Skip to content
Théophile Diot.
Navigation menu

Software engineer / open-source systems

ThéophileDiot

I make open-source infrastructure operable.

I maintain BunkerWeb and build the systems around it, from releases and constrained automation to private platform operations.

01Active file2021-present

BunkerWeb

Maintain BunkerWeb across code, releases, and documentation. BunkerWeb is a cloud-native web application firewall (WAF) that connects protection to operators, deployment environments, public documentation, and Model Context Protocol (MCP) automation clients.

The public BunkerWeb ecosystem
Conceptual map based on public project capabilities. It is not a deployment topology.
10,990GitHub starsGitHub snapshot, 2026-09-22
AGPLOpen-source licenseAGPL-3.0
4Documented environmentsLinux, Docker, Swarm, Kubernetes
BunkerWeb stars snapshot dated 2026-09-22. Other figures come from public project sources.
02

Work

Evidence
022025-presentOpen source authoring

BunkerWeb MCP

A Python Model Context Protocol (MCP) server that exposes the BunkerWeb API through constrained tools and resources.

Role
Author and maintainer
Contribution
Built the Python server and its constrained API surface.
43Built-in API toolsPublic repository, 2026-08-19
3Transportsstdio, HTTP, WebSocket
042026-presentSelf-hosted observability

AI CLI Observability

One local OpenTelemetry stack for comparing usage, latency, failures, tool activity, traces, and estimated cost across three AI coding command-line interfaces (CLIs).

Role
Author and operator
Contribution
Built the OpenTelemetry Protocol (OTLP) path, storage routing, and provisioned dashboard.
3AI CLI integrationsCodex, Claude Code, Gemini CLI
3Telemetry signalsLogs, metrics, traces
052026-presentLinux product adaptation

Claude Usage Tracker for Linux

An unofficial Linux port that joins a GNOME usage monitor, native preferences, notifications, history, and a configurable Claude Code statusline.

Role
Linux adaptation author and maintainer
Contribution
Ported the tracker to Linux with a GNOME panel and terminal statusline.
24hLocal usage chartBacked by seven days of percentage samples
3Focused test suitesUsage, statusline, and settings projection
062026-presentInfrastructure engineering

Private platform engineering

A four-host private platform run as code, with 69 in-scope Compose stacks, bounded automation, observability, and tested configuration invariants.

Role
Owner and operator
Contribution
Designed and operate the private platform described here.
91Services under managementDefined across 69 Compose stacks; 22 project stacks excluded
83/83Images digest-pinnedVersion and manifest digest, no :latest
03

How I work

Secure before configured

Defaults should be defensible before an operator touches them.

Documentation is product work

A reliable answer should survive the issue thread where it began.

Reversible by design

A change is incomplete until its way back is understood and tested.

Proof at the running edge

Rendered configuration matters. Running state decides.

Looking for a collaborator?

Bring a collaboration or infrastructure project.