Operator
ID: NET-ENG-01

LENN OKURO

NETWORK ENGINEER | INFRASTRUCTURE ARCHITECT | HELPDESK

MISSION: SPECIALIZING IN ZERO-TRUST ARCHITECTURE, VIRTUALIZATION, AND CLOUD INFRASTRUCTURE.

📍 ZURICH, CH

DEFENSIVE_METRICS
  • STATUS: UNREACHABLE
  • BANS: 0
  • ENGINE: CROWDSEC + WAF
🐍
PYTHON
POWER:9/10
TYPE:SCRIPT
🐳
DOCKER
CONTAINMENT:10/10
CLASS:OPS
🛡️
CROWDSEC
DEFENSE:8/10
STATUS:ACTIVE
☁️
S3/MINIO
STORAGE:LIVE
COST:LOW
📦
PROXMOX/LXC
NESTING:ACTIVE
CLASS:BARE-METAL
🏗️
TERRAFORM
IaC:10/10
CLASS:AUTOMATION
⚙️
CI/CD GITOPS
DEPLOY:PUSH
CLASS:GITOPS
🐧
LINUX / BASH
SCRIPTING:9/10
CLASS:CORE OS
🔐
ZERO-TRUST
AUTH:OIDC
MESH:TAILSCALE
🌐
CISCO / CCNA
ROUTING:ENTERPRISE
CLASS:NETWORKING
☁️
AZURE AD
IAM:EXPERT
CLASS:CLOUD INTUNE
⚛️
REACT / NEXT.JS
FRONTEND:8/10
CLASS:INTERFACE
05 // CERTIFICATIONS

Third-party validation of capabilities.

Cisco
Network Defense
CISCO
2025
Linux Foundation
Open Source & 5G Transition
LINUX FOUNDATION
2025
Cisco
IT Essentials
CISCO
2024
Cisco
Intro to Cybersecurity
CISCO
2024
Cisco
CCNA: Enterprise Networking, Security & Automation
CISCO
2022
Cisco
CCNA: Switching, Routing & Wireless
CISCO
2022
Cisco
CCNA: Introduction to Networks
CISCO
2022
Python Institute
PCEP -- Entry-Level Python Programmer
PYTHON INSTITUTE
2021
06 // INFRASTRUCTURE

The platform everything runs on.

TIER 1 BARE-METAL CLUSTER · PROXMOX-VE · SELF-HOSTED
🔐
IDENTITY LAYER
Authentik · Vaultwarden
SSO · OIDC · Secrets Management
🌐
EDGE / DMZ
Caddy · Tailscale
TLS Termination · Mesh VPN · Reverse Proxy
⚙️
COMPUTE NODE
C++ Engine · libvips
High-perf Image Processing · RAM-disk pipeline
🗄️
DATA LAYER
PostgreSQL · MinIO · Redis
Primary DB · Object Store · Message Bus
🏗️
APP FACTORY
Docker · Gitea · Coder
Private Registry · Source Control · Dev Workspaces
TAILSCALE MESH VPN
TIER 2 MULTI-REGION EDGE LAYER
SWISS-VPS
PRIMARY EDGE · 8GB RAM · Swiss-domiciled (Exoscale)
US-NODE
REGIONAL SLAVE · North America failover
ASIA-NODE
REGIONAL SLAVE · Latency optimisation
DNS · DDOS MITIGATION · GEO-ROUTING
☁ CLOUDFLARE
CDN · DDoS Protection · CF-IPCountry · WAF · Load Balancer
GITOPS DEPLOYMENT LIFECYCLE — THIS PORTFOLIO IS DEPLOYED THROUGH THIS EXACT PIPELINE
01
DEV WORKSPACE
Coder · VS Code
via Authentik SSO
02
SOURCE CONTROL
Self-hosted Gitea
main branch push
03
CI BUILD
Gitea Runner
Docker → Private Registry
04
CD DEPLOY
SSH → compose pull
Zero-downtime restart
The portfolio's SQLite database survives deployments via ZFS bind mount. Assets live in MinIO. CrowdSec provides live threat intelligence.
01 // DEPLOYED_MISSIONS

Systems designed, built, and shipped to production.

LIVE
Project 01

RedCup Cloud – 5-Ring Zero Trust Architecture

PROXMOX | LXC | TAILSCALE | AUTHENTIK | CADDY

Engineered a defense-in-depth bare-metal infrastructure utilizing nested virtualization and strict network segmentation. Implemented a "dumb pipe" Edge gateway routing through an encrypted Tailscale mesh, gated by Authentik OIDC SSO. Achieved complete blast-radius containment using unprivileged LXC containers and Docker bridge networks, ensuring stateless app logic remains strictly isolated from stateful PostgreSQL/MinIO data vaults.

