Skip to content
View tiran's full-sized avatar

Organizations

@zopefoundation @python @freeipa @latchset @dogtagpki @python-ldap

Block or report tiran

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tiran/README.md

Christian Heimes (he/him)

LinkedIn PyPI SpeakerDeck

πŸ“ Based in Hamburg, Germany πŸ‡©πŸ‡ͺ Β· working remotely

I'm a software engineer at Red Hat and a Python core developer, with more than 25 years of open-source experience. My work centers on Python packaging and build systems, security and cryptography, and AI/ML infrastructure, grounded in a long track record in the CPython standard library. Earlier in my career I built identity- and secrets-management systems and contributed to the Zope and Plone web platforms. My current focus is building infrastructure for Red Hat's AI platform.


About Me

  • πŸ€– I currently build infrastructure for Red Hat's AI platform β€” packaging and distributing Python and ML software across CPU, GPU, and AI-accelerator targets.
  • πŸ“¦ I have long-standing expertise in Python packaging and build systems, and I publish agent-skills to share that knowledge with other engineers.
  • 🐍 CPython core developer since 2007; former maintainer of the ssl and hashlib modules and author of several security-focused PEPs.
  • πŸ… PSF Fellow since 2008; emeritus member of the Python Security Response Team and the PSF Diversity & Inclusion Working Group.
  • πŸ”’ Creator and maintainer of defusedxml, a library that hardens Python's XML parsers against bomb and XXE attacks.
  • 🎩 Earlier at Red Hat, I worked across the identity stack β€” FreeIPA / RHEL IdM, Custodia, and python-ldap β€” and spent time as a Core Maintainer of InstructLab.
  • 🐧 A Linux user since 1997 and a Python programmer since 2001.

Areas of Expertise

Area Projects & Topics
πŸ€– Red Hat AI AI/ML build & distribution infrastructure, RHAI container images, accelerator wheel builds (CUDA/ROCm/Spyre), WheelNext
πŸ“¦ Python packaging Wheel-build tooling (fromager), build backends, packaging utilities, agent skills
🐍 Python & open source CPython core development, PSF Fellow, defusedxml, PEP authorship
πŸ”’ Security & cryptography CPython ssl/hashlib, OpenSSL, FIPS & system crypto-policies, pyca/cryptography
🎩 Identity management FreeIPA / RHEL IdM, Custodia, python-ldap, Dogtag PKI
πŸ•°οΈ Earlier career Zope & Plone, Plone Foundation board

Selected Work

πŸ€– Red Hat AI

fromager Stars

As Staff & Senior Principal Software Engineer for Red Hat's AI Platform Ecosystem, I build the infrastructure that packages and distributes Python and ML software with optimized builds across accelerator targets β€” CPU, NVIDIA CUDA, AMD ROCm, and IBM Spyre β€” published at packages.redhat.com. I also build the Red Hat AI (RHAI) container images used across Red Hat's AI products, including Red Hat AI Inference (vLLM).

The wheel-building toolchain behind this is open source. fromager is the foundation β€” a build-from-source wheel maker β€” supported by packaging and binary-analysis tools I work on: elfdeps (ELF shared-library dependency analysis), retread (compares downstream wheel rebuilds against upstream to catch differences), zipwire (reads files from remote ZIP archives over HTTP range requests), and torch-abi-audit (audits extensions for PyTorch and CPython stable-ABI compliance).

I'm Red Hat's liaison to WheelNext, the cross-industry effort to evolve the Python wheel format β€” in particular wheel variants (PEP 825) for hardware-specific builds.

Earlier I was a Core Maintainer of InstructLab, which uses Large-Scale Alignment for ChatBots (LAB) β€” an alignment tuning method for LLMs that leverages synthetic data β€” to train a model using custom taxonomy data. There I worked on hardware enablement (Intel Gaudi, CUDA, Apple MLX) and build, test, and packaging infrastructure. The project has since been refactored, with its core building blocks (synthetic data generation and training) moving into separate successor projects.


πŸ“¦ Python Packaging & Build Systems

I have deep, long-standing expertise in Python packaging β€” build backends, the wheel format, PEP-based packaging standards, and the tooling around building and distributing packages (several of my packaging and binary-analysis tools are listed in the Red Hat AI section above). I also publish agent-skills, a collection of portable, agent-neutral "skills" and playbooks for Python and packaging tasks. Each skill is dual-purpose: a guide an engineer can read directly, and a structured instruction set an AI coding assistant (such as Claude Code or Codex) can load to carry out a specialized task β€” covering areas like build-backend selection, FIPS/crypto audits, type-stub generation, and secure release pipelines. Together they distill two decades of Python experience into reusable references for both people and agents.


🐍 CPython

GitHub Stars

I joined the CPython core team in late 2007 and have contributed close to 700 pull requests over the years (among the most active contributors by commit count). For much of that time I maintained the ssl and hashlib modules β€” including porting them across the OpenSSL 1.1 and 3.0 API transitions β€” and served on the Python Security Response Team (PSRT). My work also spans the wider standard library, project governance, and CPython's WebAssembly port (the WASI and Emscripten build targets).

