Skip to content
View revendh's full-sized avatar

Block or report revendh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
revendh/README.md

Typing SVG




LinkedIn Gmail Portfolio GitHub Profile Views


🧭 Executive Summary

A DevSecOps Engineer who treats security as infrastructure, not an afterthought. I design self-healing, zero-downtime Kubernetes platforms and weave SAST, DAST, SCA, SBOM, and image-signing directly into the CI/CD fabric — so vulnerabilities are caught before merge, not after breach.

⚡ 5s

Config propagation time (down from full restarts)

📉 60%

Manual release effort cut via CI/CD automation

🛡️ 100%

Service availability during hybrid-cloud cutover

🎯 Pre-Merge

Vuln detection shift from post-deployment


🚀 About Me

role: DevSecOps Engineer @ Tata Elxsi
focus: [Kubernetes, GitOps, Application Security, Hybrid Cloud]
philosophy: "Shift security left, automate everything, break nothing"
current_mission: Building zero-downtime, self-securing delivery platforms
fun_fact: I write Rust for infrastructure that can't afford to restart
  • 🔐 Security-First Engineer — I don't bolt security onto pipelines, I build pipelines around security
  • ☸️ Kubernetes Native — from bare-metal Talos cluster provisioning to production-grade RBAC and network policy
  • ⚙️ Automation Obsessed — if a human is doing it twice, I'm already scripting it
  • 🌐 Hybrid-Cloud Practitioner — zero-downtime migrations across on-prem and cloud, validated in production
  • 📖 Perpetual Learner — currently deep in platform engineering, supply-chain security, and AI-assisted DevSecOps

💼 Impact Highlights

🏗️ What I Built📊 Measurable Result
Zero-downtime Kubernetes config hot-reload platform (Rust + NATS JetStream + Apache Arrow)Config propagation cut to <5 seconds — zero service restarts
End-to-end signed CI/CD pipeline (GitHub Actions + Cosign + Harbor/Nexus hub-spoke)~60% reduction in manual release effort
GitOps rollout with ArgoCD + Helm across multi-cluster environmentsImproved deployment consistency and faster rollback
Hybrid-cloud migration via IBM Hybrid Cloud Mesh + Concert Workflow100% service availability maintained during cutover
Full-spectrum security tooling integration (SAST/DAST/SCA/SBOM/Cosign) into CI/CDDetection shifted from post-deployment → pre-merge
Continuous remediation cycles using SonarQube, Trivy, OWASP ZAP, Nessus, KiuwanSteady reduction of open critical/high findings
Kubernetes hardening for NCCS compliance alignmentPlatform met regulatory security baselines

🛠 Tech Arsenal

Languages & Scripting

Operating Systems

Containers & Kubernetes

CI/CD & GitOps

DevSecOps & Security Tools

Cloud & Infrastructure as Code

Monitoring & Version Control


🔥 Core Competency Matrix

DomainProficiency
Kubernetes Administration
CI/CD Pipeline Engineering
DevSecOps / Shift-Left Security
GitOps (ArgoCD / Helm)
Container & Image Security
Vulnerability Management (SAST/DAST/SCA)
Hybrid-Cloud Migration
Linux Systems Administration
Infrastructure as Code
Rust for Systems Programming

📈 Professional Journey

Jun 2023 —
Present

DevOps / DevSecOps Engineer · Tata Elxsi, Chennai

  • 🏗️ Engineered a zero-downtime configuration hot-reload platform on Kubernetes (Rust + NATS JetStream + Apache Arrow) — eliminated restarts, cut propagation time to <5 seconds
  • ⚙️ Built signed, automated release pipelines (GitHub Actions + Cosign) across a Harbor/Nexus hub-spoke architecture — cut manual release effort ~60%
  • 🔄 Championed GitOps adoption (ArgoCD + Helm), boosting deployment consistency and rollback reliability across multi-cluster production
  • 🖥️ Owned Kubernetes cluster lifecycle on Talos Linux & Omni — workloads, RBAC, ConfigMaps, Secrets, network policies at production scale
  • ☁️ Led zero-downtime hybrid-cloud migrations via IBM Hybrid Cloud Mesh & Concert Workflow — 100% availability maintained
  • 🔎 Embedded SAST · DAST · SCA · secret scanning · SBOM · Cosign signing into CI/CD — moved detection pre-merge
  • 🩹 Drove continuous remediation with SonarQube, Kiuwan, Trivy, OWASP ZAP, Nessus — steadily reduced critical/high findings
  • ✅ Hardened Kubernetes workloads to meet NCCS compliance standards
  • 🌐 Supported on-prem infrastructure setup — server provisioning, network switch configuration

🚀 Flagship Projects

🛰️ TE-OSM

Network Function Orchestration Platform (ETSI-based)

Problem: Orchestration workloads needed a security-hardened, compliance-ready foundation.

Solution: Hardened configs, aligned controls to NCCS, integrated SAST/DAST/SCA into CI/CD.

Stack: Kubernetes SAST DAST SCA NCCS

Impact: Elevated platform security posture; achieved compliance readiness for ETSI orchestration workloads.

☁️ IBM Partner Program

Hybrid-Cloud Migration & Automation

Problem: Workloads needed cross-environment migration with zero disruption.

Solution: Secure connectivity via IBM Hybrid Cloud Mesh + Concert Workflow using IBM-provisioned VANs.

Stack: IBM Hybrid Cloud Mesh Concert Workflow VANs

Impact: 100% service continuity across the full migration cutover.

⚡ BloomEdge

Kubernetes Configuration Management Platform

Problem: Config changes forced restarts, causing downtime at the edge.

Solution: Zero-downtime runtime updates; automated validate → sign → distribute via GitHub Actions, ArgoCD, Helm, and Kargo-driven promotion.

Stack: Kubernetes GitHub Actions ArgoCD Helm Kargo Harbor Nexus

Impact: Fully automated OCI artifact promotion to edge — zero downtime, zero manual intervention.


📚 Certifications


🎯 Currently Leveling Up


📊 GitHub Analytics

💡 Swap revendh for your real GitHub username to bring every widget above to life.


🌱 Areas of Interest

KubernetesCloud NativeDevSecOpsPlatform EngineeringCyber SecurityInfrastructure AutomationAI-Driven DevSecOps


🤝 Let's Build Something Secure Together

LinkedIn Gmail Portfolio GitHub


💡 "Security isn't a gate at the end of the pipeline — it's the foundation every stage is built on."


Popular repositories Loading

  1. hello-world hello-world Public

    Forked from yankils/hello-world

    Java

  2. sonarqube sonarqube Public

    Forked from darinpope/java-web-app

    Java

  3. Car-Warehouse Car-Warehouse Public

    Forked from MostafaMGomaa/Car-Warehouse

    The Car Warehouse Management System is a backend application developed in Node.js and Express.js. The application allows you to perform operations such as adding new cars, retrieving existing cars,…

    JavaScript

  4. demo_concert demo_concert Public

  5. Portfolio Portfolio Public

    Resume

    HTML

  6. demo demo Public

    Forked from saravanan014/demo