Postiz

I run the security and infrastructure behind an open-source platform.

Postiz is an open-source social media scheduler. I'm its Chief Operations & Security Officer, which in practice means I run the CVE programme, the release pipeline, the monitoring and the support desk. On the side I build GHub.

#2
Contributor rank, Postiz core
405
Commits to the Postiz core
33
Advisories on the public record
1,201
Commits across these repositories
15
CVE identifiers assigned

Every figure here is read from the system that owns it. Checked 15 minutes ago. How they are counted

The job

What the job actually is

A C-level title here isn't about handing work to other people. The work is mine.

It covers security engineering and vulnerability research, trust and abuse, support and community, CI/CD, monitoring, CNA operations, and hiring.

I'm also the second-largest contributor to the core codebase, at 405 commits. My background is DevSecOps and platform engineering, and I still spend most of the week in code.

What that has produced

33 published advisories and 15 CVEs across the two programmes, three of them critical, the highest scoring 10.0.

The largest cluster is server-side request forgery, eight advisories deep. That is not an accident of the codebase. A social scheduler exists to fetch and post things on your behalf, so making outbound requests to attacker-influenced URLs is its job description rather than a mistake in it. Bug classes that come from a product's shape have to be treated structurally, not one endpoint at a time.

One rule for everything I build

If the API can do it, the UI has to do it too.

I've seen too many tools ship a feature behind an undocumented endpoint and call it done. Anything only a maintainer can drive isn't finished. It costs more up front. I've never regretted it.

Capabilities

What I actually run

Grouped by discipline instead of a wall of logos. These run in production. Things I tried once aren't on the list.

Security
CVE / CNA operations CVSS 3.1 & 4.0 CWE CVE JSON 5.1 GHSA OSV / osv.dev Coordinated disclosure
Identity & secrets
HashiCorp Vault · Raft, PKI, ACME Authentik · self-hosted OIDC OpenID Connect
Platform
Proxmox · four-node cluster Ansible Docker Kubernetes Nginx Linux VLAN segmentation
Orchestration
Temporal Jenkins CI/CD pipelines BullMQ · Redis-backed queues Turborepo · pnpm workspaces GitHub Actions GitLab CI
Monitoring
Sentry Prometheus · custom exporters Grafana
Backend
Node.js NestJS TypeScript Python Bash Fastify Express gRPC · Protobuf, typed clients
Data
PostgreSQL MySQL / MariaDB Redis MongoDB InfluxDB SQLite Prisma Drizzle ORM TimescaleDB · time-series over Postgres Meilisearch MinIO / S3-compatible storage
Frontend
React Next.js JavaScript HTML & CSS Figma Tailwind CSS tRPC
Testing
Vitest Jest Playwright · deploy-gating smoke suites

Need a second opinion on something?

Security review, setting up a CVE programme, platform work, or an architecture you are not sure about. Email is fastest.