
Rohan Patil
Senior Software EngineerFounding engineer on Contentstack Launch. The layers under the deploy button.
- Senior Software Engineer @ Contentstack · Launch
- Platform, cloud & distributed systems
- Mumbai, India
- --:--IST
- rohan.p@outlook.in
- github.com/ron766-CS
- linkedin.com/in/rohan-patil
I work on the parts of a hosting platform you only notice when they fail — build orchestration, edge routing and auth, cache invalidation, rollbacks, security scanning, and the observability to prove any of it works. On Launch since 2021, across AWS, Google Cloud, Azure and Cloudflare.
- years engineering
- 7+
- 2018 → present
- clouds in production
- 4
- AWS · GCP · Azure · Cloudflare edge
- Jira projects contributed to
- 19
- across Launch work, 2021 → now
- platform deliveries, end to end
- 3
- FY25‑26: Bitbucket Cloud, IAM keys, cache revalidation
The platform
Launch, and the layers I've owned
A multi-cloud hosting and deployment platform for enterprise websites: Git-connected builds, containerised and serverless runtimes, an edge layer with cache control and streaming functions, and the routing that puts a deployment behind a customer's domain.
Each layer below is a one-line summary; the numbers link to the case studies that go deep.
- 01
Build & delivery plane
— Multi-stage build orchestration; GitHub, Bitbucket Cloud and plain upload as sources.Study06 - 02
Multi-cloud runtimes
— Containers and serverless on AWS, Google Cloud and Azure, with HTTP streaming on all three. - 03
- 04
Public API
— A REST layer beside GraphQL, one merged OpenAPI surface, pen-tested before exposure.Study05 - 05
- 06
Observability & analytics
— Event and log pipelines on Kafka, RabbitMQ, Redis and OpenSearch; HTTP traffic analytics on ClickHouse with sub-second percentiles.Study03
Also shipped
HTTP streaming across the clouds
Chunked transfer encoding on every cloud Launch runs on, a per-environment toggle, basic-auth in streaming mode, benchmarks and load tests after the change landed.
Cache revalidation customers can drive
Purge by domain and by cache tag off the header NGINX sets, wired into the Automate connector so an editor can trigger it without an engineer; a Kafka-backed batching design for volume.
Multi-cloud resource cleanup
Orphaned serverless resources and CloudFormation stacks removed across AWS, Azure and GCP, then a cloud-agnostic cleanup script so it stops being a manual migration.
On-call, benchmarks, checklists
Set up on-call for Launch services, benchmarked deploy time and TTFB against Netlify, Vercel and Gatsby Cloud, and wrote the Go-Live checklist new customers are onboarded with.
Case studies
Seven pieces of Launch, in depth
- 01
Security · new product area
Customer code security scanning
A two-plane scanning architecture — SBOMs, vulnerability matching and secret detection over every customer deployment — with a fail-open guarantee so it can never block a deploy.
- 2planes: build & analysis
- 300shard cap, fail-open
- 74%rule overlap found, Trivy vs Gitleaks
- 02
Edge · architecture
Edge SSO for Private Environments
A two-stage Cloudflare Worker pipeline that locks a customer's non-production sites to their own organisation's SSO — with session handling that survives a 60-minute token expiry and an instant offboarding kill-switch.
- 2stage edge pipeline
- 60 mintoken expiry, decoupled from session
- 0trailing access after offboarding
- 03
Observability · data engineering
HTTP traffic analytics on ClickHouse
From a CDN-analytics spike to a shipped query API: a ClickHouse engine that gives customers a real-time view of requests, bandwidth, status codes and latency percentiles — sub-second, on pre-aggregated data.
- <1sp50 / p90 / p99 queries
- 1 minpre-aggregation grain
- 4telemetry sources unified
- 04
Reliability · design
Instant Rollbacks
A technical design for rolling back a bad deploy at the routing layer — rewiring which deployment receives traffic instead of rebuilding — so recovery costs a routing update, not a build.
- 1routing update per rollback
- 0rebuilds
- 05
Platform · API
Making the Launch API public
A REST layer alongside the internal GraphQL API, a single merged OpenAPI surface, public domains, pen-tested and documented before exposure.
- 2services given REST layers
- 1merged OpenAPI spec
- 1InfoSec pen test before launch
- 06
Integrations · epic
Bitbucket Cloud, end to end
Bitbucket Cloud as a first-class Git provider — OAuth, token lifecycle, persistence, backend, UI, a public Marketplace app, and the procurement and vendor review to get there.
- 5teams coordinated
- 3environments staged to public
- 1public Marketplace app
- 07
Security · epic
Removing long-lived credentials
Static IAM access keys replaced with IAM roles across the platform's services, and Redis moved to TLS with a live dual-write cutover — the security debt that is easy to defer forever.
