# DevOps and Cloud DevSecOps consultant in Toulouse

Adrien Murillo — Murillo Consulting

Adrien Murillo, DevOps and DevSecOps consultant in Toulouse. Kubernetes, CI/CD, Cloud security, operations and security maintenance for critical systems.

Based in Toulouse, I work as an independent DevOps and Cloud DevSecOps consultant under the Murillo Consulting name. My background in systems and cybersecurity began in 2018. I automate and secure Linux infrastructure and container platforms, from automated deployment through production operations.

I integrate security controls into CI/CD and GitOps: vulnerability analysis, secrets management and SBOMs. Production work continues through operational maintenance (MCO), security maintenance (MCS), observability and evidence for information-system security accreditation.

## Engineering in practice

### Kube Aegis Forge

A reproducible Kubernetes GitOps platform secured end to end.

Kubernetes · OpenTofu · Argo CD · Kyverno · Cosign · SBOM

CI, CodeQL, OpenTofu tests, IaC scans, hardened images, SBOMs, Cosign signatures, provenance and local kind-cluster verification.

[Architecture and limits](/en/projets/kube-aegis-forge) · [GitHub](https://github.com/murillo-consulting/kube-aegis-forge)

### Gate

A local LLM gateway with DLP, multi-provider routing, budgets and signed audit records.

Rust · Axum · DLP · LLM routing · OpenTelemetry · Helm

Canonical Anthropic and OpenAI pipeline, DLP, policies, fallback circuits, budgets, metrics, traces and signed audit journals.

[Architecture and limits](/en/projets/gate) · [GitHub](https://github.com/murillo-consulting/Gate)

### LangGraph Resilient Agent

A durable agent with human approval, idempotent effects and redacted audit data.

LangGraph · FastAPI · SQLite · Idempotency · Human approval

LangGraph checkpoints, idempotency keys, uniqueness constraints, tenant isolation and audit events without sensitive payloads.

[Architecture and limits](/en/projets/langgraph-resilient-agent) · [GitHub](https://github.com/murillo-consulting/langgraph-resilient-agent)

### ControlLoom

A Git-native workspace connecting security controls, implementation evidence and reviews.

SvelteKit · TypeScript · YAML · Git · Controls · Evidence

Catalogue imports, YAML controls, source mappings, pull-request impact analysis and a local SvelteKit interface.

[Architecture and limits](/en/projets/controlloom) · [GitHub](https://github.com/murillo-consulting/ControlLoom)

## Professional experience

### [Industrialize and secure a private-cloud KaaS platform](/en/realisations/industrialisation-kaas-defense)

Kubernetes-as-a-Service and IaaS/CaaS services in a defense environment.

A more reliable delivery chain, with SSI gaps and remediation made traceable for MCS and accreditation.

### [Secure a critical platform with more than 100 VMs](/en/realisations/securisation-plateforme-critique-100-vm)

Space and defense environment with availability, continuity, vulnerability and accreditation constraints.

Qualified gaps and CVEs, structured remediation plans and consolidated evidence for SSI accreditation review.

### [Industrialize a KYPO CyberRange for 60 users](/en/realisations/memoire-cyberrange-kypo)

Open-source platform for cyber training, attack scenarios and applied research.

A CyberRange used by 60 people, with 10 training scenarios and more than 10 virtualized or containerized environments.

### [Contribute to risk management and continuity](/en/realisations/gouvernance-risques-secteur-public)

Sensitive systems, risk analysis, security governance and continuity.

Documented risk analyses, security recommendations and action plans to support compliance and continuity follow-up.

### [Rebuild and secure an information system across six sites](/en/realisations/exploitation-multisite-reprise)

Social-care information system across 6 sites: server administration, identities, data protection and service continuity.

Rebuilt and secured the information system across six sites, with environment administration, data protection and secure access and backups.

## Areas of expertise

### [DevSecOps Cloud, Kubernetes & GitOps](/en/services/automatisation-devsecops-mco-mcs)

Industrialize critical cloud platforms and deployments by building security, traceability and operability into the delivery chain.

- CI/CD controls
- MCS runbooks
- hardening evidence
- automation backlog

### [SSI accreditation & operational compliance](/en/services/conformite-nis2-dora-cra)

Connect SSI requirements, technical gaps, remediation plans and usable evidence to support accreditation decisions.

- requirements map
- controls/evidence matrix
- remediation plan
- accreditation decision brief

### [Vulnerabilities, MCO/MCS & risk analysis](/en/services/analyse-risques-ebios-rm)

Prioritize CVEs, hardening gaps and risk scenarios by exposure, business impact and operating constraints.