VIEW_SOURCE
LIVE
Project 02

Asynchronous Event-Driven Compute Engine

DOCKER | REDIS | C++ (LIBVIPS) | MINIO | FLASK

Decoupled web application UI rendering from heavy CPU-bound tasks by building an asynchronous message bus system. Web nodes drop JSON payloads into a Redis queue, which are consumed by stateless, highly isolated C++ compute nodes. Processing occurs entirely in-memory via Linux RAM-disks (/dev/shm) and integrates directly with MinIO object storage, ensuring maximum read/write speeds with zero SSD wear and tear.

VIEW_SOURCE
ARCHIVED
Project 03

Wanyamapori Sanctuary Web Platform

PYTHON | FLASK | REACT | BOOTSTRAP | GITHUB

Developed and deployed a full-stack web application for the Wanyamapori Sanctuary. Integrated responsive frontend UI components using HTML, CSS, and React with a backend Python/Flask architecture. Managed the deployment pipeline and version control entirely through GitHub, demonstrating end-to-end development capabilities. +1

VIEW_SOURCE
ARCHIVED
Project 04

Enterprise Infrastructure & VPN Rollout

AZURE AD | INTUNE | FORTICLIENT | JIRA | LANSWEEPER

Coordinated large-scale enterprise infrastructure initiatives, including the deployment and troubleshooting of secure VPN architectures. Executed critical VLAN security enhancements and managed endpoint lifecycles using Microsoft Intune and Azure Active Directory. Handled systematic PC replacements and automated ticket resolution workflows using JIRA.

VIEW_SOURCE
ARCHIVED
Project 05

Enterprise Network Topology & Virtualization

VMWARE | CISCO | VLAN | NETWORKING | LINUX

Conducted in-office testing of complex network topologies to develop customized client solutions. Spearheaded the implementation of VMware virtualized environments, backup systems, and rigorous VLAN configurations. Bridged the gap between theory and real-world application by hosting practical networking labs for peers. Managed IT asset deployment and inventory tracking to optimize hardware resource allocation.

VIEW_SOURCE
DEPLOYED
Project 06

Automated GitOps CI/CD Factory

GITEA | DOCKER | TERRAFORM | CODER | BASH

Architected a continuous integration and deployment (CI/CD) factory utilizing Gitea and Docker runners to build and push images to a private registry. Engineered reproducible, isolated developer workspaces via Coder and Terraform, dynamically injecting ephemeral, cryptographically secure secrets. Automated the end-to-end build lifecycle utilizing Bash scripting and Linux server management, achieving near-zero downtime deployments for stateless containers.

VIEW_SOURCE
ACTIVE DEVELOPMENT
OPS-001

COMMAND CENTER

Next.js TypeScript React 19 PostgreSQL Redis Docker

Unified operations dashboard evolving from the original Kadere observer into a full command-and-control surface. Network plane controls provide real-time visibility into mesh VPN topology and encrypted tunnel health. Intrusion detection feeds aggregate into a single threat timeline with one-click response actions. Architecture Decision Records (ADRs) drive every major change, ensuring the system evolves deliberately rather than reactively. Designed to coordinate across all RedCup products from a single pane of glass.

VIEW_SOURCE
LIVE
OPS-002

REDCUP MEDIA ENGINE

Python Flask C++ (libvips FFmpeg) S3/MinIO Redis Docker

Content delivery API with a C++ compute backend for heavy media processing. Tiered caching across browser, application, and CDN layers reduces database queries by approximately 95%. Uploads queue to background workers where libvips handles image optimization and FFmpeg produces HLS-segmented video for adaptive bitrate streaming. Media streams directly from object storage to the client — the API never writes intermediate files to disk, keeping the application server stateless and memory-efficient.

VIEW_SOURCE
LIVE
OPS-003

GITOPS FACTORY

Docker Gitea act_runner BuildKit Shell YAML

Fully self-hosted CI/CD pipeline with zero external dependencies. Two-stage workflow: build on push (with BuildKit inline cache layers for sub-minute rebuilds), deploy on version tag via SSH. Runners stay dormant until repositories explicitly opt in with a workflow file. Production targets remain stateless — they pull containers from a private registry and never hold source code. The entire software delivery chain, from source control through container registry to deployment, runs on owned infrastructure.

