Skip to content
View imos64's full-sized avatar

Highlights

  • Pro

Organizations

@Greenstand

Block or report imos64

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
imos64/README.md

Imos Aikoroje — DevSecOps • SRE • Cloud Platform • AI Benchmark Engineering • Distributed Systems

Building secure infrastructure • Reliable platforms • Distributed systems • Frontier AI evaluation environments

My engineering portfolio Profile Views

DevSecOps SRE Kubernetes AI Evaluation Hyperledger


👨🏽‍💻 About Me

I am a DevSecOps Engineer, Site Reliability Engineer, Cloud & Platform Engineer, and AI Benchmark Engineer focused on secure production systems and hard technical evaluation environments.

My work spans Kubernetes, cloud infrastructure, CI/CD, GitOps, observability, distributed systems, Hyperledger Fabric, microservices, RAG infrastructure, application security, and frontier AI evaluation.

Security + Reliability + Automation + Distributed Systems + AI Evaluation
  • ☸️ Kubernetes and cloud platform engineering
  • 🔐 DevSecOps, AppSec, IAM, and software supply-chain security
  • 🔄 CI/CD, GitOps, release engineering, and Infrastructure as Code
  • 📊 Prometheus, Grafana, distributed tracing, and operational alerting
  • ⛓️ Hyperledger Fabric, consensus, ledger, identity, and chaincode infrastructure
  • 🤖 Terminal-based agent benchmarks and Senior SWE benchmark review
  • 🧪 Oracle, verifier, rubric, regression, and failure-analysis engineering
  • 🧠 RAG gateways, multi-provider inference, and AI infrastructure

🛠️ Technology Stack

Cloud • Infrastructure • Platform

AWS OCI Kubernetes Docker Terraform OpenTofu Helm Argo CD Ansible

Secure Hybrid Infrastructure Amazon EKS and EC2 Oracle OKE and Compute Proxmox VE

Networking • VPC • VCN • On-premises VLANs

AWS Networks Oracle Cloud Networks On-premises Networks

DNS • Authoritative Servers • Management • Automation

Technitium DNS Server PowerDNS PowerDNS-Admin octoDNS CoreDNS ExternalDNS BIND 9

Load Balancers

HAProxy NGINX Open Source Envoy Proxy Traefik Proxy MetalLB Keepalived + IPVS kube-vip Apache APISIX Caddy Katran

Horizontal & Vertical Scaling

Kubernetes HPA Kubernetes VPA KEDA Goldilocks Metrics Server Prometheus Adapter Knative Serving Karpenter Cluster Autoscaler

GitOps

Argo CD Flux CD Fleet PipeCD Jenkins X Kluctl werf Argo Rollouts Flagger Crossplane

K8s Certificate Management / PKI Automation

cert-manager Smallstep step-ca OpenBao PKI SPIRE trust-manager Istio CA / Istiod Linkerd Identity EJBCA Community CFSSL Kubernetes Certificate APIs

K8s Certificate Authority (CA) / TLS Certificate Management

Smallstep step-ca OpenBao PKI cert-manager EJBCA Community OpenXPKI Dogtag PKI CFSSL SPIRE Easy-RSA Boulder

CI/CD • Observability • Security

GitHub Actions Jenkins Prometheus Grafana Trivy

SonarQube Nexus Selenium Grid

FinOps • Cost Management • Sustainability

Kubecost OpenCost kube-green

Security • Runtime Protection • Posture Management • IaC Scanning

Trivy Operator Kubescape Operator Falco NeuVector Prisma Cloud Defender Checkov SonarQube

Kubernetes Cluster Bootstrap Namespace Security Baseline

Database Servers • SQL • NoSQL • Search

PostgreSQL MySQL MongoDB Cassandra CouchDB Redis OpenSearch

Development • AI

Python FastAPI Java JavaScript TypeScript

Distributed Systems • Blockchain

Hyperledger Fabric


🌟 Featured Engineering Work

🧠 Keycloak–Fabric Bridge — Identity & API Integration

Related infrastructure:

My Hyperledger Fabric Kubernetes deployment

My merged TreeTracker contribution integrates Keycloak authentication with Hyperledger Fabric identity operations.

