Tran Ngoc
Minh Duc
Design, deliver, and operate cloud-native platforms at scale — end-to-end or at any stage — where CI/CD is self-service, security is the default, and every service ships with observability built in.
# current stack
role: Platform & DevSecOps Engineer
focus: platform solutions — from design to operations
location: Hanoi, Vietnam
status: available for freelance projects
$ Skills
Featured Projects
Infrastructure and platform engineering work across cloud-native environments.
Latest Blog Posts
Thoughts on DevOps, cloud infrastructure, and platform engineering.
Technology Stack
Tools and technologies I work with daily.
Experience
From backend development to platform engineering — 3+ years operating production infrastructure across fintech, e-commerce, and SaaS. Full resume with company details available on request.
DevSecOps Engineer
Enterprise Consumer Finance
Core banking workloads · Hanoi, Vietnam
Operate hybrid infrastructure (OpenShift on-prem + AWS Landing Zone) and build the delivery platform used by multiple engineering teams.
- Re-architected CI/CD from isolated pipelines into a shared platform (Jenkins Shared Library) serving 40+ repositories — cut pipeline maintenance effort by ~70%
- Designed centralized secrets management (HashiCorp Vault) integrated with CI/CD and Kubernetes workloads — eliminated hardcoded secrets across all repositories
- Built a security gate into every release (Trivy, SonarQube, DefectDojo) — critical vulnerabilities block promotion to UAT/Prod automatically
- Deployed centralized observability (OpenTelemetry, Prometheus, Grafana) covering 100+ servers and all microservices
- Migrated legacy workloads to OpenShift HA with GitOps (ArgoCD) — zero-downtime deployments with automatic rollback
- L3/L4 on-call for UAT/Prod incidents and go-live support
DevOps Engineer
Print-on-Demand SaaS
15 tenant sites, ~300k orders/month · Hanoi, Vietnam
Owned AWS infrastructure and delivery workflow for a multi-tenant e-commerce platform (team of 12).
- Provisioned the full AWS stack with Terraform modules (VPC, EKS, RDS, ALB, IAM) — environment setup went from days to under 30 minutes
- Designed multi-tenant EKS with namespace-per-tenant isolation (NetworkPolicy, ResourceQuota) — zero cross-tenant interference at ~300k orders/month
- Cut CI pipeline duration ~50% via path-based selective builds and parallel jobs across a monorepo
- Hardened workload security: IRSA least-privilege access, restricted Pod Security Standards, deny-by-default network policies, Trivy gate in CI
- Reduced MTTD from ~30 min to under 5 via SLA-based alerting; rightsized compute to save ~$200/month
DevOps Engineer
Financial Software Provider
Investment fund management platform · Hanoi, Vietnam
First DevOps role — containerized a microservices platform and built its CI/CD from the ground up on VM + Docker Swarm infrastructure.
- Containerized microservices with multi-stage Dockerfiles; standardized Swarm stack files across dev/staging/prod — eliminated environment drift
- Built CI/CD (Jenkins, GitLab CI) covering build, test, image push, and zero-downtime rolling updates — enabled same-day hotfix delivery under production SLA
- Administered PostgreSQL/Oracle: migrations, backups, query optimization that cut report generation time for fund operations
- On-call for production issues across Kafka, Redis, Oracle integration points
Recent Labs
Engineering experiments and hands-on notes.
Deploying Falco on Kubernetes
A security audit found no runtime monitoring layer on the cluster beyond network policy, so Falco was deployed to detect anomalous behavior (container exec, sensitive file reads), with custom rules and Falcosidekick integration.
Testing Cilium Network Policies
Calico is the current CNI but lacks L7 observability (IP/port only, no HTTP path visibility), so Cilium was evaluated as a replacement with eBPF-based network policies, Hubble observability, and performance benchmarks.
WireGuard VPN Mesh Network
The current OpenVPN site-to-site setup is complex to configure and slow to onboard new peers, so a lighter peer-to-peer WireGuard mesh network was built for remote access to dev infrastructure.
CrowdSec Intrusion Detection
A public server was under continuous SSH brute-force attempts and the existing Fail2ban only blocked single IPs, so CrowdSec was deployed with community threat intel, integrating bouncers on Nginx and SSH.
Stay updated
Get notified about new blog posts, projects, and DevOps insights. No spam, unsubscribe anytime.