Skip to content
View sindredg's full-sized avatar

Block or report sindredg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sindredg/README.md

Sindre Grytebust: Infrastructure, Identity, Security

Featured project   ·   Selected work   ·   All repositories

Cloud platforms and the identity systems around them.
Build notes, architecture decisions, testing, and troubleshooting.


Featured project


Completed lab   /   Google Cloud + Kubernetes

Kubernetes platform & AI security triage

A private GKE cluster serving public workloads. Keyless delivery, measured rollouts, failure drills, and an AI agent that triages security findings.

Explore the project   ·   Decisions   ·   Worklogs   ·   Shutdown notes

Infrastructure retired in September 2026; code, worklogs, and validation notes remain.

125 req/s

8 Pods · no failures

70.5 s

Median deployment

72 → 0

Rollout connection failures

Terraform GKE GitHub Actions Cloud Armor Vertex AI Go

Under the hood: platform, delivery, and AI triage
  • Platform: private nodes, custom VPC, Cloud NAT, Gateway API, managed TLS, and autoscaling across three zones.
  • Delivery & operations: keyless federation, immutable images, gated rollouts, default-deny networking, Cloud Armor, and failure drills.
  • AI triage: Security Command Center findings flow through Pub/Sub to a worker with four scoped grants. Rules run before Vertex AI; verdicts go to an append-only ledger.

Selected work

Workforce identity across clouds. Federation, SCIM provisioning, and governed access to AWS.

ENTRA ID   /   AWS   /   TERRAFORM

Hub-and-spoke networking with an encrypted cross-premises tunnel, private endpoints, and two-way DNS.

AZURE   /   VPN   /   PRIVATE LINK

A two-site Active Directory forest synced to Entra ID, with hybrid endpoints and policy-enforced security baselines.

AD DS   /   ENTRA ID   /   POWERSHELL

A public web tier and private API, with passwordless image pulls, scale-to-zero, and automated delivery.

TERRAFORM   /   CONTAINERS   /   CI/CD

Other projects
  • AI security triage: Rules, scoped model access, and an auditable verdict ledger for cloud security findings.
  • Identity governance: Conditional Access, just-in-time administration with PIM, and access reviews.
  • Grafana SSO & provisioning: OIDC sign-in, app-role mapping, and a custom SCIM bridge.
  • Sky: An application deployed on the Kubernetes platform.
  • OAuth 2.0 in .NET: API authorization through scopes, app roles, groups, and token claims.
  • Azure MCP & RBAC: Scoped, read-only Azure access for Claude, enforced through Azure RBAC.


Notes on building and testing cloud infrastructure.

Pinned Loading

  1. cross-cloud-entra-aws cross-cloud-entra-aws Public

    Cross-cloud workforce identity from Entra ID to AWS IAM Identity Center using SAML, SCIM, access packages, JML workflows and Terraform-managed permission sets.

    HCL

  2. hybrid-network-az hybrid-network-az Public

    Azure hub-and-spoke joined to a simulated datacenter over IPsec, with firewall inspection, private endpoints, Bastion and bidirectional hybrid DNS.

    HCL

  3. k8-lab k8-lab Public

    A private kubernetes cluster in GKE, a couple of workloads, and an AI agent that handles security findings.

    HCL

  4. k8s-dr k8s-dr Public

    Python