Building and operating production-style infrastructure — CI/CD, GitOps, Kubernetes policy enforcement, and observability, end to end. Based in the Netherlands.
A Flask app operated like a real production system: GitHub Actions CI (Bandit, pytest, Trivy), ArgoCD GitOps deployment, Kyverno admission control policies (blocking pods with no resource limits or privileged containers), and a full Prometheus/Grafana/Alertmanager observability stack with Slack alerting.
Foundational Kubernetes and Terraform learning repo — Deployments, RBAC, NetworkPolicies, and Terraform modules built and applied against real AWS infrastructure, with tfsec/checkov scanning.