- π I design and build security & identity infrastructure for multi-tenant, multi-cloud systems β secrets management, KMS, workload identity federation, and zero-trust architectures
- π οΈ Currently: Software Engineer @ Baseten, previously Uber and VMware Tanzu
- πΈοΈ Deep in SPIFFE/SPIRE, Vault, JWT/PKI, and Okta β I led Uber's migration from OneLogin to Okta, introducing passwordless auth and JIT/PAM access patterns
- βοΈ Cloud-native engineering across GCP & AWS, Kubernetes, Docker, Terraform, and GitOps (ArgoCD)
- π§ Building resilient, distributed systems β cross-region replication, Raft consensus, high-availability design
- π¦ Long-time interest in runtime & workload isolation β from CRIU-based container live migration and ARM TrustZone early in my career, to container/sandbox isolation today
- π§ Currently exploring identity observability with knowledge graphs for AI agents, policy-as-code (OPA), eBPF, and WebAssembly β see my BSides Seattle 2026 talk below
- βοΈ Also into blockchain & cryptography β co-authored the Kite whitepaper on trustless payment infrastructure for agentic AI
- βοΈ I write about security & distributed systems on my blog
- π¬ Open to chatting about open source, security architecture, or infra design β feel free to reach out
Languages
Cloud & Infra
Identity & Security
Emerging Interests
π Secrets & Key Management Building and hardening secrets infrastructure β encryption, key derivation, and policy-driven access.
hcl-to-spicedbβ converts Vault HCL policy into SpiceDB (Zanzibar-style) fine-grained authorizationkdf-golangβ key derivation function reference implementation in Gogolang_openssl_private_encrypt_rsaβ3 β RSA PKCS1.5 private encryption in Gosecrets-sharing-pocβ a design for sharing secrets safely in/outside a company
π Multi-Cloud & Workload Identity Federation
kube-oidc-fedβ lets pods on any number of Kubernetes clusters get AWS/GCP credentials from a single OIDC identity provider, without per-cluster OIDC registrationkube-iam-assumeβ5 β secretless cloud access for any Kubernetes cluster; brings EKS-style IRSA to self-hosted clusterskubeAssume-quick-pocβ companion proof-of-concept for the above
πͺͺ Identity, Okta Migration & JIT/PAM
- Led Uber's migration from OneLogin β Okta, rolling out passwordless authentication and just-in-time (JIT) privileged access management (PAM) patterns to cut down standing access
okta-jwt-cliβ CLI for Okta JWT operations using the Private Key JWT auth methodsshgateway/sshproxyβ SSH CA-based authentication termination proxy with Kubernetes service-account validation
π¦ Runtime Isolation: CRIU & ARM TrustZone Early in my career, before it was called "sandboxing" β checkpoint/restore container live migration and hardware-backed isolation.
docker_based_cloudletβ19 β container-based cloudlet with live migration using CRIUCRIU_dockerβ4 β Docker live-migration testing with CRIU- Hands-on work with ARM TrustZone for hardware-backed trusted execution and isolation
BSides Seattle 2026 β "Identity Observability with Knowledge Graph: Beyond Monitoring to Enforcement"
Kubernetes Secrets Handbook β Packt Publishing, 2024, co-author (with Emmanouil Gkatziouras and Rom Adams) Design, implement, and maintain production-grade Kubernetes Secrets management solutions.
Trustless Payment Infrastructure for Agentic AI β Kite whitepaper, co-author An identity and payment solution for AI agents β my entry point into blockchain and applied cryptography.
- π OIDC authentication β lets Baseten deployments authenticate to cloud resources (S3, container registries) with short-lived OIDC tokens instead of long-lived credentials
- π₯οΈ SSH access to training jobs β full terminal access into running training containers on Baseten-managed GPU hardware for debugging and inspection
| Repo | Stars | What it does |
|---|---|---|
docker_based_cloudlet |
β19 | Container-based cloudlet with live migration using CRIU |
kube-oidc-fed |
Pods on any number of Kubernetes clusters get AWS/GCP credentials via a single OIDC identity provider | |
kube-iam-assume |
β5 | Secretless cloud access for any Kubernetes cluster β EKS-style IRSA for self-hosted clusters |
sshgateway |
SSH CA-based authentication termination proxy with Kubernetes service-account validation |




