Skip to content
View mella7's full-sized avatar

Block or report mella7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mella7/README.md

Mohamed Ali Mellah

Cloud-Native & DevSecOps Engineer · Munich, Germany 🇩🇪

I build and secure Kubernetes platforms — from the Linux primitives underneath them to the policy and runtime-detection layers on top. Most of my work sits at the intersection of platform engineering and security: shipping infrastructure that developers actually want to use, without leaving the attack surface unattended.

🎤 Speaking at ContainerDays Hamburg 2026 and Cloud Identity Summit Frankfurt 2026 🏆 Global 1st Prize, Huawei ICT Competition 2025–2026 (Computing Track, Shenzhen) 🎓 CS Engineering degree (SSIR), TEK-UP University 🌍 Open to roles across DACH & Switzerland


🛠️ What I work with

Orchestration & Platform Kubernetes Docker Helm ArgoCD Operators / CRDs Apache CloudStack

Cloud & IaC AWS (EKS, EC2, IAM) Terraform Ansible GitHub Actions GitLab CI

Security Falco Trivy Kyverno Snyk SonarQube eBPF OPA

Observability Prometheus Grafana Loki

Languages Go Python Bash Java TypeScript


📜 Certifications

CKA Certified Kubernetes Administrator
CKAD Certified Kubernetes Application Developer
RHCSA Red Hat Certified System Administrator

🔧 Selected projects

Container Networking from Scratch — Rebuilt container networking without Docker: Linux namespaces, veth pairs, a bridge, and iptables NAT, wired together by hand. The best way I found to actually understand what a CNI plugin does.

Kubernetes Operator — ProjectClaim CRD — A custom controller that provisions self-service namespaces with quotas, RBAC, and network policies from a single declarative claim. Written in Go with controller-runtime.

cloudstack-dc — Full-stack automation platform for Apache CloudStack deployments: form-driven UI, live-streaming provisioning logs, and a Next.js + SQLite backend. Tested end-to-end on real 4-node hardware.

DevSecOps Platform on AWS — Cloud-native delivery pipeline on EKS with Terraform, ArgoCD, and GitHub Actions, with security gates at every stage (SonarCloud, Snyk, Trivy) and Falco for runtime detection.


💬 Talks

How Clusters Fail Under Attack, and How We Detect It at Runtime with eBPF Signals ContainerDays Hamburg 2026 — Walking through reverse shells, unexpected process execution, and privilege escalation inside a live cluster, and what the kernel can tell you about them.

Identity Risk in CI/CD Pipelines Cloud Identity Summit Frankfurt 2026


📫 Get in touch

🌐 mella7.me · ✉️ mellah.mohamedali@outlook.com · 💼 LinkedIn

🇨🇭 Eligible for the Switzerland–Tunisia Young Professionals Agreement — no standard visa sponsorship required for Swiss roles.

Pinned Loading

  1. SecureDiscord SecureDiscord Public

    Tek up SSIR-2-P Python project

    Python 1

  2. DevSecOps-Security-Suite DevSecOps-Security-Suite Public

    Shell

  3. eJPT_notes eJPT_notes Public

    Welcome to my eLearnSecurity Junior Penetration Tester (eJPT) Notes and Cheat Sheet