I build the tooling that makes container supply chains trustworthy at scale.
For the past two years I have been responsible for running and evolving the OCI artifact supply chain of SNCF, France's national railway company — Harbor, ~140k repositories, 13 TB, on Kubernetes across AWS, Azure and on-premises Talos, fully managed as code.
I author and maintain two open-source tools: knock, a single front door for external container images — mirror or hardened rebuild, OCI provenance, signed SLSA/in-toto attestations, SBOM as an OCI referrer, with a nightly verifiable proof; and Regis, container security and policy-as-code orchestration, published as a GitHub Action.
Developer at heart, twenty years in. Near Lyon, remote-first — LinkedIn.




