Skip to content
View Miguel-DevOps's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report Miguel-DevOps

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Miguel-DevOps/README.md

Hello, I'm Miguel Lozano

Infrastructure & FinOps Engineer | DevSecOps & Data Platforms

Building resilient systems that remain yours.


🚀 The Mission: Capital Efficiency & Sovereignty

I help engineering teams make deliberate infrastructure decisions, choosing the right tool for the job, whether that's a hyperscaler, bare metal, or a hybrid approach with a focus on cost efficiency, observability, and data sovereignty.

My engineering philosophy is "Boring is Better": I reject unnecessary complexity (like premature Kubernetes) in favor of robust, maintainable, and cost-effective architectures that you can actually debug at 3:00 AM.

🎯 Core Focus

  • 📉 Cloud-Exit Strategy (FinOps): Migrating workloads to Bare Metal, typically cutting monthly OpEx by 40-60%.
  • 🛡️ Edge Security & DevSecOps: Enforcing OWASP/NIST compliance at the ingress using custom Caddy + Coraza WAF builds.
  • 📊 Sovereign Data Platforms: Deploying multi-tenant ELT pipelines to eliminate proprietary SaaS sprawl.

⚔️ My Tech Stack

I maintain a strict, pragmatic stack designed for Observability, Security, AI, Pipelines and low TCO.

Domain Technologies
☁️ Infrastructure AWS GCP Oracle Cloud Bare Metal Hetzner
🐧 Operating Systems Debian Ubuntu RHEL Amazon Linux CentOS ArchLinux Enterprise OS
⚙️ Orchestration Kubernetes K3s Docker Swarm Portainer BE
🛠️ IaC & Config Terraform OpenTofu Ansible Python Go Docker Woodpecker CI GitHub Actions Deterministic Config
🛡️ Security & Edge Caddy Coraza WAF CrowdSec Tailscale SOPS NIST 800-53
👁️ Observability Grafana Alloy OpenTelemetry Prometheus Grafana Loki VictoriaMetrics cAdvisor
🧠 AI Infrastructure DeepSeek R1 DeepSeek v4 Flash Qwen 3.6 GLM-5.3 MiniMax m3 Nemotron 3 Kimi k3 Granite 4.1 LangGraph
📊 Data Platforms dbt dlt PostgreSQL 17+ MariaDB MySQL ClickHouse BigQuery Redis Valkey Metabase Data Governance

📂 Featured Public Engineering

While most of my work involves confidential infrastructure under NDA, I maintain key public repositories to demonstrate architectural standards:

  • Developmi Analytics Kit: Sovereign ELT platform extracting marketing data via dlt and dbt into isolated PostgreSQL schemas for multi-tenant Metabase dashboards.
  • Developmi Stack: Ansible framework enforcing NIST 800-53 controls (SSH, AuditD) and Zero-Trust networking via Tailscale across hybrid fleets.
  • Caddy WAF: Production-hardened Docker image with Caddy + Coraza WAF + OWASP CRS v4.29.0. Supply chain security built-in: Cosign signing, SLSA provenance, Trivy scanning, non-root (UID 1337), multi-arch amd64/arm64.
  • PassiveSentry: Passive OSINT security auditing framework aligned to OWASP Top 10 2025 (A01-A10). Delivers deterministic reports with zero intrusive testing.

"Efficiency is the only metric that matters."

Explore my production benchmarks & case studies →

Popular repositories Loading

  1. nist-hardening-suite nist-hardening-suite Public

    Automated compliance as code for hybrid cloud hardening. NIST Hardening Suite converts NIST 800-53 controls into executable, auditable Ansible workflows that reduce drift and support SOC 2 and DORA…

    Jinja 3

  2. passive-sentry passive-sentry Public

    Passive OSINT security auditing framework aligned to OWASP Top 10:2025 - deterministic risk scoring, JSON/PDF reporting, and Streamlit dashboard. No exploitation, no brute force, 100% passive.

    Python 1

  3. Miguel-DevOps Miguel-DevOps Public

  4. chatbot-demo chatbot-demo Public

    Educational full-stack chatbot blueprint demonstrating evolutionary software architecture with Clean Code, comprehensive testing (99 tests passing), and progressive deployment strategy.

    PHP

  5. hybrid-swarm-kit hybrid-swarm-kit Public

  6. finops-alert-cli finops-alert-cli Public