Independent Engineering · Alsfeld, Germany

Complex systems.Clearly under control.

I design secure identity, mail and platform services — from architecture and code to dependable operations.

System landscape connecting
01Identity
02Policy
03Mail
04DNS
05Observability
status unknownpublic service checks
Independent since
2002
Focus
Go & Open Standards
Principle
Secure · Observable · Operable

Expertise

Security is never a property of just one component.

It emerges from protocols, identities, data flows and operations that make deviations visible.

01

Identity & Access

OIDC, SAML, MFA, passkeys, LDAP and policy engines for explainable authentication and authorisation.

  • OIDC
  • SAML
  • WebAuthn
  • LDAP
02

Secure Mail

Mail infrastructure built on Postfix, Dovecot and Rspamd, secured with DKIM, DANE, MTA-STS and TLSRPT.

  • SMTP
  • DKIM
  • DANE
  • TLSRPT
03

Reliable Platforms

Container and Kubernetes platforms whose rollouts, dependencies and failure states remain verifiable.

  • Kubernetes
  • Containers
  • GitOps
  • HA
04

Observability

Metrics, logs and traces as part of the architecture — for sound conclusions instead of assumptions.

  • Prometheus
  • Grafana
  • OpenTelemetry
  • Zabbix

Selected open-source projects

Tools shaped by real operational problems.

Each project combines protocol fidelity, secure defaults and a clear path into production.

Approach

A system is not finished until its behaviour can be proven.

  1. 01
    Understand

    Start with the real data flow

    Configuration, source and runtime are examined together. The visible symptom is rarely the complete cause.

  2. 02
    Design

    Make secure states structural

    Fail-closed behaviour, clear ownership and verifiable transitions are design properties.

  3. 03
    Prove

    Evidence before confidence

    Tests, metrics, traces and readbacks show whether a change really works where it is supposed to.

  4. 04
    Operate

    Treat operations as a product property

    Monitoring, rollback and understandable runbooks belong to the solution, not to a later backlog.

Perspectives

What matters in security-critical systems.

01

Identity is a runtime system, not a login form.

Trust emerges from protocols, key material, policies and observable decisions — never from the interface alone.

02

Mail security does not end at ‘DKIM=pass’.

Transport encryption, DNS trust, key lifecycles and deliverability have to work as one connected chain.

03

A green rollout is more than a replica count.

Image identity, restarts, endpoints, metrics and relevant failure paths determine whether the new state is dependable.

About

Christian Rößner

Computer scientist, open-source developer and independent system engineer, particularly interested in the difficult boundaries between protocols, software and operations.

Since 2002, I have worked with companies and public-sector organisations on demanding infrastructure and software projects. I focus on the areas where standard recipes fall short: distributed failures, security-critical identities, mail protocols and systems that must remain explainable under real production conditions.

Based in
Alsfeld, Germany
Education
B.Sc. Computer Science
Languages
German · English
Development
Go · Lua · TypeScript

Contact

Do you have a system that needs to be understood more precisely?

Send me a short note with the context, your goal and the point where the system is currently not dependable enough.