DevSecOps Cloud / defense

Industrialize and secure a private-cloud KaaS platform

Kubernetes-as-a-Service and IaaS/CaaS services in a defense environment.

My role

DevSecOps engineering and cloud foundation security.

Documented elements
IaC and GitOpsTrivy / Grype scansSBOM and Nexus artifactsCVE trackingMCS evidence

01 / Understand

The starting point

Kubernetes-as-a-Service and IaaS/CaaS services in a defense environment.

02 / Frame

The challenge to resolve

Align deployment automation with technical, functional and SSI requirements without reducing the operability of the platform foundation.

03 / Implement

My contribution

Secured Kubernetes, Rancher and Podman foundations and automated delivery with Terraform, Ansible, GitLab CI/CD, Argo CD and Flux. Integrated Trivy, Grype, SBOM, Nexus and CVE tracking.

DevSecOps engineering and cloud foundation security.

04 / Verify

The documented outcome

A more reliable delivery chain, with SSI gaps and remediation made traceable for MCS and accreditation.

  • IaC and GitOps
  • Trivy / Grype scans
  • SBOM and Nexus artifacts
  • CVE tracking
  • MCS evidence

05 / Scope of the story

What this page documents

Reworded professional experience. Sensitive architecture and operational details are not published. No organizational endorsement is implied.

This page describes my role and documented outcomes. It does not establish a commercial relationship between the named organization and Murillo Consulting.