Skip to content
View geek-kb's full-sized avatar

Block or report geek-kb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
geek-kb/README.md

Itai Ganot

Principal DevOps Engineer | Cloud-Native Architecture | Kubernetes Security

I design and lead the implementation of secure, scalable cloud-native platforms.

My work focuses on platform architecture, Kubernetes security strategy, GitOps operating models, and infrastructure design across multi-environment and multi-account cloud systems.

I operate at the intersection of architecture, automation, and security — building platforms that enable teams to move fast without compromising reliability or control.

Architecture & Technical Leadership

Platform Engineering
Designing internal platforms that standardize infrastructure patterns, enforce security baselines, and reduce cognitive load for development teams.

Cloud Architecture
Multi-account AWS design, environment isolation, IAM boundary modeling, secure networking, and production-grade deployment workflows.

Kubernetes & GitOps
Cluster architecture, workload security boundaries, admission control strategies, and declarative delivery using ArgoCD and Helm.

Infrastructure as Code
Terraform, Terragrunt, Crossplane — building reusable, composable infrastructure modules aligned with organizational standards.

Security Engineering
Kubernetes hardening, RBAC design, network segmentation, mTLS, CIS alignment, and DevSecOps integration within CI/CD pipelines.

Selected Work

k8s_security
A structured knowledge base exploring Kubernetes attack vectors and mitigation strategies.
Connects threat modeling with practical defensive architecture patterns.

trivy-ui
A web interface for analyzing and operationalizing Trivy vulnerability scan results.
Focused on improving security visibility and remediation workflows in DevSecOps environments.

Infrastructure & Automation Patterns
Reusable infrastructure components and deployment workflows for multi-environment cloud systems.

Technical Focus Areas

  • Kubernetes security architecture and threat modeling
  • GitOps operating models at scale
  • Secure cloud-native platform design
  • Infrastructure standardization and governance
  • Production reliability and observability patterns

Writing & Knowledge Sharing

https://k8s-security.guru

https://geek-kb.com

Community contributions:

https://serverfault.com/users/109833/itai-ganot

https://stackoverflow.com/users/1702942/itai-ganot

Connect

LinkedIn
https://www.linkedin.com/in/itai-ganot/

Pinned Loading

  1. DevopsStuff DevopsStuff Public

    A curated set of practical DevOps resources including infrastructure as code, automation scripts, configuration management playbooks, and Kubernetes deployment examples.

    Python 14 7

  2. k8s_security k8s_security Public

    Comprehensive Kubernetes security guide covering attack vectors, best practices, mitigation strategies, and tools aligned with CKS certification domains.

    TypeScript 6 2

  3. dotfiles dotfiles Public

    Cross-platform development environment configuration for Zsh, Neovim, WezTerm, Git, and modern DevOps tooling.

    Lua

  4. trivy-ui trivy-ui Public

    A modern, secure, and lightweight web interface for browsing, filtering, and visualizing Trivy vulnerability scan reports, with support for file upload and detailed analysis.

    Python 1