Quittez le Cloud.
Maîtrisez votre infrastructure.
Welcome to the digital mind of a Cloud-Native Architect. Scroll through my IT experiences to explore how I build high-availability Kubernetes platforms, secure zero-trust workloads, and scale edge AI clusters.
| NAME | ROLE | RAM | GPU | OS / ARCH |
|---|---|---|---|---|
| controlplane-100 | control-plane | 16 GB | None | Talos v1.12.6 (amd64) |
| controlplane-101 | control-plane | 8 GB | None | Talos v1.12.6 (amd64) |
| controlplane-102 | control-plane | 16 GB | None | Talos v1.12.6 (amd64) |
| worker-103 | worker | 24 GB | None | Talos v1.12.6 (amd64) |
| worker-104 | worker | 24 GB | None | Talos v1.12.6 (amd64) |
| gpu-105 | worker | 96 GB | RTX 2060 | Talos v1.12.6 (amd64) |
| worker-106 | worker | 16 GB | None | Talos v1.12.6 (amd64) |
| gx10 | worker | 128 GB | GB10 Blackwell | Ubuntu 24.04 (DGX OS) (arm64) |
Core Platform & Network CNI
A minimal, production-grade bare-metal architecture built with an API-managed immutable OS and kernel-level networking.
Talos Linux
Immutable, security-hardened Linux distribution. No SSH, no systemd, managed entirely through gRPC.
Cilium CNI
eBPF-based container networking, replacing kube-proxy with kernel-level routing and Gateway API ingress.
Hubble
eBPF network flow observability, mapping internal microservice dependency streams in real-time.
GitOps & Infrastructure IaC
Fully declarative GitOps control plane where every system configuration, secret sync, and network policy is versioned.
ArgoCD App-of-Apps
Continuous delivery engine managing 45+ applications across 35+ namespaces with automated reconciliation.
Terraform Modules
Infrastructure as code managing Vault credentials, Keycloak client integrations, and Grafana data sources.
Renovate Engine
Automated dependency manager tracking and validating Helm chart bumps and Docker tag updates.
Zero-Trust Security & Policies
Comprehensive cluster defense-in-depth, incorporating automated identity, secrets injection, and runtime audits.
Keycloak IAM
Centralized Single Sign-On (SSO) with custom theme, protecting all admin portals via OIDC/SAML.
HashiCorp Vault HA
High-availability Raft cluster serving as the encrypted database of truth for API keys and certificates.
Kyverno Policy Engine
Kubernetes admission controller enforcing security compliance, mutating resources, and blocking root containers.
Grafana LGTM+ Telemetry Stack
Unified telemetry pipeline gathering all five signals (metrics, logs, traces, profiles, and costs) across the nodes.
Grafana Mimir & Loki
Scalable metrics and log engines providing long-term retention and fast multi-tenant querying.
Tempo & Pyroscope
Correlated distributed tracing and continuous CPU/Memory profiling to diagnose microservice latency.
HolmesGPT AI Operator
Autonomous AI-powered troubleshooting assistant investigating cluster anomalies using Minimax LLM.
Storage & Distributed Databases
Resilient stateful storage layer with replicated block pools, HA database clusters, and secure offsite object storage.
Longhorn Storage
Cloud-native block storage with active 3-way synchronous replica distribution across physical NVMe disks.
CloudNativePG
Enterprise-grade PostgreSQL operator handling automated replication, backups, and point-in-time recovery.
Garage S3 Object Storage
Lightweight distributed S3 object store providing secure backup targets for PG databases and Velero.
Bare-Metal AI & GPU Workloads
Edge-AI computing cluster deploying local LLM inference models on bare metal with dedicated GPU hardware.
NVIDIA DGX Spark Node
Worker node powered by Grace Blackwell GB10 Superchip, featuring 128GB unified memory and ConnectX-7 link.
AIBrix Gateway
Advanced model serving control plane providing prefix-cache-aware routing and LLM request load balancing.
vLLM Inference Runtime
High-throughput LLM engines serving Qwen-2.5 and Llama models with PagedAttention optimizations.
Take Back Your Infrastructure
Explore the fully functional platform code, Kubernetes manifests, and automation scripts powering the PKC cluster.