██████╗ ██╗ ██████╗ ██╗ ██╔══██╗ ██║ ██╔══██╗ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ██████╔╝ ██║ ██████╔╝ ██║ ╚═════╝ ╚═╝ ╚═════╝ ╚═╝
$ kubectl describe deployment didi
Name: didi
Role: Cloud Platform Engineer @ idealo
Status: Kubestronaut
Focus: Managed EKS at scale · Internal Developer Platforms
Supply Chain Security
Exploring: Crossplane · Backstage · kagent
Events:
Reason Message
------ -------
JoinedTeam Cloud Platform Engineer @ idealo - Runtime team, building
mEKS: the managed EKS platform internal product teams
ship on
ProjectLaunched kubewhy - an LLM assistant that root-causes
Kubernetes issues with evidence
BlogPublished The Argo CD Vulnerability That Spreads From One Pod
to Your Entire Cluster: one compromised pod reaches the
repo-server and escalates to full cluster control - still no
patch, but one NetworkPolicy shuts the door
BlogPublished The Trivy CI/CD Hack: hijacked pipeline secrets
and the Kubernetes clusters they could reach
BlogPublished An AI Broke Into AWS Faster Than You Can Imagine: four
stolen keys, one IP, same second - how it happened and what stops it
$ kubectl config current-contextCloud Platform Engineer @ idealo — Runtime team
I work on mEKS, idealo's managed EKS platform: the Kubernetes foundation that internal product teams run their services on. Day to day that means:
- Fleet-scale EKS — multi-cluster provisioning and lifecycle as Terraform modules
- Guardrails, not gates — Kyverno ClusterPolicies that enforce best practice without blocking teams
- Networking — Cilium as CNI, IPAM and network policy across the fleet
- Capacity & cost — Karpenter provisioning, consolidation and disruption budgets; Descheduler for topology spread
$ kubectl get projects -l tier=featured- 🧠 kubewhy - Read-only Kubernetes assistant: an LLM inspects the cluster step by step, explains each check in plain English, and returns the root cause with evidence.
- 🏗️ eks-idp-platform - Production IDP on AWS EKS: Terraform, ArgoCD, Kyverno, Cilium, Karpenter, and supply-chain-hardened CI (SHA-pinned actions,
harden-runner, Trivy). - 🔐 tokenguard-operator - Kubernetes operator that scores ServiceAccount least-privilege by comparing RBAC grants against audit-log usage and detects external IP token abuse. Go, Kubebuilder, controller-runtime.
- 🥷 NinjaDevOps - Interactive DevOps challenge platform: 80+ real-world scenarios (Linux, Docker, CKA/CKAD/CKS) on live GCP VMs, all from a browser terminal.
- 🧬 vcluster-platform - The isolation of a real cluster at the cost of a namespace: teams get virtual Kubernetes clusters by opening a PR, with GitOps tenant onboarding.
- 🛠️ self-service-idp - Self-service IDP assembled from open-source parts (Kratix, Backstage, Flux) on k3s - the work was the integration. One command deploys the whole stack.
- 🛡️ practical-aks - Blank Azure subscription → Workload Identity-secured, Trivy-scanned AKS running a live LLM proxy, with supply-chain-hardened CI/CD (the attack it defends against).
$ kubectl get projects -l tier=platform - 2 more platform builds
- gke-production-patterns - Production-grade GKE reference architecture: Cloud SQL, Memorystore, Terraform, Helm, observability, Temporal workflows, incident response.
- Sovereign-Mesh - Multi-tenant AI PaaS on Hetzner: vLLM, Qdrant, and TEI on a hardened K3s cluster with tenant isolation and ArgoCD GitOps.
$ helm list -n stack$ kubectl get certifications
CKA ✓ CKAD ✓ CKS ✓ KCNA ✓ KCSA ✓ AWS-SAA ✓ → KUBESTRONAUT 🧑🚀$ kubectl get projects -n archive - older experiments
- k0s-hetzner-cluster - 2-node k0s cluster on Hetzner via Terraform
- terraform-aws-chatops-site - Deploy static sites by texting a Telegram bot
- youtube-comment-classifier-mlops - MLOps pipeline with FastAPI + K3s
- youtube-channel-intelligence - Serverless YouTube monitoring + AI analysis on GCP
📖 Off the clock: I wrote Social Freedom Unleashed, a book on overcoming social anxiety.



