[{"data":1,"prerenderedAt":158},["ShallowReactive",2],{"navigation":3,"work-page":14,"ventures":31,"oss":51,"engagements":105},[4],{"title":5,"path":6,"stem":7,"children":8,"page":13},"Blog","\u002Fblog","blog",[9],{"title":10,"path":11,"stem":12},"Kubernetes 101","\u002Fblog\u002Fkubernetes-introduction","blog\u002Fkubernetes-introduction",false,{"id":15,"title":16,"body":17,"description":18,"extension":19,"links":20,"meta":25,"navigation":26,"path":27,"seo":28,"stem":29,"__hash__":30},"pages\u002Fwork.yml","What I have built",null,"One venture, one tool I maintain, and the client work I can describe without naming anyone. The engagements below are anonymised on purpose.","yml",[21],{"label":22,"icon":23,"color":24},"Schedule a call","i-lucide-calendar","neutral",{},true,"\u002Fwork",{"title":16,"description":18},"work","9qDoML0_QptCdaeuHMFhmauXAWyZoLRaubVPqY15F68",[32],{"id":33,"description":34,"extension":19,"meta":35,"name":36,"order":37,"period":38,"role":39,"slug":40,"stack":41,"stem":47,"tagline":48,"url":49,"__hash__":50},"ventures\u002Fwork\u002Fventures\u002Fstart-alpha.yml","A sovereign control plane for fleets that cannot assume connectivity. A single declarative blueprint covers workloads, OS configuration, cloud resources, security policy and disaster recovery; agents reconcile it across every site autonomously. Built on Kubernetes and OpenTelemetry, with export so the definition stays yours.",{},"Start-Alpha",1,"2026 — present","Co-founder & CTO","start-alpha",[42,43,44,45,46],"Kubernetes","k3s","Go","OpenTelemetry","SPIFFE\u002FSPIRE","work\u002Fventures\u002Fstart-alpha","One blueprint to deploy, govern and recover distributed infrastructure — from edge to cloud. Secure software supply-chain, from OS to applications.","https:\u002F\u002Fstart-alpha.io","bUXmRvaZL5nHtGzSaPvPBx-GogtjN6x367nKeLKxgs8",[52,63,74,85,96],{"id":53,"description":54,"extension":19,"featured":26,"language":44,"meta":55,"name":56,"order":37,"repo":57,"role":58,"slug":59,"stem":60,"why":61,"__hash__":62},"oss\u002Fwork\u002Foss\u002Ftwin-model.yml","A toolkit for authoring ontology. Compact YAML transpiles to OPC-UA ModelDesign.xml, CESMII i3X 1.0 JSON.  Embedded catalog of companion specifications and MCP server.",{},"twinmodel","https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Ftwin-model","author","twin-model","work\u002Foss\u002Ftwin-model","It deliberately does not emit NodeSet2.xml itself — Part 5 compliance is the ModelCompiler's job. The point is to make the information model a reviewable artefact in git instead of hand-written XML, so the data contract can be argued about like any other code.","ts1e2Dx3E3cspcOUQ9dhtdLiFvj8F7GuizHH0Ud7ZrU",{"id":64,"description":65,"extension":19,"featured":13,"language":44,"meta":66,"name":45,"order":67,"repo":68,"role":69,"slug":70,"stem":71,"why":72,"__hash__":73},"oss\u002Fwork\u002Foss\u002Fopentelemetry.yml","The vendor-neutral standard for traces, metrics and logs.",{},2,"https:\u002F\u002Fgithub.com\u002Fopen-telemetry","watching","opentelemetry","work\u002Foss\u002Fopentelemetry","Every observability argument I make assumes a signal format that outlives the tool consuming it. Industrial systems change vendors far more often than they change physics.","QOtHP5rFwrPxf1ddcxyJ6qkHquIZGNOtcX1Bru_xXnw",{"id":75,"description":76,"extension":19,"featured":13,"language":44,"meta":77,"name":78,"order":79,"repo":80,"role":69,"slug":81,"stem":82,"why":83,"__hash__":84},"oss\u002Fwork\u002Foss\u002Fopamp.yml","Open Agent Management Protocol — remote configuration, health reporting and upgrade of telemetry agents at fleet scale.",{},"OpAMP",3,"https:\u002F\u002Fgithub.com\u002Fopen-telemetry\u002Fopamp-go","opamp","work\u002Foss\u002Fopamp","Managing a hundred collectors by hand is not a strategy. OpAMP is the piece that makes edge telemetry operable rather than merely