PEPs I authored as sole creator:

  • PEP 370 β€” Per-user site-packages directory, the mechanism behind pip install --user.
  • PEP 456 β€” Secure and interchangeable hash algorithm (SipHash, now CPython's default string-hash algorithm).
  • PEP 644 β€” Require OpenSSL 1.1.1 or newer.

I also co-authored:

  • PEP 452 β€” the cryptographic hash-function API. (co-author)
  • PEP 543 β€” a unified TLS API. (co-author)
  • PEP 594 β€” "removing dead batteries." (co-author)

πŸ”’ Security & Cryptography

defusedxml Stars PyPI Downloads

I created and maintain defusedxml, which provides drop-in replacements for Python's XML parsers that defend against entity-expansion ("billion laughs"), external-entity (XXE), and DTD-retrieval attacks. For roughly a decade I also maintained CPython's ssl and hashlib modules β€” moving hostname verification onto OpenSSL's native checks, bringing up TLS 1.3 support, making SSLContext secure by default, and porting both modules through successive OpenSSL API transitions. I implemented the usedforsecurity mechanism and a C-based HMAC so Python behaves correctly under FIPS-mode OpenSSL, contributed fixes upstream to OpenSSL itself, and wrote the FIPS-mode algorithm restrictions in pyca/cryptography. My CPython --with-ssl-default-suites=openssl build option is what lets Fedora/RHEL's system-wide crypto-policies apply to Python's ssl connections.


🎩 Identity Management β€” FreeIPA, Custodia & python-ldap

FreeIPA Stars Custodia Stars python-ldap Stars

Much of my earlier work at Red Hat was across the identity-management stack. FreeIPA (shipped as Red Hat Identity Management, RHEL IdM) is an open-source identity-management system, largely written in Python, that integrates an LDAP directory (389 Directory Server), Kerberos (MIT krb5), a certificate authority (Dogtag PKI), and DNS into a single managed security domain. In FreeIPA I designed and implemented four features β€” Member Manager, Hidden Replicas, LDAPI Autobind, and Subordinate IDs (the last relevant to Podman and rootless containers) β€” each with a published design document on freeipa.readthedocs.io. I co-maintained Custodia, a secrets-management service for cloud applications, together with its founder Simo Sorce. I also contributed to python-ldap as an upstream collaborator, including its modernization to the stable abi3 ABI and a number of memory-leak and security fixes.


🎀 Speaking

I've spoken at Python and open-source conferences for well over a decade, including PyCon US, EuroPython, PyCon DE, PyCon UK, and DevConf (Czechia and India). Topics have ranged from TLS/PKI and Python's ssl module to security engineering, WebAssembly, and open-source AI. Keynotes include:

  • DevConf.IN 2018 (Bengaluru, India) β€” "Everyday Security Issues and How to Avoid Them," the keynote at the first-ever DevConf India.
  • PyCon DE 2022 (Berlin) β€” "Python 3.11 in the Web Browser – A Journey," on CPython's WebAssembly port.

Slides for many of my talks are on SpeakerDeck.


🐘 Zope & Plone

Zope is one of the original Python web application servers (with its own object database, the ZODB), and Plone is the content management system built on top of it β€” for years one of the most widely deployed Python web platforms.

From 2003 to 2007 I was a core developer of both and an elected board member of the Plone Foundation. I was the primary maintainer of Products.Archetypes (the schema-based content-type framework) and Products.ATContentTypes (Plone's default content types built on it).


πŸ•°οΈ Earlier Career

Before CPython and Red Hat, roughly in order:

  • 1997–1999 β€” Built and ran a Linux server and Internet router for my school under the German Schulen ans Netz ("Schools on the Net") initiative to bring schools online.
  • 2000–2005 β€” Administered a student dormitory network: qmail mail server, Courier IMAP, and network security.
  • 2008–2013 β€” semantics GmbH: Python developer on Visual Library, a digitization and digital-library platform for libraries, archives, and museums (stack: Python, CherryPy, Firebird, lxml; METS/MODS metadata; SAN storage over a Fibre Channel fabric).
  • 2014–2015 β€” About You / Project Collins (Otto Group): backend / Shop API developer on the e-commerce platform (Python, Elasticsearch, Redis).

Pinned Loading

  1. defusedxml defusedxml Public

    Python 555 61

  2. cpython-wasm-test cpython-wasm-test Public

    Test CPython WebAssembly builds with Emscripten SDK

    Shell 51 3

  3. python/cpython python/cpython Public

    The Python programming language

    Python 77.6k 38k

  4. freeipa/freeipa freeipa/freeipa Public

    Mirror of FreeIPA, an integrated security information management solution

    Python 1.3k 397

  5. pyasn1/pyasn1 pyasn1/pyasn1 Public

    Forked from etingof/pyasn1

    Generic ASN.1 library for Python

    Python 53 44