Skip to content
View Lionel-Rousseau's full-sized avatar

Block or report Lionel-Rousseau

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Lionel-Rousseau/README.md

Lionel Rousseau

Administrateur Systèmes Linux & Sécurité Opérationnelle Pays de la Loire - Disponibilité immédiate - Mobilité nationale


Certifications

CySA+ Security+ CSAP

Badges vérifiables sur Credly.


Profil

Plus de 25 ans d'exploitation Linux en production : serveurs, réseaux, services exposés, supervision, sauvegardes, incidents. Les dépôts ci-dessous sont des extraits d'une infrastructure réelle exploitée 24/7 depuis 2018, publiés comme démonstration de pratique opérationnelle.

Compétences clés : Administration Linux · SecOps · Postfix/Dovecot/Rspamd · Proxmox · OPNsense · Wazuh · Ansible · Bash · LUKS · durcissement sytème & réseau

Anglais C1/C2 — TOEIC 980.


📄 Dossier technique

Présentation complète de l'architecture, des contrôles de sécurité, des procédures de continuité et des retours d'expérience associés : LRO_Dossier_Technique_2026.pdf — 16 pages.


Dépôts

Architecture SecOps & continuité d'une infrastructure Linux multi-sites en production, 7 ans d'exploitation autonome, défense en profondeur, PCA documenté.

Postfix / Rspamd hardened mail stack. Configuration de messagerie Linux durcie, issue d’une plateforme de production : Postfix, Dovecot, Rspamd, OpenDKIM/OpenDMARC/OpenARC, SPF/DKIM/DMARC/ARC, DANE/MTA-STS, MX secondaire, Fail2ban, ipset et scripts d’exploitation.

Orchestration de sauvegardes multi-hôtes — rsync, containers LUKS, opérations idempotentes, vérification SHA-256, et une boucle de contrôle qui a détecté des échecs silencieux sur 7 ans d'exploitation continue.

Automatisation Terraform/Ansible d’un résolveur DNS Unbound en LXC Proxmox, avec validation DNS, DNSSEC et DNS-over-TLS par script Bash. Dépôt anonymisé issu d’un cas réel d’exploitation Linux/SecOps.

Pipeline Certbot DNS-01 → Let's Encrypt → déploiement API Freebox OS : renouvellement automatisé, audit multi-hôtes d'expiration TLS, secrets cloisonnés. Code issu d'un cas réel d'exploitation, anonymisé et adapté pour publication.


Liens

🌐 lionel.rousseau.kr  ·  💼 LinkedIn  ·  🏅 Credly



English version

Linux Systems Administrator & SecOps practitioner Pays de la Loire, France - available immediately, open to relocation.


Certifications

CySA+ Security+ CSAP

All badges verifiable on Credly.


Profile

25+ years running Linux in production : servers, networks, exposed services, monitoring, backups, incident response. The repositories below are distillations of a real infrastructure operated 24/7 since 2018, published as evidence of operational practice rather than side projects.

Core competencies: Linux administration · SecOps · Postfix/Dovecot/Rspamd · Proxmox · OPNsense · Wazuh · Ansible · Bash · LUKS · system & network hardening

English C1/C2 — TOEIC 980.


Repositories

SecOps architecture & continuity of a multi-site Linux production infrastructure, 7 years of autonomous operation, defense in depth, documented disaster recovery plan.

Postfix / Rspamd hardened mail stack. Production-derived hardened Linux mail configuration featuring Postfix, Dovecot, Rspamd, OpenDKIM/OpenDMARC/OpenARC, SPF/DKIM/DMARC/ARC, DANE/MTA-STS, secondary MX, Fail2ban, ipset, and operational scripts.

Multi-host backup orchestration — rsync, LUKS containers, idempotent remote operations, SHA-256 verified config sync, and a verification loop that has actually caught silent failures over 7 years of 24/7 operation.

Terraform/Ansible automation of an Unbound DNS resolver in Proxmox LXC, with DNS, DNSSEC, and DNS-over-TLS validation via Bash script. Anonymized repository based on a real-world Linux/SecOps deployment.

Certbot DNS-01 → Let's Encrypt → Freebox OS API deployment pipeline: automated renewal, multi-host TLS expiry audit, secrets isolated at 600. Based on a real-world deployment, anonymized for publication.


Links

🌐 lionel.rousseau.kr  ·  💼 LinkedIn  ·  🏅 Credly

Pinned Loading

  1. laflanelle-secops-architecture laflanelle-secops-architecture Public

    Architecture SecOps & continuité d'une infrastructure Linux multi-sites en production • 7 ans d'exploitation autonome, défense en profondeur, PCA documenté.

    1

  2. postfix-rspamd-hardened-config postfix-rspamd-hardened-config Public

    Production-tested Postfix + Rspamd + Dovecot configuration with full SPF/DKIM/DMARC/ARC chain, DANE, MTA-STS, postscreen, Bayes training, and tuned anti-spam policies. Maintained continuously since…

    Shell

  3. proxmox-unbound-iac proxmox-unbound-iac Public

    Reproducible Unbound resolver in a Proxmox LXC, provisioned with Terraform + Ansible and validated (DNSSEC, DoT).

    Shell

  4. linux-prod-backup-toolbox linux-prod-backup-toolbox Public

    Multi-host backup orchestration for a small Linux production infrastructure, rsync, LUKS containers, idempotent remote operations, SHA-256 verified config sync, and a verification loop that has act…

    Shell

  5. letsencrypt-cert-pipeline letsencrypt-cert-pipeline Public

    Automated Let's Encrypt TLS pipeline for Freebox OS : DNS-01 renewal, API deployment and multi-host expiry audit.

    Shell