Senior Network Automation Engineer

I turn manual network operations into reliable software.

12+ years in network engineering and 15+ in telecom. I build the automation and platforms that let large service-provider networks be changed safely, at scale: Python and Go services, Kubernetes, Ansible, CI/CD pipelines, and the validation that keeps production healthy.

Download résumé Get in touch LinkedIn GitHub

Portrait of Travis Sandmann
70,000+network elements on the platform
1,000+devices turned up with my zero-touch provisioning
700+routers upgraded with my automation
2–4 → 10–20safe concurrent upgrades per run
PythonGoKubernetesCI/CDGitOps · ArgoCDAnsibleDockerLinuxPrometheus · GrafanaBGP · MPLS · Segment RoutingAll skills →

Selected professional work

Projects from my time at Cox Communications, described at a high level. Happy to go deeper in conversation.

Network engineering platform

Internal platform aggregating topology, inventory, telemetry, and service data for 70,000+ network elements, used by 1,000+ employees. Python and Go microservices on Kubernetes, with dashboards, Redis caching, and Prometheus/Grafana monitoring.

PythonGoKubernetesRedis

Multi-vendor zero-touch provisioning

A Python bootstrap that devices fetch over DHCP/HTTP, detect their own platform, pick the right software, and upgrade themselves across Juniper, Cisco, and Arista. Paired with a service that resolves the correct production config from a serial number. Used on 1,000+ turn-ups.

PythonZTPDHCPREST APIs

Nationwide software-upgrade automation

Staged Ansible/AWX workflows for 700+ IOS XR routers plus Nexus, Arista, and Juniper, with routing and service verification and failure gates. Raised safe concurrency from 2–4 devices to 10–20.

AnsibleAWXValidation

Reproducible network labs

A Go-based platform, built on Containerlab, that creates reproducible network labs derived from production for testing, troubleshooting, and change validation.

GoContainerlabLabsChange validation

Segment Routing & telemetry rollout

Replaced manual Segment Routing deployments with staged workflows that validate the underlay before traffic activation. Automated streaming-telemetry deployment and per-device certificate rotation across four vendors.

Segment RoutingTelemetryCertificates

Safe AI-assisted engineering

Daily use of AI coding agents for development, review, testing, and documentation, plus controlled tooling that gives agents structured platform context while blocking direct production-device access.

Claude CodeAgentsGuardrails

Projects I run in production

Beyond my day job, I design, build, and operate software and infrastructure for a working livestock and hay farm. The code is private; I'm glad to walk through architecture and decisions in an interview.

Self-hosted GitOps platform

A multi-cluster Kubernetes environment I designed and run end to end. ArgoCD is the source of truth for everything deployed; Kargo promotes first-party app images from dev to prod; Renovate keeps charts and third-party images current. Secrets are encrypted in Git with sops/age and decrypted in-cluster. A WireGuard mesh links the nodes so internal services never touch the public internet. Includes Prometheus/Grafana monitoring, SSO, S3-compatible object storage, Ansible-based node bootstrap, and documented backup and disaster-recovery procedures.

Kubernetes (k3s)ArgoCDKargoRenovatesops/ageWireGuardPrometheusGrafanaAnsible

CI/CD pipelines

Every change goes through pipelines I built. Gitea Actions builds a container image on each push: feature branches publish a dev image, merges to main publish the release image, and every pull request builds its own tagged image. An Argo CD pull-request generator deploys that image as an ephemeral preview environment at a predictable URL, a bot comments the link on the PR, and the environment is torn down when the PR closes. Kargo then promotes release images through dev and prod stages, with Renovate opening dependency-update PRs and sops keeping secrets encrypted in Git. The same pattern ships the farm app, the website, the game server, and the server list.

Gitea ActionsDockerArgo CD ApplicationSetsPR preview environmentsKargoRenovateGitOps

Farm management application

A FastAPI and MongoDB web app for livestock, pastures, hay inventory and sales, fields, and equipment, with a retail store (Square payments) and an LLM-assisted equipment troubleshooting agent. I built the foundation: the data model, modular routes, role-based access control, API tokens, a CLI, and a test suite. We've grown it together with my farm partner, who was new to software development when we started and whom I mentored along the way.

PythonFastAPIMongoDBRBACDockerCI/CD

Farm website & storefront

The farm's public Flask site, with product pages, a contact form, a live Facebook feed, and QR-code landing pages for printed campaigns. The /shop storefront is a thin server-rendered client of the farm app's key-authenticated API, so pricing and inventory logic live in one place and the API key never reaches the browser.

PythonFlaskREST APISquare

s4ndmod26: game mod & in-browser client

A Return to Castle Wolfenstein mod and community server, written mostly in C. The game client is compiled to WebAssembly, so anyone can play in the browser with nothing to install; browsers can't send raw UDP, so the client reaches the server through a UDP-over-WebSocket bridge. Native players get a one-command install for Linux and Windows. The site adds live server status, a live-watch view, and game history. Runs on Kubernetes through the GitOps platform above.

CWebAssemblyWebSocketsGame serverKubernetes

q3master: master server & server list

A Go reimplementation of the Quake 3-style master server, which game servers register with so players can find them. It backs a public RTCW / ET server list that tracks online servers, player counts, mods, and master uptime over time. Deployed through the same GitOps pipeline.

