Aditya Bhalerao

Software Engineer @ Geminus Space

Pune, MH, India · 08:21 pm IST

get in touch ->
Aditya Bhalerao, software engineer

I’m a backend software engineer focused on building reliable, scalable systems with Go, Python, Kubernetes, and distributed systems. I enjoy working close to infrastructure, designing APIs, orchestration platforms, storage systems, and data pipelines that solve real-world problems.

I’m particularly interested in distributed systems, cloud infrastructure, authorization, and space-data platforms. Outside work, I build systems from scratch, contribute to open source, and write about the engineering concepts I’m learning.

TechLanguages, tools, and infrastructure I work with
GoLang
GORM, Concurrency Patterns, Echo, gRPC, Gorilla Mux
Python
FastAPI, REST APIs
FastAPI
JWT Auth, Pydantic, Async Endpoints
Docker
Docker Compose, Containerization, Container Networking
Kubernetes
CKA, Helm Charts, Ingress, RBAC
Argo Workflows
Workflow Templates, DAGs, Container Orchestration
PostgreSQL
Transactions, Indexing, Joins
MongoDB
Transactions
InfluxDB
Flux Query Language, Data Retention, Backups
Keycloak
OIDC, Realm Management, Access Control, Magic Link Login
Experience3 backend roles since 2023

Geminus Space

October 2024 - Present

Software Engineer (Backend)

Unified Ground Ops Platform

  • Architected and built a multi-tenant platform supporting multiple satellites and ground stations, enabling end-to-end downstream data processing workflows—from pass schedule ingestion and event-driven pipeline instantiation, through registry-based data acquisition, configurable processing chains, and long-term archival systems—using microservices in Go.
  • Designed and implemented a reconciliation engine with concurrent control loops managing data pipeline lifecycles, orchestrating multi-stage Argo Workflows with dynamic workflow generation, artifact chaining across L0/L1/L2 stages, and MinIO-backed object storage.
  • Developed a binary TCP protocol client for SAFRAN CORTEX HDR, supporting chunked streaming downloads (∼1500 blocks/request) and complex state machines for session discovery, file listing, and telemetry block reconstruction, with Python-based mock servers for development and testing.

Unified Data Platform

  • Developed a Python-based catalog importer to ingest satellite imagery from ISRO's Bhoonidhi platform.
  • Integrated commercial SAR imagery from Umbra Space, building ingestion pipelines backed by AWS S3 public catalogs with support for GEC, SICD, and SIDD (NITF) data formats.
  • Implemented ingestion support for Planet Labs SkySat and Tanager catalogs, including recursive traversal of hierarchical catalog structures specific to Planet Labs datasets.

Geminus Tech

July 2024 - September 2024

Software Engineer (Backend)

Antaris

  • Integrated multiple internal services within the Antaris Cloud Platform, enabling reliable cross-service communication and improving overall platform orchestration.
  • Worked extensively on the Mission Orchestrator, contributing to task scheduling and optimization for satellite operations by factoring in satellite constraints and imaging order priorities.

Pyro

  • Implemented Keycloak-based authentication, API key management, and multitenancy, enabling secure tenant isolation and scalable access control.
  • Designed and built backend infrastructure primitives including organization-scoped data isolation, role-based authorization, and resilient API layers to support distributed services.

Diamanti

October 2023 - July 2024

SDE Intern (Backend)

  • Resolved 2 critical Kubernetes RBAC vulnerabilities in Ultimate Enterprise and Ultima Accelerator, strengthening least-privilege access and improving cluster security.
  • Contributed to KubeVirt integration within Diamanti's Kubernetes-native platform, testing and validating ∼30 VM pods per cluster across multiple clusters to support VM-based workloads and hybrid container–VM deployments.
EducationDegrees and grades

Savitribai Phule Pune University

Pune, India

Bachelor of Engineering - Computer Engineering

July 2020 - June 2024

CGPA: 9.02

Chhatrapati Shahu Vidyalaya & Jr. College

Kolhapur, India

Higher Secondary Certificate

July 2018 - March 2020

Percentage: 80%

Dr. D. Y. Patil's Academy Shantiniketan

Kolhapur, India

Secondary School Certificate

March 2018

Percentage: 95%

Open source7 pull requests and 4 issues across 4 projects
ProjectsThings built outside work

geotriage

Python · FastAPI · PostgreSQL · PostGIS · Docker · rasterio · MinIO · Ollama · React · MapLibre

A satellite imagery triage platform - describe a job in a sentence or draw it on a map, and it scores every matching archive image and ranks them green / yellow / red so analysts open only what matters.

