# Learn by making decisions.

Adrien Murillo — Murillo Consulting

Adrien Murillo, DevOps and DevSecOps consultant in Toulouse. Kubernetes, CI/CD, Cloud security, operations and security maintenance for critical systems.

## Public projects, distinct from professional engagements

### [Kube Aegis Forge](/en/projets/kube-aegis-forge)

A reproducible Kubernetes GitOps platform secured end to end.

The AWS extension is validated offline. No real AWS deployment is claimed.

[GitHub](https://github.com/murillo-consulting/kube-aegis-forge)

### [BastShield](/en/projets/bastshield)

A sovereign Kubernetes foundation for cloud, local virtualization and disconnected environments.

The Scaleway path remains experimental and requires operator review before deployment.

[GitHub](https://github.com/murillo-consulting/BastShield)

### [Fortplane](/en/projets/fortplane)

A secure Kubernetes baseline for connected, limited-egress and air-gapped environments.

Cluster validation and offline assembly require Zarf and a dedicated Kubernetes environment.

[GitHub](https://github.com/murillo-consulting/Fortplane)

### [Labz](/en/projets/labz)

A disposable AWS cyber range for training, attack simulation and detection.

AMIs depend on account and region. Real deployment can be billable and intentionally vulnerable.

[GitHub](https://github.com/murillo-consulting/Labz)

### [Gate](/en/projets/gate)

A local LLM gateway with DLP, multi-provider routing, budgets and signed audit records.

Live keys remain runtime-injected. Deployment examples require production hardening.

[GitHub](https://github.com/murillo-consulting/Gate)

### [ControlLoom](/en/projets/controlloom)

A Git-native workspace connecting security controls, implementation evidence and reviews.

Sensitive evidence and private audit reports must not be stored in a public workspace.

[GitHub](https://github.com/murillo-consulting/ControlLoom)

### [LangGraph Resilient Agent](/en/projets/langgraph-resilient-agent)

A durable agent with human approval, idempotent effects and redacted audit data.

Header identity and SQLite are local adapters that must be replaced for production.

[GitHub](https://github.com/murillo-consulting/langgraph-resilient-agent)

### [Spring AI Secure RAG](/en/projets/spring-ai-secure-rag)

Tenant-isolated RAG with verified citations and deterministic abstention.

The in-memory index and header identity are explicitly limited to the local demonstration.

[GitHub](https://github.com/murillo-consulting/spring-ai-secure-rag)

### [Impôts France MCP](/en/projets/impots-france-mcp)

A French tax MCP with a Rust/Wasm engine and versioned official rules.

No shared endpoint is guaranteed and outputs remain simulations, not tax advice.

[GitHub](https://github.com/murillo-consulting/impots-france-mcp)

### [cli-skills](/en/projets/cli-skills)

Portable skills for auditing, documenting and designing with coding agents.

Skills assist the work. They do not replace human review or target-project tests.

[GitHub](https://github.com/murillo-consulting/cli-skills)

## Incident & governance

An internal platform is unavailable. An administrator account shows an unusual sign-in. You are part of the decision team.

### The first minutes

You do not yet know whether the outage and sign-in are related. What is your first proposal?

Bring in the accountable teams, contain the suspect account and preserve useful evidence.

Coordination helps define containment with operations. Preserving evidence supports investigation. Rebuilding everything too soon may remove useful information.

Timestamps, account, affected systems and containment decision.

### Pressure to restore

A backup is available. The business wants immediate recovery. What must be established?

That the backup is usable and restoration can be checked in a controlled environment.

A backup’s existence proves neither integrity nor recovery capability. Define technical and business checks, then validate the restoration result.

Restoration report, integrity checks and business validation.

### Accepting remaining risk

The service can restart with a temporary control. A weakness remains open. How should the decision be handled?

Have the authorized risk owner approve it with an action, an owner and a review date.

The decision belongs to the risk owner. Explicit scope, ownership and a review date make a temporary measure traceable.

Dated decision, residual risk, owner and deadline.

## AI assistant & permissions

A team is building an assistant that retrieves internal documents and can create tickets. You are reviewing the architecture before the pilot.

### An instruction inside a document

A retrieved document tells the assistant to send its context to an external address. Which control matters first?

Treat the document as untrusted data and block unauthorized outputs and tools.

Retrieved content must not become trusted instructions. The system performing actions needs access and output controls, tested against injection scenarios.

Injection test with inspection of tool calls and network egress.

### The right document, the wrong person

The assistant cites a document the user is not allowed to read. Where should the control sit?

In retrieval and document access, using the user’s identity and permissions.

Filtering an answer too late may already expose data. Retrieval should enforce permissions before passing documents to the model, followed by output checks appropriate to the context.

Cross-user tests with two identities and documents with different permissions.

### From suggestion to action

The pilot can now modify existing tickets. What condition do you add?

Per-action authorization, human approval for sensitive effects and a change log.

Autonomy should be proportional to its effects. Specific permissions and approval for sensitive actions limit the impact of errors. Logs reveal what changed.

Allowed-action matrix and a test of a rejected modification.

## Rust & robustness

You are building a small Rust tool that imports configuration and calls an API. It compiles successfully. You are preparing delivery.

### Unexpected input

A required value is missing from the file. Which behavior do you prepare?

An explicit, tested error without undocumented partial effects.

The compiler does not define business behavior for invalid input. An explicit error supports diagnosis. Testing this path prevents a routine failure from becoming an unexplained interruption.

Invalid-input test, useful error message and non-zero exit code.

### An unresponsive API

The tool is waiting for an external response. What should you specify?

A timeout, a retry strategy and which operations can safely be replayed.

The language does not define network policy. Retrying a non-idempotent action may duplicate it. Timeouts, attempt limits and failure behavior must be decided and tested.

Timeout test and verification that retries do not duplicate an action.

### Handover to another team

The binary works on your computer. What else do you deliver?

Source, dependency versions, instructions and tests describing the tool’s contract.

Ownership requires the ability to rebuild and verify the component. Limits and error behavior matter as much as the happy path.

Build in a clean environment and documented test execution.

## [Rustlings](https://github.com/rust-lang/rustlings)

Rust exercises solved with the compiler. Practice types, error handling and tests progressively.

Local setup · requires Rust and Cargo · MIT

## [Backdoors & Breaches](https://github.com/blackhillsinfosec/play.backdoorsandbreaches.com)

A tool for facilitating incident-response simulations. Useful for discussing roles and the order of actions.

Facilitated workshop · prepare the scenario and rules · GPL-3.0

## [OWASP Juice Shop](https://github.com/juice-shop/juice-shop)

A deliberately vulnerable application for learning web security through challenges. Use it in an isolated lab.

Separate lab · installation required · MIT

## Navigation
- [DevOps and Cloud DevSecOps consultant.](/en/profil)
- [Engineering services.](/en/services)
- [Selected work.](/en/realisations)
- [Open-source projects.](/en/projets)
- [Guides to put into practice.](/en/ressources)
- [Let’s discuss your project.](/en/contact)
- [From scope to handover.](/en/approche)
- [Real contexts. Real constraints.](/en/secteurs)
- [Learn by making decisions.](/en/lab)
- [Legal notice](/en/mentions-legales)
- [Privacy](/en/confidentialite)
- [Terms of use](/en/conditions-utilisation)
- [Train your teams. Through practice.](/en/formation)

[Contact](mailto:contact@adrien-murillo.com)
