Skip to content
View m3yyyyy's full-sized avatar
  • Selangor
  • 22:23 (UTC +08:00)
  • LinkedIn in/m3y

Block or report m3yyyyy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
m3yyyyy/README.md

Muhammad Khairil Ilman

IT Operations · Platform Engineering · Security Automation

I build practical tools that turn IT operations, security evidence, and platform standards into clear workflows people can safely use. My portfolio combines hands-on operations knowledge with modern TypeScript applications, structured APIs, automation, observability, and human approval gates.

My current focus is the point where IT operations meets modern developer tooling: internal developer platforms, AI-assisted incident response, MCP integrations, cloud-native observability, identity security, and software supply-chain assurance.

Platform Engineering IT Operations Security Automation Human in the Loop

Featured portfolio

Orbit Platform Portal dashboard

Project What it demonstrates Explore
Internal Developer Platform Portal Service catalog, evidence-aware scorecards, golden paths, dependency context, policy-checked self-service plans, approval gates, and audit trails. Live demo
IT Incident Triage Agent Incident classification, confidence scoring, local runbook retrieval, read-only diagnostics, timelines, and human-approved response plans. Live demo
MCP IT Ops Server A safe Model Context Protocol server for local knowledge retrieval and allowlisted, read-only IT diagnostics with structured outputs. Repository
Cloud Ops Observability Lab OpenTelemetry-style metrics, traces, logs, alerts, SLOs, request correlation, and incident timelines in one operational view. Live demo
Identity Security Posture Dashboard Microsoft Entra-focused posture controls, fail-closed evidence scoring, remediation approvals, and auditable security decisions. Live demo
Secure Software Supply Chain Dashboard SBOM risk, SLSA provenance, attestations, policy gates, dependency evidence, and human-reviewed exceptions. Live demo

What ties the work together

  • Safe by default — local or synthetic infrastructure, read-only diagnostics, explicit allowlists, and no destructive actions.
  • Humans remain accountable — plans and exceptions require an approve/reject decision before any action is represented as accepted.
  • Unknown is not healthy — incomplete evidence stays visible as NoData instead of silently improving a score.
  • Operations are explainable — structured JSON, timelines, evidence sources, runbooks, and audit events make decisions traceable.
  • Delivery quality is part of the product — strict TypeScript, automated tests, GitHub Actions, security notes, Docker/Render configuration, screenshots, and demo guides.

Technical toolkit

Applications and APIs
TypeScript · React · Node.js · Express · Zod · Vite · REST · Structured JSON

Platform and operations
Platform Engineering · Service Catalogs · MCP · OpenTelemetry · SLOs · Incident Response · Runbooks · Docker · Render

Security and identity
Microsoft Entra ID · Active Directory · Microsoft 365 · Identity Lifecycle · SBOM · SLSA · Policy Gates · Auditability

Automation and delivery
GitHub Actions · Dependabot · PowerShell · Python · CI/CD · Human-in-the-Loop Workflows

Earlier foundations

Connect

Pinned Loading

  1. it-incident-triage-agent it-incident-triage-agent Public

    Human-approved IT incident triage with runbook retrieval, audit trails and safe diagnostics.

    TypeScript

  2. mcp-it-ops-server mcp-it-ops-server Public

    Safe, read-only MCP server for IT operations diagnostics and local knowledge retrieval.

    TypeScript

  3. cloud-ops-observability-lab cloud-ops-observability-lab Public

    Local-first OpenTelemetry observability lab that correlates metrics, traces, logs, alerts, SLOs and incident timelines.

    TypeScript

  4. identity-security-posture-dashboard identity-security-posture-dashboard Public

    Local-first Microsoft Entra identity security posture dashboard with fail-closed evidence scoring, human approval gates and audit trails.

    TypeScript

  5. internal-developer-platform-portal internal-developer-platform-portal Public

    Evidence-aware developer portal with service catalog, scorecards, golden paths, safe self-service plans, approval gates and audit trail.

    TypeScript

  6. secure-software-supply-chain-dashboard secure-software-supply-chain-dashboard Public

    Local-first DevSecOps dashboard for SBOM risk, SLSA provenance, attestations, policy gates and human-reviewed exceptions.

    TypeScript