Skip to content
View Brsalcedom's full-sized avatar
🕗
🕗

Block or report Brsalcedom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
brsalcedom/README.md

👋 Hi, I’m Bryan Salcedo

DevOps GitOps IaC
Pentesting Kubernetes Networking AWS Cloudflare

DevOps | CloudOps | GitOps Engineer · Security Enthusiast & Pentester · Infrastructure-as-Code Advocate
I build automated, secure, and reproducible infrastructures from bare-metal to cloud, with a strong background in self-hosting, Linux, and offensive security.


🧩 Areas of Expertise

Domain Tools / Technologies
DevOps & IaC Terraform · Packer · Ansible · GitHub Actions
GitOps ArgoCD · FluxCD · Helm · Kustomize · Renovate
CloudOps AWS · GCP · Cloudflare · Lambda · IAM · Route 53 · WAF · Transfer Family
Kubernetes EKS · GKE · K3s · Gateway API · Cilium · Istio · Linkerd · Cert‑Manager · MetalLB
Networking DNS (Pi‑hole + Unbound) · WireGuard · Netbird · VPC · Routing & NAT
Storage Rook + Ceph · Longhorn · S3 / MinIO
Observability Grafana · Prometheus · Loki · Alertmanager
Security & Pentesting Pentesting · Bug Bounty · SOPS · IAM Policies · OIDC · Cloudflare Access · Kyverno · OPA
Scripting Bash · Python · PowerShell · YAML

📃 Certifications & Skills

These certifications validate my skills in DevOps, Cloud, Security, and Languages:

  • ☁️ AWS Certified Solutions Architect – Professional (AWS)
  • GitHub Actions Certified – GitHub workflows, CI/CD automation
  • GitHub Administration Certified – GitHub repo/org management, security best practices
  • 🛡 eWPT – Web Application Penetration Tester (INE Security, 2023)
  • 🛡 eJPT – Junior Penetration Tester (INE Security, 2021)

🛠️ What I Build

  • 🌐 Fully automated homelab with GitOps stack using K3s, Terraform, ArgoCD, and FluxCD.
  • ☁️ Hybrid-cloud architecture with Cloudflare DNS/WAF/Access integrated with AWS and GCP.
  • 🔐 Zero-Trust access setup using Cloudflare Access + Netbird for secure remote operations.
  • 🧰 Infrastructure modules via Terraform and Packer, with CI/CD pipelines in GitHub Actions.
  • 📦 Self-hosted services orchestrated with Docker Swarm within LXC containers on Proxmox.
  • 🔍 Security-aware deployments and pentesting writeups, available through my personal blog.

🌍 Current Setup

  • 🖥️ Hardware: Beelink Intel N100 mini PC · 16 GB RAM · 500 GB SSD · Proxmox VE
  • 📦 Environments:
    • VM 1: Rocky Linux + K3s (ArgoCD-managed cluster)
    • VM 2: Rocky Linux + K3s (FluxCD-managed cluster)
    • LXC Containers: swarm-01 & swarm-02 running Docker Swarm workloads
    • VM 3: Home Assistant
  • 🌐 Domain: cervant.net managed via Cloudflare (DNS + WAF + Access)
  • 🔐 Internal DNS: Pi-hole + Unbound
  • 🔑 Certs: DNS‑01 challenges via Cloudflare DNS and Cert‑Manager

🔍 Blogs & Research

I write and document my learning, research, and homelab experiments in two separate blogs:

  • 📓 brsalcedom.github.io – Focused on pentesting, security research, bug bounty writeups, and network assessments.

  • 🛠 blog.cervant.net – Dedicated to DevOps, IoT, electronics, and detailed guides about my homelab, infrastructure automation, and self-hosting.

Topics covered:

  • GitOps, Kubernetes, Terraform, CI/CD pipelines
  • Self-hosted services, observability, remote access (Cloudflare Access, VPNs)
  • Electronics projects, microcontrollers, sensors and automation with Home Assistant
  • Cloud and hybrid architectures (AWS, GCP)
  • Web app and network security

📦 Featured Projects

  • homelab-iac – Modular infrastructure as code for my homelab.
  • rshellz – CLI Tool | Reverse shell generator for pentesting.
  • dotfiles – Dotfiles for my linux desktop configuration.
  • amigo-secreto – Simple CLI tool for organizing Secret Santa gift exchanges.

All projects embrace automation, modularity, reproducibility, and security-first design.


📚 Currently Exploring

  • Policy tools for Kubernetes (OPA, Kyverno, Gatekeeper)
  • Self-hosted AI/LLMs & pipelines (Open WebUI, Ollama, n8n)
  • Distributed storage (Rook, Longhorn)
  • Cloud Security Posture Management (CSPM) tools
  • Real-time dashboards and SLO tracking

📬 Let’s Connect


“Automate what’s repeatable. Audit what’s critical. Document what’s important.”
“Security is not a feature — it’s the foundation.”

Pinned Loading

  1. dotfiles dotfiles Public

    dotfiles from Arch Linux rice

    Shell

  2. rshellz rshellz Public

    rshellz is a simple bash tool to quickly generate reverse shell payloads for Pentesting or CTF

    Shell

  3. tf-modules tf-modules Public

    Terraform/OpenTofu modules

    HCL