Keycloak • JWT authentication • Fabric CA • wallet management • API endpoints • Docker • security configuration


⛓️ Hyperledger Fabric on Kubernetes

Hyperledger Fabric on Kubernetes

Kubernetes-based Hyperledger Fabric infrastructure covering certificate authorities, peers, orderers, CouchDB, channels, connection profiles, and chaincode lifecycle.

Grafana = Fabric health and performance
Prometheus = metrics collection
Alertmanager = operational alerts
Hyperledger Explorer = blockchain visibility


🌳 TreeTracker / HLF Enterprise Productionization

Related infrastructure:

My Fabric network deployment My Argo CD deployment

Community:

Greenstand

Productionization work across the TreeTracker and Hyperledger Fabric stack:

  • TreeTracker web, admin, authentication, capture, and token services
  • Kubernetes and Argo CD GitOps
  • GHCR image delivery
  • PostgreSQL and Keycloak migration and persistence
  • Fabric peers, orderers, CAs, CouchDB, and wallets
  • Hyperledger Explorer and CouchDB Fauxton
  • Headlamp, Prometheus, and Grafana
  • Backup, restoration, credentials, and persistence documentation

⚙️ DevOps Engineering Portfolio

Related delivery tooling:

My Helm platform toolkit My Jenkins platform deployment

My TreeTracker Wallet work covers GitHub Actions CI/CD, Docker builds, security scanning, SBOM generation, and Kustomize deployment overlays.


📊 Kubernetes Observability

Prometheus Grafana Loki and Alloy Alertmanager SigNoz

My Prometheus, Grafana, Loki and Alertmanager deployment repositories are derived from my running Hyperledger Fabric / TreeTracker stack. SigNoz is an additional deployment package. Each includes Helm charts, native Kubernetes manifests, Terraform and OpenTofu deployments, high-level architecture, and operations runbooks.

Prometheus, Grafana, Loki and Alertmanager were validated in an isolated cluster: metrics collection, 15 Grafana dashboards, log ingestion and queries, alert handling, and persistence across pod restarts. Production profiles document their storage, identity, availability, and recovery requirements.


🤖 Frontier AI Benchmark Engineering

221 Projects Terminal Bench Senior SWE Bench

Community:

Harbor Framework

The recovered Harbor and TBench workspace contains 221 task/project directories after obvious template and test scaffolding are excluded. I use this portfolio to demonstrate breadth across secure systems, software engineering, infrastructure, distributed systems, and AI-agent evaluation.

Portfolio accuracy note: the 221 figure represents recovered task/project directories. It is not presented as 221 accepted benchmark submissions. Historical month grouping is based on current workspace timestamps and should be treated as an approximate timeline.

🧪 Terminal-Bench 1.0 / 2.0 / 2.1 / 3.0

Terminal Bench 2 Terminal Bench 2.1 Terminal Bench 3

Engineering work includes:

  • Task authoring and proposal development
  • Proposal grading and technical review
  • Reviewer guidelines and calibration
  • Packaging and external-submission work
  • Containerized execution environments
  • Oracle and reference-solution engineering
  • Separate-verifier and acceptance-test hardening
  • Rubric and behavioral validation
  • Failure-mode and regression analysis
  • Reproducibility and edge-case testing
  • Multi-step agent tasks with interacting invariants

🔐 Selected AppSec, Identity & DevSecOps Tasks

prevent-http-request-smugglingfix-crlf-injectionprevent-open-redirect-abuseautomated-idor-discoveryprototype-pollution-deep-scanxxe-payload-reconstructionrefresh-token-rotationstrict-jwt-validationoauth-client-credential-rotationdpop-proof-of-possession-for-high-risk-api-tokensprivileged-mfa-enforcementcredential-stuffing-defense-deploymentjwks-cache-hardeningpassword-reset-token-securitymfa-sign-in-bypass-fixpr-from-fork-executes-secretsdocker-security-hardening-v4.6http2-rapid-reset-vulnerability-assessment-tool_20260123_184244