VIEW_SOURCE
LIVE
SEC-001

SECURE REMOTE ACCESS LAB

WireGuard Authentik Caddy CoreDNS RustDesk Docker

Zero-trust mesh networking across distributed infrastructure. WireGuard encrypted tunnels provide node-to-node connectivity — no port forwarding, no dynamic DNS, no traffic through third-party relay servers. An identity-aware reverse proxy enforces SSO/OIDC authentication before any request reaches an application. CoreDNS handles internal service discovery with split-horizon resolution. Self-hosted remote desktop relay keeps interactive sessions fully private.

VIEW_SOURCE
RESEARCH
SEC-002

AUBAND

Python Fernet/AES-128 HMAC-SHA256

Symmetric encryption utility for directory-level file protection. Toggle operation: run once to encrypt, run again to decrypt. Auto-generates keys, detects encryption state, and protects its own key files from recursive encryption. Built for quick field use on sensitive directories where full-disk encryption is impractical.

VIEW_SOURCE
DEPLOYED
INF-001

CREATIVE-HQ INFRA

Python Docker MinIO PostgreSQL Redis Caddy Cloudflare

Distributed infrastructure defined as code across four layers: gateway (reverse proxy with WAF and automatic TLS), application (event-sourced CMS with webhook-driven cache invalidation), data (relational database plus S3-compatible object storage), and observability (centralized logging, metrics collection, and alerting pipelines). Zero-trust access control via mesh VPN identity verification — no services are directly exposed to the public internet.

VIEW_SOURCE
ACTIVE DEVELOPMENT
SEC-003

SECURITY ARCHITECTURE

Python YAML CoreDNS WireGuard Suricata scikit-learn

Ten-plane adversarial defense system that treats security as a living organism rather than a perimeter. Network, Control, Data, Application, Compute, Build, Bot, Security Operations, ML Pipeline, and Ops planes compose into layered defense-in-depth. The Bot plane runs red-team and blue-team agents driven by YAML profiles — attack scripts probe for weaknesses while defensive agents learn to detect and block them. An ML pipeline trains classifiers on behavioral signals (mouse dynamics, keystroke cadence, motor control jerk) to distinguish human users from automated traffic. Built on the philosophy of 'attack first, train from that.'

VIEW_SOURCE
ACTIVE DEVELOPMENT
FIN-001

TOKEN SERVICE

Python Flask PostgreSQL Redis Docker

Shared microservice providing a two-token economic model across the entire RedCup ecosystem. A double-entry ledger ensures every token movement is an immutable debit-credit pair — balances are derived, never stored directly. Reputation tokens are soulbound (non-transferable, earned through contribution) while utility tokens are transferable between members. Three-layer architecture: Truth (immutable ledger), Policy (configurable rules engine), and Operations (human intervention for disputes and edge cases). Designed with negative programming — adversarial scenarios are the primary test suite.

VIEW_SOURCE
02 // RESEARCH_LAB

Questions I am actively investigating.

BEHAVIORAL BIOMETRICS
MASTER'S THESIS

SAMOSA PROJECT

Can scarcity pressure reveal bots? A behavioral biometrics platform that exploits cognitive load differences between humans and automated agents under time-limited auction conditions.

Dutch Auction endpoints create artificial scarcity, inducing cognitive load that exposes behavioral divergence between human users and bots. Three signal families drive classification: mouse dynamics (Fitts's Law compliance, overshoot correction), keystroke timing (digraph inter-key intervals), and motor control jerk (third-derivative smoothness of cursor paths). A Random Forest classifier trained on 47 features achieves strong human-bot separation without CAPTCHAs or explicit challenges. All signal processing is in-session — raw behavioral data is never stored as PII. FADP-compliant by design.

Behavioral Biometrics Dutch Auction Fitts's Law Shannon Entropy Motor Control Jerk Random Forest FADP
DOMAINCybersecurity
METHODML Classification
SIGNALS47 Features
STATUSActive
PLATFORM ENGINEERING
DSR ARTIFACT

REDCUP COOPERATIVE PLATFORM

A Design Science Research artifact: full-stack cooperative platform investigating fair-trade models for creative economies in East Africa.

RedCup is a 20-member creative cooperative built on entirely self-hosted infrastructure. The platform (Next.js 16, TypeScript, Tailwind) integrates a C++ media processing engine, event-sourced CMS, and a two-token economic model (soulbound reputation + transferable utility tokens on a double-entry ledger). Multiple products serve distinct markets: a music platform, a football scouting network, and community commerce tools. The entire ecosystem deploys through a sovereign GitOps pipeline with zero external CI/CD dependencies. As a DSR artifact, the platform tests the thesis that cooperative ownership structures can resist the extraction patterns documented in East African digital economies.

