π Based in Hamburg, Germany π©πͺ Β· working remotely
I'm a software engineer at Red Hat and a Python core developer, with more than 25 years of open-source experience. My work centers on Python packaging and build systems, security and cryptography, and AI/ML infrastructure, grounded in a long track record in the CPython standard library. Earlier in my career I built identity- and secrets-management systems and contributed to the Zope and Plone web platforms. My current focus is building infrastructure for Red Hat's AI platform.
- π€ I currently build infrastructure for Red Hat's AI platform β packaging and distributing Python and ML software across CPU, GPU, and AI-accelerator targets.
- π¦ I have long-standing expertise in Python packaging and build systems, and I publish agent-skills to share that knowledge with other engineers.
- π CPython core developer since 2007; former maintainer of the
sslandhashlibmodules and author of several security-focused PEPs. - π PSF Fellow since 2008; emeritus member of the Python Security Response Team and the PSF Diversity & Inclusion Working Group.
- π Creator and maintainer of defusedxml, a library that hardens Python's XML parsers against bomb and XXE attacks.
- π© Earlier at Red Hat, I worked across the identity stack β FreeIPA / RHEL IdM, Custodia, and python-ldap β and spent time as a Core Maintainer of InstructLab.
- π§ A Linux user since 1997 and a Python programmer since 2001.
| Area | Projects & Topics |
|---|---|
| π€ Red Hat AI | AI/ML build & distribution infrastructure, RHAI container images, accelerator wheel builds (CUDA/ROCm/Spyre), WheelNext |
| π¦ Python packaging | Wheel-build tooling (fromager), build backends, packaging utilities, agent skills |
| π Python & open source | CPython core development, PSF Fellow, defusedxml, PEP authorship |
| π Security & cryptography | CPython ssl/hashlib, OpenSSL, FIPS & system crypto-policies, pyca/cryptography |
| π© Identity management | FreeIPA / RHEL IdM, Custodia, python-ldap, Dogtag PKI |
| π°οΈ Earlier career | Zope & Plone, Plone Foundation board |
As Staff & Senior Principal Software Engineer for Red Hat's AI Platform Ecosystem, I build the infrastructure that packages and distributes Python and ML software with optimized builds across accelerator targets β CPU, NVIDIA CUDA, AMD ROCm, and IBM Spyre β published at packages.redhat.com. I also build the Red Hat AI (RHAI) container images used across Red Hat's AI products, including Red Hat AI Inference (vLLM).
The wheel-building toolchain behind this is open source. fromager is the foundation β a build-from-source wheel maker β supported by packaging and binary-analysis tools I work on: elfdeps (ELF shared-library dependency analysis), retread (compares downstream wheel rebuilds against upstream to catch differences), zipwire (reads files from remote ZIP archives over HTTP range requests), and torch-abi-audit (audits extensions for PyTorch and CPython stable-ABI compliance).
I'm Red Hat's liaison to WheelNext, the cross-industry effort to evolve the Python wheel format β in particular wheel variants (PEP 825) for hardware-specific builds.
Earlier I was a Core Maintainer of InstructLab, which uses Large-Scale Alignment for ChatBots (LAB) β an alignment tuning method for LLMs that leverages synthetic data β to train a model using custom taxonomy data. There I worked on hardware enablement (Intel Gaudi, CUDA, Apple MLX) and build, test, and packaging infrastructure. The project has since been refactored, with its core building blocks (synthetic data generation and training) moving into separate successor projects.
I have deep, long-standing expertise in Python packaging β build backends, the wheel format, PEP-based packaging standards, and the tooling around building and distributing packages (several of my packaging and binary-analysis tools are listed in the Red Hat AI section above). I also publish agent-skills, a collection of portable, agent-neutral "skills" and playbooks for Python and packaging tasks. Each skill is dual-purpose: a guide an engineer can read directly, and a structured instruction set an AI coding assistant (such as Claude Code or Codex) can load to carry out a specialized task β covering areas like build-backend selection, FIPS/crypto audits, type-stub generation, and secure release pipelines. Together they distill two decades of Python experience into reusable references for both people and agents.
