About Montassar
- K8S Environments
- Cloud Infrastructure Provisioning as Code
- Continuous Integration and Continuous Deployment
- GitOps Paradigm
- Microservices Architecture
- Certified Kubernetes Application Developer (CKAD)
- Certified Kubernetes Administrator (CKA)
- Certified Kubernetes Security Specialist (CKS)
- HashiCorp Vault Associate 002
- HashiCorp Terraform Associate 003)
- AWS Cloud Practitioner
- AWS Architect Associate
- AWS Developer Associate
Arabic
Native or bilingual
French
Native or bilingual
English
Fluent
Experience
- EasyTeamDevSecOps EngineerJune 2022 - Today (4 years)Description:CloudForms is a project developed to offer a modern solution for automating the deployment chain of microservices and managing applications in K8S environments.Achievements:
- Implementation and maintenance of application (microservices) Helm charts and Helm Libraries.
- Implementation and maintenance of DevSecOps pipelines for continuous integration with Jenkins.
- Implementation of Talisman for sensitive data detection during code commit.
- Configuration of PIT test for mutation testing.
- Integration of SonarQube for code quality.
- Analysis of vulnerabilities in dependencies and libraries using OWASP dependency check.
- Analysis of vulnerabilities and potential risks in images using Trivy.
- Analysis and verification of static scripts (Dockerfile, K8S Manifests) with OPA/Conftest.
- Reporting of security risks in K8S manifests with kubesec.
- Reporting of CIS benchmarks with AquaSec Kube-Bench.
- Definition and maintenance of Helm chart pipelines.
- Implementation of Pod autoscaling using various methods: HPA, Prometheus metrics, Keda.
- Installation of ArgoCD via Helm in the management cluster (K8S) in HA multi-tenant mode.
- Automation of ArgoCD application creation and configuration of automatic synchronization, auto pruning, and self-healing strategies.
- Integration of ArgoCD with Okta via Dex for user management.
- Integration of ArgoCD with Vault for secret injection using the Vault agent sidecar strategy.
- Deployment of ArgoCD Image Updater for automatic management of image version and tag updates.
- Implementation of ArgoCD metrics export via the kube-prometheus-stack operator.
Jenkins, Groovy, Talisman, PIT Mutation, SonarQube, Trivy, OPA/Conftest, Regokubesec, kube-bench, ArgoCD, Scrum - EasyTeamDevSecOps EngineerJune 2022 - Today (4 years)Description:Morpheus is a project developed to offer a solution that automates the management of on-premise virtual machines and DevOps tools.Achievements:
- Automation of QEMU/KVM virtualization hypervisor installation and uninstallation with Ansible.
- Automation of virtual machine operating system creation using Packer.
- Automation of virtual machine creation and deletion with Ansible.
- Automation of virtual machine configuration via Cloud-init.
- Automation of SSH key distribution among virtual machines with Ansible.
- Automation of tool installation and uninstallation through the following Ansible roles: Gitlab-ci, Gitlab-Runners, Jenkins Docker, Harbor, OpenLdap, Terraform.
- Implementation of Ansible role tests with Molecule and Test-Infra.
- Usage of Test-Infra modules: package, service, file, Users/Groups, command.
- Participation and facilitation of technical workshops within the team.
- Participation in various Scrum ceremonies.
- Writing technical documentation and operational manuals in Confluence.
Shell, Debian, SSH, Ansible, Molecule, TestInfra, Python, QEMU/KVM, Cloud-Init, Packer, Scrum - EasyTeamDevSecOps EngineerJune 2022 - Today (4 years)Description:K8S-MESH is a project developed to offer a solution that automates the creation of K8S clusters and the integration of the Istio service mesh.Achievements:
- Automation of K8S cluster creation with Kubeadm and Ansible.
- Automation of K8S cluster upgrades with Ansible.
- Automation of K8S cluster internal certificate updates with Ansible.
- Migration of K8S cluster management pipelines from Kubeadm to Kubespray.
- Configuration of Etcd secret encryption (Secret data at Rest).
- Implementation of K8S secrets using Bitnami Sealed Secrets and Kubeseal.
- Migration of secrets from Bitnami Sealed Secrets to HashiCorp Vault.
- Securing K8S clusters with Seccomp and AppArmor profiles.
- Configuration of unusual behavior detection in K8S with Falco.
- Integration of Falco alerts with falcosidekick-ui and dedicated Slack Channel.
- Implementation of Slack notifications with Alert Manager and Prometheus using the kube-prometheus-stack Helm chart.
- Implementation of Canary release traffic management and A/B Testing with Istio.
- Implementation of mutual TLS encryption (MTLS) for inter-cluster communication with Istio.
- Implementation of Access restrictions based on RBAC/Auth policies with Istio.
- Implementation of Circuit Breaking resilience policies, as well as retries and timeouts with Istio.
- Configuration of chaos engineering techniques using fault injection in Staging environments with Istio.
- Implementation of Loki-Grafana for centralized application logging.
- Writing technical documentation and operational manuals in Confluence.
Shell, Ansible, Kubernetes 1.27, Kubeadm, Kubespray, Istio,Bitnami Sealed Secrets, HashiCorp Vault, Prometheus, Alert Manager, Falco, Scrum
Recommendations
Be the first to recommend Montassar
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- MIAGEISG2009
- TIBCO BUSINESSWORKSTIBCO2017
Certifications
- AWS ARCHITECT ASSOCIATEAMAZON
- AWS DEVELOPER ASSOCIATEAMAZON