Skip to content

Instantly share code, notes, and snippets.

@mcarbonneaux
Last active February 13, 2026 12:14
Show Gist options
  • Select an option

  • Save mcarbonneaux/c324802af76138530b08aa6c2f4eb4cf to your computer and use it in GitHub Desktop.

Select an option

Save mcarbonneaux/c324802af76138530b08aa6c2f4eb4cf to your computer and use it in GitHub Desktop.
{
"basics": {
"name": "Mathieu CARBONNEAUX OSUAGWU",
"label": "Complex Systems Architect | Cloud-Native, Infrastructure & Security Expert",
"image": "https://www.ch2o.info/en/about/photocv.jpg",
"website": "https://www.ch2o.info",
"summary": "### Overview\n\nPassionate about computing since childhood, I began programming at **age 12** (Logo, Basic, Z80 assembly, 680x0, C/C++). My initial training, focused on electronics and industrial computing followed by business IT, provided me with a **comprehensive vision of computing, from hardware to software**.\n\nWith nearly **30 years of professional experience** (since 1997), I have held successive roles as a Developer, DBA, Systems/Network/Security Engineer, and Middleware Expert. **I am a multipotentialite**: my profile naturally extends beyond established frameworks. I consistently manage architecture, operations, implementation, and design in parallel (**Architect and DevOps**).\n\n### Major Technical Achievements\n\n* **SFR Proprietary API Gateway (since 2006)**: 15+ years of continuous evolution (IBM DataPower → Open Source mod_perl → REST → Zeus/vTM Event-Driven Architecture).\n* **Multi-level Load Balancer**: **DSR (Direct Server Return)** architecture based on **eBPF/Cilium** with **Maglev** consistent hashing, driven by a custom in-house Kubernetes operator.\n* **Security Data Lake**: **300 TB** of data on **ClickHouse/Kafka**, centralizing all security logs for the SFR Information System (FW, Proxy, VPN).\n* **Transformation Pioneer at SFR**: Introduction of Linux (2004), virtualization (2006), and then Kubernetes (2020).\n* **GCP Landing Zone (2023)**: Complete implementation (Dedicated Interconnect, Keycloak SSO, MLOps platform).\n\n### Current Expertise\n\nCurrently, I am involved in nearly all infrastructure architecture directions for **SFR SI**. I am proficient in over 10 languages, particularly the **Java/J2EE** ecosystem (WebLogic, JBoss, Tomcat). My current research focuses on **AI and Machine Learning** for implementing intelligent **anti-DDoS** mechanisms.",
"location": {
"city": "Thonon-les-Bains (Mobility: Geneva / Lausanne / Lake Geneva Area)",
"countryCode": "FR",
"region": "Haute-Savoie"
},
"profiles": [
{
"network": "Home Page",
"username": "My Personal Page",
"url": "https://www.ch2o.info"
},
{
"network": "Github",
"username": "mcarbonneaux",
"url": "https://github.com/mcarbonneaux"
},
{
"network": "Github",
"username": "ZenProjects",
"url": "https://github.com/ZenProjects"
},
{
"network": "Linkedin",
"username": "mcarbonneaux",
"url": "https://www.linkedin.com/in/mcarbonneaux/"
}
]
},
"work": [
{
"company": "SFR",
"position": "Monitoring Tools Expert",
"startDate": "2014",
"summary": "Massive scale observability architecture. Collaboration with Zabbix (v2.3) for LLD. Design of a 300 TB security data lake (ClickHouse/Kafka). Evangelizing modern observability practices.",
"highlights": [
"Implementation of a 300+ TB data lake on ClickHouse/Kafka",
"Introduction of Zabbix and contribution to v2.3 development",
"Standardization of metrics and logs across the entire Information System",
"Full observability stack (metrics, logs, traces)"
]
},
{
"company": "SFR",
"position": "Infrastructure Solutions Architect",
"startDate": "2010",
