systems Administrator

Grinnell College

Owned the identity stack — PKI, Active Directory, ADFS, Shibboleth IdP, and LDAP — and migrated authentication from ADFS to Azure pass-through agents. Re-architected campus DNS onto BlueCat with Ansible-deployed BIND secondaries in Azure. Automated RBAC and Microsoft licensing with PowerShell-driven dynamic security groups.

2015 – 2017

Systems and Network Administrator

VP Group & Aveda Institute Des Moines

Sole IT for a Midwest-spanning group of salons and schools. Replaced the aging network end to end to fix chronic multi-site connectivity problems, then built inventory, monitoring, patching, and Group Policy from scratch. Stood up onsite and offsite DR with Veeam.

Skills

Kubernetes
Cluster API, Talos, Cilium, Argo CD, Rook, Rancher
Virtualization
Proxmox VE, Ceph, ZFS, Proxmox Backup Server, Nutanix, Hyper-V, ESXi
Cloud
AWS, Azure, Cloudflare, Wasabi
Automation
Terraform, OpenTofu, Ansible, GitLab CI, GitHub Actions
Networking
Arista EOS, pfSense, BGP, Ubiquiti, BIND, BlueCat, Route 53
Identity
Active Directory, Entra ID, Okta, Duo, Shibboleth, PKI, 1Password
Platforms
Ubuntu, Flatcar, Windows Server, macOS, Microsoft 365
Scripting
PowerShell, Bash, Python

Education

University of Oklahoma

M.Ed., Instructional Leadership & Academic Curriculum

Harding University

B.A., English — Creative Writing