I will review your docker, github actions, and secrets setup for risks
DevSecOps and Automation Engineer
About this Gig
Leaked cloud keys in a repo, containers running as root, CI workflows with far more permissions than they need: most small-team breaches start as configuration mistakes, not clever attacks. A review now is much cheaper than an incident later.
I am an infrastructure engineer who manages production secrets, OIDC-based CI access to AWS, and secure deployment workflows daily, and I am a Computer Networks and Cybersecurity undergraduate. I review your configuration the way I maintain my own: practically, with fixes, not fear.
What I review:
- Dockerfiles and compose files (root users, baked-in secrets, unpinned images, exposed ports)
- GitHub Actions workflows (over-broad permissions, secrets exposure, third-party action risk)
- Secrets handling (what is in the repo, env files, CI secrets vs OIDC)
- Basic AWS IAM sanity for CI users and roles
You get a written report: each finding explained in plain language, ranked by risk, with the exact fix. Higher tiers include me applying the fixes.
This is a configuration review of systems you own. It is not penetration testing and no attack traffic is involved.
Tools:
Docker
•
GitHub
Frameworks:
Npm
•
Terraform
Cloud Provider:
Amazon Web Services
•
Google Cloud Platform
Programming language:
Bash
•
JavaScript
•
Python
Expertise:
Installation
•
Debugging
•
Configuration
Other DevOps Engineering Services I Offer
FAQ
Is this penetration testing?
No. I read and assess configuration in systems you own; I do not attack anything, run exploits, or send attack traffic. If you need a penetration test, you need a specialist under a signed scope agreement.
What do you need from me?
Repo access, confirmation that you own or are authorized to have this codebase reviewed, and for IAM checks a read-only or screenshotted view of the relevant CI user or role policies. Never send me secret values.
Will you keep findings confidential?
Yes. Findings go to you alone through the order. I do not publish, reuse, or mention client findings anywhere.
What does the report look like?
A markdown or PDF document: each finding has what I found, why it matters, how risky it is (high, medium, low), and the exact change to make.
Can you review AWS beyond IAM for CI?
A broader AWS account review (S3 exposure, network config, logging) is possible as a custom order after we agree scope in chat.