"summary": "SOA standardization and Web architecture. Leading the GCP Landing Zone (2023): full management via Terraform (Network Interconnects, VPC, IAM). Implementation of GitOps on a massive internal GitLab instance.",
"highlights": [
"SOA/API Architect and SI standardization",
"Terraform Automation: Network Interconnect, VPC, and IAM on GCP",
"Management of one of the largest internal GitLab instances (GitOps, CI/CD)",
"Design of high-performance Load Balancers (eBPF/Cilium/Maglev)",
"Technology evangelism: from virtualization to Kubernetes"
]
},
{
"company": "SFR",
"position": "SOA – API Gateway Expert",
"startDate": "2006",
"summary": "Design and evolution of the API Gateway (15 years). Expertise in Java/J2EE (Strategic Legacy) and application servers (WebLogic, JBoss, Tomcat). Migration to event-driven microservices architectures.",
"highlights": [
"Initial design of SFR API Gateway (2006)",
"Java Application Server expertise (WebLogic, JBoss, WebSphere)",
"Migration from IBM DataPower → Open Source (Apache/mod_perl)",
"Full support for SOAP and REST",
"Event-driven architecture (vTM)"
]
},
{
"company": "SFR",
"position": "Directory and IAM (SSO) Expert",
"startDate": "2006",
"summary": "IAM engineering and LDAP directories. Migration from SiteMinder to Keycloak. Implementation of advanced MFA (WebAuthn, OCRA). Application of Agile methodologies (Scrum/Kanban).",
"highlights": [
"LDAP directory management (Netscape → 389 DS)",
"SSO migration: SiteMinder → Proprietary solution → Keycloak",
"MFA: TOTP, WebAuthn, FIDO, Passkeys, OCRA",
"Project leadership using Agile (Scrum / Kanban)"
]
},
{
"company": "SFR",
"position": "Web Hosting Infrastructure & Network Expert",
"startDate": "2005",
"summary": "High-performance architecture. First Apache Linux foundation. Carrier-grade network expertise (BGP, VPN). Kubernetes design (Talos/Cilium) via GitOps and operators.",
"highlights": [
"Design of the first SFR Apache Linux foundation",
"High-availability hosting architecture",
"Multi-level Load Balancing (BGP/ECMP/eBPF/Cilium/HAProxy)",
"DSR with Maglev consistent hashing"
]
},
{
"company": "SFR",
"position": "Unix AIX and Linux Platform Expert",
"startDate": "2004",
"summary": "Lead on the introduction of Linux. Industrialization of packaging and deployment automation. Evangelizing the shift of low-level layers toward Open Source.",
"highlights": [
"Introduction of Linux at SFR (2004)",
"Virtualization and container evangelism",
"Multi-platform industrialization and packaging",
"Deployment automation (Kickstart, NIM, Foreman)"
]
},
{
"company": "SFR",
"position": "Technical Expert: OLTP Tuxedo, IBM TXSeries & MOM MQSeries",
"startDate": "2003-04-01",
"summary": "Critical transactional systems (XA, 2PC). L3/L4 support for Tuxedo and Encina. Complex modeling via UML and Merise.",
"highlights": [
"L3/L4 Support for Tuxedo and TXSeries/Encina",
"Distributed transaction expertise (XA, 2PC)",
"Merise and UML modeling for transactional systems",
"MQSeries Administration & Kafka Migration"
]
},
{
"company": "CEGETEL / SFR",
"position": "Technical Expert: DCE TXSeries/Encina",
"startDate": "2001-03-01",
"endDate": "2003-03-31",
"summary": "Expertise in DCE and TXSeries/Encina across heterogeneous Unix environments. Critical operations of 30 Encina cells.",
"highlights": [
"L3/L4 Support for DCE and TXSeries/Encina",
"Multi-platform operations",
"Expertise in MQSeries, Oracle, Informix"
]
},
{
"company": "ATOS Origin (for Bouygues Télécom)",
"position": "Outsourcing Manager - 6ème Sens Project",
"startDate": "2001-01-01",
"endDate": "2001-03-31",
"summary": "Outsourcing of the WAP/WEB portal to ATOS. Windows 2000, COM/DCOM, and MSMQ architecture.",
"highlights": [
"Outsourcing of Bouygues 6ème sens WAP portal",
