
Who I am#
I'm a DevSecOps-focused engineer. The core of my work is making security a native part of the pipeline rather than a bolt-on layer: embedding image scanning, signed artifacts and policy-as-code gates into CI/CD; building reliable, scalable and observable platforms on Kubernetes; managing infrastructure as code with Terraform/OpenTofu; and making everything visible through metrics, logs and traces.
My approach is opinionated and action-first: if a tool is no longer recommended in 2026, I say "don't" — I don't stay neutral. "It works" isn't enough — it has to survive production, oncall and audit.
What I do#
- Platform & Kubernetes — production-ready clusters, HPA/VPA/KEDA, multi-tenancy, secure defaults.
- GitOps & CI/CD — pull-based reconciliation with ArgoCD/Flux, fast and safe pipelines.
- DevSecOps — SLSA/SBOM, cosign signing, Trivy scanning, Kyverno/OPA policy, Falco runtime.
- Observability & SRE — OpenTelemetry, Prometheus, SLO/error budgets, incident response.
- IaC & Cloud — Terraform/OpenTofu modules, drift management, AWS.
- Compliance (TR/EU) — KVKK, GDPR, ISO 27001, SOC 2 — with engineering controls.
Philosophy#
"Style is not personal taste — it's a service. A consistently written repo reads like a single file even at 1,000 pages."
Good engineering is what's repeatable, measurable and handoff-able. Discipline over heroics; runbooks over one-off fixes; reproducible builds over "worked on my machine".
Stack & Skills#
Featured work#
-
The DevSecOps Handbook
A DevSecOps handbook with deep TR/EU regulatory coverage — 21 topics, 134 deep-dives, 85K+ lines. This site itself.
-
databases-stack
A one-command self-hosted stack for 4 databases + backup automation + Google Drive sync.
-
api-sentinel
Third-party API schema change detection — plugin-based, severity-aware.
-
All projects
file-crypter, wakapi-admin, cheat-sheet and more.
Get in touch#
For collaboration, opportunities or a question — reach out.