Ping Pong
A classic pong-style game built in Unreal Engine to learn 2D input, ball physics and UI.
I architect identity & access management solutions and build scalable web applications with Java, React, SQL, NoSQL, and Elasticsearch.
What I'm building now and what's next — across identity & access management consulting, indie software engineering and solo game development.
A classic pong-style game built in Unreal Engine to learn 2D input, ball physics and UI.
An arcade-style road crossing game in Unreal Engine featuring grid-based movement, obstacles, collectibles and a scoring system.
A CodeCrafters challenge solution: an HTTP/1.1 server built from scratch in Java with request parsing, routing, persistent connections, gzip compression and file read/write endpoints.
The same CodeCrafters HTTP/1.1 server challenge implemented in JavaScript (Node.js): request parsing, routing, keep-alive connections, gzip compression and file endpoints.
This site. A personal portfolio built with Next.js, TypeScript and Tailwind CSS, covering my IAM and full-stack work along with this roadmap.
A game development portfolio for Solaras Light.
A turn-based missile duel built with libGDX. Each turn both sides place a missile launcher and a flare dispenser, then fire at once, and the enemy learns your habits. Runs on desktop, in the browser and on Android.
A modern IBM i (AS/400) 5250 terminal emulator built from scratch in Java 17. The protocol engine (Telnet negotiation, 5250 data stream parsing, EBCDIC conversion) is fully independent of the UI, with two front ends on top: a JavaFX desktop client and a Spring Boot browser client.
A fully spec-compliant Authorization Server in Spring Boot, built without the Spring Authorization Server abstraction so that every grant type and token behavior is implemented by hand.
An endless driving game with a cyber style, built with Unreal Engine and targeting Android.
A Java mailing framework to manage sending mail from Java applications.
One Keycloak authorization server in front of three independently written resource servers — Spring Boot (Java), FastAPI (Python) and Express.js (Node) — each enforcing the same JWT validation and RBAC rules through its own idiomatic security stack.
Migrates thousands of users from an old database or a legacy Okta instance into Keycloak using a lazy (just-in-time) migration strategy, so users see no service disruption or forced password resets on day one.
A not-so-simple grid library.
Federates three identity sources — Okta (corporate employees), a SAML 2.0 IdP and Google (customer/social login) — behind one Keycloak realm, with a Spring Boot API that normalizes every provider's claims into one internal identity shape. Covers the simpler two-IdP Okta + Keycloak employee/customer bridge as a base case along the way.
Manages identity configuration entirely as code, so Dev, Staging and Prod environments deploy deterministically without manual changes in the admin UI.
A racing game in the spirit of SkyRoads and Nitronic Rush.
Secures an ecosystem of Spring Boot microservices with the Backend-for-Frontend (BFF) pattern, keeping raw JWT access tokens out of browser storage to minimize security vulnerabilities.
Implements the OAuth 2.0 Device Authorization Flow and PKCE natively inside Unreal Engine 5, Unity and Godot, all authenticated against a real Keycloak server.