Skip naar content
de_sprint
Bas Franken

Bas Franken

AI Platform Engineer @ Cloudchamps

Bas werkt sinds 2025 bij Cloudchamps als AI Platform Engineer. Hij bouwt aan een intern cloudplatform op Azure en AWS waarop klantteams hun eigen omgevingen uitrollen, en aan de AI-tooling daaromheen.

De kern is een Terraform-modulebibliotheek op Azure Verified Modules: tientallen herbruikbare bouwblokken en kant-en-klare patronen voor onder meer AKS, Key Vault, SQL, storage en netwerk, waarmee vijf klantteams consistent en veilig uitrollen. Security zit standaard ingebakken, elke module heeft geautomatiseerde tests en versies lopen automatisch bij via Renovate.

Daarbovenop ontwikkelde hij de landing zone die per klant een complete Azure-omgeving neerzet: hub-and-spoke of Virtual WAN met firewall en VPN, eigen Azure Policy-definities, monitoring, toegangsbeheer en geautomatiseerde uitgifte van subscriptions. Klantconfiguratie in YAML gaat via een zelfgebouwde Python-vertaler naar Terraform. CIS Level 1 is de standaard en Level 2 is per omgeving inschakelbaar. Er is tooling om bestaande omgevingen zonder herbouw onder beheer te brengen, en een accelerator voor nieuwe omgevingen op Azure, AWS en GCP.

Op AWS bouwde hij dezelfde fundamenten: een cloud foundation en centrale Terraform-modules die gehard zijn volgens CIS Level 1 en 2, een AI-foundation, en een opzet met Amazon Bedrock AgentCore. De AI-gateway die daarop draait laat developers Claude-modellen binnen de EU gebruiken via Bedrock, met uitgavenlimieten per developer, team en organisatie en inloggen via Entra ID.

Aan de AI-kant bouwt hij MCP-servers in TypeScript waarmee assistenten zoals Claude Code veilig met interne systemen werken, waaronder een server die de Terraform-catalogus doorzoekbaar maakt. Daarnaast een set read-only agents die platformtaken ondersteunen en elke wijziging als pull request voorstellen, en een onboardingassistent op LangGraph en Azure AI Search.

Verder werkt hij aan Aurora, een intern developer-portaal in .NET 10 en Blazor met dashboards voor cloudkosten, secrets, governance en AI-verbruik, gevoed door collectors in Python en FastAPI. Daarvoor zette hij bij Bimcollab een Azure cloud foundation in Bicep neer, met management groups, landing zones, een hybride VPN-koppeling en volledige CI/CD via Azure DevOps. Hij streamt sinds 2019 op Twitch.

Vakgebieden

  • Platform engineering
  • AI agents
  • Agentic AI
  • Microsoft Azure
  • Amazon Web Services
  • Terraform
  • Azure Verified Modules
  • Bicep
  • Infrastructure as Code
  • Azure Landing Zones
  • CIS Benchmarks
  • Model Context Protocol
  • Azure DevOps
  • Python
  • FinOps
  • Cloud security
  • Amazon Bedrock
  • AWS AgentCore
  • Multicloud

Certificeringen

  • Azure Solutions Architect Expert (AZ-305)
  • Cybersecurity Architect Expert (SC-100)
  • Microsoft 365 Administrator Expert (MS-102)
  • Azure AI Engineer Associate (AI-102)
  • Azure Administrator Associate (AZ-104)
  • Identity and Access Administrator Associate (SC-300)
  • Power BI Data Analyst Associate (PL-300)
  • Security in Azure en Microsoft 365: Pentest Azure/Microsoft 365
  • Azure Fundamentals (AZ-900)
  • Azure AI Fundamentals (AI-900)
  • Azure Data Fundamentals (DP-900)
  • Security, Compliance and Identity Fundamentals (SC-900)
  • Microsoft 365 Fundamentals (MS-900)
  • Power Platform Fundamentals (PL-900)

Applied Skills

  • Integrate model context protocol tools with agents in Microsoft Foundry
  • Develop an agent with integrated tools
  • Secure AI Solutions in the Cloud
  • AWS Agentic AI Demonstrated
  • Implement knowledge mining with Azure AI Search
  • Develop generative AI apps with Azure OpenAI and Semantic Kernel
  • Build a natural language processing solution with Azure AI Language
  • Create an intelligent document processing solution with Azure AI Document Intelligence
  • Deploy cloud-native apps using Azure Container Apps
  • Implement security through a pipeline using Azure DevOps
  • Automate Azure Load Testing by using GitHub Actions
  • Secure Azure services and workloads with Microsoft Defender for Cloud regulatory compliance controls
  • Configure secure access to your workloads using Azure networking
  • Secure storage for Azure Files and Azure Blob Storage
  • Deploy and configure Azure Monitor
  • Deploy and manage Microsoft Azure Arc-enabled servers
  • Deploy and administer Linux virtual machines on Microsoft Azure
  • Administer Active Directory Domain Services
  • Get started with identities and access using Microsoft Entra
  • Get started with cloud security and monitoring tasks
  • Get started with Azure management tasks
  • Implement retention, eDiscovery, and Communication Compliance in Microsoft Purview

Afleveringen met Bas Franken

Elders