⛓️ Selected Hyperledger Fabric & Blockchain Tasks

chaincode-access-controlordering-service-disaster-recovery-securitypeer-impersonation-preventionsecure-couchdb-or-leveldb-accesssecure-peer-to-peer-gossip-channelsfabric-event-listener-securityprevent-cross-channel-data-leakageprevent-identity-reuse-across-channelsraft-leader-election-abuse-detectionrotate-msp-configs-without-network-outagetransaction-integritytransaction-signing-enforcementchaincode-dependency-failurefabric-plus-ferretdb-recoveryhlf-dynamic-peer-additionmulti-database-ledger-synchronizationmulti-org-governance-conflictpeer-join-idempotencyraft-consensus-state-recoveryci-cd-chaincode-deploymentledger-replay-consistencyledger-replay-into-ferretdb

📊 Selected SRE, Cloud & Platform Tasks

harden-cluster-creationprevent-insecure-rolloutssensitive-k8s-namespace-protection-modelshadow-infrastructure-detectionprometheus-grafana-monitoringlog-rotation-debuggerreproducible-rust-release-ciblock-risky-releases-before-they-hit-productionincident-containment-kill-switch-controlsdisaster-recoveryautofix-prod-bugsdistributed-tracing-end-to-endglobal-outage-simulationperfect-observabilitypayment-api-capacitypayment-jvm-warmuppayment-microservice-warmupselenium-grid-optimizationzero-downtime-iac-migration

🌐 Selected Distributed Systems & Data Tasks

chain-replication-log-repairlamport-logical-clock-ordering-debuggerevent-stream-repairpostgres-mixed-workload-optimizationevent-ordering-collapsemulti-language-microservice-meshmulti-subnet-identity-federationunified-data-mesh-implementationpolyglot-data-processing-pipelinecollapse-repairrouter-collapse-repairreversal-guard

🧠 Selected AI/ML & Research Tasks

end-to-end-ml-trust-chainintegrate-security-scanning-into-ml-pipelinesisolate-unverified-models-before-promotionprotect-proprietary-models-from-theftbank-marketing-ensembleprotein-interaction-mapperbittensor-appstate-reconstructionbittensor-data-platformbittensor-validator-state-on-cassandragpu-resource-arbitrationreal-time-ai-marketplace-integrationresponse-ranking-service101B-learngene-tells-you-how-to-customize-task-aware-parameter-initialization-at-flexible-scales124b-proxytransformation-preshaping-point-cloud-manifold-with-proxy-attentiongemini-embeddingharmonized-reasoning-pruninglearngene-customizationspargeattention-acceleration


🛡️ Terminus 3 — AppSec Benchmark Development

Work included AppSec task development plus separate-verifier hardening.

Representative areas:

  • HTTP request framing and request-smuggling defenses
  • Header and CRLF injection defenses
  • Redirect safety
  • Signed metadata replay protection
  • Security boundary validation
  • Independent verifier behavior

📚 PaperBench+ — Research Reproduction & GPU Tasks

Worked on paper-reproduction and CUDA/GPU task development.

Research-oriented task areas include:

  • LearnGene task-aware parameter initialization
  • ProxyTransformation point-cloud manifold work
  • Harmonized reasoning pruning
  • SpargeAttention acceleration
  • GPU resource arbitration

🧠 Senior SWE-Bench

SWE Bench

Repository-scale review work includes:

Project Recovered task/work
Better Auth better-auth-pr9059-fix plus prior better-auth-pr9930-feature history
Prefect prefect-pr19962-fix, prefect-pr22113-fix, prefect-pr22404-fix
PostHog posthog-pr48403-fix

Core evaluation skills include repository investigation, production-fix review, regression validation, acceptance criteria, verifier behavior, and coding-agent failure analysis.


🎮 Wordle AI Benchmark

Wordle AI Benchmark

LLM benchmarking environment for strategic reasoning with:

OpenRouter • LiteLLM • local vLLM • concurrent evaluation • cost tracking • token analysis • model trajectories • success-rate analytics


📄 ExtractBench

ExtractBench

Schema-guided enterprise document extraction benchmark covering structured-output accuracy, completeness, grounding, and model evaluation.


