intive was eager to do a step forward in adopting cloud technologies and infrastructure as code. On the one hand, advancing their infrastructure landscape to offer more flexibility and on the other hand driven by project tasks commissioned by customers. We introduced a new DevOps team and an ecosystem based on tools like Artifactory, CMake, Conan etc and trained the developers.
The intention of AVL to get Linux and open-source tools into their portfolio was a sensible and promising, but in the end they struggled with their own IT organisation to get it rolling in a productive way.
The continuous integration and continuous deployment process on the Brocade Web Application Firewall provided the possibility to introduce new technologies like Docker to shorten release cycles.
The participation in the development of the stingrayaf Web Application Firewall showed that the testing as a whole is an important but also complex task. The idea of continuous integration helped to obtain new views and on how testing and how to pull the team together to create a better product for the customer.
The internship gave a hands-on experience diving into the Linux kernel space dealing with a Broadcom wireless driver on the lowest level. The task was to extract the RSSI and MAC address of mobile clients before they get associated with an access point and deliver the data over the network.
CERT
MAIN
He was always curious to know about how technical things work, especially computer systems, which began in the early days of the Commodore64. He started an apprenticeship in office administration, most likely motivated by his father?s background, and obtained valuable knowledge and skills in business management. But due to his inquisitiveness about computer systems he finally made his decision to start an academic life and found his way into computer science in which he graduated successfully. During his time at the university of applied sciences in Regensburg he gained knowledge about computer systems and electronic devices. Gentoo Linux become his favourite operating system and the Fraunhofer Institute in Nuremberg, Germany, gave him the opportunity to pull up his sleeves to get a hands-on experience in the Linux kernel space. After his thesis about regular expression engines he got a chance to be employed by an IT-security company previously known as art of defence. During his work on the web application firewall eco-culture, especially on developing, managing and evolving the testing procedures and processes, for several platforms and architectures like Linux, Windows and Solaris and amd64 and i386, he gained significant experience in automated testing and the DevOps thinking in general. Due to acquisitions by some American companies art of defence changed the name from Zeus to Riverbed and merged into Brocade. The latter company decided to sell off the software department before merging into Broadcom. This gave him a chance to move into the automotive industry. After a short stop at AVL Software and Functions, intive became his new professional home where he was responsible for tasks to help the company to adopt cloud technologies like containerization of services and infrastructure as code. He was responsible for continuous integration and continuous delivery modernizing the build systems for several related embedded, classic AUTOSAR customer projects. He helped to give the pipelines to a modern shape and promoted new systems company-wide, trained developers and introduced new open-source software. After his journey with intence and intive continued as freelancing software engineer. He was contractor for Continental Automotive and Temic Microelectronic and had a major role in bringing Classic and Adaptive Autosar projects to the next level. He supported in managing and fixing C-based tests and frameworks, embedded Linux environments for builds and testing and updated old systems to CMake/Ninja/Conan/VS Code with bootstrapping mechanism based on Python for several hundred of developers world-wide.
SKILL
CHARACTER CLOUD
terminal, cloud, security, ambitious, VPN, macOS, Buildroot, inquisitive, focused, Linux, CI/CD, AWS, pipeline, Autosar, Rust, reverse-engineering, Posix, buildsystem, DevOps, site-reliability, intrinsic motivation, embedded, blockchain, web, Git, DNS, automotive, networking, crypto
Side Quest
FARMLAND.ROCKS
A build orchestration system to distribute builds to nodes, cloud-native and cloud agnostic based on Rust.
ROBBERS AND COPS
A flutter-based mobile game, on-premise kubernetes backend infrastructure with ingress load balancer and JWT-based authorization.
CRYPTO LENDING PLATFORM
A Python-based agent network which automates tasks for different crypto exchanges. K8s-based with on-premise and self-managed nodes, public ingress with VPN.
EXPERTISE
Automotive and Embedded
The automotive industry renders a more conservative picture of the IT world. This is also caused by the tools landscape and the high security and safety standards like Misra, CertC or ISO 26262. Highly static embedded classic autosar systems and linux related adaptive autosar bring a lot of complexity that needs to be handled carefully. The complicated SDLC for such projects costs a lot of resources and developer time but AI seems to bring here tremendous new potential to speed up development cycles in the future.