+ details
  • Workflow builder agent - a sentence becomes a draft workflow, with a local 4B model calling tools for the catalogue and place lookup, answering through a tool call the server validates
  • The model proposes, the server decides - drafts are checked against the catalogue, dates and guardrails, sent back for up to 2 repairs, then turned into an honest refusal; geometry never passes through the model, only opaque place ids
  • Eval harness over 63 cases and 10 metrics - 0.95 on answer kind and 1.00 on schema validity, against a 0.23 always-asks baseline, with pinned dates, recorded geocoder answers and hash-versioned prompts so runs stay comparable
  • Pluggable detectors and data sources as Docker images on a shared base - new analyses are registered, never coded into the platform
  • Sandboxed runs - short-lived containers with read-only filesystems, dropped privileges, resource limits, and no network for detectors
  • Storage policies per workflow - keep imagery only for the scenes that scored Alert, or maps only, or scores only; the rest is deleted after scoring
  • Disk guardrails at three points - the draft, the form and the start of every run, sizing scenes by their overlap with the area and refusing before anything is downloaded
  • Cost-aware pipeline - filters cloud cover at search time, drops dull scenes from a low-res preview, and reads bands at the coarsest usable resolution
  • Archive-agnostic bands - Sentinel-2 and Landsat mapped to common names and physical units, so one detector runs on any source
  • PostgreSQL job queue - parallel workers, retries with backoff, crash recovery, and scheduled re-runs for continuous monitoring
  • React + MapLibre analyst app and a Python SDK with a CLI to validate plugins and test them on real scenes
  • 249 tests across the SDK and platform

causality-bench

Python · NumPy · pandas · NetworkX · SciPy · Matplotlib · Discrete-Event Simulation

An experiment measuring Lamport vs vector clocks - a deterministic simulator records the true event order independently of both, then scores how much ordering the cheaper clock loses and what the exact one costs.

+ details
  • Independent ground truth built from program order and message send/receive, never from either clock's timestamps
  • Same execution for both clocks, so every difference comes from clock design alone
  • Every pair checked - a precomputed ancestor index makes all ~50M event pairs per run a single lookup, verified against brute-force search and NetworkX transitive closure
  • 1,320 runs over 2-128 nodes, 5 topologies, 3 delay models, 6 message rates, and 16 loss/crash settings (30 seeds each) - Lamport misorders 95.4%-99.3% of concurrent pairs; vector clocks cost 16.3x more per receive and N× more metadata
  • Crash-recovery modeling - nodes keep clock state through outages to preserve ordering guarantees
  • 163 tests across the clocks, causality engine, simulator, metrics, and notebooks

overpass

Python · FastAPI · Skyfield · SGP4 · Geodesy · WebSockets · React · Docker

A live "what's above this point?" view - pick a location and radius to see the aircraft in that circle and the satellites overhead, including which are visible to the naked eye right now.

+ details
  • True naked-eye visibility - above the horizon, sunlit, and against a dark enough sky, computed with Skyfield and JPL's DE421 ephemeris
  • WGS-84 geometry that handles date-line crossings, polar areas, and true-circle trimming
  • Live orbits from CelesTrak propagated with SGP4, with data age reported since predictions drift ~1 km/day
  • Upstream-friendly caching - aircraft every 5s, orbits every 2h, concurrent identical requests collapsed into one call
  • Robust OpenSky client - cached OAuth2 tokens, retry on expiry, and rate-limit waits passed back to callers
  • Graceful partial failure - sources fetched in parallel and served over REST and a live WebSocket stream
  • Flight numbers from callsigns, decoded against 136 airlines to separate commercial from private traffic
  • Layered architecture (API → services → clients → domain), started with one `docker compose up`

cadutrace

Go · CCSDS · Binary Protocol Parsing · Bubble Tea · mmap

An offline analyzer for CCSDS spacecraft telemetry - unpacks raw ground-station recordings from transfer frames to reassembled packets to decoded data, producing a health report or an interactive terminal UI.

+ details
  • Packet reassembly across frames, detecting lost or truncated packets
  • Zero-copy mmap parsing - multi-GB, larger-than-RAM captures stream at ~1.6 GB/s
  • Wrap-aware gap detection classifies missing, duplicate, and out-of-order data across counter rollover
  • CFDP file-transfer tracking down to the exact missing byte ranges, even with out-of-order or overlapping pieces
  • Standards coverage - TM/AOS frames, Space/Encapsulation packets, CLCW reports, optional derandomization
  • Isolated, pluggable decoders selected by packet ID, so one crashing decoder can't stop the analysis
  • Two interfaces - a deterministic text/JSON report for CI diffs and a Bubble Tea TUI for browsing frames, packets, hex dumps, and transfers
  • Synthetic generator for byte-exact, lossy, gigabyte-scale test recordings

walrus

Go · Write-Ahead Log · Key-Value Store · HTTP API

A single-node persistent key-value store in Go (zero dependencies), fast in-memory reads backed by a segmented write-ahead log for durability and crash recovery, with optional per-key TTL.

