01 Profile

Nathaël Bonnal,
architect for robust and scalable systems

I build IAM primitives, distributed architectures and production systems. From the first API contract to the last alert resolved.

Stack
Rust · IAM · Kubernetes · OIDC
Scope
Distributed systems & security
Ref
FerrisKey · lead-maintainer
Currently at
Cloud IAM
Profile Fig.01 · 1:1

Rust

services · CLI

Nathaël Bonnal

IAM

OIDC · tokens

K8s

operators

RBAC

OPA · policy

Obs

traces · SLO

What I Do

Three things I'm built for

Not a list of frameworks. What I actually deliver, end to end: get the system design right, make it work at scale, and keep it running in production.

01

Identity & Architecture

I design systems at the domain level: service boundaries, API contracts, and data ownership, before I touch a framework. My IAM expertise (OIDC, policies, multi-tenancy) comes from building FerrisKey, an identity platform where correctness isn't optional.

02

Distributed Systems

I build services that coordinate reliably at scale: event-driven architectures, Kubernetes orchestration, and consistency models designed for failure, not just for the happy path.

03

Production Lifecycle

I don't stop at the deploy. CI/CD pipelines, structured observability with Prometheus and Loki, and the mindset of an owner, not a contractor. If it pages at 3am, I'm the one who fixed the design that caused it.

Expertise

From identity to distributed platforms.

I focus on the parts of a system where product design, security constraints and operational reality meet.

01 · IAM

IAM & OIDC

OIDC, OAuth2, FerrisKey, token lifecycle, multi-tenant realms and secure product boundaries. Protocol implementation from spec

02 · AUTHZ

Authorization & policy

OPA, RBAC, ABAC, delegated authorization and policy-as-code. Fine-grained access control that stays auditable when security teams need answers.

03 · K8S

Platform identity

Kubernetes-native identity, service-to-service auth, mTLS and SPIFFE/SPIRE between workloads. IAM at the infrastructure layer.

04 · DIST

Distributed security

Event-driven auth flows, Kafka-based audit pipelines, and consistency decisions for systems that stay explainable under failure.

05 · OPS

Operational security

Auth systems that are observable and recoverable. Structured audit logs, token flow metrics, and SLOs for security-critical infrastructure.

Flagship Product

FerrisKey

FerrisKey

Open-source IAM platform, built in Rust

FerrisKey is an identity and access management platform built for production, the kind of system where correctness isn't optional. I co-founded it, designed the architecture, wrote the core, and I still own the production stack.

Architecture Hexagonal · Rust
Distributed Kubernetes · events
Production CI/CD · SLO
Architecture
Hexagonal architecture in Rust. Service boundaries designed before the first line of code. API contracts that the entire stack depends on.
Distributed
Multiple services on Kubernetes. Event-driven coordination, eventual consistency, and horizontal scalability by design.
Production
GitHub Actions CI/CD, Prometheus + Loki for observability, all held to SLO discipline so nothing just ships and gets forgotten.
Rust Hexagonal Kubernetes Event-driven CI/CD Prometheus · Loki SLO

Projects

Open source products, not demo code

Each project is a system decision made concrete: an architecture choice, a protocol design, years of upkeep.

Blog

Latest articles

Stay up to date with the latest news and updates.

// Contact

Let's work together

Have a project in mind or just want to chat? Feel free to reach out.

Nathaël Bonnal

Software Engineer at Cloud IAM, lead maintainer of FerrisKey. I design distributed systems and identity primitives in Rust from the first API contract to the last alert resolved.

Resources

© 2026 Nathaël Bonnal. All rights reserved.

Built with ❤️ using Explainer