Marc Bourrel · Freelance Cloud & SRE Architect · Toulouse, France & remote

Infra that holds up in prod.

Ten years on systems where mistakes are expensive: defence, healthcare, finance, real estate. I design, secure and run cloud platforms. And I build my own products, from the first line of code all the way to production.

Trusted with their production

  • Crédit Agricole ImmobilierTech Lead · ongoing
  • VIASANTÉ MutuelleHealthcare
  • Airbus Defence and SpaceDefence
  • FinzzleFintech
  • SQUAD ConseilIT consulting

What I fix

No catalogue, no buzzwords. Five areas where I work as a technical partner, accountable for the outcome from diagnosis to deployment. Every line comes with proof.

  1. Architecture & platforms

    Kubernetes when you need it, Docker Swarm when it's enough. Platforms sized for your real load, not for the sales deck.

    ProofAirbus Defence and Space: Kubernetes clusters and OpenStack tenants migrated, scaled and decommissioned with zero downtime.

    AKS · Tanzu · OpenStack · Helm · Docker

  2. Observability

    Knowing a service is down isn't enough. Knowing why, since when and what it hit, within minutes: that's what cuts time-to-diagnosis.

    ProofVIASANTÉ Mutuelle: Grafana, Prometheus and Loki stack, decision dashboards, NFS incidents caught before users noticed.

    Grafana · Prometheus · Loki · Graylog

  3. Security & resilience

    Hardening, secrets, identity, backups. Security treated as an architecture constraint, not a box ticked at the end.

    ProofFinzzle: RBAC, Network Policies and TLS on Tanzu, Azure CVEs closed before exploitation. VIASANTÉ: Keycloak and API gateway backups industrialised.

    Keycloak · Entra ID · RBAC · Key Vault

  4. CI/CD & infrastructure as code

    Reproducible pipelines and infrastructure described in code, so anyone on the team can ship with confidence, no manual steps.

    ProofAirbus: VMs, networks and storage provisioned with Terraform, Cloud-Init and Ansible, GitLab CI pipelines. Crédit Agricole Immobilier: GitOps with ArgoCD on AKS.

    Terraform · Ansible · GitLab CI · ArgoCD

  5. Sovereign AI

    Bring Claude, Gemini or a local model into your workflows without exposing your data: anonymisation, agents, integration with your systems.

    ProofTokenVeil, my product: 0% measured leakage across 3,340+ sensitive values, hosted on your own infrastructure.

    Claude API · Ollama · Presidio · spaCy

I don't just advise. I ship.

Two products designed, coded, secured and operated end to end, from idea to production. The best proof that I can run a whole platform, not just talk about one.

TokenVeil · enterprise licence · alpha

AI at work, without your data tagging along.

A self-hosted proxy between your teams and Claude, Gemini or OpenAI. Names, IPs, secrets and identifiers are swapped for tokens before the request leaves, then put back in the answer. The model never sees the real data.

Born on a client engagement: faced with AI, the only security answer companies had was to ban it. Teams used it anyway, on their personal accounts.

What the user types
Prod error for customer Sophie Marchand
(sophie.marchand@acme-corp.com)
server 10.42.8.17, here is the log:
apikey=sk-live-4f8a9c2e1b7d3c
What you type, then what the AI receives. The mapping stays encrypted on your server.
Measured leakage
0% across 3,340+ values, random-seed fuzzing, CI gate pinned at zero leaks
Providers
8: Claude, Gemini, OpenAI, Mistral, Azure OpenAI, Vertex AI, Bedrock, GitHub Models
Detection
Presidio, spaCy NER (FR/EN) and custom rules: IPs, IBANs, cards, API keys, JSON logs
Documents
Word, Excel, PDF, OCR for scans, export of a redacted copy
Enterprise
Self-hosted, multi-tenant LDAP / Active Directory, audit log without the data, Ed25519 licensing
TokenVeil interface: the preview sent to Claude replaces the customer name, email, internal IP and API key with tokens.
The anonymised preview updates live as you type.

Setlist · free music game · setlist.gg

The card game where every card is a real song.

Dig through record crates, complete albums, trade with friends, battle in blind tests. A side project that grew into a real game platform, built phone-first.

Same standards as client work: the economy is simulated before it's tuned, anti-cheat runs server-side, and every deploy goes through a backup and a health check.

