A single-node production homelab built on kubeadm, evolved from a legacy Docker host. Fully declarative and GitOps-managed with Flux; all secrets encrypted at rest with SOPS and age. Cilium provides eBPF-based networking as a complete kube-proxy replacement, with L2 announcements, L7 ingress controllers and Gateway API routing. Split-horizon DNS via k8s-gateway with Quad9 DoT upstream and Cloudflare DDNS for external access. Central IAM via Keycloak with OIDC, Google IdP federation and custom RBAC across self-hosted services, plus a self-hosted Headscale control plane for cross-site tunnels with embedded DERP relays.
Orchestrator
kubeadm (single node)
Identity
Keycloak OIDC / RBAC
An internal developer-platform application giving teams - including non-technical users - one-click, on-demand isolated QA environments, fully automated through Flux. Includes real-time per-pipeline tracking, a foreground deploy modal spanning build, release and health stages, background suspend/resume/delete operations with an activity window, a navigation guard against leaving mid-deploy, a one-click Slack support flow that carries the failing pipeline's last log lines, and an inactive-tab notification.
Users
All teams, incl. non-technical
Provisioning
One click, fully automated
Backend
Node.js with its own frontend
Backend microservices powering search, cataloguing and distribution for over a million online courses. Took a monolithic scraping and data-cataloguing system apart into multiple independent, faster services, and owned their CI/CD with Terraform IaC on AWS. Includes the company website and blog, built from scratch as a multilingual Wagtail project.
Catalogued
1M+ online courses
Architecture
Monolith to microservices
Responsive corporate website for Abika S.r.l., built on Bootstrap 4 and delivered during my time leading the DevOps team there.
A collection of modular, reusable Makefiles for build and CI work - part of my ongoing practice of turning recurring build steps into composable, version-controlled pieces.
A CMS for a local venue, originally written in PHP with no framework, later rewritten as a Django project. Built as my final diploma project at ITI Angioy; both versions remain available.
A minimal Python scraper for an online Sarde dictionary, built with Beautiful Soup and designed to run on a smartphone.
Custom Docker images and docker-compose configurations for self-hosted services, alongside personal infrastructure projects including custom onePlus 6T HEVC recording tooling (C), NVIDIA GPU fan control for an AMDGPU laptop, an rEFInd bootloader configuration, an EFI shim, an AUR package for an Epson inkjet driver, and a custom bash prompt.