I build cloud-native platforms where infrastructure, automation, security, and AI meet.
Working across Kubernetes, Terraform, GitOps, CI/CD, observability, DevSecOps, and AI infrastructure.
I’m interested in one question:
How do we make complex infrastructure easier to operate without making it less secure?
Currently exploring platform engineering, autonomous operations, secure software supply chains, and distributed cloud systems.
- Cloud-native platforms
- Kubernetes & platform engineering
- AI-powered operations
- Secure software supply chains
- GitOps & observability
- Infrastructure automation & FinOps
What if a vulnerability could trigger its own remediation — and then prove the fix works?
AI-driven CVE remediation pipeline for container workloads.
- Trivy → detect
- LLM → patch
- Docker → build
- KinD → validate
- Trivy → verify
- GitHub → review
- Ollama for local inference
- Gemini / OpenAI providers
- AI-generated
Dockerfile.patched - Controlled transformation pipeline
- Docker syntax validation
- Hallucination defense
- Runtime verification
- CrashLoopBackOff detection
- RBAC-aware execution
- Automated PR evidence
🔗 Repository: https://github.com/barbaria888/SupplyChain-Guardian-AI-Github_Action
What if Kubernetes troubleshooting could remember what happened last time?
An AI-assisted operations system combining cluster signals, historical incidents, reasoning, and controlled remediation.
- Detect
- Retrieve context
- Reason
- Propose
- Approve
- Remediate
React + Vite → FastAPI → AI → ChromaDB → Kubernetes
Ollama / Gemma / NVIDIA NIM
K8sGPT / Kubernetes API / kubectl
- Human approval
- RBAC boundaries
- Destructive-operation guardrails
- Local inference
- Incident history
- Auditability
🔗 Repository: https://github.com/barbaria888/KubeOps-AI
What happens when developers stop managing infrastructure directly?
A configuration-driven Internal Developer Platform reference architecture for GitOps, multi-environment delivery, observability, tenancy, and FinOps.
config.yaml → Argo CD → Kubernetes
- Test / Stage / Prod
- App-of-Apps
- ApplicationSet Matrix
- Terraform
- Kubernetes / k3s
- Floci
OpenTelemetry → Prometheus / Loki / Tempo → Grafana
OpenCost → namespace-level cost visibility
- Namespace isolation
- NetworkPolicy
- ResourceQuota
- LimitRange
- GitOps configuration
- Golden paths
- Standardized onboarding
🔗 Repository: https://github.com/barbaria888/FrugalZeus
| ☁️ Cloud & Kubernetes | ⚙️ DevOps & Platform | 🔐 Security |
|---|---|---|
| Architecting with Google Kubernetes Engine — Specialization | DevOps Foundation — Linux & Systems | Google Cloud Security Engineer Labs |
| Architecting with Google Kubernetes Engine: Workloads | Mastering Docker & Containers | Model Armor — Securing AI Deployments |
| Professional Cloud Architect — Certification Preparation | Application and DevSecOps | Vulnerability Management for Platform Engineers |
| Professional Cloud DevOps Engineer — Certification Preparation | Azure Pipeline Agents & Pools | GKE RBAC / NetworkPolicy / Private Cluster Labs |
| Observability in Google Cloud | Monitoring & Observability for DevOps | |
| Logging & Monitoring in Google Cloud | GitOps with Argo CD | |
| Introduction to Data Engineering on Google Cloud |
| 🤖 AI Infrastructure | 🏗️ Applied Architecture |
|---|---|
| Build & Deploy Agents in Production | GKE Distributed Tracing |
| MCP Tools with Google ADK Agents | Cloud Ops Agent |
| Model Context Protocol | BigQuery / Dataform Pipelines |
| Google Agent Development Kit | Event-driven Cloud Storage → BigQuery |
| OWASP LLM Security | Datastream → BigQuery CDC |
| Ollama / Gemma | Secure GKE Architecture |
| Agentic Kubernetes Operations | IAM / RBAC / Pod Security / NetworkPolicy |
OBSERVE IN SILENCE · BUILD IN DEPTH · STRIKE WITH PRECISION
Engineered beneath the surface. Proven where it matters.





