Featured project · Selected work · All repositories
Cloud platforms and the identity systems around them.
Build notes, architecture decisions, testing, and troubleshooting.
|
Completed lab / Google Cloud + Kubernetes A private GKE cluster serving public workloads. Keyless delivery, measured rollouts, failure drills, and an AI agent that triages security findings. Explore the project · Decisions · Worklogs · Shutdown notes Infrastructure retired in September 2026; code, worklogs, and validation notes remain. | ||
| 8 Pods · no failures |
Median deployment |
Rollout connection failures |
Terraform GKE GitHub Actions Cloud Armor Vertex AI Go
Under the hood: platform, delivery, and AI triage
- Platform: private nodes, custom VPC, Cloud NAT, Gateway API, managed TLS, and autoscaling across three zones.
- Delivery & operations: keyless federation, immutable images, gated rollouts, default-deny networking, Cloud Armor, and failure drills.
- AI triage: Security Command Center findings flow through Pub/Sub to a worker with four scoped grants. Rules run before Vertex AI; verdicts go to an append-only ledger.
Other projects
- AI security triage: Rules, scoped model access, and an auditable verdict ledger for cloud security findings.
- Identity governance: Conditional Access, just-in-time administration with PIM, and access reviews.
- Grafana SSO & provisioning: OIDC sign-in, app-role mapping, and a custom SCIM bridge.
- Sky: An application deployed on the Kubernetes platform.
- OAuth 2.0 in .NET: API authorization through scopes, app roles, groups, and token claims.
- Azure MCP & RBAC: Scoped, read-only Azure access for Claude, enforced through Azure RBAC.
Notes on building and testing cloud infrastructure.



