I build the services, ship the pipelines, and operate what I deploy. Currently open to DevOps / Platform / SRE roles — remote or relocation.
- 🌍 Portfolio: mattdev0.tech · Live dashboard: devops.mattdev0.tech
- 📫 Contact: LinkedIn | t.me/mattDev0 | amatthew642@gmail.com
- ⚡ Fun fact: I am stubborn to problems
- DevOps Control Center — a self-hosted infrastructure dashboard (Rust agent, Spring Boot orchestrator, React UI) running in production on a single 1 vCPU Azure VM. Docker Compose behind Caddy, GitHub Actions + Trivy delivery over an SSH pipeline that validates the commit SHA, Prometheus/Grafana observability with
absent()-based alerting, and JWT roles with a read-only guest mode. Previously ran on K3s — the migration and its trade-offs are written up in an ADR. - WSL Traffic Monitor — a native Windows tray app in Rust that measures WSL2 network traffic, which Windows exposes nowhere natively. 8-crate workspace, Win32 IP Helper/Registry APIs,
redbhistory, typed errors, 31 tests, automated release pipeline with checksums and an installer. GPL-3.0. - Polyglot Portfolio — three microservices (React, Rust/Axum, Spring Boot) on GCP Cloud Run, scaling to zero, with automated CI/CD, Trivy scanning and Bucket4j rate limiting.
Official device maintainer for the Pixel 3 and 3 XL on StatiXOS and helluvaOS: device trees, kernels, monthly AOSP security patches and OTA release pipelines. I authored the official release threads on XDA (crosshatch · blueline), releases were downloaded ~1,600 times, another ROM project forked my kernel tree, and other people published install guides for my builds.
- Production operations on constrained hardware: memory limits, swap tuning, graceful degradation.
- Delivery pipelines that fail closed — SHA-validated deploys, preflight secret checks, vulnerability scanning.
- Observability that catches missing signals, not just bad values.
- Low-level systems work in Rust, from Win32 FFI to Linux telemetry.


