Val Kafedzhy
AI Infrastructure Security Architect · enterprise platforms, networks and cloud
Washington, D.C. · 20+ years. I design and secure the platforms AI runs on, at scale: identity, keys, networks, and the controls an auditor signs off on. Firewalls and zero trust, cryptography and PKI, eBPF and the Linux kernel, DNS, email and SMTP, Kubernetes, and multi-region networking across AWS, Google Cloud and Azure. I write it up here: reference architectures with working configs and honest trade-offs, down to the failure modes that actually bite in production. Not vendor slideware.
Certified: CKA · CKAD · CKS · AWS Solutions Architect (Professional) · Google Professional Cloud Architect · Cisco CCNP · RHCE
Start here
The flagship pieces. Each ships with a working reference config or policy, not just prose.
BGP for the AI Era
Multi-region routing for inference: anycast + BGP that fails over on real inference SLOs, not process liveness. Ships with a working FRR config and health agent.
eBPF in Production
Kernel-level observability and security without sidecars, with runnable Tetragon and Cilium samples on GitHub.
Zero Trust, Beyond the Buzzword
A vendor-neutral reference architecture: PDP/PEP, SPIFFE identity, and a real Cilium policy for production.
Focus areas
Networking & Routing
BGP, enterprise routing, IPv6, high-performance networking, multi-region connectivity.
Cloud & Platform Networking
Cloud networking, service meshes, and eBPF-native data planes.
Zero Trust & Platform Security
Zero Trust networking and enterprise platform security architecture.
AI Infrastructure Networking
The networking layer under AI training and inference at scale.
Systems & Ops Notes
Field notes from 20+ years across Linux, DevOps, SRE, and encryption.