I'm a systems architect working on enterprise infrastructure security and automation: zero-trust networking, identity, and the platform automation that makes both hold up at scale.

I'm building Innerwall, an open-source microsegmentation platform, and writing about how these systems are designed.

Currently at Mastercard, building enterprise-scale systems.

Projects

Recent Writing

View all posts →

Upcoming Writing

Microsegmentation from First Principles

A series working through the design decisions behind Innerwall, one problem at a time.

  1. 1.Observe Before You Enforce: Why Segmentation Starts with a Flow Map
  2. 2.Simulation as a Deployment Stage: Running Policy Without Dropping a Packet
  3. 3.Labels, Not Addresses: Workload Identity in Network Policy
  4. 4.Streaming Desired State: Snapshots, Deltas, and Per-Workload Versions
  5. 5.Short-Lived Certificates for an Agent Fleet: Enrollment and Renewal
  6. 6.Inbound First: Scoping Enforcement for a First Release
  7. 7.Native Firewalls as the Enforcement Plane: Compiling Policy Atomically