Jeff Hulford
Systems & platform engineering Chicago

Jeff Hulford.
From the kernel up.

I build delivery platforms, operating systems, and tools that help engineers understand the systems they run.

Enterprise infrastructure is my day job. Independent systems projects are where I explore the rest of the stack.

Approach /

Build it. Understand it. Keep it running.

I care about what happens after the first successful demo: how a system fails, how someone diagnoses it, and whether the next engineer can safely change it.

The work below connects those questions across enterprise infrastructure and independent projects. The notes include the decisions, tests, and unfinished parts.

01 / Professional work

Less friction. More repeatable work.

Representative, anonymized work from enterprise engineering environments.

Delivery Platform

Git migration and CI/CD modernization

Moved an engineering organization to a new Git organization and GitHub Actions delivery model, then connected Vault JWT authentication, artifact storage, and certificate automation. The durable result was one repeatable path from source to deployment instead of a collection of manual handoffs.

100%
Codebase migrated
40+
Processes automated
Vault
JWT-based secrets
Developer Experience

Engineering dashboard with codebase search

Replaced a legacy Windows Forms workflow with a WPF engineering console for build monitoring, deployment tracking, and documentation search. A retrieval-backed assistant made a large codebase searchable in natural language without displacing the operational controls engineers relied on.

RAG
Codebase discovery
WPF
Workflow modernized
1
Operational console
02 / Independent systems

A little further down the stack.

Operating systems, shared services, and applications. Different problems; the same interest in how the pieces actually work. Smaller experiments live in Side Quests.

AI/ML · Platform

JefeAI

In use

A local inference and retrieval platform that gives multiple applications one governed path to models. It combines RAG collections, backend routing with explicit timeouts and fallbacks, experiment tracking, and evaluation tooling so model behavior can be measured instead of guessed.

PythonOllamavLLMChromaDBMLflow
Security · Automation

Sentinel

In use

An automated security-review pipeline built around grounded evidence. Deterministic scans from Semgrep, Trivy, grype, pip-audit, and npm-audit feed structured triage; experimental model-driven sweeps remain separate and require verification. The design choice is to make repeatable findings the operational path instead of treating model output as proof.

PythonSemgrepTrivyCI/CD
Security · Secrets Management

JefeVault

In active use

A service-oriented secrets broker with scoped service tokens, operator handoff tokens, encrypted storage, rotation and version workflows, policy reporting, and guarded deployment and rollback paths. The emphasis is less on a feature checklist than on making secret handling explicit and reviewable.

TypeScriptAES-256-GCMToken AuthAudit
AI · Interactive Fiction

Adventure GUI

Private alpha

A tabletop campaign application with persistent world state, an AI Lore Master workflow, and optional narration and generated scene art. It is also a practical test of where probabilistic generation belongs in a product and where ordinary application state must stay authoritative.

PythonFastAPIComfyUITTS
03 / Underneath the projects

The infrastructure they share.

The systems above are products and workloads. Underneath them is a smaller, deliberately conventional infrastructure layer that handles compute, source, delivery, routing, and evidence. That separation lets product experiments move quickly without turning every service into platform infrastructure, while shared operational concerns stay observable and replaceable.

Titan
Ubuntu · GPU compute
JefeGit (Forgejo)
Source control and review
CI/CD (Jenkins)
Build, test, and deployment jobs
Monitoring
Metrics, dashboards, and alerts
Service Edge
Routing and public ingress
Data Services
Relational storage and caching

Operate: Linux, Docker, CI/CD, observability, routing, identity, secrets, and recovery.

Build: C++ and Rust systems; Python and TypeScript services; React, FastAPI, and Express applications.

04 / Engineering notes

What changed. What I learned.

Evidence-backed notes from ongoing engineering work, including the decisions, regressions, and validation behind the finished screenshots.

Ask the portfolio assistant optional · retrieval-backed

A small interface to the same professional background summarized above. It is here as a convenience, not as the main event.

assistantJefeAI + retrieval
[assistant] Ask about Jeff's experience, systems, or engineering decisions.

Prompts are sent to the JefeAI backend and may be logged. Do not submit sensitive data. Chat history is kept only in this open page.

Get in touch /

Have a systems problem in mind?

For engineering roles, platform work, or a conversation about something you read here.