I will manage AWS, azure devops with docker and ansible automation
DevSecOps CloudNative Engineer
About this Gig
Most containers ship with more access than they need. Running as root, no resource limits, base images carrying a hundred known CVEs, secrets baked into layers. It usually works fine right up until it doesn't.
I harden Docker and Kubernetes setups so a compromised container stays a contained problem.
Docker and image hardening
Minimal or distroless base images, multi-stage builds
Non-root users, dropped capabilities, read-only filesystems
Vulnerability scanning wired into your build (Trivy, Grype)
Getting secrets out of images and env vars
Kubernetes hardening
RBAC that follows least privilege instead of cluster-admin everywhere
Pod Security Standards, security contexts, resource limits
Network policies so pods can't talk to everything
Secrets management, sealed secrets or external secret stores
Admission control policies
What you get
Audit report with findings ranked by actual risk, not just CVE count
Hardened Dockerfiles and manifests you can drop in
Explanation of every change, so your team understands the why
Re-scan after fixes to show the before and after
Message me with your stack before ordering and I'll scope it honestly.