GoNetworkingUDP protocolsKubernetes

Data-driven farming decisions

The farm app keeps dated weights and events for every animal, plus hay inventory and equipment hours, so decisions can start from the record instead of memory. The litter comparison tool is the clearest example. Pick up to six litters and it lines them up by days since farrow (or AI date), so litters born weeks apart can be judged on equal footing. For each one it shows survivors and mortality, average and median weight, average daily gain, weight at 56 days, days to reach 50 lb, and the top individual growers, with middle-50% bands so one outlier pig doesn't mislead.

The point is to replace "that litter seemed good" with numbers when choosing which sows and boars to rebreed, which animals to keep as breeding stock, and which to sell or process. The same thinking runs through the rest of the app: weight alerts flag animals that are falling behind, and a maintenance dashboard shows which equipment is down or overdue. The screenshots below use fictional demo data, and the same boar produces the slowest litter with one sow and the fastest with another. That is the kind of result memory tends to miss, and the reason pairings get judged on the record rather than on any one animal.

Growth curvesAverage daily gainMortalitySire × dam pairingsWeight alertsMaintenance trackingChart.js

Commit activity

Less More · From my self-hosted Git server, where this work lives.

Skills

Automation & software
Python, Go, C, FastAPI, Flask, Ansible, AWX, Jinja, REST APIs, WebAssembly, dynamic inventory, zero-touch provisioning
CI/CD & GitOps
CI/CD pipelines, Jenkins, Gitea Actions, ArgoCD, Kargo (dev → prod promotion), Renovate, Kustomize, PR preview environments, container image build and release pipelines, Git-based Infrastructure as Code
Platform & infrastructure
Linux, Kubernetes (k3s), Docker, Containerlab, Traefik, Redis, MongoDB, S3-compatible object storage, backup and disaster recovery
Observability
Prometheus, Grafana, streaming telemetry
Security & access
sops/age secrets in Git, cert-manager and TLS, SSO (Authentik), WireGuard, TACACS+, RBAC, certificate rotation
Networking
BGP, OSPF, IS-IS, MPLS/LDP, Segment Routing, BFD, RSVP-TE, IPv4/IPv6, ECMP, L2/L3 services
Network platforms
Cisco IOS XR / IOS / Nexus, Juniper MX / QFX, Arista EOS, Nokia SR OS
AI-assisted engineering
Claude Code, Codex CLI, OpenCode, agentic workflows, controlled CLI/API integrations

Experience

  1. Apr 2024 – Present

    Senior IP Solutions Design Engineer

    Cox Communications · Platform Engineering / DevOps / Network Automation

    Build and support the internal network engineering platform. Python and Go services, Kubernetes, GitOps with Jenkins and ArgoCD, and shared production ownership of what the team ships.

  2. Oct 2019 – Apr 2024

    Senior Network Engineer, Network Automation Tiger Team

    Cox Communications

    Technical lead on a team chartered to stand up ZTP that grew into provisioning, validation, and upgrade automation. Led weekly reviews and mentored network engineers new to Python, Ansible, and software practices.

  3. Apr 2014 – Oct 2019

    Network Operations / Field Engineering Operations Engineer

    Cox Communications

    Production engineering across seven markets and 80+ hub sites. Led regional modernization, including the move from Cisco 7600s to ASR 9000, plus maintenance windows, escalations, and on-call.

  4. 2010 – 2014

    Technical Support Lead, then Field Service Assurance

    Cox Communications

    Started in inbound technical support and moved up to technical support lead. Then went into the field as a service assurance technician, gaining hands-on experience with equipment turn-ups and troubleshooting, including racking and cabling, fiber patching, and work in data centers and hub sites.

Recognition
Cox Gold Standard Award, 2022, for network automation contributions
Certification
Cisco Certified Network Associate (CCNA), active
Education
Associate Degree, Liberal Studies, Rose State College

How this page ships

This portfolio is deployed the same way as the apps above: a git push becomes a container image, a promotion, and a rollout on my own Kubernetes cluster, with one deliberate manual gate before production.

1. Open a pull request

Every change starts as a PR, and every PR gets its own environment.

  1. Branch & PRPush a branch and open a pull request in Gitea
  2. Gitea ActionsBuilds a preview image on a separate registry path, so it can never be promoted
  3. Argo CDNotices the PR within a minute and creates a throwaway namespace for it
  4. Preview environmentThe PR's own copy of the site comes up at its own URL
  5. PR commentA bot posts the link on the PR and keeps it current on every push
  6. Review & iterateEach commit rebuilds the preview. Merging or closing the PR removes it

2. Merge to ship it

Merging promotes the same image through staging to production, with a person in the loop before prod.

  1. Merge to mainThe PR's preview environment is torn down
  2. Gitea ActionsBuilds the release image, tagged like v26.10.01-ab12cd34
  3. Kargo → stagingSpots the new image and promotes it to staging automatically
  4. Manual gateI check staging, then approve the promotion to production in Kargomanual
  5. Argo CDSyncs the production manifests from my GitOps repo
  6. Kubernetes + TraefikRolls out new pods, served over HTTPS by Traefik and cert-manager

Let's talk

I'm interested in network automation, platform engineering, DevOps, and infrastructure roles where deep networking experience meets software.

travissandmann@gmail.com LinkedIn GitHub Résumé (PDF) Cover letter (PDF)

Oklahoma City, OK