Skip to content
View Thomas2500's full-sized avatar
๐Ÿ‡ฆ๐Ÿ‡น
๐Ÿ‡ฆ๐Ÿ‡น

Block or report Thomas2500

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
Thomas2500/README.md

Hi, Iโ€™m Thomas Bella ๐Ÿ‘‹๐Ÿ˜„

Tech Lead Cyber Security based near Vienna, Austria ๐Ÿ‡ฆ๐Ÿ‡น
I build security foundations that scale (PKI, IAM, hardening, automation), and I ship pragmatic open-source tools in my spare time โš™๏ธ๐Ÿ›ก๏ธ


๐Ÿš€ About me

  • ๐Ÿ›ก๏ธ Tech Lead Cyber Security (engineering-focused: architecture + implementation)
  • ๐Ÿ” Deep into PKI, IAM/SAML/OIDC, Zero Trust-ish pragmatism, and secure automation
  • ๐Ÿงฐ DevOps-minded security: I like repeatable, observable, boring-in-a-good-way systems
  • ๐Ÿงช Homelab enjoyer: self-hosting, monitoring, networking, automation
  • ๐Ÿƒโ€โ™‚๏ธ Outside the terminal: hiking, swimming, photography (and quantified-self stuff) ๐Ÿ“ธโ›ฐ๏ธ๐ŸŠโ€โ™‚๏ธ

๐ŸŒ Portfolio & links


๐Ÿงฉ Featured projects

๐ŸŸฆ uDomainFlag

Browser extension + backend that surfaces useful server/domain/security context โ€” running at scale for years.
Stack: Go backend, high-volume APIs, autoscaling, reliability-first mindset โšก
Repo: https://github.com/thomas2500/uDomainFlag

๐ŸŸฉ GoAPTCacher

APT caching proxy (think apt-cacher-ng style) focused on performance and fewer external dependencies.
Repo: https://gitlab.com/bella.network/GoAPTCacher

๐ŸŸจ PassBeyond

SAML SP / reverse-proxy layer with modern session handling (JWT), built for enterprise reality.
Repo: https://gitlab.com/bella.network/PassBeyond


๐Ÿ›ก๏ธ What I focus on (security-wise)

  • ๐Ÿ›๏ธ Security engineering in real orgs: policy โ†’ implementation โ†’ operations
  • ๐Ÿงพ Compliance work that actually lands: ISO 27001 / NIS2-aligned execution (not just paperwork)
  • ๐Ÿ”‘ Enterprise PKI modernization: roots/intermediates, lifetimes, automation (ACME), inventory hygiene
  • ๐Ÿงท Identity & access: SAML/OIDC/OAuth2 patterns, claims, app onboarding, secure auth flows
  • ๐Ÿ“ˆ Observability: logging/metrics first, incident response readiness, and โ€œprove itโ€ telemetry

๐Ÿงฐ Tech stack & tools I like

Languages: Go ยท PHP ยท JavaScript ยท Bash ยท PowerShell
Infra: Linux ยท Docker ยท GitLab CI/CD ยท nginx ยท HAProxy ยท IPv6
Security: PKI ยท SSO ยท hardening ยท threat modeling ยท secure defaults
Ops: monitoring, alerting, and automation Other: MariaDB ยท MySQL ยท PostgreSQL ยท Redis ยท MQTT ยท FontAwesome


๐Ÿ“Œ Currently tinkering with

  • ๐Ÿ”„ Removing unnecessary dependencies from services (less glue, fewer moving parts)
  • ๐Ÿงฑ Making infrastructure more self-documenting (dashboards, inventories, automation)
  • ๐Ÿ“ฆ Improving caching/proxy workflows for faster, more reliable deployments

๐Ÿค Letโ€™s connect


โœจ Fun facts

  • ๐Ÿง  I strongly prefer systems that are simple, observable, and boring (thatโ€™s a compliment).
  • ๐Ÿ“ธ If Iโ€™m not building something, Iโ€™m probably outside taking photos or on a trail.

Pinned Loading

  1. uDomainFlag uDomainFlag Public

    uDomainFlag is a browser extension which shows the country flag of the currently visible website

    JavaScript 30 3

  2. mailcow/mailcow-dockerized mailcow/mailcow-dockerized Public

    mailcow: dockerized - ๐Ÿฎ + ๐Ÿ‹ = ๐Ÿ’•

    JavaScript 12.1k 1.6k

  3. go-fitbit go-fitbit Public

    Fitbit API for Go to fetch, add, update and delete data on Fitbit using REST API

    Go 12 6

  4. golang-helper golang-helper Public

    Docker Helper Image to simplify Go builds and further processing of these builds.

    Dockerfile