deployed.","yon4Ya3Wd3NuC-tEujMUHya62K2hZiVWyKH143JdbWw",{"id":86,"description":87,"extension":19,"featured":13,"language":44,"meta":88,"name":89,"order":90,"repo":91,"role":69,"slug":92,"stem":93,"why":94,"__hash__":95},"oss\u002Fwork\u002Foss\u002Fspiffe-spire.yml","Workload identity without shared secrets — short-lived SVIDs issued and rotated automatically.",{},"SPIFFE \u002F SPIRE",4,"https:\u002F\u002Fgithub.com\u002Fspiffe\u002Fspire","spiffe-spire","work\u002Foss\u002Fspiffe-spire","Identity is the part of edge security most projects defer until it is expensive. Distributing long-lived certificates across a hundred sites is a problem you only want to solve once.","bkzUkW53lNxpISVWmFD46EKsXc4MOcMKSdPYqNh345E",{"id":97,"description":98,"extension":19,"featured":13,"language":44,"meta":99,"name":43,"order":100,"repo":101,"role":69,"slug":43,"stem":102,"why":103,"__hash__":104},"oss\u002Fwork\u002Foss\u002Fk3s.yml","A certified Kubernetes distribution small enough to run in a plant cabinet.",{},5,"https:\u002F\u002Fgithub.com\u002Fk3s-io\u002Fk3s","work\u002Foss\u002Fk3s","It is the reason \"if it needs a datacenter it does not belong at the edge\" is a design constraint rather than a complaint.","VFzFEQeRQHsxeOcQknHeoEoI6ks_dqacKmCHVZfZj7c",[106,123,139],{"id":107,"alias":108,"caseStudy":17,"confidential":26,"extension":19,"meta":109,"order":37,"outcomes":110,"period":113,"scope":114,"sector":115,"slug":116,"stack":117,"stem":121,"__hash__":122},"engagements\u002Fwork\u002Fengagements\u002Funs-backbone.yml","CAC40 industrial group",{},[111,112],"Architecture accepted as the group-wide target for plant data","Proof of value delivered against real site constraints rather than a lab","Recent","Design and first proof of value for a unified namespace backbone spanning more than one hundred sites worldwide, including the reference architecture and modelling layer.","Multi-sector manufacturing","uns-backbone",[118,119,120],"MQTT","OPC-UA","i3X","work\u002Fengagements\u002Funs-backbone","GYr4JkQO8devZHVhn8HYK0glFf_OGH4ed9Mb0b7QgWM",{"id":124,"alias":125,"caseStudy":17,"confidential":26,"extension":19,"meta":126,"order":67,"outcomes":127,"period":113,"scope":132,"sector":133,"slug":134,"stack":135,"stem":137,"__hash__":138},"engagements\u002Fwork\u002Fengagements\u002Fedge-observability.yml","CAC40 process manufacturer",{},[128,129,130,131],"Cost-optimised observability across 100+ hosts, instrumenting camera, ML inference and display latency end to end","Resource-efficient UNS on edge infrastructure, reducing proprietary software reliance by 90%","Optimisation algorithm deployed to edge, integrated with SCADA and PLCs under real-time constraints, with yield improvements validated by R&D","Planning and scheduling tool in production use by 10+ planners and operations users","Observability, unified namespace and optimisation delivery across an edge estate supporting a critical manufacturing process, plus end-to-end delivery of a multi-plant planning and scheduling tool.","Manufacturing — critical process","edge-observability",[43,45,118,119,136],"Python","work\u002Fengagements\u002Fedge-observability","GrCaNKTwj4w3mjD1aLa6w0_3dxye_q9UU4MT2FI0SyM",{"id":140,"alias":141,"caseStudy":17,"confidential":26,"extension":19,"meta":142,"order":79,"outcomes":143,"period":113,"scope":147,"sector":148,"slug":149,"stack":150,"stem":156,"__hash__":157},"engagements\u002Fwork\u002Fengagements\u002Fgreenfield-ipaas.yml","CAC40 car manufacturer",{},[144,145,146],"Platform provider scoped and selected, first integrations delivered across ERP, PLM, PLC and SCADA","Integration costs reduced by 40%","First validation app proved out data contracts and was used during line commissioning ahead of full MES rollout","Launched integration platform foundations and defined the target architecture for the OT-to-MES-to-Cloud integration layer.","Greenfield Electric Vehicle components","greenfield-ipaas",[151,152,153,154,155],"iPaaS","PLC\u002FSCADA","MES","ERP","PLM","work\u002Fengagements\u002Fgreenfield-ipaas","hB5k5QyhO3kO13YTbJ_cYxOgyMcY4abXZBmSKLLYMkg",1791414106274]