Distributed Systems · Event-Driven Architectures · High-Performance Runtimes
Master’s in Computer Science (Software & Systems Engineering) @ EPITA Paris · Ex-Backend SRE Intern @ Padoa
Designing low-latency, event-driven platforms and cross-service systems in Rust, Go, and TypeScript.
| Domain | Focus & Architectural Patterns | Core Stack |
|---|---|---|
| Distributed Systems & Messaging | Transactional Outbox, Exactly-Once Semantics, Event Sourcing, Scatter-Gather, Compensating Sagas | Kafka, Redis Streams, Valkey, BullMQ |
| High-Throughput Runtimes | Incremental AST parsing, immutable snapshot models, Rayon concurrency, zero-copy indexing | Rust, Go, Tree-sitter, Tokio |
| Zero-Trust Security | AES-256-GCM encryption at rest, blind indexing, Linux seccomp sandboxing, cascading token auth | Cryptography, Sealed Secrets, Linux seccomp |
| Cloud-Native & Observability | GitOps continuous delivery, Restricted Pod Security, distributed tracing, unified telemetry | Kubernetes (K3s), ArgoCD, Traefik, OpenTelemetry |
Frontend & Mobile (Supporting)
Causal Mesh — High-Performance Polyglot Codebase Graph & MCP Server
Local-first Model Context Protocol (MCP) server written in Rust that builds an in-memory structural knowledge graph of large polyglot codebases to empower AI coding agents (Claude Code, Cursor, Windsurf) with instant cross-service context.
- Cross-Service Contract & Dependency Graph: Discovers and maps cross-boundary relationships across Protobuf definitions, gRPC servers/clients (
*ImplBase, stubs, wire breaking change detection against Git base), Kafka producers/consumers, BullMQ queues, OpenAPI/AsyncAPI specs, and declarations across 10+ languages (Rust, Go, TypeScript, Python, Java, Kotlin, C#). - High-Throughput Tree-sitter Pipeline: Parallel AST extraction using Tree-sitter across Rayon worker threads protected by strict
AstGuardinvariants (guarding against binary files, nesting depth > 64, oversized lines, and parser stalls). - Persistent LRU Cache & Atomic Snapshots: Workspace-scoped SQLite cache storing pre-parsed AST trees for sub-second warm boots; file changes are incrementally reconciled into an immutable, in-memory graph (
MeshSnapshot) swapped atomically. - Daemon Architecture (
meshd): Stdio JSON-RPC proxy connecting to a background daemon over Unix domain sockets (or named pipes), deduplicating indexing across editor windows with FSEvents/inotify change coalescing. - Hardened Security & RSAH Governance: Completely offline with zero outbound network client code, Linux seccomp thread sandboxing (blocking socket creation), Unicode-canonicalized path sandboxing (
ValidatedScope), automated secret masking, and SHA-256 tamper-evident SQLite audit trails.
VaultedMind — Zero-Trust Mental Health Vault
Full-stack application for journaling mood and personal reflections without ever exposing raw data, even internally.
- Encryption at Rest: Each sensitive field is encrypted with AES-256-GCM before persistence; email addresses are protected with blind indexing to allow searching without revealing PII.
- Strict Network Isolation: Kubernetes NetworkPolicies guaranteeing that only the frontend communicates with the backend, and only the backend communicates with the database.
- AI Insights Module (
ai-insights): Built in NestJS with hexagonal architecture (domain/application/infrastructure); adata-sanitizer.serviceanonymizes logs and journals before any LLM invocation, aprompt.serviceconstructs structured prompts, and scheduled cron jobs periodically generate personalized insights. - CI/CD & Security: GitHub Actions pipelines with secret scanning, automated GitOps deployments via ArgoCD and Kustomize.
SentiGraph Finance — Real-Time Crypto Market Intelligence
Low-latency polyglot microservices architecture composed of four independent services interconnected through a Redis (DragonflyDB) backbone:
- Harvester (Rust): High-frequency ingestion of Binance Futures WebSocket streams (ticker, order book depth, liquidations) with automatic exponential backoff reconnection.
- Analyst (Go): Worker pool for sentiment analysis via Ollama, batch persistence in TimescaleDB, and real-time broadcasting via WebSocket.
- Scout (Go): Multi-source RSS and Nitter intelligence monitoring pipeline, dispatched to Analyst for sentiment scoring.
- Dashboard (Next.js): Financial monitoring terminal powered by
lightweight-charts, featuring sub-second updates driven by WebSockets.
NightQuizz — Live Quiz Platform & DDD Microservices
Yarn monorepo (Fastify + Domain-Driven Design) partitioned into five services: api-gateway, ms-user, ms-quiz-management, ms-session, ms-response, plus a dedicated real-time ws-service.
- Cascading Zero-Trust Auth: The API gateway verifies the external JWT, then mints a request-scoped internal token signed with RSA; each downstream microservice validates it via Fastify hooks (
hookAccessToken/hookInternalToken), never trusting direct internal calls. - Guaranteed Kafka Idempotency: Every event (
USER_CREATED, etc.) carries a unique UUIDeventId; consumers check it against aprocessed_eventstable within the same TypeORM transaction, ensuring exactly-once processing despite Kafka's at-least-once semantics. - Valkey as Shared Cache & Broker: Open-source Valkey (Redis fork) deployed across microservices via dedicated Kubernetes manifests (
k8s/services/cache). - End-to-End Observability: OpenTelemetry for distributed tracing, Jaeger for trace visualization, OpenSearch + Dashboards for centralized logging, and custom Grafana/Prometheus dashboards.
- Deployment: Multi-profile Docker Compose (
infra/app) for local development, K8s manifests with ArgoCD overlays for production.
Volontariapp — Scalable Event-Driven Volunteering Ecosystem
Umbrella meta-repository orchestrating a dozen independent repositories (microservices, workers, mobile app, shared packages), documented according to the C4 model (context, containers, async flows, deployment).
- Transactional Outbox Pattern: Each microservice writes its business entity and a pending job within the same ACID Postgres transaction, eliminating dual-write issues between the database and the message bus.
- Job → Audit → Stream Pipeline: An
outbox-runnerpushes jobs to BullMQ (Redis); aworkerexecutes them and logs the execution result, triggering an automatic SQL trigger that republishes the event to a Redis Stream, consumed in turn bypost-processors. - WebSocket-Orchestrated Scatter-Gather: When an event is created, multiple independent post-processors (geocoding, Neo4j graph writes in
ms-social) run in parallel;ws-serviceaggregates acknowledgments bycorrelation_idand only notifies the client once all steps succeed — with a compensating Saga (Neo4j rollback) upon partial failure. - Synchronous gRPC + Asynchronous Redis: The API Gateway routes fast synchronous requests via gRPC to isolated microservices (each with its own Postgres database), while heavy asynchronous processing is handled by the Redis event streaming pipeline.
- GitOps & Hardened Security: K3s cluster with "Restricted" Pod Security Admissions (non-root, read-only root filesystem, seccomp), secrets encrypted using Bitnami Sealed Secrets, and default-deny NetworkPolicies across domains.
- Mobile: Cross-platform React Native app (Expo 54) consuming the ecosystem via the API Gateway.



