My Projects

Real repositories I own and ship: distributed systems, data platforms, ML infrastructure, and low-level software. Each card links to the code behind it.

Flagship Systems

ForgeCI

Completed

Distributed Systems: A CI engine built from scratch in Go to explore the control plane behind remote execution. It persists DAG state, schedules jobs across runners, freezes each submission as an immutable source snapshot, and delivers logs, artifacts, cache entries, and GitHub Checks through durable boundaries.

GoPostgreSQLDockerGitHub AppsContent-addressed storage
Design highlight: every job lease is fenced by runner, run, job, lease ID, generation, and expiration. A stale worker cannot download source, transfer artifacts, append logs, or report completion after ownership changes.

Lost remote jobs are conservatively marked aborted; automatic job retry and reassignment are intentionally out of scope.

CommerceCore

Completed

Backend Engineering: A correctness-first Spring backend for checkout under inventory contention, request retries, payment ambiguity, and message redelivery. A separate Payment Service provides a real PostgreSQL-backed gRPC ownership boundary rather than an in-process mock.

JavaSpring BootPostgreSQLgRPCKafkaTestcontainers
Design highlight: a payment deadline does not become a false decline. CommerceCore persists UNKNOWN, then reconciles by looking up the provider's durable result without reauthorizing; stable request identity makes retries idempotent.

The project models one merchant and one currency; it is a correctness laboratory, not a complete commerce product.

PgSentry

Completed

Database Reliability: A PostgreSQL high-availability and recovery lab using Patroni with etcd quorum, streaming replication, and HAProxy routing. It separates failover from data recovery through partition tests, durability experiments, backups, WAL archiving, and point-in-time recovery.

PostgreSQLPatronietcdHAProxyWALDocker Compose
Design highlight: replicas can preserve and reproduce a valid destructive write. The recovery path therefore restores database history from a base backup plus archived WAL instead of treating automatic failover as a substitute for recovery.

A local failure lab with deliberate faults, not a hosted database service or a claim of zero data loss under every configuration.

MatchSense

Active Development

Distributed Systems: Real-time football (soccer) analytics: simulated match events flow through Kafka into a stats aggregator, an ML prediction service, and a live Grafana dashboard. The interesting part isn't the sport, it's making the event pipeline survive retries, duplicates, and partial failures.

GoPython / FastAPIKafkaRedisOpenTelemetryKubernetes / ArgoCDKyverno
Design highlight: idempotent event ingestion via client-supplied or generated event IDs, so retried publishes are deduplicated instead of double-counted, with an OpenTelemetry trace context propagated through Kafka headers end to end.

Match events and ML training data are simulator-generated, not live sports data.

Aegis

Completed

Platform Engineering / Security: A self-hosted GitOps Kubernetes platform built to prove security and reliability controls under real, deliberate failure: leaked secrets, unsigned images, lateral network movement, database destruction, host reboot, a signed-but-broken release.

KubernetesFlux (GitOps)KyvernoCiliumCosignPrometheus / GrafanaSOPS + age
Design highlight: a fully signed, policy-admitted release still shipped a real latency regression: Kubernetes, Kyverno, and network tracing all reported the workload healthy; only a Prometheus SLO caught it, proving that passing every supply-chain gate is not the same as working correctly.

A development-security posture, evidence-backed at every layer tested; not described as zero-trust, and its feature set is intentionally frozen.

Market Pulse

Active Development

Data Engineering: A local stock-market analytics lakehouse. Daily OHLCV price bars land raw in an Iceberg bronze table, get cleaned into silver, and roll up into a gold analytics layer (returns, moving averages, volatility, volume-anomaly detection) via dbt-on-Trino, orchestrated by Airflow.

Apache IcebergMinIOTrinodbtAirflowTerraformSuperset
Design highlight: incremental ingestion with an idempotent delete-and-replace-partition write pattern, dbt data-quality tests on every layer, and a manual/weekly end-to-end workflow that runs the real stack against Trino rather than trusting fixtures alone.

Linux Kernel Lab

Completed

Systems Programming: Built Linux 6.10 from source and booted it in QEMU with a custom BusyBox initramfs, wrote a character-device driver, and attached GDB to a paused kernel at start_kernel to step through early boot.

Linux 6.10CQEMUGDBBusyBoxGCC / LLVM
Design highlight: the debugging trail, not the driver itself: a GCC 15/C23 keyword collision breaking the boot decompressor, a GCC-vs-Clang/LTO module mismatch, and an "Attempted to kill init" panic that turned out to be QEMU's default CPU model, not a kernel bug.

Personal Cognitive Load Monitor

Active Development

MLOps: An educational MLOps platform around a FastAPI cognitive-load classifier: experiment tracking, data versioning, containerized serving, and drift monitoring, built to exercise the full path from notebook to (would-be) production.

FastAPIMLflowDVCDocker / HelmKServePrometheus / GrafanaEvidently
Design highlight: KServe scale-to-zero serving behind an HPA, with Evidently drift reports, Tempo tracing, and Loki logging wired into the same coverage-gated CI/CD pipeline as the model code.

Uses synthetic data for an educational MLOps demonstration, not a medical or clinically validated system.

Company Research

Completed

Applied AI / Full Stack: A full-stack platform for researching companies against a resume: a Retrieval-Augmented Generation pipeline matches resumes to job postings using LangChain retrieval and LangGraph orchestration over a pgvector store, streamed back to the client over Server-Sent Events.