"Implementation of complete infrastructure"
]
},
{
"company": "ATOS Origin (for SFR/CEGETEL)",
"position": "Technical Architect - SIMP Project",
"startDate": "2000-07-01",
"endDate": "2001-12-31",
"summary": "Performance optimization of SIMP. Merise modeling for complex migration to Oracle 8i.",
"highlights": [
"SIMP performance optimization",
"Encina/Informix → TXSeries/Oracle migration",
"C/C++ and Unix Shell development"
]
},
{
"company": "Adesium (for SFR/CEGETEL)",
"position": "Developer and Technical Architect - SRPP/Dual Slot Project",
"startDate": "2000-03-01",
"endDate": "2000-06-30",
"summary": "Development of SRPP (Prepaid Top-ups). Object-oriented modeling and Informix ESQL/C development.",
"highlights": [
"N-tier architecture for top-up system",
"C/C++ and ESQL/C development"
]
},
{
"company": "Adesium (for SFR/CEGETEL)",
"position": "Developer and Technical Architect - SIMP Project",
"startDate": "1999-03-01",
"endDate": "2000-02-29",
"summary": "Design of n-tier architecture for payment methods. Full Merise modeling.",
"highlights": [
"Full n-tier architecture design",
"Merise modeling",
"TITAN FT → BBA FT migration"
]
},
{
"company": "Adesium (for SFR/CEGETEL)",
"position": "Technical Architect and Coordinator - CSP to Visual Age Migration",
"startDate": "1998-08-01",
"endDate": "1999-02-28",
"summary": "Y2K migration of CSP code on OS/390 Mainframe. DB2 Client/Server architecture.",
"highlights": [
"Y2K CSP/MVS Migration",
"DB2 Client/Server Architecture",
"DRDA/SNA Gateways"
]
},
{
"company": "Adesium (for SFR/CEGETEL)",
"position": "Project Manager - KART Project",
"startDate": "1998-08-01",
"endDate": "1999-02-28",
"summary": "Distributed document management. Merise modeling under HP-UX/Oracle.",
"highlights": [
"KART Project Manager",
"Distributed Client/Server architecture",
"Merise modeling"
]
},
{
"company": "Adesium (for SFR/CEGETEL)",
"position": "Project Manager / Developer - PACT Project",
"startDate": "1998-04-01",
"endDate": "1998-07-31",
"summary": "GSM ticket management. Oracle migration and Y2K compliance.",
"highlights": [
"GSM/PABX ticket billing",
"Oracle and Windows migration",
"Y2K Compliance"
]
},
{
"company": "Adesium (for SFR)",
"position": "Developer - SIM Center Project",
"startDate": "1998-01-01",
"endDate": "1998-03-31",
"summary": "CAM (Computer-Aided Manufacturing) for SIM cards. UML modeling and multi-platform C++ development.",
"highlights": [
"SIM card CAM system",
"UML and Merise modeling",
"C++ and Oracle OCI development"
]
},
{
"company": "Adesium (for SFR)",
"position": "Project Manager / Developer - PACT Project",
"startDate": "1997-09-01",
"endDate": "1997-12-31",
"summary": "C/Pro*C Oracle development for GSM ticket billing under HP-UX.",
"highlights": [
"C and Pro*C Oracle development",
"PowerBuilder and SQL*NET"
]
},
{
"company": "Adesium (for SFR)",
"position": "Developer - SGD Project (ULYSSE Project)",
"startDate": "1997-06-01",
"endDate": "1997-08-31",
"summary": "N-tier architecture for distributor management via Encina and DCE under AIX.",
"highlights": [
"N-tier architecture with Encina",
"OTS and DCE development",
"OMT modeling"
]
},
{
"company": "ICEP",
"position": "Technical Architect, Developer, Network & System Administrator",
"startDate": "1996-09-01",
"endDate": "1997-05-31",
"summary": "Unix systems and network administration. C++ development with Oracle database access.",
"highlights": [
"Network and server administration",
"C/C++ and Oracle development",
"TCP/IP technology watch"
]
}
],
"education": [
{
"institution": "ICEP",
"area": "Computer Science",
"studyType": "Bachelor of Science (TRIO)",
"startDate": "1995",
"endDate": "1996"
},
{
"institution": "ICEP",
"area": "Industrial Computing",