Cover of A Night at the Opera, QueenLegendary
Bohemian RhapsodyQueen85991975
Cover of Thriller, Michael JacksonLegendary
ThrillerMichael Jackson88991982
Cover of Nevermind, NirvanaLegendary
Smells Like Teen SpiritNirvana91841991
Cover of Discovery, Daft PunkLegendary
One More TimeDaft Punk82902001
Cover of 8 Mile, EminemLegendary
Lose YourselfEminem91902002
Catalogue
13,500+ real tracks, growing every week, 5 rarity tiers
Rarity
Computed fame score: Last.fm, Wikipedia, Deezer and track longevity
Blind test
Server-side timing, anti-cheat, ELO ladder and a monthly Top 50
Social
Trades, auctions, crews, real-time messaging, 76 achievements
Cadence
66 releases shipped in three days, in French and English

It all runs here. At my place.

TokenVeil, Setlist, client sites and this page are served from a server I run like production: a single entry point, TLS everywhere, automatic updates. Snapshot taken on 29 September 2026.

  • One way in. All public traffic goes through the reverse proxy with automatic Let's Encrypt TLS; administration happens over a WireGuard tunnel.
  • Updates without me. Watchtower rolls out new images; product deploys go through backup, build and health check.
  • Isolation where it matters. Download traffic only leaves through a VPN tunnel with a kill switch; LLMs run locally.
Public code homelab-platform The packaged version of this setup: Traefik reverse proxy in Terraform, Ansible hardening (SSH, fail2ban, ufw), Prometheus, Loki, Grafana, validation CI on every push. View on GitHub

From cable to cluster

Ten years through every layer: support, networks, systems, Kubernetes, cloud. That's what lets me chase an incident without stopping at the edge of my scope.

  1. Aug 2026 → now

    Crédit Agricole Immobilier

    Tech Lead DevOps, IT development division · via Joopin's Lab

    Integrating a vendor SaaS into the information system, level-3 run on AKS, .NET and Java, GitOps with ArgoCD, Keycloak and Entra ID identity, coordination between infra, security and vendor.

  2. Dec 2025 → now

    Joopin's Lab

    Founder

    Architecture and DevOps engagements, in-house products: TokenVeil (enterprise licence) and Setlist.

  3. Jan 2026 → Jun 2026

    VIASANTÉ Mutuelle

    IT expert & DevOps engineer

    Multi-environment Docker Swarm platform stabilised, end-to-end observability, critical backups industrialised, secrets and pipelines hardened.

  4. May 2025 → Sep 2025

    Airbus Defence and Space

    Cloud & DevOps engineer · via SQUAD Conseil

    OpenStack tenants and production Kubernetes clusters, infrastructure in Terraform and Ansible, GitLab CI pipelines, Artifactory lifecycle.

  5. Nov 2023 → May 2025

    Finzzle

    Network & systems administrator

    Kubernetes clusters on VMware Tanzu, Azure infrastructure in Terraform, CVE remediation, availability and deployment KPIs.

  6. 2020 → 2023

    SQUAD Conseil

    Network engineer, then project manager

    Secured Stormshield and Cisco networks, 300+ managed devices, Azure AD and Intune, server room move with zero downtime.

  7. 2016 → 2020

    Telespazio France · OKTAL · STUDEC

    ICT administration, networks, support

Toolbox

What I use on engagements and in production, not a keyword list.

Orchestration
Kubernetes (AKS, Tanzu), OpenStack, Docker, Docker Swarm, Helm
Cloud
Azure: AKS, Key Vault, Entra ID, Intune, Security Center, Azure DevOps
IaC & CI/CD
Terraform, Ansible, Cloud-Init, GitLab CI, GitHub Actions, ArgoCD, Artifactory
Observability
Grafana, Prometheus, Loki, Graylog, Uptime Kuma
Security & network
Keycloak, RBAC, Network Policies, TLS, WireGuard, Nginx, Traefik, Stormshield, Cisco
Data
PostgreSQL, MongoDB, Elasticsearch, Oracle, SQLite
Code
Python, Bash, TypeScript, .NET, Java, FastAPI, SvelteKit
AI
Claude API, Ollama, Presidio, spaCy, Playwright

Let's talk about your platform.

Scaling, securing, bringing order to an environment that grew too fast, or bringing AI in without exposing your data. Based in Toulouse, France, working remotely anywhere. Reply within 24 hours, in English or French.