Platform security
I build security into the platform itself: certificates, secrets, identity and access, and checks in CI.
Scope
-
Certificates and secrets
- cert-manager with an enterprise certificate authority
- External Secrets Operator with a cloud secret manager
- Trusted CA distribution across the cluster
-
Identity and access
- OIDC single sign-on
- Group-based RBAC
- Least-privilege service accounts
-
Secure delivery
- Secret detection in CI and pre-commit hooks
- Changes reviewed through merge requests
- Audit log forwarding
Relevant experience
- Set up cert-manager, External Secrets and OIDC sign-in on OpenShift at Telenet.
- Configured Argo CD with single sign-on group RBAC and a least-privilege controller role.
- Added secret detection to the CI of the GitOps repositories.
Scope and planning are agreed per engagement. The full background is in my CV (opens in a new tab).
Contact
- Phone
- +32 477 38 01 67
- Address
- Langstraat 65A, 2270 Herenthout, Belgium