I joined the CPython core team in late 2007 and have contributed close to 700 pull
requests over the years (among the most active contributors by commit count). For
much of that time I maintained the ssl and hashlib modules β including
porting them across the OpenSSL 1.1 and 3.0 API transitions β and served on the
Python Security Response Team (PSRT). My work also spans the wider standard
library, project governance, and CPython's WebAssembly port (the WASI and
Emscripten build targets).
PEPs I authored as sole creator:
- PEP 370 β Per-user
site-packagesdirectory, the mechanism behindpip install --user. - PEP 456 β Secure and interchangeable hash algorithm (SipHash, now CPython's default string-hash algorithm).
- PEP 644 β Require OpenSSL 1.1.1 or newer.
I also co-authored:
- PEP 452 β the cryptographic hash-function API. (co-author)
- PEP 543 β a unified TLS API. (co-author)
- PEP 594 β "removing dead batteries." (co-author)
I created and maintain defusedxml, which provides drop-in replacements for
Python's XML parsers that defend against entity-expansion ("billion laughs"),
external-entity (XXE), and DTD-retrieval attacks. For roughly a decade I also
maintained CPython's ssl and hashlib modules β moving hostname verification
onto OpenSSL's native checks, bringing up TLS 1.3 support, making SSLContext
secure by default, and porting both modules through successive OpenSSL API
transitions. I implemented the usedforsecurity mechanism and a C-based HMAC so
Python behaves correctly under FIPS-mode OpenSSL, contributed fixes upstream to
OpenSSL itself, and wrote the FIPS-mode
algorithm restrictions in
pyca/cryptography. My CPython
--with-ssl-default-suites=openssl build option
is what lets Fedora/RHEL's system-wide crypto-policies apply to Python's ssl
connections.
Much of my earlier work at Red Hat was across the identity-management stack.
FreeIPA (shipped as Red Hat Identity Management, RHEL IdM) is an open-source
identity-management system, largely written in Python, that integrates an LDAP
directory (389 Directory Server), Kerberos (MIT krb5), a certificate authority
(Dogtag PKI), and DNS into a single managed security domain. In FreeIPA I designed
and implemented four features β Member Manager, Hidden Replicas, LDAPI Autobind,
and Subordinate IDs (the last relevant to Podman and rootless containers) β each
with a published design document on
freeipa.readthedocs.io. I co-maintained
Custodia, a secrets-management service
for cloud applications, together with its founder Simo Sorce. I also contributed to
python-ldap as an upstream collaborator, including its modernization to the
stable abi3 ABI and a number of memory-leak and security fixes.
I've spoken at Python and open-source conferences for well over a decade, including
PyCon US, EuroPython, PyCon DE, PyCon UK, and DevConf (Czechia and India). Topics have
ranged from TLS/PKI and Python's ssl module to security engineering, WebAssembly,
and open-source AI. Keynotes include:
- DevConf.IN 2018 (Bengaluru, India) β "Everyday Security Issues and How to Avoid Them," the keynote at the first-ever DevConf India.
- PyCon DE 2022 (Berlin) β "Python 3.11 in the Web Browser β A Journey," on CPython's WebAssembly port.
Slides for many of my talks are on SpeakerDeck.
Zope is one of the original Python web application servers (with its own object database, the ZODB), and Plone is the content management system built on top of it β for years one of the most widely deployed Python web platforms.
From 2003 to 2007 I was a core developer of both and an elected board member of the Plone Foundation. I was the primary maintainer of Products.Archetypes (the schema-based content-type framework) and Products.ATContentTypes (Plone's default content types built on it).
Before CPython and Red Hat, roughly in order:
- 1997β1999 β Built and ran a Linux server and Internet router for my school under the German Schulen ans Netz ("Schools on the Net") initiative to bring schools online.
- 2000β2005 β Administered a student dormitory network: qmail mail server, Courier IMAP, and network security.
- 2008β2013 β semantics GmbH: Python developer on Visual Library, a digitization and digital-library platform for libraries, archives, and museums (stack: Python, CherryPy, Firebird, lxml; METS/MODS metadata; SAN storage over a Fibre Channel fabric).
- 2014β2015 β About You / Project Collins (Otto Group): backend / Shop API developer on the e-commerce platform (Python, Elasticsearch, Redis).