I turn an organisation's policy into code: what was written runs, and what ran can be proven.
For the past two years I have been responsible for running and evolving the OCI artifact supply chain of SNCF, France's national railway company — Harbor, ~140k repositories, 13 TB, on Kubernetes across AWS, Azure and on-premises Talos, fully managed as code.
Two open-source tools, which I author and maintain: knock, a single front door for external container images — mirror or hardened rebuild, OCI provenance, signed SLSA/in-toto attestations, SBOM as an OCI referrer, with a nightly verifiable proof; and Regis, container security and policy-as-code orchestration, published as a GitHub Action.
Developer at heart, twenty years in. Ain, between Lyon and Geneva — remote-first — LinkedIn.