"studyType": "BTS (Associate Degree)",
"startDate": "1990",
"endDate": "1994"
},
{
"institution": "Lycée Pasteur",
"area": "Electronics",
"studyType": "Baccalauréat F2 (High School Diploma)",
"startDate": "1987",
"endDate": "1989"
}
],
"skills": [
{
"name": "Architecture & Governance Expertise",
"level": "Master",
"keywords": [
"SI Standardization & Tech Evangelism",
"Merise & UML Modeling (Data/Process Design)",
"SOA Governance & API Architecture (SOAP/REST)",
"GCP Landing Zone Design (Interco, VPC, IAM via Terraform)",
"Java/J2EE Legacy Architecture (WebLogic, JBoss, WebSphere)",
"Transactional Engineering (XA, 2PC, OLTP)",
"Agile Methodologies (Scrum, Kanban)"
]
},
{
"name": "DevOps, GitOps & CI/CD",
"level": "Expert",
"keywords": [
"Massive GitLab Instance Management (CI/CD, Runners)",
"Infrastructure as Code (Terraform, Ansible, Puppet)",
"GitOps (ArgoCD, Flux, Helm)",
"Automation & Industrialization (Foreman, NIM, Kickstart)",
"Deployment Pipeline Management"
]
},
{
"name": "Identity & Security (IAM)",
"level": "Expert",
"keywords": [
"Keycloak (Central IDP)",
"SAML2 / OpenID Connect / OAuth2",
"MFA (WebAuthn, FIDO2, Passkeys, OCRA RFC 6287)",
"Massive Directory Management (389 DS, iPlanet, Oracle DS)",
"Perimeter Security (WAF, Reverse Proxy, IPS)"
]
},
{
"name": "Infrastructure & Networking",
"level": "Expert",
"keywords": [
"Kubernetes (Talos Linux, Cilium, Operators)",
"Carrier Networking (BGP, ECMP, VXLAN, SDN, Anycast)",
"Traffic Management (F5 BIG-IP, Ivanti vTM, HAProxy)",
"Unix/Linux Systems (RedHat, AIX, Solaris, HP-UX)",
"Virtualization (VMware, KVM)"
]
},
{
"name": "Observability & Data Engineering",
"level": "Expert",
"keywords": [
"Big Data (ClickHouse, Kafka 300+ TB)",
"Zabbix Core Contributor (LLD, Provisioning API)",
"Observability (Prometheus, Thanos, Grafana, ELK)",
"Databases (Oracle, Informix, DB2, SQL Server)"
]
},
{
"name": "Programming & Middleware",
"level": "Expert",
"keywords": [
"Languages (C/C++, Golang, Java J2EE, Rust)",
"Low-Level (Z80/68k Assembly, eBPF/XDP)",
"Scripting (Perl/mod_perl, Python, KSH, TCL)",
"TP Monitors (Tuxedo, TXSeries/Encina, DCE)",
"Messaging (MQSeries, Kafka)",
"Open Source (FastCGI Maintainer)"
]
}
],
"languages": [
{
"language": "French",
"fluency": "Native"
},
{
"language": "English",
"fluency": "Professional (C1/C2 - Technical and conversational)"
}
],
"interests": [
{
"name": "Outdoor Activities",
"keywords": [
"Kayaking",
"Canyoning",
"Climbing",
"Trekking"
]
},
{
"name": "Computing",
"keywords": [
"Open Source",
"IoT",
"Video Games",
"Electronics",
"Retro-gaming"
]
}
],
"projects": [
{
"name": "ZenProjects",
"description": "My various Open Source projects contributing to the community",
"highlights": [
"Zabbix PHP Module - Extension for Zabbix monitoring",
"Apache Authmemcookie Module - Distributed authentication based on Memcached",
"Apache Status Text Module - Metric export in text format",
"Apache Chroot Module - Security through isolation",
"Apache Proxy FastCGI Module - Experimental FastCGI proxy",
"PHP SPF Extension - SPF validation for PHP",
"Chromium Web Page Screensaver - Screensaver based on Chromium",
"phpSMTPd - SMTP server in PHP (experimental project)",
"JavaScript OCRA Implementation - OCRA implementation for SSO"
],
"keywords": [
"Open Source",
"C/C++",
"PHP",
"JavaScript",
"Apache Modules",
"Security",
"Authentication"
],
"startDate": "2006",
"endDate": "",
"website": "https://github.com/ZenProjects",
"roles": [
"Creator and Lead Maintainer"
],
"entity": "Personal Open Source Projects",
"type": "application"
}
],
"meta": {
"theme": "even",
"version": "v2.5.0",
"lastModified": "2026-02-06"
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment