Skip to content
View heyvaldemar's full-sized avatar
🐳
Docker Captain · valdemar.ai
🐳
Docker Captain · valdemar.ai

Highlights

  • Pro

Organizations

@docker-captains @community-snyk

Block or report heyvaldemar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
heyvaldemar/README.md

Vladimir Mikhalev

Docker Captain · IBM Champion · CNCF Ambassador · AWS Community Builder


What I Do

One of fewer than 250 Docker Captains worldwide. 10 vendor-recognized community titles across Docker, IBM, CNCF, AWS, HashiCorp, Snyk, Cypress, Notion, GitKraken, and Platform Engineering, earned through contribution rather than credentials.

Every architecture recommendation backed by production experience. Designed and delivered cloud infrastructure at Amazon, IBM, Thales, and a Series D data platform serving Fortune 500 clients. I design scalable systems and publish what I learn: reference architectures for container security, AI governance, and platform engineering used by practitioners worldwide.


Recognition

Docker CEO on my contributions to the ecosystem

Docker CEO Scott Johnston recognizes Vladimir Mikhalev at Docker Captains Summit 2024

"Vladimir has written more than 100 pieces of content for Docker in the past year. He has also helped us find customer stories that we've been able to document and share throughout the rest of the community. And he's met with multiple product managers internally to share his product feedback."

— Scott Johnston, CEO, Docker (2019–2025)

Snyk Ambassador Award Finalist · Four named first-hand references, with linked proof


Published Work

Selected publications on vendor platforms


Engineering Standard

Formalized supply-chain hardening program for public deployment-template repositories

Self-Host Repo Hardening Runbook is a 7-phase program that brings deployment-template repositories to a supply-chain-hardened baseline: commit-SHA-pinned GitHub Actions with per-job permissions, digest-pinned upstream images with a daily freshness check, OpenSSF Scorecard, CI linting, Trivy upstream scanning.

Reference implementations, three repository shapes with one hardening rigor:

Repository Shape Supply-chain surface
aws-kubectl-docker Image-publishing Cosign keyless signing · SBOM (SPDX) · SLSA build provenance · Trivy SARIF · digest-pinned base · OpenSSF Scorecard
keycloak-traefik-letsencrypt-docker-compose Deployment template Digest-pinned upstream images · daily freshness check against the registry · daily CI deployment smoke · lint + Trivy scan · OpenSSF Scorecard · OpenSSF Best Practices passing · keyless-signed releases · SLSA build provenance
fleet-ops The automation that runs the fleet Lint · OpenSSF Scorecard · OpenSSF Best Practices passing · keyless-signed releases · SLSA build provenance

88 repositories under this standard: 49 self-hosted applications behind Traefik, 14 game servers, 6 other stacks, 8 Terraform pipelines on AWS, 11 operations tools and scripts. Every template is pinned by digest, boots in CI daily, upgrades from its previous release on the same volumes, and is released only after that passes. fleet-ops recounts them once a day and rewrites this line when a number changes; these last changed 2026-09-25 04:23 UTC.


Evidence, Not Green Checks

How an AI agent is run on this fleet

An AI agent does most of the typing across these repositories, and nothing it writes ships on its word. It is fast, and it is wrong on a schedule, so a release is cut only after the release commit itself deploys, backs up and restores in CI, and every fleet rule is tested against a planted violation before it is trusted.

Today: 73 restore scripts across 48 repositories, every one of them run by CI. 955 releases are tagged across the fleet. 47 of 47 templates restored an older release's backup into the current release on a machine that had never run the stack, the fastest in 20 s. OpenSSF Scorecard, run by OpenSSF and not by me, puts the median at 7.4 across 97 repositories. The OpenSSF Best Practices badge, a questionnaire I answered and OpenSSF publishes with every answer, is passing on 90 of 90 registered repositories. The 7 public repositories that hold no code to rate, this profile among them, are not registered. fleet-ops recounts these once a day and rewrites this line when a number changes; these last changed 2026-09-28 14:08 UTC.

What those checks caught on 23 September 2026, the day that line was first written:

  • A team wiki whose backup logged Data backup OK for 12 days and 8 releases while it archived a storage volume nothing writes to. The uploaded files were in no backup. The fix now restores a file through S3 in CI on every push.
  • On that day, all 72 restore scripts the fleet then carried, across 47 templates, had never been run by CI, the oldest since May 2021. The tests had restored with their own copy of the commands. One of the scripts, before and after: it refused to run on the stack it shipped with. All of them run the shipped script now, and a fleet rule fails any that stops.
  • Six mistakes by the agent itself in one day, from an apostrophe that stopped a backup loop to a database client the image does not ship. None reached a release.

And on 24 September, the day after: two defects in the fleet's own watcher, found and fixed before its morning run. A test's fake failed the way the real function never does, so 116 green tests hid a crash; and three templates whose cron had changed the day before would have been reported sixty-two hours late. Both are in the ledger with the rule each produced. The same day every public repository gained a rule against rewriting main and, where it was missing, a security policy; OpenSSF Scorecard scores the result, and the evidence page repeats that score with every check below ten and what it means here.

On 24 September the clean-machine drill went from four templates to every template that ships a restore script, all 47, in one day: each one restores its previous release's backup into the current release on a runner that has never run the stack, weekly, and the time is on the evidence page beside the recovery point the template ships with. The line above counts them; a template whose drill fails is listed as failing and carries no time.

Green is a claim. A restore is evidence.

The evidence, with a restore measured on a clean machine · Every finding, with the rule it produced · The decisions, and what each one cost


Production Background

Enterprise infrastructure architecture at Fortune 500 scale

Sole architect and technology leader for North American operations at a Series D enterprise serving Fortune 500 clients. Designing scalable cloud architecture on AWS for enterprise accounts: container orchestration, zero trust governance, AI-augmented platforms, multi-region infrastructure.

Previously: Amazon, IBM, Thales. Designed disaster recovery architecture at scale, distributed systems across continents, reliability engineering for deployments processing millions of requests per minute.

Every architecture decision I publish is backed by production experience. Four named, first-hand references, each with linked proof: from Docker's then-CEO, a published security author, and the lead of Snyk's ambassador program.


Community Titles

10 active vendor-recognized programs

Organization Title Domain
Docker Captain Container architecture, security, and developer workflows
IBM Champion Enterprise AI, Cloud, Automation, HashiCorp/Terraform portfolio
AWS Community Builder Cloud architecture, EKS, Serverless
CNCF Ambassador Kubernetes and the cloud native ecosystem
HashiCorp Ambassador Terraform, Vault, infrastructure as code
Platform Engineering Ambassador Internal Developer Platforms
Snyk Ambassador Application security, supply chain
Cypress Ambassador Test automation, AI agents in testing
GitKraken Ambassador Git workflows, version control
Notion Ambassador Engineering knowledge management

Vladimir Mikhalev

Docker Captain · IBM Champion · CNCF Ambassador · AWS Community Builder

The Verdict — production-tested analysis on YouTube. 100,000+ subscribers.

YouTube · Blog · LinkedIn

Pinned Loading

  1. keycloak-traefik-letsencrypt-docker-compose keycloak-traefik-letsencrypt-docker-compose Public

    Keycloak with Let's Encrypt Using Docker Compose

    Shell 147 57

  2. nextcloud-traefik-letsencrypt-docker-compose nextcloud-traefik-letsencrypt-docker-compose Public

    Nextcloud with Let's Encrypt Using Docker Compose

    Shell 92 34

  3. zabbix-traefik-letsencrypt-docker-compose zabbix-traefik-letsencrypt-docker-compose Public

    Zabbix with Let's Encrypt Using Docker Compose

    Shell 54 38

  4. outline-keycloak-traefik-letsencrypt-docker-compose outline-keycloak-traefik-letsencrypt-docker-compose Public

    Outline with Keycloak and Let's Encrypt Using Docker Compose

    Shell 40 8

  5. gitlab-traefik-letsencrypt-docker-compose gitlab-traefik-letsencrypt-docker-compose Public

    GitLab with Let's Encrypt Using Docker Compose

    Shell 34 15

  6. ollama-traefik-letsencrypt-docker-compose ollama-traefik-letsencrypt-docker-compose Public

    Ollama with Let's Encrypt Using Docker Compose

    Shell 26 4