I will review your docker, github actions, and secrets setup for risks

Kenya

I speak English, Swahili, Japanese

DevSecOps and Automation Engineer

I help teams deploy, automate, and secure technical workflows using Docker, CI/CD, Kubernetes, cloud tools, and workflow automation. I work as a Full Stack Engineer at Esheria Ventures, doing mostly D...
About this Gig

Leaked cloud keys in a repo, containers running as root, CI workflows with far more permissions than they need: most small-team breaches start as configuration mistakes, not clever attacks. A review now is much cheaper than an incident later.


I am an infrastructure engineer who manages production secrets, OIDC-based CI access to AWS, and secure deployment workflows daily, and I am a Computer Networks and Cybersecurity undergraduate. I review your configuration the way I maintain my own: practically, with fixes, not fear.


What I review:

- Dockerfiles and compose files (root users, baked-in secrets, unpinned images, exposed ports)

- GitHub Actions workflows (over-broad permissions, secrets exposure, third-party action risk)

- Secrets handling (what is in the repo, env files, CI secrets vs OIDC)

- Basic AWS IAM sanity for CI users and roles


You get a written report: each finding explained in plain language, ranked by risk, with the exact fix. Higher tiers include me applying the fixes.


This is a configuration review of systems you own. It is not penetration testing and no attack traffic is involved.

Tools:

Docker

GitHub

Frameworks:

Npm

Terraform

Cloud Provider:

Amazon Web Services

Google Cloud Platform

Programming language:

Bash

JavaScript

Python

Expertise:

Installation

Debugging

Configuration

Other DevOps Engineering Services I Offer