01Platform · GitOpsAgicap · 2024 — NowManual deploys and two-hour rollbacks, fixed with a git revert.
Manual deploys → merge-to-main self-serve. Rollback dropped from ~2 h to < 90 s.
- →Moved deploys behind ArgoCD, so merging to main is the deploy. Nothing else to click.
- →Put Terraform behind Atlantis so every infra change is a PR with the plan visible in the review.
- →Repackaged the apps as Helm charts with separate values per environment. No more copy-pasted YAML.
- →Wired up Prometheus and Grafana so when something goes sideways, the dashboard is already open.
< 90 sto roll back
100%infra by PR
×2clouds
ArgoCDAtlantisHelmTerraformAKSGKEPrometheusGrafana
02Security · Network · IdentityAgicap · 2024WiFi that you can’t share on Slack.
Shared WiFi password retired across offices in two countries. Zero credentials to rotate.
- →Set up FreeRADIUS as the auth backend, with EAP-TLS so each device authenticates with its own certificate.
- →Pushed the client certificates silently through the MDM we already had (Intune + Apple Business Manager).
- →Let Cisco Meraki handle the LAN and WiFi, and Fortinet the perimeter. The rest of the stack stayed untouched.
~3 sto connect
4platforms
0auth failures
EAP-TLSFreeRADIUSIntuneABMMerakiFortinet
03Industrial · SEVESO · VoIPElkem Silicones · 2021 — 2023Replacing the phones on a high-risk chemical site, with the plant still running.
SEVESO site telephony fully replaced. 570 people kept working. Zero safety-critical downtime.
- →Walked the site and inventoried every phone, every key line, and every safety-critical station before writing any plan.
- →Cut over in small blocks with the old and new systems running in parallel, so we could fall back in seconds if something looked wrong.
- →Did the work after hours, with the ops team fully briefed and allowed to stop me at any point, no questions asked.
0 ssafety downtime
570migrated
100%inventoried up front
VoIPSIPLinuxVMware ESXIndustrial networkProject mgmt