
Ben kimim?#
DevSecOps odaklı bir mühendisim. İşimin özü, güvenliği sonradan eklenen bir katman değil, pipeline'ın doğal bir parçası yapmak: CI/CD'ye taranan imaj, imzalı artifact ve policy-as-code kapıları gömmek; Kubernetes üzerinde güvenilir, ölçeklenen ve gözlemlenebilir platformlar kurmak; altyapıyı Terraform/OpenTofu ile kod gibi yönetmek; ve her şeyi metrics/logs/traces ile görünür kılmak.
Yaklaşımım yargılı ve eylemsel: bir araç 2026'da artık önerilmiyorsa "yapma" derim, nötr kalmam. "Çalışıyor" yetmez — production'da, oncall'da, denetimde ayakta kalması gerekir.
Ne yapıyorum?#
- Platform & Kubernetes — production-ready cluster, HPA/VPA/KEDA, multi-tenancy, güvenli defaults.
- GitOps & CI/CD — ArgoCD/Flux ile pull-based reconcile, hızlı ve güvenli pipeline'lar.
- DevSecOps — SLSA/SBOM, cosign imzalama, Trivy tarama, Kyverno/OPA policy, Falco runtime.
- Observability & SRE — OpenTelemetry, Prometheus, SLO/error budget, incident response.
- IaC & Cloud — Terraform/OpenTofu modülleri, drift yönetimi, AWS.
- Compliance (TR/EU) — KVKK, GDPR, ISO 27001, SOC 2 — mühendislik kontrolleriyle.
Felsefe#
"Stil 'kişisel zevk' değil, hizmet. Tutarlı yazılan repo, 1000 sayfa olsa bile tek dosya gibi okunur."
İyi mühendislik tekrarlanabilir, ölçülebilir ve devredilebilir olandır. Kahramanlık değil disiplin; tek seferlik çözüm değil runbook; "bende çalışıyordu" değil reproducible build.
Who I am#
I'm a DevSecOps-focused engineer. The core of my work is making security a native part of the pipeline rather than a bolt-on layer: embedding image scanning, signed artifacts and policy-as-code gates into CI/CD; building reliable, scalable and observable platforms on Kubernetes; managing infrastructure as code with Terraform/OpenTofu; and making everything visible through metrics, logs and traces.
My approach is opinionated and action-first: if a tool is no longer recommended in 2026, I say "don't" — I don't stay neutral. "It works" isn't enough — it has to survive production, oncall and audit.
What I do#
- Platform & Kubernetes — production-ready clusters, HPA/VPA/KEDA, multi-tenancy, secure defaults.
- GitOps & CI/CD — pull-based reconciliation with ArgoCD/Flux, fast and safe pipelines.
- DevSecOps — SLSA/SBOM, cosign signing, Trivy scanning, Kyverno/OPA policy, Falco runtime.
- Observability & SRE — OpenTelemetry, Prometheus, SLO/error budgets, incident response.
- IaC & Cloud — Terraform/OpenTofu modules, drift management, AWS.
- Compliance (TR/EU) — KVKK, GDPR, ISO 27001, SOC 2 — with engineering controls.
Philosophy#
"Style is not personal taste — it's a service. A consistently written repo reads like a single file even at 1,000 pages."
Good engineering is what's repeatable, measurable and handoff-able. Discipline over heroics; runbooks over one-off fixes; reproducible builds over "worked on my machine".
Stack & Yetkinlikler / Skills#
Öne çıkan çalışmalar / Featured work#
-
DevOps Notebook
Türkçe DevSecOps başucu kitabı — 21 konu, 125 deep-dive, 70K+ satır. Bu sitenin kendisi.
-
databases-stack
Tek komutla 4 veritabanı self-hosted stack + backup automation + Google Drive sync.
-
api-sentinel
- parti API schema değişikliği tespiti — plugin tabanlı, severity-aware.
-
Tüm projeler
file-crypter, wakapi-admin, cheat-sheet ve daha fazlası.
İletişim · Get in touch#
İş birliği, fırsat ya da bir soru için çekinme. / For collaboration, opportunities or a question — reach out.