Service pillar / 05

Cybersecurity & DevSecOps

Harden cloud systems with collaborative CrowdSec intrusion detection, automated Kyverno admission controllers, and encrypted secrets via SOPS & Age.

What this is, and who it is for

Security here is enforced by the platform rather than by review, on a zero-trust basis where no workload is trusted by default: Kyverno and OPA Gatekeeper block non-compliant workloads at admission, Trivy scanning and SBOM generation run in the pipeline, container images are signed with Cosign to protect the supply chain, secrets are encrypted with SOPS and Age so they can live safely in Git, and CrowdSec provides collaborative intrusion detection across every ingress point. It is for teams that need to answer what is running, who shipped it, and whether it is permitted.

Start a conversation

Harden cloud systems with collaborative CrowdSec intrusion detection, automated Kyverno admission controllers, and encrypted secrets via SOPS & Age.

CrowdSecKyvernoSOPSAgeWireGuardTrivy

Based in Casablanca (GMT+1): overlapping working hours with European teams and a morning overlap with North America.

Cybersecurity & DevSecOps

Capabilities

01

CrowdSec collaborative intrusion defense

02

Kyverno policy admission controllers

03

SOPS + Age GitOps secret encryption

04

Linux kernel hardening & WireGuard mesh

Delivered architecture

Multi-Node CrowdSec Hub-and-Spoke Cluster

ProblemSiloed edge server logs and delayed IP blocking across distributed reverse proxies.
ArchitectureCentralized Local API (LAPI) CrowdSec hub in isolated Proxmox LXC, orchestrating multi-node edge bouncers via mTLS.
ResultReal-time threat remediation across all ingress points in <100ms; zero false-positive blockages.

Credential

IBM / Security

01

Application Security for Developers and DevOps Professionals

IBM / Security

OWASP, Observability, Security, Monitoring, Logging

Credential IDWFUQWCQQRJGLVerify credential

Questions, answered

Technical questions, answered directly.

What is CrowdSec and how is it deployed here?

CrowdSec is a collaborative intrusion detection engine. In this architecture a centralised Local API hub runs in an isolated Proxmox LXC container and orchestrates multi-node edge bouncers over mTLS, so a signal seen at one ingress is enforced at every ingress.

How fast is threat remediation?

Real-time across all ingress points in under 100ms, with zero false-positive blockages.

What does policy as code mean in practice?

Admission policies written as Kubernetes manifests — Kyverno rules or OPA Gatekeeper constraints that block root containers and unsigned images — so a workload that violates policy cannot start, and the rule itself is versioned and reviewed like code.

How are secrets and the supply chain handled?

Secrets are encrypted with SOPS and Age so encrypted values can be committed to Git and decrypted only in-cluster. SBOMs are generated in the pipeline and container images are signed with Cosign so deployment can verify provenance.

Is there a credential behind this practice?

Yes. Application Security for Developers and DevOps Professionals, issued by IBM, credential ID WFUQWCQQRJGL, verifiable through the public Coursera link on this page.

Have a hard system problem?

Bring the messy version.

We can start with a 15-minute conversation and a shared map of what is actually happening.

Start a conversation