Skip to content
View bloogefest's full-sized avatar

Organizations

@sogeor

Block or report bloogefest

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bloogefest/README.md

George Sopin

DevOps engineer with a development background. I set up delivery from commit to cluster and run the cluster itself. Led a development team on a commercial project, and still write the services that live in the infrastructure I build.

Software Engineering student at RTU MIREA, Moscow. Writing code since 2020.


Infrastructure

Kubernetes Linux Istio Calico cert-manager containerd cri-o MetalLB Flannel Nginx Proxmox Packer Ansible Talos Linux cloud-init WireGuard Hyper-V

Hand-provisioned with kubeadm: a 5-node cluster with a 3-master HA control plane.

Golden VM images for Proxmox built with Packer: Ubuntu autoinstall, Kubernetes node images, Talos Image Factory schematics. Every template is tested by booting a clone.

Delivery

GitHub Actions Docker Git Nexus Bash Renovate pre-commit

From commit to cluster in one pipeline: tests, image builds with Docker Buildx, publishing to a self-hosted registry, rollout to Kubernetes.

Security & supply chain

OpenSCAP Trivy goss gitleaks ShellCheck zizmor OpenSSF Scorecard

Images scanned against the CIS Level 1 benchmark with OpenSCAP and for CVEs with Trivy, verified with goss. Hardened CI: actions pinned by SHA, minimal permissions, secrets scoped to protected environments; the cloud runner reaches the lab only through a per-job WireGuard peer, nothing is exposed to the internet. OpenSSF Best Practices passing badge and Scorecard.

Data & observability

PostgreSQL Kafka Prometheus Grafana Keycloak MongoDB CloudNativePG Strimzi Alertmanager MySQL

Stateful workloads through operators, not hand-written manifests. SSO on Keycloak, internal dashboards behind OAuth2 Proxy.

Development

Java Spring C++ C Python Rust JUnit OpenAPI Gradle Maven CMake NASM GAS FASM

Microservices in Java with Spring Boot. Systems code in C and C++: freestanding environments without libc, manual memory management, ELF and the linker.

Pinned Loading

  1. sogeor/images sogeor/images Public

    Hardened VM images for the sogeor platform: Packer templates for Proxmox (Ubuntu 24.04 base and Kubernetes) and a Talos Image Factory schematic, scanned with goss, OpenSCAP CIS and Trivy with SBOM.

    Shell

  2. sogeor/docs sogeor/docs Public

    Documentation of the sogeor DevSecOps platform: overview, cluster constructor, network, security and compliance, platform ADRs, runbooks and threat models, with pinned docs of every platform reposi…

    Python

  3. sogeor/workflows sogeor/workflows Public

    Reusable GitHub Actions workflows and composite actions for the sogeor DevSecOps platform: pinned, least-privilege CI building blocks.

    Shell