- risk scenarios
- CVE/remediation backlog
- KPI/KRI
- residual-risk decisions

### [Cyber crisis, recovery & BCP/DRP](/en/services/reprise-rancongiciel-pra-pca)

Frame response, restoration and continuity with procedures that remain usable under pressure.

- crisis runbook
- recovery order
- BCP/DRP test
- remediation plan

### [Secure AI applications](/en/services/securite-ia)

You are integrating an assistant, RAG system or agents with your tools. I help map data flows, limit access and build security tests for your use case.

- Data and permission map
- Abuse scenarios and repeatable tests
- Control prototype within an agreed scope
- Risk register and implementation plan

### [Build reliable tools in Rust](/en/services/developpement-rust)

A script has become critical, an integration needs a maintainable component or you need a Rust prototype. I scope the expected behavior, develop the component and prepare your team to own it.

- Source code and build instructions
- Functional and error-path tests
- Interface documentation and technical decisions
- Demonstration and team handover

### [Train teams in cybersecurity](/en/services/formation-cybersecurite)

I design and facilitate awareness sessions and workshops for technical and business audiences. We define the objective first: understand a risk, execute a procedure or justify a decision.

- Audience-specific program and objectives
- Material and exercise instructions
- Explained solutions and learning assessment
- Resources for independent practice

## Public projects, distinct from professional engagements

### [Kube Aegis Forge](/en/projets/kube-aegis-forge)

A reproducible Kubernetes GitOps platform secured end to end.

The AWS extension is validated offline. No real AWS deployment is claimed.

[GitHub](https://github.com/murillo-consulting/kube-aegis-forge)

### [BastShield](/en/projets/bastshield)

A sovereign Kubernetes foundation for cloud, local virtualization and disconnected environments.

The Scaleway path remains experimental and requires operator review before deployment.

[GitHub](https://github.com/murillo-consulting/BastShield)

### [Fortplane](/en/projets/fortplane)

A secure Kubernetes baseline for connected, limited-egress and air-gapped environments.

Cluster validation and offline assembly require Zarf and a dedicated Kubernetes environment.

[GitHub](https://github.com/murillo-consulting/Fortplane)

### [Labz](/en/projets/labz)

A disposable AWS cyber range for training, attack simulation and detection.

AMIs depend on account and region. Real deployment can be billable and intentionally vulnerable.

[GitHub](https://github.com/murillo-consulting/Labz)

### [Gate](/en/projets/gate)

A local LLM gateway with DLP, multi-provider routing, budgets and signed audit records.

Live keys remain runtime-injected. Deployment examples require production hardening.

[GitHub](https://github.com/murillo-consulting/Gate)

### [ControlLoom](/en/projets/controlloom)

A Git-native workspace connecting security controls, implementation evidence and reviews.

Sensitive evidence and private audit reports must not be stored in a public workspace.

[GitHub](https://github.com/murillo-consulting/ControlLoom)

### [LangGraph Resilient Agent](/en/projets/langgraph-resilient-agent)

A durable agent with human approval, idempotent effects and redacted audit data.

Header identity and SQLite are local adapters that must be replaced for production.

[GitHub](https://github.com/murillo-consulting/langgraph-resilient-agent)

### [Spring AI Secure RAG](/en/projets/spring-ai-secure-rag)

Tenant-isolated RAG with verified citations and deterministic abstention.

The in-memory index and header identity are explicitly limited to the local demonstration.

[GitHub](https://github.com/murillo-consulting/spring-ai-secure-rag)

### [Impôts France MCP](/en/projets/impots-france-mcp)

A French tax MCP with a Rust/Wasm engine and versioned official rules.

No shared endpoint is guaranteed and outputs remain simulations, not tax advice.

[GitHub](https://github.com/murillo-consulting/impots-france-mcp)

### [cli-skills](/en/projets/cli-skills)

Portable skills for auditing, documenting and designing with coding agents.

Skills assist the work. They do not replace human review or target-project tests.

[GitHub](https://github.com/murillo-consulting/cli-skills)



## Navigation
- [DevOps and Cloud DevSecOps consultant.](/en/profil)
- [Engineering services.](/en/services)
- [Selected work.](/en/realisations)
- [Open-source projects.](/en/projets)
- [Guides to put into practice.](/en/ressources)
- [Let’s discuss your project.](/en/contact)
- [From scope to handover.](/en/approche)
- [Real contexts. Real constraints.](/en/secteurs)
- [Learn by making decisions.](/en/lab)
- [Legal notice](/en/mentions-legales)
- [Privacy](/en/confidentialite)
- [Terms of use](/en/conditions-utilisation)
- [Train your teams. Through practice.](/en/formation)

[Contact](mailto:contact@adrien-murillo.com)