🗂️ Full Recovered Benchmark Task / Project Catalog — 221

Expand the complete recovered Harbor & TBench inventory

The month labels below use current directory timestamps as the best available historical marker. They are not guaranteed creation dates.

December 2025 — 56

adjust-cloud-policies-based-on-threat-signalsapplication-secrets-boundariesappsec-pipeline-self-testasorb-volumetric-attacks-safelyautomated-idor-discoveryblock-exploits-without-redeploying-workloadschaincode-access-controlcloud-cost-security-risk-frameworkcloud-threat-detection-integrationcode-maintenance-refactoring-and-optimizationcross-cloud-identity-federation-blueprintcrypto-boundary-mappingdast-scan-not-triggeringdata-maskingdetect-malicious-crash-loopsdetect-sso-flawsencrypt-ledger-data-at-restend-to-end-ml-trust-chainharden-cluster-creationhello-worldimmutable-infrastructure-enforcement-blueprintimplementing-continuous-threat-exposure-managementimprove-throughputintegrate-security-scanning-into-ml-pipelinesisolate-unverified-models-before-promotionkernel-level-runtime-guardsload-balancer-waf-integrationmulti-tenant-isolation-brokenoauth-device-code-hijackordering-service-disaster-recovery-securitypeer-impersonation-preventionpevent-wildcard-origin-abusepipeline-resource-abuse-detectionpr-from-fork-executes-secretsprevent-insecure-rolloutsprotect-control-componentsprotect-proprietary-models-from-theftprototype-pollution-deep-scanremove-instances-without-impactrsa-key-managementruntime-auto-containmentsecrets-governance-as-codesecure-cloud-landing-zonesecure-couchdb-or-leveldb-accesssecure-peer-to-peer-gossip-channelssecurity-stage-skipped-on-hotfixsecurity-tool-rationalizationsensitive-k8s-namespace-protection-modelserverless-security-reference-architectureservice-to-servic-identityshadow-infrastructure-detectiontest-defenses-under-attackthreat-prioritization-enginetrack-transitive-risksvulnerability-sla-enforcement-enginexxe-payload-reconstruction

January 2026 — 22

anti-enumeration-auth-responsesauth-endpoint-waf-hardeningauth-event-logging-hardeningcentralized-sso-for-admin-accesscontact-change-step-up-securitycredential-stuffing-defense-deploymentdast-staging-gatedpop-proof-of-possession-for-high-risk-api-tokensjwks-cache-hardeningoauth-client-credential-rotationoauth2-oidc-best-practices-enforcementpasskeys-web-authn-enablementpassword-policy-enforcementpassword-reset-token-securityprevent-privilege-escalation-via-idp-claimsprivileged-mfa-enforcementrefresh-token-rotationrisk-based-authenticationsensitive-action-re-authenticationsignup-and-password-reset-abuse-controlsstrict-jwt-validationthreat-intelligence-integration

February 2026 — 56

astronomical-observatory-schedulerbackdated-posting-preventionbank-marketing-ensemblecard-pan-tokenization-strategychain-replication-log-repaircobol-insurance-discount-validatorconfigure-bazel-remote-cacheconvoycore-banking-zero-trust-blueprintcpp-concurrent-map-segfault-debug-20260107-100522csv-edadetect-live-exploitation-attemptsdocker-security-hardening-v4.6environment-dbpeilfabric-event-listener-securityfake-job-postingsfirewall-port-knock-setupflake8-plugingame5-30game_last_standheat-exchanger-network-optimizerhospital-lab-auditorhsm-backed-key-management-blueprinthttp2-rapid-reset-vulnerability-assessment-tool_20260123_184244implement-bloodhound-acl-parser_20260127_190114lamport-logical-clock-ordering-debuggerlog-rotation-debuggermasscanmerge-debug-taskmonorepo-static-analysis-strictmulti-factory-batch-optimizermulti-vendor-cve-policy-hardening-2025_20260111_160349network-forensics-analysispassword-hashing-hardeningpbn-bridge-submissionprevent-cross-channel-data-leakageprevent-identity-reuse-across-channelsprogressive-login-throttling-and-backoffprometheus-grafana-monitoringprotein-interaction-mapperraft-leader-election-abuse-detectionreplica-placement-optimizerreproducible-rust-release-cirotate-msp-configs-without-network-outagescim-jit-provisioning-and-automated-deprovisioningsecrets-runtime-revocationsecurity-posture-attack-surface-reductionsub-rev13-4system-servicesystem-utlizationtbrain-elf-ret2win-root-shelltoken-binding-via-mtls-or-dpoptransaction-integritytransaction-signing-enforcementvideo-transcoding-pipeline-3wire-transfer-callback-validation

