Paris, France · Targeting English-speaking platform, backend, cloud and AI-platform roles
Merged upstream: MCP TypeScript SDK #2862 — shipped in @modelcontextprotocol/client@2.2.0
Portfolio · Engineering brief · Case studies · LinkedIn · Email
Platform and backend engineer, focused on backend services, CI/CD and GitOps delivery, Kubernetes controls, telemetry, and AI systems that run on local infrastructure rather than external APIs. Work follows a single delivery path, so everything can be reviewed, released, observed and rolled back:
code → tests → immutable artifact → reviewed GitOps → runtime → telemetry → rollback
Public work is grouped below by domain; each project is labeled by scope so the evidence stays honest.
The strongest proof is in the written studies — each maps a real system to what was built, how it was verified, and what it cost:
- LC Website & Network Security Hardening — audit → remediation → verification on LC's production Next.js platform: retired the live HTML uploader, sandboxed embedded content, bounded the lead APIs, 13/13 hardened tests.
- Linguistic Communication — Public Platform, LC Academy & Operations — WordPress → versioned Next.js catalogue (299 SSG pages), staging/prod delivery on one VPS, and the LC Academy multi-agent classroom.
- Multi-Tenant GitOps Platform — CI → immutable image → reviewed GitOps → Argo CD → Prometheus-gated rollouts → rollback, on a multi-tenant Kubernetes model.
- Secure Teacher Onboarding & Document Pipeline — NAS + Cloudflare + local-API document pipeline for LC teacher onboarding.
- OpsPilot — Local-First AI Operations Copilot — RAG over runbooks with bounded, fail-closed LLM calls and Langfuse tracing.
- LLM Council — Local Multi-LLM Orchestrator — local Ollama inference behind an authenticated gateway, anonymized peer review and chairman synthesis.
| Project | Scope | Engineering signal |
|---|---|---|
| Multi-Tenant GitOps Platform Lab | Production-style lab | GitHub Actions, multi-arch GHCR images, Helm overlays, Argo CD reconciliation, Prometheus-gated Argo Rollouts, RBAC, NetworkPolicy, Grafana + Loki. Case study |
| Cloud Analytics ML Pipeline | Production-style data lab | Config-driven PySpark ingestion, feature engineering, MLlib training/evaluation, dashboard artifacts, local-to-GCP Dataproc parity. |
| LC production infrastructure | Employer org — documented | WordPress → versioned Next.js/TypeScript catalogue (299 SSG pages), separate staging/prod GitHub Actions paths on one VPS, incident recovery. Covered in the engineering brief. |
A recurring thread is local AI: self-hosted inference (Ollama serving a 30B Qwen model) behind an authenticated OpenAI-compatible gateway bound to loopback, agent workflows orchestrated through Hermes gateways — including fixing a tool-call defect and validating real agent tool execution — and bounded workflows built on LangGraph and LangChain rather than dependent on external inference APIs.
| Project | Scope | Engineering signal |
|---|---|---|
| Thales Optronic Video Indexing | Academic collaboration | FastAPI, Celery/Redis, frame sampling, YOLO, OCR, Whisper transcription, semantic search, JSON/PDF/CSV reporting. |
| Local Multi-LLM Orchestrator | Personal systems project | Local Ollama services (30B Qwen), anonymized peer review, chairman synthesis, strict JSON/Zod contracts, SQLite run history, health/latency observability. |
| OpsPilot | Personal systems project | Local-first RAG operations copilot: evidence collection across logs/metrics/deployments/runbooks, bounded structured LLM calls, persisted investigation steps, Ollama/Gemini provider boundaries, typed contracts, fail-closed validation, Langfuse tracing. |
| LC Academy (OpenMAIC) | Employer org — deployed | AI-assisted multi-agent classroom adapted from an open-source system, with organisation-aware access control and teacher review/publishing workflows. |
| Project | Scope | Engineering signal |
|---|---|---|
| ISO 27001 Lab | Deployed learning product | Bilingual Next.js platform for evidence, risk treatment, SoA, audit, nonconformity, Annex A controls, mock-exam practice. |
| Lightweight Authentication for LIN/CAN Probes | Research prototype | Message-authentication scheme for automotive LIN/CAN buses. |
| Bangladesh E-Voting | Research prototype | Blockchain e-voting with Solidity, React and Web3.js — cast-as-intended integrity. |
| Project | Scope | Engineering signal |
|---|---|---|
| ATouPay | Product MVP | Expo/React Native client, Fastify API, Firebase identity/data, backend-owned critical writes, receipts, recovery, provider boundary for payments. |
| SyntaxMap | Teaching product | Interactive classroom tool for English grammar practice, built and used at Linguistic Communication. |
Work lands upstream in maintained projects. Each entry states its real status — nothing is presented as merged before it is.
