Building Autonomous AI Infrastructure for LATAM -- DevSecOps · Agentic AI · Platform Engineering · GovTech
I build autonomous AI systems that keep running when I am not looking. As a solo engineer, I designed an AI operating environment where deterministic scripts handle the repetitive work, persistent memory keeps every session context-aware, and a model only steps in when judgement is required. Security is designed in from the start -- traceability, human veto gates, and no data egress by default.
The result is a single-engineer platform that spans threat intelligence (MISP, OpenCTI, STIX/TAXII), identity and access (MFA, SSO), GovTech procurement tooling, and offline LLM runtimes that run entirely on local hardware.
| Focus | Capability |
|---|---|
| Agentic Engineering | Autonomous agent frameworks with deterministic-first orchestration and human veto gates |
| Security & Identity | MFA with privacyIDEA + FreeRADIUS + OpenLDAP + Authentik SSO, SHA256 evidence traceability, sandboxed DevSecOps tooling |
| Threat Intelligence | MISP + OpenCTI lifecycle management, STIX/TAXII interoperability, automated SOC reporting pipelines |
| GovTech | Guatecompras intelligence, OCDS-compliant procurement tooling, Cloudflare-native delivery |
| Offline AI | Portable LLM runtimes, GGUF quantization, local-first agent workspaces with zero data egress |
| Focus | Status |
|---|---|
| AI knowledge packs | Turning technical books into queryable skills -- 528K tokens indexed, zero-token extraction |
| Autonomous ecosystem | 49 skills, 14 deterministic scripts, 10 MCP servers operating as one system |
| Threat intelligence | MISP + OpenCTI lifecycle tooling for security operations at scale |
An autonomous AI operating environment I engineered on Ubuntu 24.04 -- designed to maximize autonomy while minimizing token spend.
| Component | Count | Status |
|---|---|---|
| Deterministic Scripts | 22 | Active |
| Custom Skills | 27 | Active |
| Agent Skills | 22 | Active |
| MCP Servers | 10 | Active |
Decision framework: every project traces to a central criteria (problem -> mission -> goal), so nothing runs without purpose.
Persistent memory: cross-session knowledge base -- past decisions guide future work, eliminating re-exploration.
Book-to-skill: technical books become queryable knowledge packs with zero-token extraction.
Daily radar: automated collection and scoring of opportunities; the model runs only when judgement adds value.
Architecture: Cron -> Scripts -> Files -> OpenCode reads -> Agent responds.
Patterns that recur across every system in the ecosystem:
| Pattern | Description |
|---|---|
| Pipeline | Source -> Process -> Render -> Deliver |
| Two-Tier Generator | Generator produces deployable harnesses |
| Serverless Desktop | Zero-DB, encrypted local JSON |
| Multi-Backend Render | Local GPU + cloud API abstraction |
| Dual-Repo Governance | Public showcase + private mirror |
| Domain | Tools |
|---|---|
| Security & Identity | MFA · privacyIDEA · FreeRADIUS · OpenLDAP · Authentik SSO · Wazuh · Burp · Nessus · SonarQube · Fernet · PBKDF2 |
| Threat Intelligence | MISP · OpenCTI · TAXII · STIX · Threat Feeds · SOC Reporting |
| AI/LLM | Groq · OpenRouter · Gemini · ComfyUI · Replicate · llama.cpp · GGUF · Ollama |
| Infra | Docker · Apache · Nginx · MySQL · PostgreSQL · Redis · Nextcloud · Odoo · Vaultwarden · n8n · Cloudflare Workers |
| DevSecOps | CustomTkinter · PyInstaller · Azure DevOps · Jira · ServiceNow · SharePoint Graph · SHA256 Traceability |
| GovTech | VS Code Extension · Cloudflare Pages · OCDS · Guatecompras · AWS SES |
| Stack | Python 3.12+ · TypeScript · Bash · FastAPI · Pydantic · Pandas · httpx · Uvicorn · PyInstaller |
Guatemala City. Budget limits -> encrypted local configs. Remote support -> deterministic generation. Compliance -> SHA256 traceability. Every architecture carries a default answer to "what happens when resources are tight?"
Auto-generated · Last sync: 2026-08-19 06:00 UTC
