Skip to content
View chriswayneh's full-sized avatar
馃憤
馃憤

Block or report chriswayneh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don鈥檛 include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user鈥檚 behavior. Learn more about reporting abuse.

Report abuse
chriswayneh/README.md

Chris Hickman

IAM and Platform Engineer. I design identity workflows, access controls, and container-native platforms you can run, inspect, and verify locally.

Day-to-day focus: account lifecycle, least-privilege access, integration troubleshooting, and making auth and ops failures diagnosable. Portfolio work below shows the same ideas as runnable labs and reference platforms, with documented trust boundaries rather than marketing claims.

Featured projects

lab-in-a-box - identity + infra lab (v2.0.0)

One-command Docker Compose lab: Keycloak, Vault, Gitea, Traefik, Prometheus/Alertmanager/Grafana, and more. v2.0.0 adds Traefik ForwardAuth (oauth2-proxy + Keycloak OIDC/PKCE and realm roles), Alertmanager routing, and hardened observability UI access.

Also includes joiner/mover/leaver automation, a read-only RBAC simulator ("what can this person reach, and why?"), access-review campaigns, and Vault ACL policies. Local lab with documented defaults, not an internet-hardened product.

Release notes 路 README

kube-foundry - local Kubernetes reference platform (v1.0.0)

Kind-based platform for deploying apps, validating infra changes, and testing recovery without cloud spend. Ships Argo CD GitOps, default-deny networking, scoped observer RBAC, admission policies, TLS routing, monitoring, and verified database recovery. Sample app has no user auth; cluster admins remain trusted operators.

v1.0.0 路 Architecture 路 Verification

local-mcp-toolbox - read-only MCP inspection (v1.5.2)

Local MCP server scoped to approved files, Git/GitHub metadata, logs, container health, and static Python checks. Controls: explicit allowlists, bounded output, central redaction, sanitized audit records. No arbitrary command execution or mutation tools.

v1.5.2 路 README 路 Limits & verification

detdrift - detection drift check (v1.0.0)

CLI, reusable Action, and CI check for detection field drift (Sigma default; optional KQL/SPL via dialect): compare before/after NDJSON samples and report which rules would go quiet when fields disappear from a mapping change. Offline, exit-code friendly, stable 1.0 report contract (schema_version 1). Not a SIEM and not a matcher. Complements pipeline and detection-as-code work without owning ingest.

v1.0.0 路 README 路 Architecture 路 Roadmap

RedDock - authorized assessment tooling

Vulnerability discovery and validation for authorized local environments: fail-closed target scope checks, fixed tool arguments, separate validation approvals, and evidence-linked findings. Operator boundary is local authorization, not shared multi-tenant access control.

Other

Personal job-search workspace (targeted queries, tracking; optional cloud sync with server-verified sessions). Development currently inactive.

How I write about security

I prefer naming mechanisms (OIDC, forward-auth, least privilege, policy-as-code, allowlists, audit evidence) over slogans. When a project borrows from zero trust, its README states what is enforced and what is still trusted (see lab-in-a-box security notes).

Contact

LinkedIn 路 GitHub

Pinned Loading

  1. lab-in-a-box lab-in-a-box Public

    Self-hosted infrastructure and identity governance lab with Docker, lifecycle automation, RBAC analysis, and observability.

    Python 2

  2. local-mcp-toolbox local-mcp-toolbox Public

    Zero-trust, read-only MCP inspection with explicit allowlists, bounded evidence, redaction, and audit trails.

    Python