| Contribution | Status | What changed |
|---|---|---|
MCP TypeScript SDK #2862fix(client): preserve _meta on input_required results |
Merged · shipped in @modelcontextprotocol/client@2.2.0 |
A server's result-level _meta (including the serverInfo stamp) was dropped before an allowInputRequired: true caller could see it — the 2026-07-28 decode seam rebuilt the payload from inputRequests and requestState only. Traced the loss to both decode sites, passed the field through, added regression tests that fail unpatched. commit |
OpenTelemetry browser #429feat(instrumentation): add Long Animation Frames instrumentation |
In review · changes requested | Long Animation Frames instrumentation for the OpenTelemetry browser SDK, the successor to the deprecated long-task API. Reviewed by three maintainers; the open asks are documenting behaviour around the browser's own ~200-entry buffer and not replaying that buffer on re-enable. |
OpenTelemetry JS contrib #3669fix(instrumentation-long-task): deprecate package |
In review | Deprecation notice, runtime warning and regression test for the long-task package ahead of its removal. |
OpenTelemetry JS contrib #3788test(instrumentation-aws-sdk): make three silent-pass tests assert their failure paths |
In review | Three AWS SDK instrumentation tests passed whether or not the behaviour they describe worked: a matcher that was never chained, error-path assertions stranded inside a catch, and six streaming tests that exited early — which the test runner counts as a pass. Each now fails when the behaviour breaks. |
Process: reproduce the issue → propose a focused change → sign the CLA → iterate with maintainers → land. One earlier attempt, Grafana MCP #1166, was closed as won't-fix — the maintainer prefers the HTTP transport for that case.
A proportionate security baseline applied to Linguistic Communication's public Next.js platform, validated in staging then production:
- Retired the live HTML uploader in favour of Git-reviewed publication.
- Sandboxed embedded content without
allow-same-origin. - Bounded the two lead APIs (
quiz-lead,b2b-diagnostic-lead): content-type checks, 64 KB body cap, field/array limits. - Bot and abuse controls: honeypot, minimum completion time, short-window duplicate suppression, SMTP rate limits.
- Edge identity and headers: trusted client-IP restoration behind Cloudflare, baseline security headers, CSP report-only, disabled
X-Powered-By, Nginx body/rate limits,security.txt+ data-handling policy. - Evidence: a baseline-vs-hardened scenario harness (13/13 hardened tests pass; primary runtime/static classes 1/14 → 14/14) plus staging and production validation.
Full write-up: LC Website & Network Security Hardening — audit → remediation → verification.
| Platform delivery | Backend systems | Observability & AI |
|---|---|---|
| Linux · Docker · Kubernetes · Helm · Argo CD · GitHub Actions | TypeScript · Python · FastAPI · Fastify · PostgreSQL | OpenTelemetry · Prometheus · Grafana · LangGraph · LangChain · RAG · pgvector · Ollama |
Open to platform, backend, cloud, and AI-platform roles — Paris or remote. The fastest read is the six-page engineering brief; the deepest is the portfolio evidence map.




