Paris, France | kanmegneandre@gmail.com | linkedin.com/in/laurel-kanmegne-2a861425a/ | github.com/AndreLiar
Platform & AI Engineer with a Bac+5 RNCP Level 7 — designing and operating production systems that are secure, observable, AI-native, and compliance-ready. Author of the minicloud platform: a 90-phase enterprise Kubernetes project simulating the complete IS of a B2B insurance company — 54+ active workloads, OPA Gatekeeper zero-trust, full AI governance stack (LiteLLM + vLLM + Qdrant RAG + Langfuse + minicloud-crew-agent), ERPNext with French PCG 2025 + TSCA + Factur-X, and a ToyotaGPT-inspired agent factory architecture. Currently an IT Automation Engineer Apprentice at HDI Global SE France, applying the same engineering rigour to real enterprise workflows.
State-recognised Bac+5 (RNCP Level 7) covering fullstack development, DevOps, cloud infrastructure, software architecture, and enterprise systems. Core modules: React, Node.js, Next.js, Docker, Kubernetes, GitHub Actions, Azure, Software Architecture, Agile/Scrum, AI & Data Science, Application Security.
Production-grade enterprise Kubernetes platform on a self-hosted cluster simulating the complete information system of a B2B French insurance company (ktayl solution). 90+ delivery phases, 54+ active workloads across 15 IS domains: policy management, claims, underwriting, ERP/finance, AI governance, communication, document management, compliance (ACPR/DORA), and workplace AI (minicloud Copilot). GitOps-delivered via ArgoCD app-of-apps, hardened with zero-trust NetworkPolicy, OPA Gatekeeper deny-mode admission control, and full supply-chain security.
Technologies: k3s (Kubernetes, 5 nodes), ArgoCD (app-of-apps), Helm / Kustomize, HashiCorp Vault + ESO, Authentik (OIDC/SSO), OPA Gatekeeper + Falco, Cilium eBPF + Hubble, Prometheus / Grafana / Loki / Tempo, LiteLLM (AI Gateway), vLLM (on-cluster inference), Qdrant (vector DB), minicloud-crew-agent (LangGraph), minicloud-agent (ReAct), Flowise + MLflow, Langfuse (LLMOps), ERPNext (French PCG 2025 + TSCA + Factur-X), Temporal (workflow orchestration), n8n (business automation), Stalwart mail + Matrix + Jitsi, Nextcloud + OnlyOffice, Backstage (IDP), Harbor, Longhorn + Velero + MinIO, NATS JetStream / KEDA, Ansible / OpenTofu / MAAS, Tailscale + Cloudflare Tunnel
Domain-restricted AI financial assistant with a production PromptOps architecture. Built a LiteLLM CustomLogger (LangfusePromptHandler) that fetches the active production-labelled prompt from Langfuse at request time with 5-minute in-process cache and a three-layer fail-open chain — enabling instant prompt rollbacks without code deploys or image rebuilds. Includes a 25-case CI eval suite enforcing 100% pass rate as a deployment gate.
Technologies: Groq llama-3.1-8b-instant (primary), Ollama phi4-mini ×3 (fallback), LiteLLM (routing + CustomLogger), Langfuse (Prompt Management + Tracing), Python, GitHub Actions (Eval CI), Kubernetes (k3s), Presidio (PII/DLP guardrail), Valkey (prompt cache)
Built a full multilingual RAG pipeline for French insurance document retrieval across three custom-built repos. minicloud-markitdown-proxy (FastAPI): routes documents by type — PDF/images to Docling OCR, Office/HTML to MarkItDown in-pod — exposing a Docling-compatible API surface. minicloud-rag-ingest (FastAPI): full ingestion pipeline in one HTTP endpoint — convert → structure-aware heading chunk (French insurance regex) → bge-m3 1024-dim embed → pgvector HNSW INSERT. minicloud-postgresql-noavx512: custom PostgreSQL image with pgvector's vector.so rebuilt without -mavx512f/bw/vl/dq to fix a SIGILL crash on i7-8565U/i7-10510U CPUs caused by AVX-512 EVEX instructions in pgvector 0.8.4. Hybrid search layer: BM25 with French Snowball stemmer + NLTK stop-words injected via init container patching rank_bm25/utils.py at pod start. Cross-encoder re-ranking (ms-marco-MiniLM-L-6-v2) filters to top-3.
Technologies: Python, FastAPI, PostgreSQL + pgvector (custom noavx512 build, C / Makefile), bge-m3 (Ollama), Docling (OCR/PDF), MarkItDown, rank_bm25 + NLTK (French BM25), ms-marco-MiniLM-L-6-v2 (cross-encoder), Docker, GitHub Actions, cosign, Kubernetes init containers
Multi-provider LLM routing and enterprise governance platform built on LiteLLM on Kubernetes. Unified 8 cloud and local providers (Groq, OpenAI, Gemini, DeepSeek, Mistral, Anthropic Claude, HuggingFace featherless-ai via router.huggingface.co, and local Ollama) behind a single API endpoint with intelligent fallback routing (Ollama→Groq→DeepSeek), Presidio PII/DLP scrubbing, 3-tier department key governance with per-dept budget caps and model allowlists, circuit breaker protection, Valkey prompt cache, and full Langfuse LLMOps tracing. Cost visibility delivered via a Grafana dashboard reading LiteLLM's PostgreSQL usage tables. Includes Langfuse v3.201.1 with ClickHouse analytics backend and Authentik OIDC SSO, plus an NVIDIA NIM tier (nemotron-70b, llama-8b, deepseek-r1).
Technologies: LiteLLM (AI Gateway), Presidio (PII/DLP), Valkey (prompt cache), Langfuse v3.201.1 (LLMOps), ClickHouse (Langfuse analytics), Grafana (cost dashboard), PostgreSQL (usage data), Ollama (local inference), Python, Kubernetes (k3s), Authentik (OIDC/SSO), GitHub Actions
Deployed Open WebUI as a production enterprise AI chat interface serving 16 business departments through Authentik OIDC SSO. Connects the full AI backend stack — LiteLLM AI Gateway (8 providers), RAG pipeline (French insurance knowledge base), and SearXNG real-time web search — into a single product accessible to non-technical business users. phi3-financial serves as the default model for finance analysts, domain-restricted and prompt-governed at runtime via Langfuse. Conversation history and user management backed by PostgreSQL for production-grade persistence.
Technologies: Open WebUI, Authentik (OIDC/SSO), LiteLLM (AI Gateway), Ollama (local model serving), SearXNG (web search), PostgreSQL (persistence), pgvector + bge-m3 (RAG), Langfuse (prompt management), Kubernetes (k3s), Helm
Production-hardened Internal Developer Portal built on Backstage 1.52, deployed on a self-hosted Kubernetes cluster with GitOps delivery, Authentik OIDC SSO, Software Templates, TechDocs, and a custom Plane Issues plugin.
Technologies: Backstage 1.52, TypeScript, React, Node.js, ArgoCD, Authentik OIDC, Harbor, Cosign (keyless), Trivy, syft (SBOM), PostgreSQL, k3s, Tailscale, mkdocs-techdocs-core, Plane CE
AI in Education, Music, Football, Travel, Tech Trend