March 2026 — 18

atm-transaction-integrity-monitoringblock-risky-releases-before-they-hit-productioncyber-resilience-under-kinetic-attackdetect-compromised-operator-credentialsevent-stream-repairincident-containment-kill-switch-controlsiso-20022-message-integrity-enforcementmaintain-integrity-under-solar-stormspin-translation-hardeningsecure-c4isr-architecture-validationsecure-satellite-link-encryptionsecure-tactical-cloud-deployment-modelspace-robotics-remote-takeover-preventionspacecraft-firmware-tamper-preventionssh-ca-bastion-setupstrategic-cyber-escalation-safeguardstest-dynamic-threat-intelligence-integrationvisualize-high-risk-services-and-accounts

April 2026 — 7

auto-code-fixcollapse-repairdisaster-recoverydynamic-threat-intelligence-integrationpostgres-mixed-workload-optimizationreversal-guardrouter-collapse-repair

May 2026 — 35

autofix-prod-bugsbittensor-appstate-reconstructionbittensor-data-platformbittensor-validator-state-on-cassandrachaincode-dependency-failurecustom-incentive-enginedistributed-tracing-end-to-endevent-ordering-collapsefabric-plus-ferretdb-recoveryfx-settlement-surgeglobal-outage-simulationgpu-resource-arbitrationhlf-dynamic-peer-additionmainframe-to-cloud-migrationmfa-sign-in-bypass-fixminer-reputation-persistencemodular-platform-refactormonolith-decompositionmulti-database-ledger-synchronizationmulti-language-microservice-meshmulti-org-governance-conflictmulti-subnet-identity-federationpayment-api-capacitypayment-jvm-warmuppayment-microservice-warmuppeer-join-idempotencyperfect-observabilitypolicy-enforcementraft-consensus-state-recoveryreal-time-ai-marketplace-integrationresponse-ranking-servicetrading-card-game-rules-enginetwo-way-coupled-fluid-simunified-data-mesh-implementationwallet-identity-federation

June 2026 — 7

ci-cd-chaincode-deploymentelectric-fix-sync-service-fix-hardledger-replay-consistencyledger-replay-into-ferretdbpolyglot-data-processing-pipelineselenium-grid-optimizationzero-downtime-iac-migration

July 2026 — 12

101B-learngene-tells-you-how-to-customize-task-aware-parameter-initialization-at-flexible-scales124b-proxytransformation-preshaping-point-cloud-manifold-with-proxy-attentionbetter-auth-pr9059-fixedi-to-modern-api-bridgegemini-embeddinggimp-sdk-api-compatibility-debuggerposthog-pr48403-fixprefect-pr19962-fixprefect-pr22113-fixprefect-pr22404-fixspeedrun-friendly-enginespeedrun-friendly-engine-advanced

August 2026 — 8

canonical-metadata-headersfix-crlf-injectionharmonized-reasoning-pruninglearngene-customizationprevent-http-request-smugglingprevent-open-redirect-abusesecure-signed-metadata-replayspargeattention-acceleration

Previous names / retired directories recovered from history

auto-fix-production-bugsautofix-prod-bugs
canonical-export-metadata-headerscanonical-metadata-headers
cross-team-policy-enforcement, policy-enforcement-may12, policy-enforcement-may25policy-enforcement family
eliminate-crlf-header-injectionfix-crlf-injection
eliminate-http1-framing-desync, normalize-conflicting-http-request-framingprevent-http-request-smuggling
124B ProxyTransformation point-cloud completion with proxy operations → later manifold/proxy-attention version

