Nguyễn Trung Hoàng Hải

Infrastructure / DevSecOps Engineer

Ho Chi Minh City, Vietnam

I build and defend the layers underneath other people's applications: the firewalls and routers at the edge, the Kubernetes clusters above them, and the pipelines that ship to both.

About

I work on system architecture, network engineering and DevSecOps across on-premises and cloud-native infrastructure. The same week can involve an HA firewall pair, a Kubernetes upgrade and a CI pipeline that refuses to ship an image with a critical CVE.

I work from the physical layer up: if I deploy a platform, I also run the network it sits on and the pipeline that feeds it. Alongside this I am finishing a Cyber Security degree at FPT University, which keeps the security half of the job grounded in more than tooling.

Stack

Systems Programming & Tooling

The parts I write myself when nothing off the shelf fits

  • Go: DHCP, TFTP and HTTP servers, iPXE chainloading, iSCSI targets
  • Rust: an internal VPN for remote access, with Windows and Linux clients
  • Cloudflare Workers, D1 and React: control planes and dashboards for the above
  • Custom WinPE environments built on WinRE
  • GitHub Actions: reusable composite actions, published as open source

DevSecOps & Application Security

Checks that run before anything reaches production

  • CI/CD security pipelines: Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST
  • Kubernetes hardening: Kyverno policies, Pod Security Standards, RBAC
  • Web application security testing: source-code review, privilege-escalation analysis, exposed-secret discovery
  • Incident response: root-cause analysis, webshell and malware removal, data recovery
  • Digital forensics: FTK Imager, Autopsy
  • Rust supply-chain tooling: cargo audit, cargo deny, cargo geiger

Cloud-Native & Platform Engineering

Where the applications actually run

  • Kubernetes: kubeadm clusters, Calico CNI, Traefik ingress, ArgoCD GitOps, CloudNativePG
  • Autoscaling: HPA and metrics-server tuning against real workload profiles
  • Proxmox VE: multi-node clusters, live VM migration across independent clusters, REST API automation
  • Docker: distroless image builds, deployment through Dokploy
  • Self-hosted services: Odoo, Strapi, GitLab CE
  • Monitoring: Zabbix with TimescaleDB, Prometheus and Grafana

Network & Security Infrastructure

The edge: routing, firewalls, wireless and identity

  • CCNA-level routing and switching: OSPF, ACLs, NAT, VPN, SDN
  • FortiGate: HA clustering, VLANs, IPsec and SSL VPN, IKEv2, VIP/DNAT, traffic shaping
  • Config migration between FortiGate models and generations without vendor conversion tooling
  • UniFi network administration across sites
  • Windows Server: Active Directory, RADIUS, Group Policy
  • Zimbra mail server administration

Projects

Education

FPT University
B.Sc. Information Security Final year, graduating December 2026

Contact

Reach me at hainthvl@gmail.com. Most of my work lives on GitHub: morningstar-sudo for tooling and infrastructure, morningstar-sudo for the published container images. I'm also on LinkedIn.