Design Science Research Cooperative Platform Token Economics Self-Hosted GitOps East Africa
FRONTENDNext.js 16 + React 19
BACKENDFlask + C++ Engine
TOKENSDouble-Entry Ledger
STATUSLive
DEVOPS & SOVEREIGNTY
CASE STUDY

PIPELINE SOVEREIGNTY FOR SMEs

How small teams can own their entire software delivery chain — from source control to production — without third-party dependencies or unpredictable SaaS billing.

Most SMEs depend on GitHub Actions, Vercel, or Netlify for deployment, creating vendor lock-in and exposing source code to external systems. This case study documents a production-proven alternative: private source control, private container registry, host-mode CI/CD runners with BuildKit caching, and SSH-based zero-downtime deployment. Two-stage pipeline design separates build (on push) from deploy (on version tag). Production servers remain stateless — they pull containers but never hold source code. The entire pipeline costs less than a single SaaS CI/CD subscription and operates independently of any external service availability.

GitOps Pipeline Sovereignty Self-Hosted CI/CD Docker Zero-Downtime SME Infrastructure
SCOPEFull Pipeline
COST< 1 SaaS Sub
TARGETSSMEs / Startups
STATUSActive
DIGITAL ECONOMICS
MASTER'S THESIS

FROM COFFEE TO CONTENT

Tracing extraction patterns from colonial commodity trade to modern platform economies in East Africa — and building cooperative alternatives.

The thesis traces a structural parallel between colonial-era commodity extraction (documented in Wakiaga's 1964 MBA thesis on Kenya's coffee trade) and modern platform extraction in East African digital economies. The core insight: 'high attention + low opportunity = highly monetizable populations.' Global platforms capture creative labor at near-zero marginal cost while returning minimal value to producers. Design Science Research methodology frames the RedCup cooperative platform as an artifact that tests whether self-hosted, member-owned infrastructure can break this extraction cycle. The research sits at the intersection of information systems, development economics, and platform governance.

Digital Colonialism Platform Economics Design Science Research Cooperative Models East Africa Wakiaga
FIELDInformation Systems
METHODDesign Science Research
ARTIFACTRedCup Platform
STATUSWriting
ADVERSARIAL SECURITY
R&D PROGRAM

TEN-PLANE DEFENSE ARCHITECTURE

Security as a living organism: ten specialized planes that compose into layered defense-in-depth with continuous adversarial pressure testing.

Traditional security architectures split into three layers (network, application, data) and leave critical surfaces undefended. This research program develops a ten-plane model: Network, Control, Data, Application, Compute, Build, Bot, Security Operations, ML Pipeline, and Ops. Each plane has defined responsibilities, interfaces, and failure modes codified in RCCP-SEC standards. The Bot plane is the primary innovation — YAML-driven red-team agents generate attack profiles that blue-team agents must learn to detect. An ML pipeline trains on behavioral signals (mouse dynamics, keystroke cadence, motor control jerk) for session-level bot classification. The architecture is designed to evolve under adversarial pressure rather than calcify behind static rules.

Defense-in-Depth Red Team Blue Team ML Pipeline Behavioral Biometrics SOAR IDS
PLANES10 Specialized
TESTINGAdversarial-First
MLBehavioral Classifier
STATUSActive
07 // PACKET_TRACE

The journey of an HTTP request through the stack.

VISITOR
01 // VISITOR
Your browser sends an HTTP request to l3nn.org
CLOUDFLARE
02 // CLOUDFLARE
CDN cache check, DDoS mitigation, WAF rules, geo-routing to nearest edge
SWISS VPS
03 // SWISS VPS
TLS termination, Caddy reverse proxy, CrowdSec threat analysis
TAILSCALE
04 // TAILSCALE
WireGuard encrypted tunnel, zero-trust mesh authentication
HOME CLUSTER
05 // HOME CLUSTER
Proxmox hypervisor, LXC container routing, internal DNS resolution
CONTAINER
06 // CONTAINER
Flask app processes request, queries SQLite + Redis, generates response
THE JOURNEY OF AN HTTP REQUEST -- VISITOR TO CONTAINER AND BACK
08 // NETWORK_RADAR

Live threat intelligence from the defense stack.

REDCUP · THREAT SCAN
THREATS BLOCKED
0
DEFENSE STATUS
○ OFFLINE
THREAT LEVEL
LOW
PROTECTION STACK
CROWDSEC
CLOUDFLARE WAF
03 // CONTACT_UPLINK

Open channel. 24-48 hour response.

LOCATION
📍 ZURICH, SWITZERLAND
AVAILABILITY
OPEN TO OPPORTUNITIES
RESPONSE_TIME
24–48 HRS
SERVICES ONLINE
CV // Lenn_Okuro__CV.pdf
[OPEN IN TAB]