Other older or no-longer-present directories:

86-proxytransformation-preshaping-point-cloud-completion-with-proxy-operationsbetter-auth-pr9930-featureci-hermetic-enforcersql-injection-defensevideo-transcoding-pipelinetactical-cloud-validator


☸️ Kubernetes & Platform Engineering

Kubernetes Solutions Helm Charts Cloud on K8s Kubernetes Manifests Velero Cert Manager Argo CD OpenTofu

kube-green Kubecost Infracost Robusta KRR OpenCost Nginx Tomcat

Kronic CronWizard Technitium DNS Server PowerDNS PowerDNS-Admin octoDNS CoreDNS ExternalDNS BIND 9

My component deployment repositories below include Kubernetes manifests, Helm, Terraform, OpenTofu, architecture diagrams and operations runbooks. Database packages use three-member HA topologies; each repository records its validation evidence and remaining production acceptance requirements.


🔐 DevSecOps & Security Engineering

Trivy Kubescape Operator Falco NeuVector Prisma Cloud Defender Checkov Gitleaks WebGoat Harbor

Focus: AppSec • IAM • OAuth/OIDC • JWT • DPoP • mTLS • container security • secret detection • CI/CD security • Kubernetes security • TLS • secure software delivery • runtime protection • supply-chain security


🏗️ Broader Engineering Portfolio

🔧 Fixam4me

Application and Kubernetes/platform engineering for a service marketplace platform.

🛡️ Quantus Immunefi Security Audit

Security audit work included CLI transfer and cold-signing attack surfaces.

☸️ Kubernetes Maintenance

kind-dev maintenance work included zero-ready ReplicaSet cleanup and cluster troubleshooting.

🖥️ Systems Diagnostics

Windows/WSL performance and disk-storage diagnostics.


📈 GitHub Activity

GitHub contribution streak


🎯 Current Engineering Focus

  • Production-grade Hyperledger Fabric on Kubernetes
  • Automated cryptographic material and certificate lifecycle management
  • Fabric observability with Prometheus, Grafana, and Alertmanager
  • Kubernetes platform engineering and GitOps
  • Secure CI/CD and AppSec automation
  • AI-agent evaluation and benchmark engineering
  • RAG infrastructure and multi-provider inference
  • Cloud-native microservices and distributed systems

🤝 Let's Connect

I am interested in DevSecOps, SRE, cloud infrastructure, AI systems, distributed systems, security engineering, and platform engineering opportunities and collaborations.

Explore my Kubernetes platform baseline Explore my Helm platform toolkit

Build securely • Operate reliably • Automate intelligently

Pinned Loading

  1. hyperledger-fabric-network-kubernetes hyperledger-fabric-network-kubernetes Public

    Hyperledger Fabric Network on Kubernetes — Kubernetes manifests, Helm, Terraform, OpenTofu, architecture and recovery runbooks.

    Python

  2. Greenstand/treetracker-blockchain-capture Greenstand/treetracker-blockchain-capture Public

    The TreeTracker Capture Service is a Node.js microservice that ingests geo-tagged tree capture data, validates and stores media uploads, and secures all private endpoints with Keycloak (JWT + RBAC)…

    TypeScript 1

  3. couchdb-kubernetes couchdb-kubernetes Public

    CouchDB HA Cluster on Kubernetes — Kubernetes manifests, Helm, Terraform, OpenTofu, architecture and recovery runbooks.

    Python

  4. trivy-operator-kubernetes trivy-operator-kubernetes Public

    Continuous image vulnerability, configuration and RBAC reports as Kubernetes custom resources, with bounded scan concurrency and expiring scan jobs

    Python

  5. Greenstand/treetracker-blockchain-auth Greenstand/treetracker-blockchain-auth Public

    A comprehensive authentication microservice for the TreeTracker system that integrates with Keycloak for identity management and Hyperledger Fabric for blockchain-based user enrollment.

    TypeScript 3