Virtualization and Cloud
Managing infrastructure depends on virtualization more than ever before. Containerized applications, bare-metal or software hypervisors, virtual machines or even more growing managed cloud services are key aspects for a stable and future-proof environment for development, testing and production. By abstracting infrastructure components from the physical layer it enables rapid adoption to new or changed requirements and avoids potential problems with static systems.
Application Containers
Containers gained a lot of traction in the last years though the concept is not new. FreeBSD Jails and Solaris Zones are complete implementations with similar concept but lack popularity. Especially in testing and DevOps containers proved easy to use. The product or service is packed in containers and deployed without having to deal with dependencies. Container orchestration tools like Kubernetes are industry standard to schedule containers across physical borders at scale or even across datacenters at a production grade level and enable horizontal scaling.
Infrastructure as Code
Infrastructure is important in every IT Project but Infrastructure as Code gives the possibility to set up entities with a push of a button. The Terraform tool for example could be used to utilise an on-premise bare-metal hypervisor like VMware or a cloud-provider like Amazon AWS. Configuration of such entities becomes auditable and therefore reviewable because it manifests in code. This is an important step forward and helps to create infrastructure in a fraction of the time and avoids configuration drift. IaC together with immutable infrastructure renders the next step in a modern cloud-native IT environment.
Continuous Integration
To create a better product the team needs to collaborate and share thoughts and results about builds and tests of the features currently developed. The continuous integration and continuous deployment paradigm helps to shorten the development cycles and integrate all parties in a responsive loop. The SDLC gets more transparent and the team can focus on the real things to create a better product. Having good and robust pipelines is important to the whole SDLC but is also a challenging task especially in more hardware related projects like embedded AUTOSAR.
Information Security
Awareness of emerging security risks like zero-day exploits or ransomware has been growing in recent years. Ransomware especially poses a great risk to smaller companies, and supply-chain attacks against CICD pipelines with cloud-services and open-source software bring new challenges. Not just technologies but also the attack vectors became more sophisticated. Exploits like Shellshock showed that vulnerabilities could remain hidden for years. Fixing vulnerabilities for web apps could lead to a big effort which would be easily mitigated with a web application firewall that helps to block such attacks. Working at the WAF brought in-depth awareness of IT security, and ongoing trainings and self-study from pen testing to reverse engineering helps to keep this growing field in mind.
intive was eager to do a step forward in adopting cloud technologies and infrastructure as code. On the one hand, advancing their infrastructure landscape to offer more flexibility and on the other hand driven by project tasks commissioned by customers. We introduced a new DevOps team and an ecosystem based on tools like Artifactory, CMake, Conan etc and trained the developers.
The intention of AVL to get Linux and open-source tools into their portfolio was a sensible and promising, but in the end they struggled with their own IT organisation to get it rolling in a productive way.
The continuous integration and continuous deployment process on the Brocade Web Application Firewall provided the possibility to introduce new technologies like Docker to shorten release cycles.
The participation in the development of the stingrayaf Web Application Firewall showed that the testing as a whole is an important but also complex task. The idea of continuous integration helped to obtain new views and on how testing and how to pull the team together to create a better product for the customer.
The internship gave a hands-on experience diving into the Linux kernel space dealing with a Broadcom wireless driver on the lowest level. The task was to extract the RSSI and MAC address of mobile clients before they get associated with an access point and deliver the data over the network.
CERT
MAIN
He was always curious to know about how technical things work, especially computer systems, which began in the early days of the Commodore64. He started an apprenticeship in office administration, most likely motivated by his father?s background, and obtained valuable knowledge and skills in business management. But due to his inquisitiveness about computer systems he finally made his decision to start an academic life and found his way into computer science in which he graduated successfully. During his time at the university of applied sciences in Regensburg he gained knowledge about computer systems and electronic devices. Gentoo Linux become his favourite operating system and the Fraunhofer Institute in Nuremberg, Germany, gave him the opportunity to pull up his sleeves to get a hands-on experience in the Linux kernel space. After his thesis about regular expression engines he got a chance to be employed by an IT-security company previously known as art of defence. During his work on the web application firewall eco-culture, especially on developing, managing and evolving the testing procedures and processes, for several platforms and architectures like Linux, Windows and Solaris and amd64 and i386, he gained significant experience in automated testing and the DevOps thinking in general. Due to acquisitions by some American companies art of defence changed the name from Zeus to Riverbed and merged into Brocade. The latter company decided to sell off the software department before merging into Broadcom. This gave him a chance to move into the automotive industry. After a short stop at AVL Software and Functions, intive became his new professional home where he was responsible for tasks to help the company to adopt cloud technologies like containerization of services and infrastructure as code. He was responsible for continuous integration and continuous delivery modernizing the build systems for several related embedded, classic AUTOSAR customer projects. He helped to give the pipelines to a modern shape and promoted new systems company-wide, trained developers and introduced new open-source software. After his journey with intence and intive continued as freelancing software engineer. He was contractor for Continental Automotive and Temic Microelectronic and had a major role in bringing Classic and Adaptive Autosar projects to the next level. He supported in managing and fixing C-based tests and frameworks, embedded Linux environments for builds and testing and updated old systems to CMake/Ninja/Conan/VS Code with bootstrapping mechanism based on Python for several hundred of developers world-wide.
