← All work
infraPlatform Infrastructure · DevSecOps

neoCedrus — the infrastructure behind a 4-product suite

The DevSecOps backbone for neoCedrus, AUI's product unit — I run the CI/CD, security, monitoring, and deployments that keep Kudos, Xpress, BeHive, and the feedback hub live for the whole university.

Year2024 — present
RoleDevSecOps Engineer
ClientneoCedrus · Al Akhawayn University
neoCedrus — the infrastructure behind a 4-product suite
4
products supported
588+
deployments shipped
Self-hosted
runners & storage
Hardened
secured pipelines
The problem

neoCedrus ships and maintains several production platforms for Al Akhawayn University at once. Each needs reliable, secure, repeatable infrastructure — not fragile manual deploys — and one person owning the operational layer across all of them.

Approach
  • Own the shared DevSecOps layer across the suite: CI/CD, containerization, environments, and the release process for every product.
  • Bake security into the pipeline — automated checks, environment isolation, access control, secrets handling, and routine vulnerability scanning.
  • Run monitoring, backups, and recovery so data stays intact and the platforms stay up for the university.
  • Standardize tooling (Docker, self-hosted runners, staging/production parity) so every product team ships the same reliable way.
Outcome

A single hardened infrastructure layer underpinning the entire neoCedrus product suite — 588+ deployments shipped reliably, security built into every release, serving the whole AUI community.

Tech

CI/CD

GitHub ActionsSelf-hosted runners

Containers

DockerDocker Compose

Security

Env isolationAccess controlVuln scanning

Data & storage

PostgreSQLMongoDBRedisMinIO

Have a project like this?

Get in touch