ReactNode.jsFastAPIMongoDBPostgreSQL / pgvectorLangChainLangGraph
Design highlight: a three-node LangGraph pipeline (retrieve → rate → advise) streaming results incrementally via SSE instead of blocking on a single long response.

QuorumKV

In Progress

Distributed Systems: A distributed key-value store built to study consensus from first principles. Raft is implemented from scratch here, not imported as a library: persistent state, log replication, leader election with PreVote, snapshotting, joint-consensus membership changes, leadership transfer, and quorum-confirmed reads, driven by a real node executable over real TCP.

GoRaft (from scratch)TCPReadIndex
Design highlight: at-most-once PUT/DELETE effects for retried requests via a replicated per-client request identity, and quorum-confirmed (ReadIndex) linearizable GET to eliminate stale reads from an isolated old leader; crash-recovery correctness is checked with real subprocess kills at each meaningful write point, not simulated failures.

Correctness properties are implemented and tested, not formally proven.

PageDB

In Progress

Systems Programming: A relational database engine built bottom-up in C23: persistent slotted pages, a Clock buffer pool, multi-page table heaps, typed schemas and catalog, a persistent B+ tree index, pull-based physical execution operators, and a bounded SQL parser/planner behind a loopback-only server speaking a custom binary wire protocol.

C23CMakeASan / UBSanB+ Tree
Design highlight: each layer of the storage stack (disk manager, slotted pages, buffer pool, heap, index, executor, SQL) is built and tested on top of the one below it, so the current read-only SELECT subset runs end to end through a real page cache and B+ tree rather than an in-memory stand-in.

Physical execution is read-only, single-threaded, and single-table; no joins, transactions, WAL, or crash recovery yet.

Wirestack

In Progress

Systems Programming: A userspace TCP/IP network stack in C++20, built from a Linux TAP device up through Ethernet, ARP, IPv4, ICMP, UDP, and TCP to a minimal HTTP server. The goal is understanding the protocols by implementing them: real handshakes, real congestion control, real retransmission.

C++20Linux TAPTCP/IPReno / NewReno
Design highlight: the TCP path implements MSS/window-scale/SACK negotiation, Reno-style congestion control with NewReno partial-ACK recovery, and RTT-adaptive retransmission, then live-qualifies the handshake, a real curl request, and out-of-order delivery against an actual Linux kernel in an isolated-namespace test harness with packet-capture evidence.

A learning project prioritizing protocol correctness over performance; TCP simultaneous open, DSACK, and modern congestion control (CUBIC/BBR) are not implemented.

TensorForge

In Progress

ML Systems: An analytical AI-accelerator performance modeling toolkit for GEMM, Transformer, and Conv2D workloads. It makes every step of accelerator performance reasoning explicit and traceable to a formula: arithmetic intensity, PE-array mapping, SRAM feasibility, tiling, and roofline-based compute/memory timing.

PythonRoofline ModelingDesign-Space Exploration
Design highlight: three explicit, fully-specified tiling/loop schedules (c-resident, a-resident, b-resident) each derive a different exact DRAM traffic total from the same GEMM arithmetic, and a bounded design-space search ranks user-supplied tile/schedule/PE-array candidates by modeled execution time.

An analytical modeling toolkit, not a cycle-accurate simulator or a complete Transformer/CNN inference simulator.

Earlier Projects & Labs

Earlier application work, infrastructure labs, and smaller tools.

MatchSense

Earlier Project

Event-driven football analytics built around idempotent Kafka ingestion, Redis state, cross-service traces, and simulator-generated events.

Market Pulse

Earlier Project

A local Iceberg lakehouse with incremental ingestion, dbt-on-Trino transformations, data-quality gates, and a verified end-to-end workflow.

Linux Kernel Lab

Completed Lab

A Linux source build, BusyBox initramfs, QEMU/GDB early-boot workflow, and character-device driver with recorded toolchain failures.

Personal Cognitive Load Monitor

Course Project

An educational MLOps system using synthetic data, tracked experiments, FastAPI serving, drift reports, and Kubernetes manifests.

Company Research

Earlier Project

A full-stack company research application with a pgvector retrieval path and streamed resume-fit evaluation.

LearnOps Tracker

Completed

Full-stack DevOps learning tracker: skills, certifications, roadmap items, and analytics, with GitHub repo linking and import/export.

Next.jsTypeScriptPrismaPostgreSQL

NoteKeeper Platform

Completed

GitOps microservices platform: three Go services, CI security gates (Gitleaks, Trivy, Cosign), and Kyverno admission policies enforced through ArgoCD.

GoArgoCDKyvernoCosign

Lay-Off-Link

Active Development

End-to-end MLOps and data platform: model training/serving, data pipelines, and Kubernetes deployment behind a multi-stage CI/CD pipeline.

KubernetesHelmTerraformMLflow

DevSecOps Lab

In Progress

A personal, from-scratch DevSecOps pipeline across multiple VMs: Jenkins security gates before pushing to a private Harbor registry and deploying via Helm to Kubernetes.

JenkinsKubernetesHelmGitleaks / Semgrep / Trivy

DevOps SSH Lab

Completed

Secure remote Linux administration over a private Tailscale network: SSH hardening, key-based access, and connectivity troubleshooting.

LinuxSSHTailscale