+ details
  • WAL-first writes - every mutation is appended and fsynced to disk before the in-memory map is updated, so acknowledged writes survive crashes
  • Segmented binary log (64MB segments) with a 21-byte header + CRC32 per record (~25 bytes fixed overhead)
  • Crash recovery by replaying segments on startup in a single O(n) pass; corrupted tail entries are detected and skipped
  • Zero-allocation reads (0 allocs/op) served directly from the in-memory map
  • Per-key TTL with two-tier eviction, lazy on read plus a background sweeper goroutine
  • Zero external dependencies, built entirely on the Go standard library; HTTP/JSON API
  • Tested and benchmarked - 26 unit tests and 6 benchmarks across the WAL, store, and HTTP layers

meerkat

Go · gRPC · BadgerDB · Protocol Buffers · Consistent Hashing · Prometheus

A distributed key-value database with CRC32 consistent hashing, replication (factor 2), and automatic key migration as nodes join or leave the cluster.

+ details
  • Consistent hash ring (CRC32) with O(log n) lookup, adding a node remaps only ~1/N of keys, vs ~100% under modulo hashing
  • Synchronous replication (factor 2) with read fallback from primary to replica, tolerating a single-node failure
  • Automatic key migration on node join/leave, drain-before-remove and live ring reconciliation
  • Health monitoring over gRPC with automatic failure detection and node removal
  • 5-method gRPC service per storage node, backed by BadgerDB (pure-Go LSM engine)
  • Prometheus metrics and a /cluster topology endpoint; Docker Compose (1 manager + 3 nodes)
  • Tested and benchmarked - 28 unit tests and 7 benchmarks across the hashing and storage layers

otter

Go · gRPC · Raft · Protocol Buffers · Distributed Consensus

A from-scratch implementation of the Raft consensus protocol in Go over gRPC - leader election, log replication, and crash-safe persistence across a multi-node cluster.

+ details
  • Randomized leader election (150–300ms timeouts) with term-based voting and 50ms heartbeats
  • Log replication with per-follower nextIndex/matchIndex tracking, backtracking, and conflict truncation
  • Commit-safety rule - advances the commit index only on majority match of a current-term entry
  • Crash-safe persistence - currentTerm, votedFor, and the log written via atomic temp-file + rename, restored on restart
  • Replicated key-value state machine (SET/DEL) kept consistent across all nodes
  • Tolerates the loss of a minority of nodes (e.g. 1 of 3, 2 of 5); works for any odd cluster size

autorollout

Go · Kubebuilder · Kubernetes Controller · Client-Go · Docker

A CRD-free Kubernetes operator that triggers rolling restarts of Deployments when the ConfigMaps or Secrets they consume actually change.

+ details
  • Label-based opt-in (autorollout.io=true) and CRD-free - installs from a single YAML, no custom resources
  • Detects all 4 reference patterns (env valueFrom, envFrom, volume mounts, imagePullSecrets)
  • Event-filtered reconciliation - ignores Create/Delete and metadata-only updates, firing only on real data changes
  • Namespace-scoped Deployment scan rebuilds the dependency graph live from pod specs (no stored state)
  • Delegates the restart to Kubernetes' native rolling update via a pod-template annotation patch
  • Built on controller-runtime with RBAC, health probes, and an authn/authz-protected metrics server
  • End-to-end tested on a real Kubernetes (Kind) cluster - controller startup, pod health, metrics exposure, and restart-on-change

graphauth

Go · Neo4j · REST API · Docker · Graph Theory

A Zanzibar-inspired ReBAC authorization engine modeling permissions as a graph of relationships, resolving inherited access through bounded recursive traversal.

+ details
  • Relationships-as-edges model - Users, Groups, and Documents as typed nodes
  • Bounded recursive traversal (Cypher MEMBER_OF*0..15 + relation edge) resolving transitive, group-inherited access in a single query - O(path length)
  • Pluggable storage behind a GraphStore interface, Neo4j (bolt) and in-memory implementations
  • Stateless REST API for nodes, relationships, and permission checks, returning allow/deny + reason
  • Relation types - VIEWER, EDITOR, OWNER, MEMBER_OF with strict validation; Neo4j uniqueness constraints per label
  • Docker and docker-compose support for containerized deployment
  • 9 unit tests covering relationship and permission-traversal scenarios

Smaller builds

geotriage-sdk

The Python SDK for geotriage plugins - base classes for detectors and data sources, a CLI to validate them and test them against a live archive and a real scene, and the Docker base image every plugin builds on.

go-software-raid

User-space RAID 0/1/5/6 in Go, file-backed disks with block I/O through a RAID abstraction layer. RAID 5 (XOR) survives 1 disk failure and RAID 6 (Galois-field dual parity) survives 2; usable capacity 100/50/75/50%. Covered by 14 unit tests.

CoWIN-Slot-Finder

A vaccination-slot discovery web app from India's 2021 COVID drive, a React (Vite) SPA over a stateless FastAPI proxy to the public CoWIN API, with State -> District -> Center navigation and pincode search. No database, no auth; migrated from an original Django build.

Writing26 posts, all on Medium
PapersPapers and what I took from them
ContactThe form goes straight to my inbox

or, directly:

© 2026 Aditya Bhalerao

source · updated