Baptiste Parmantier,
architect for systems that stay alive

I build IAM primitives, distributed architectures and production systems. From the first API contract to the last alert resolved.

Rust backend
IAM and security
Open source lead
Baptiste Parmantier

Rust

services, CLI, APIs

IAM

Keycloak, OIDC

K8s

OPA, AuthZen, MCP

Flagship Product

FerrisKey

FerrisKey

Open-source IAM platform, built in Rust

FerrisKey is an enterprise-grade identity and access management platform — the kind of system where correctness is non-negotiable. I co-founded it, designed the architecture, wrote the core, and own the production stack.

Architecture

Hexagonal architecture in Rust. Service boundaries designed before the first line of code. API contracts that the entire stack depends on.

Distributed

Multiple services on Kubernetes. Event-driven coordination, eventual consistency, and horizontal scalability by design.

Production

GitHub Actions CI/CD, Prometheus + Loki for observability. Maintained with SLO discipline — shipped and kept alive.

What I Do

Three things I'm built for

Not a list of frameworks. What I actually deliver, end to end.

01

Identity & Architecture

I design systems at the domain level — defining service boundaries, API contracts, and data ownership before touching a framework. My IAM expertise (OIDC, policies, multi-tenancy) comes from building FerrisKey: an identity platform where correctness isn't optional.

02

Distributed Systems

I build services that coordinate reliably at scale. Event-driven architectures, Kubernetes orchestration, and consistency models designed for failure — not just for the happy path.

03

Production Lifecycle

I don't stop at the deploy. CI/CD pipelines, structured observability with Prometheus and Loki, and the mindset of an owner — not a contractor. If it pages at 3am, I'm the one who fixed the design that caused it.

Expertise

From identity to distributed platforms.

I focus on the parts of a system where product design, security constraints and operational reality meet.

IAM & OIDC

OIDC, OAuth2, FerrisKey, token lifecycle, multi-tenant realms and secure product boundaries. Protocol implementation from spec — not from tutorials.

Authorization & policy

OPA, RBAC, ABAC, delegated authorization and policy-as-code. Fine-grained access control that stays auditable when security teams need answers.

Platform identity

Kubernetes-native identity, service-to-service auth, mTLS and SPIFFE/SPIRE between workloads. IAM at the infrastructure layer.

Distributed security

Event-driven auth flows, Kafka-based audit pipelines, and consistency decisions for systems that stay explainable under failure.

Operational security

Auth systems that are observable and recoverable. Structured audit logs, token flow metrics, and SLOs for security-critical infrastructure.

Projects

Open source products, not demo code

Each project is a system decision made concrete — architecture choices, protocol design, and long-term maintenance.

Blog

Latest articles

Stay up to date with the latest news and updates.

Let's work together

Have a project in mind or just want to chat? Feel free to reach out.

Baptiste Parmantier

A modern documentation framework built with Astro. Create beautiful, fast, and accessible docs with ease.

© 2026 Baptiste Parmantier. All rights reserved.

Built with ❤️ using Explainer