Cybersecurity Student | Hands-on Security Projects & Labs
I build practical cybersecurity projects focused on infrastructure security, network isolation, cloud-native security, access control, automation, and observability. I use my GitHub profile to document reproducible labs, implementation decisions, validation evidence, and the lessons learned from each project.
- Cloud & Kubernetes Security
- Network Security & Segmentation
- Identity, RBAC & Least Privilege
- Linux & Infrastructure Security
- DevSecOps & GitOps
- Security Monitoring & Observability
Platforms & Systems
Linux · Kubernetes · K3s · Docker
Networking & Security
Cilium · NetworkPolicy · CiliumNetworkPolicy · RBAC · Pod Security Admission · TLS/HTTPS
Automation & Delivery
Git · GitHub · Helm · Argo CD
Observability
Prometheus · Grafana · Loki · Grafana Alloy · Cilium Hubble
A security-focused multi-tenant Kubernetes platform designed to isolate tenant workloads, network traffic, API permissions, persistent data, and resource consumption while keeping deployments reproducible through GitOps.
Highlights:
- Default-deny tenant network isolation with Cilium
- Least-privilege RBAC and dedicated ServiceAccounts
- Restricted Pod Security Admission
- ResourceQuota and LimitRange governance
- TLS/HTTPS through Traefik and cert-manager
- Reusable Helm tenant baseline
- GitOps reconciliation with Argo CD ApplicationSet
- Metrics, logs, and network-flow visibility
- Positive and negative security validation tests
I aim to go beyond simply making a system work. My projects emphasize security controls, reproducibility, validation, evidence, and clear technical documentation.
I am progressively turning my hands-on cybersecurity work into a structured technical portfolio, with project documentation, GitHub repositories, security labs, and practical validation evidence.
More cybersecurity projects and labs will be added progressively.