I build IAM primitives, distributed architectures and production systems. From the first API contract to the last alert resolved.
Rust
services · CLI
IAM
OIDC · tokens
K8s
operators
RBAC
OPA · policy
Obs
traces · SLO
What I Do
Not a list of frameworks. What I actually deliver, end to end: get the system design right, make it work at scale, and keep it running in production.
I design systems at the domain level: service boundaries, API contracts, and data ownership, before I touch a framework. My IAM expertise (OIDC, policies, multi-tenancy) comes from building FerrisKey, an identity platform where correctness isn't optional.
I build services that coordinate reliably at scale: event-driven architectures, Kubernetes orchestration, and consistency models designed for failure, not just for the happy path.
I don't stop at the deploy. CI/CD pipelines, structured observability with Prometheus and Loki, and the mindset of an owner, not a contractor. If it pages at 3am, I'm the one who fixed the design that caused it.
Expertise
I focus on the parts of a system where product design, security constraints and operational reality meet.
OIDC, OAuth2, FerrisKey, token lifecycle, multi-tenant realms and secure product boundaries. Protocol implementation from spec
OPA, RBAC, ABAC, delegated authorization and policy-as-code. Fine-grained access control that stays auditable when security teams need answers.
Kubernetes-native identity, service-to-service auth, mTLS and SPIFFE/SPIRE between workloads. IAM at the infrastructure layer.
Event-driven auth flows, Kafka-based audit pipelines, and consistency decisions for systems that stay explainable under failure.
Auth systems that are observable and recoverable. Structured audit logs, token flow metrics, and SLOs for security-critical infrastructure.
Flagship Product
Open-source IAM platform, built in Rust
FerrisKey is an identity and access management platform built for production, the kind of system where correctness isn't optional. I co-founded it, designed the architecture, wrote the core, and I still own the production stack.
Projects
Each project is a system decision made concrete: an architecture choice, a protocol design, years of upkeep.
IAM platform built in Rust: OIDC, multi-tenancy, a policy engine, and Kubernetes-native, for systems where correctness isn't optional.
An open-source, Discord-like communication platform: servers, channels, and realtime chat, built in Rust.
An open-source SaaS platform that centralizes core business tools: CRM, ERP, HR, and messaging, in one system.
A distributed, multi-tenant key-value database in Rust, built to expose wire-compatible protocols, Postgres among them, on top of its storage engine.
Discover all my open-source projects on GitHub.
Blog
Stay up to date with the latest news and updates.