Skip to content
View sindredg's full-sized avatar

Block or report sindredg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sindredg/README.md

Sindre Grytebust

Selected work   All repositories


Selected work

Recovering a stateful service after losing a region. Three drills rebuilt a kubeadm cluster from code in a second region and restored an offsite backup in under 20 minutes.

Google Cloud, Terraform, Ansible, Flux

A private GKE cluster serving public workloads, with keyless delivery, measured rollouts, failure drills, and an AI agent that triages security findings.

GKE, Terraform, GitHub Actions

Workforce identity across clouds. Federation, SCIM provisioning, and governed access to AWS.

Entra ID, AWS, Terraform

Hub-and-spoke networking with an encrypted cross-premises tunnel, private endpoints, and two-way DNS.

Azure, VPN, Private Link

A two-site Active Directory forest synced to Entra ID, with hybrid endpoints and policy-enforced security baselines.

AD DS, Entra ID, PowerShell

A public web tier and private API, with passwordless image pulls, scale-to-zero, and automated delivery.

Terraform, containers, CI/CD

Other projects
  • AI security triage: Rules, scoped model access, and an auditable verdict ledger for cloud security findings.
  • Identity governance: Conditional Access, just-in-time administration with PIM, and access reviews.
  • Grafana SSO & provisioning: OIDC sign-in, app-role mapping, and a custom SCIM bridge.
  • Sky: An application deployed on the Kubernetes platform.
  • OAuth 2.0 in .NET: API authorization through scopes, app roles, groups, and token claims.
  • Azure MCP & RBAC: Scoped, read-only Azure access for Claude, enforced through Azure RBAC.


Notes on building and testing cloud infrastructure.

Pinned Loading

  1. cross-cloud-entra-aws cross-cloud-entra-aws Public

    Cross-cloud workforce identity from Entra ID to AWS IAM Identity Center using SAML, SCIM, access packages, JML workflows and Terraform-managed permission sets.

    HCL

  2. hybrid-network-az hybrid-network-az Public

    Azure hub-and-spoke joined to a simulated datacenter over IPsec, with firewall inspection, private endpoints, Bastion and bidirectional hybrid DNS.

    HCL

  3. k8-lab k8-lab Public

    A private kubernetes cluster in GKE, a couple of workloads, and an AI agent that handles security findings.

    HCL

  4. k8s-dr k8s-dr Public

    Recovering a stateful service after losing a whole region. Gitea and PostgreSQL run on a kubeadm cluster built on VMs. A drill rebuilds the cluster from code in a second region, restores an offsite…

    Python