Skip to main content

Projects

Everything here is documented, not just listed. Where a project has a write-up, the last column links to it; where the code is public, so does the repo. Private employer and client work has no repo link; the write-up is the artifact.

For the three-minute version, the homepage has the highlights.

Platform & DevSecOps work​

From my role at Developer Akademie GmbH. The repositories are private; the write-ups and the numbers are not.

ProjectOutcomeStackWrite-up
Terraform golden paths on GCPProvisioning 4 h → 45 minTerraform, Cloud Run, Cloud SQL, IAMBlog
Agentic runbooks with an approval gateResponse time −60% on known failuresGo, MCP, GCP, Terraform stateBlog
Ephemeral per-user AWS sandboxes80+ envs, compute spend −50%AWS EC2 (t3/t4g), Terraform, n8nBlog
SLO-gated deploys with automatic rollbackDeploy error rate under 2%Prometheus, Grafana, GitHub ActionsBlog
Security scanning in the delivery pathSAST and DAST blocking, not advisoryBandit, Semgrep, OWASP ZAP, Trivynone

Products​

Things I build and run myself.

ProjectWhat it isStackLinks
Agent Delivery PipelineGated delivery for agent-generated n8n workflows: builder and reviewer agents whose rights are enforced by hooks, a forced failure before the real run, and an acceptance log that is actually counted.Claude Code agents, n8n, Python, DockerDocs · Blog
FalarSpeaking tutor for European Portuguese on OpenAI's Realtime API, in internal test on Google Play. The phone talks to the model directly; the backend owns the session, guards every call over a sideband connection and measures minutes by its own clock.Expo, Django, OpenAI Realtime, GCP OAuth, DockerDocs · Blog
RunnzMulti-tenant SaaS for trade-fair construction scheduling. Reusable workflow blocks derive every deadline from the build date; secret scanning and dependency audit block in pre-commit and CI.NestJS, PostgreSQL, React, DockerDocs · Live
Emavi (formerly HepaAssist)Barrier-free multi-tenant PWA for assisted-living facilities: residents log daily mood, staff see trends and generate reports.Next.js, FastAPI, PostgreSQL, Docker, Web PushDocs
AI Chatbot PlatformMulti-tenant chatbot with appointment booking, embeddable as a widget with Shadow DOM isolation and per-tenant CORS validation.Next.js, Prisma, OpenAI, Shadow DOMDocs
CaptureDeskLoom recorder for Linux on the Loom Record SDK. Runs third-party code next to the screen and camera, so permissions are decided by origin and the local server rejects foreign Host headers against DNS rebinding.Electron, Node.js, ExpressDocs · Blog · Repo
This siteDocusaurus on GitHub Pages behind a custom domain. Zero third-party requests, self-hosted fonts, offline search.Docusaurus 3, GitHub ActionsDocs

Smaller projects​

Containers and deployment work. Older and smaller, still documented.

ProjectWhat it coversLinks
Conduit pipelineGitHub Actions: clone → build image → deploy over SSH with ComposeDocs · Repo
Conduit containerCompose stack for an Angular frontend and a Django backendDocs · Repo
Truck Signs APIDjango + DRF store with Stripe, containerisedDocs · Repo
VM setup & hardeningnginx, SSH keys, disabling password auth, managing multiple identitiesDocs · Repo

Security exercises​

Deliberate practice against intentionally vulnerable targets, documented as I worked through them. These are exercises, not client engagements. Labelling them as anything else would be dishonest, and they are more useful this way: the value is in the reasoning, not the trophy.

SetWhat it coversLinks
OWASP Juice ShopFour challenges end to end (API-only XSS, CAPTCHA bypass, admin registration, deluxe fraud) with the request tracesDocs · Repo
Python security toolingScripted scanning, cracking and metadata extraction (nmap, hydra, hashcat, exiftool-style metadata handling), one page per toolDocs · Repo
Authorised testing only

Everything in that section was run against targets I own or that exist to be attacked. Running these techniques against systems you have no written permission to test is illegal.