- Implemented verified boot in U-Boot for OpenWrt-based access points, with authenticated kernel and rootfs validation across dual-image flash layouts.
- Built and validated a complete secure-boot workflow for Qualcomm IPQ60xx platforms: key provisioning, image signing, fuse programming, and boot-chain verification from PBL to Linux.
- Developed a hardened firmware-signing pipeline with RSA-PSS signing, SHA-384 fuse hashing, and signed recovery images.
- Diagnosed secure-boot failures through vendor tooling analysis, boot metadata inspection, and controlled fuse generation.
- Low-level recovery over serial console, emergency download mode, and flash-level workflows.
Work
Most recent first. Campus and production infrastructure to begin with, then WAN failover and virtualization, and firmware and secure boot now.
- Built a multi-link WAN switching and aggregation engine for seamless failover across uplinks.
- Deployed a clustered virtualization environment on enterprise rack servers with redundant SAN storage over multipath I/O.
- Isolated management, cluster, and storage traffic across dedicated interfaces and VLANs.
- Validated failover under simulated link and controller outages, and wrote the operational documentation.
- Added JWT access control for internal dashboards using a custom-compiled NGINX module integrated with a Rails service.
- Set up centralized monitoring with Zabbix and Grafana, alerting on certificate expiry, outages, and anomalies.
- Migrated GitLab Enterprise to a containerized deployment with automated backups and health checks.
- Migrated 40+ containers and 15+ VMs to a high-availability cluster with zero downtime.
- Built a Dockerized Moodle test environment for isolated API testing.
- Designed and deployed a network access control testbed using PacketFence, OPNsense, and VLAN segmentation.
- Configured VLAN-based enforcement with dynamic device onboarding, DHCP handling, and access policies.
- Validated end-to-end enforcement with VLAN tagging and PVIDs across simulated endpoint scenarios.