SKILL
CHARACTER CLOUD
terminal, cloud, security, ambitious, VPN, macOS, Buildroot, inquisitive, focused, Linux, CI/CD, AWS, pipeline, Autosar, Rust, reverse-engineering, Posix, buildsystem, DevOps, site-reliability, intrinsic motivation, embedded, blockchain, web, Git, DNS, automotive, networking, crypto
Side Quest
FARMLAND.ROCKS
A build orchestration system to distribute builds to nodes, cloud-native and cloud agnostic based on Rust.
ROBBERS AND COPS
A flutter-based mobile game, on-premise kubernetes backend infrastructure with ingress load balancer and JWT-based authorization.
CRYPTO LENDING PLATFORM
A Python-based agent network which automates tasks for different crypto exchanges. K8s-based with on-premise and self-managed nodes, public ingress with VPN.
EXPERTISE
Automotive and Embedded
The automotive industry renders a more conservative picture of the IT world. This is also caused by the tools landscape and the high security and safety standards like Misra, CertC or ISO 26262. Highly static embedded classic autosar systems and linux related adaptive autosar bring a lot of complexity that needs to be handled carefully. The complicated SDLC for such projects costs a lot of resources and developer time but AI seems to bring here tremendous new potential to speed up development cycles in the future.
Virtualization and Cloud
Managing infrastructure depends on virtualization more than ever before. Containerized applications, bare-metal or software hypervisors, virtual machines or even more growing managed cloud services are key aspects for a stable and future-proof environment for development, testing and production. By abstracting infrastructure components from the physical layer it enables rapid adoption to new or changed requirements and avoids potential problems with static systems.
Application Containers
Containers gained a lot of traction in the last years though the concept is not new. FreeBSD Jails and Solaris Zones are complete implementations with similar concept but lack popularity. Especially in testing and DevOps containers proved easy to use. The product or service is packed in containers and deployed without having to deal with dependencies. Container orchestration tools like Kubernetes are industry standard to schedule containers across physical borders at scale or even across datacenters at a production grade level and enable horizontal scaling.
Infrastructure as Code
Infrastructure is important in every IT Project but Infrastructure as Code gives the possibility to set up entities with a push of a button. The Terraform tool for example could be used to utilise an on-premise bare-metal hypervisor like VMware or a cloud-provider like Amazon AWS. Configuration of such entities becomes auditable and therefore reviewable because it manifests in code. This is an important step forward and helps to create infrastructure in a fraction of the time and avoids configuration drift. IaC together with immutable infrastructure renders the next step in a modern cloud-native IT environment.
Continuous Integration
To create a better product the team needs to collaborate and share thoughts and results about builds and tests of the features currently developed. The continuous integration and continuous deployment paradigm helps to shorten the development cycles and integrate all parties in a responsive loop. The SDLC gets more transparent and the team can focus on the real things to create a better product. Having good and robust pipelines is important to the whole SDLC but is also a challenging task especially in more hardware related projects like embedded AUTOSAR.
Information Security
Awareness of emerging security risks like zero-day exploits or ransomware has been growing in recent years. Ransomware especially poses a great risk to smaller companies, and supply-chain attacks against CICD pipelines with cloud-services and open-source software bring new challenges. Not just technologies but also the attack vectors became more sophisticated. Exploits like Shellshock showed that vulnerabilities could remain hidden for years. Fixing vulnerabilities for web apps could lead to a big effort which would be easily mitigated with a web application firewall that helps to block such attacks. Working at the WAF brought in-depth awareness of IT security, and ongoing trainings and self-study from pen testing to reverse engineering helps to keep this growing field in mind.