- 0static IAM keys left in Launch services
- 0downtime for the Redis cutover
How I work
Four habits the case studies keep showing
- 01
Shipped, measured, proven — in that order.
Streaming didn't count as done when it deployed; it counted when the benchmark report and the load test after the change said the same thing. If a claim can be measured, I'd rather measure it than assert it.
- 02
Decide the expensive question first.
Whether a scanner can run embedded and what its memory floor costs decides an entire architecture. I answer that before writing product code, so the cheap decisions downstream stay cheap.
- 03
Put invariants in code, not configuration.
Two access modes that must never coexist are checked at the edge worker on every request. Fail-open has a hard cap in the collector. Configuration drifts; enforced invariants don't.
- 04
Cleanup is part of the design.
A rollback design that doesn't say when old deployments are deleted is half a design. Orphaned cloud resources bill until someone notices — so the cleanup script ships with the feature.

Seven years in, most of them on one platform. Before Contentstack I built admin platforms and back-office systems for enterprise clients — including a site on Contentstack's CMS, as a customer.
I like problems where the answer can be measured, and I'd rather write the design doc before the code than the post-mortem after it.
- Languages
- GoNode.jsTypeScriptJavaScriptLua
- APIs & architecture
- RESTGraphQLgRPCEvent-driven systemsDistributed systems
- Cloud & infrastructure
- AWSAzureGoogle CloudCloudflareKubernetesDockerTerraformCloudFormationGoCD
- Data & messaging
- KafkaRabbitMQRedisMongoDBElasticsearchClickHouse
- Edge & delivery
- NGINX/OpenRestyCloudflare WorkersCache control
- Frontend
- ReactReduxNext.jsReact Testing Library
- Practice
- Trunk-based developmentTDDObservabilitySecurity reviewsDesign docs
Career
2018 to now, in order
Full-stack product work for enterprise clients — admin platforms, back-office orchestration, and content-driven sites — mostly on React/Redux and Node.
- NBAAdmin Platforms — SKU & Package Management
- NBAOpen Identity Network (OPIN) Admin Portal
- SchneiderEnterprise web platform
- VMwareGovCloud BackOffice Orchestration
- TIBCODocumentation Platform
Founding engineer on Launch, Contentstack's multi-cloud hosting and deployment platform. Led architecture of the delivery plane and build orchestration, built high-performance APIs and services in Go and Node.js, designed the event and log pipelines, and developed edge routing and authentication on NGINX/OpenResty and Cloudflare Workers.
Joined as a founding engineer while the product was still called Contentfly. GitHub project import and deployment previews.
Request/response logging across every service; duplicate-deploy and CDN-purge bugs fixed; upload-based redeploys shipped.
Carried the rename to Launch through the codebase, benchmarked deploy time and TTFB against Netlify, Vercel and Gatsby Cloud, wrote the customer Go-Live checklist, and set up on-call for Launch services.
Serverless deploys on Azure Container Apps, Launch enabled across Azure and GCP, Cloudflare cache keyed per deployment via Terraform, audit logging, and the first named-account incidents.
REST layer and OpenAPI surface made public and pen-tested; Bitbucket Cloud shipped end to end as a marketplace app; IAM keys and plaintext Redis removed; cache revalidation by tag and domain.
Two-plane customer code scanning designed and prototyped; HTTP traffic analytics built on ClickHouse; edge SSO for private environments; the Instant Rollbacks design.
Education
Master of Computer Applications
MET Mumbai · 2021
B.Sc. Information Technology
Viva College · 2014
Recognition
Awards, and the things that don't fit a ticket
2024
Above and Beyond Award
Contentstack
2019
Rising Star Award
Raw Engineering
- 2023
Set up on-call for Launch services
Defined the rotation and paging for the platform's services before there was one.
- 2023
Go-Live checklist adopted for customer onboarding
Reliability, security, performance and cost — written once, handed to every new Launch customer since.
- 2023
Competitive benchmarks vs Netlify, Vercel, Gatsby Cloud
Deploy time and TTFB, head to head, used to set platform priorities.
- FY25‑26
Three platform deliveries in one fiscal year
Bitbucket Cloud integration, IAM key removal, cache revalidation — each owned end to end.
- 2025
Vendor risk assessment & procurement for a Git provider
Unusual scope for an engineer: the paperwork that let the Bitbucket integration exist at all.
- 2025
Public API pen-tested before exposure
InfoSec review as a gate, not a follow-up.
Writing
Notes from the platform
Status
No posts published yet. The first one is likely to be about why a security scanner should never be the reason a deploy fails.
Writing indexContact
Talk to me about platforms that have to stay up.
Distributed systems, deploy infrastructure, edge routing, security reviews, or a design doc you want a second pair of eyes on. Email is fastest; I reply from Mumbai, IST (UTC+5:30).
- GitHub · ron766-CS
- +91 82377 27221mobile
- Based in Mumbai, IndiaIST (UTC+5:30)