Skip to content
View farhanashrafdev's full-sized avatar
:octocat:
I GIT CODE
:octocat:
I GIT CODE

Organizations

@Fsociety-Bulc @Learn-With-Fun-BULC @SidHacksCommunity @Cloud-Native-Security-Pakistan

Block or report farhanashrafdev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
farhanashrafdev/README.md
Typing SVG

Open Source Maintainer & Contributor Profile Views

🎀 Speaker β€’ πŸ† Hackathon Enthusiast β€’ 🌍 Open to Remote Opportunities


πŸš€ About Me

name: Farhan Ashraf
role: AISecOps Engineer @ Systems Ltd
location: Pakistan

what_i_do:
  - Securing Generative AI Systems (guardrails, model safety)
  - Cloud Native Security (Kubernetes, OpenShift, Docker)
  - DevSecOps Pipeline Automation
  - Security Observability, Threat Detection & Response (OpenTelemetry)

passionate_about:
  - 🎀 Speaking at tech conferences & meetups
  - πŸ† Building cool stuff at hackathons
  - πŸ“š Creating open-source learning resources
  - 🀝 Collaborating on security projects

currently_learning:
  - 🧠 Advanced AI & Custom Model Training
  - πŸ€– LLM Fine-tuning & Architecture
  - πŸ›‘οΈ AI Security (Adversarial ML)
  - ⚑ High-Performance Model Serving

open_to:
  - Remote roles in DevSecOps / Cloud Security
  - Speaking opportunities
  - Open source collaborations
  - Hackathon teams

πŸ† Open-Source Contributions & Impact

Selected work framed as Situation β†’ Task β†’ Action β†’ Result, with project-level reach separated from the direct outcome of each change.

  • πŸ”₯ 90DaysOfCyberSecurity β€” Creator

    • Situation: Cybersecurity beginners faced a broad, fragmented learning landscape without a practical sequence to follow.
    • Task: Turn the core skills into an approachable, day-by-day path from fundamentals to hands-on security work.
    • Action: Created and continue to maintain a free 90-day roadmap spanning networking, Linux, Python, traffic analysis, ELK, cloud, and ethical hacking.
    • Result: The roadmap has earned 18.8k+ stars and 2.1k+ forks, demonstrating sustained global discovery and community reuse.
    • GitHub stars GitHub forks
  • 🧠 AWS IA Terraform Bedrock β€” Merged PR #162

    • Situation: The reusable module lacked image-filter guardrails and typed coverage for newer Bedrock Cloud Control resources, leaving configuration gaps and weaker validation.
    • Task: Bring the module's guardrail and resource schemas in line with current Bedrock capabilities.
    • Action: Added image-filter support, strongly typed guardrail inputs, automated-reasoning policies, and broader Cloud Control schema coverage.
    • Result: Teams can define text and image safeguards with earlier validation and better IDE guidance; the capability is now available in a module with 119k+ Terraform Registry downloads.
  • πŸ€– AWS IA Terraform AgentCore β€” Merged PR #20

    • Situation: AgentCore gateways had no first-class Terraform support for request and response Lambda interceptors.
    • Task: Make gateway-boundary controls reusable without requiring teams to wire Lambda access manually.
    • Action: Implemented validated interceptor configuration, outputs, documentation, and automatic Lambda invoke permissions.
    • Result: Teams can add authorization, payload transformation, PII masking, and policy enforcement at the gateway boundary through a module with 21k+ Terraform Registry downloads.
  • πŸ›‘οΈ OWASP DevSecOps Guideline β€” Merged PR #98

    • Situation: Legacy repository paths contained |, a Windows-reserved character that prevented a complete working-tree checkout on Windows.
    • Task: Remove the contributor-access barrier without changing the guideline's content or breaking other platforms.
    • Action: Renamed the invalid paths and updated the affected files consistently across the repository.
    • Result: Windows users can now obtain a complete checkout, removing this prerequisite barrier to contribution. That matters on an OS reported by 49.5% of professional-developer respondents in Stack Overflow's 2025 survey, for an OWASP project with 1.1k+ stars and 260+ forks.
  • πŸ”­ CNCF Inspektor Gadget β€” Merged PR #5721

    • Situation: The default Prometheus annotation targeted legacy port 2223 while the OpenTelemetry metrics listener used 2224, sending discovery to the wrong endpoint.
    • Task: Restore correct default metrics discovery and keep generated deployment paths aligned.
    • Action: Corrected the scrape port and regenerated the Helm and kubectl gadget deploy manifests.
    • Result: Default Prometheus discovery now targets the live metrics endpoint across both installation paths in a 2.9k+ star / 370+ fork CNCF project whose instrumentation also underpins Microsoft Defender for Containers.

Reach figures checked 1 September 2026. Downloads, stars, and forks indicate project scaleβ€”not the number of users who consumed a specific change.


🎀 Speaking & Community

I love sharing knowledge! I regularly speak at:

  • Tech Conferences - Cloud, Security, DevOps topics
  • University Events - As a GitHub Campus Expert
  • Meetups & Workshops - Hands-on security training

πŸ’‘ Interested in having me speak at your event? Reach out!


πŸ› οΈ Tech Stack

Cloud & Infrastructure

AWS Azure GCP Kubernetes OpenShift Docker Terraform

Security & DevSecOps

Trivy Snyk SonarQube Falco OpenTelemetry

Languages & Tools

Python Go Bash Linux

πŸ“Š GitHub Metrics

GitHub Metrics

πŸ“ˆ 3D Contribution Graph

3D Contribution Graph


🀝 Let's Connect!

Blog LinkedIn Twitter Email


Open to remote DevSecOps and cloud security roles, security-focused open source, speaking slots, and hackathon teams. Let's build something awesome together.

Popular repositories Loading

  1. 90DaysOfCyberSecurity 90DaysOfCyberSecurity Public

    This repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, …

    19k 2.2k

  2. 90DaysOfGoogleCloudPlatform 90DaysOfGoogleCloudPlatform Public

    86 16

  3. farhanashrafdev farhanashrafdev Public

    42 9

  4. TheUltimateDevOpsBible-ZeroToHero TheUltimateDevOpsBible-ZeroToHero Public

    This repository is your complete, internet-independent, production-grade guide to becoming an elite DevOps, DevSecOps, AI SecOps, or AIOps engineer. It contains the equivalent of 3+ years of real-w…

    30 2

  5. DevSecOpsGuideline DevSecOpsGuideline Public

    Forked from OWASP/DevSecOpsGuideline

    The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

    Python 16 3

  6. GenAI-Kubernetes-Security-Scanner GenAI-Kubernetes-Security-Scanner Public

    A Kubernetes security scanner powered by Generative AI (GenAI) for detecting, analyzing, and remediating security risks in Kubernetes pods. It leverages AWS Bedrock’s Large Language Models (LLMs) t…

    Python 5 2