We are TinyOrbit, a DevOps and DevSecOps engineering company in Hanoi. We build CI/CD pipelines, cloud and Kubernetes platforms, security guardrails and SRE practice for teams shipping regulated software, then keep those systems in orbit after handover. The repositories here are tools we run in production first and publish second.
| Capability | What it covers |
|---|---|
| CI/CD | Pipeline design and delivery automation on GitLab CI, GitHub Actions and Jenkins. Build once, promote by digest. |
| Cloud and Kubernetes platforms | AWS, Azure, GCP and on-premises. Cluster lifecycle, networking, storage, cloud migration, infrastructure as code with Terraform and Crossplane. |
| DevSecOps | SAST, SCA and secrets scanning as policy gates. Controls that fail the build, not the audit. |
| SRE and operations | 24/7 operations, monitoring and incident practice for the platforms we hand over. |
| Repository | What it does | Stack | License |
|---|---|---|---|
| provider-nexus | Crossplane provider for Sonatype Nexus Repository, generated with Upjet. 119 managed resources across repositories, blob stores, security, system and tasks. Runs the Terraform plugin in-process, so no Terraform CLI in the cluster. Cluster-scoped and namespaced APIs, Crossplane v2. | go · crossplane · upjet |
Apache-2.0 |
| terraform-provider-sonatyperepo | Terraform provider for Sonatype Nexus Repository Manager. Fork of sonatype-nexus-community/terraform-provider-sonatyperepo; provider-nexus is generated from this provider. |
go · terraform-plugin-framework |
Apache-2.0 |
| orbit-object-console | Self-hosted web console for S3-compatible storage: MinIO, Ceph RGW, Cloudflare R2, Backblaze B2, Wasabi, AWS S3. OIDC sign-in with PKCE, no local passwords. Connection secrets encrypted at rest with AES-256-GCM. Browse, upload, preview, presigned share links, on-demand bucket usage scans. | typescript · react · node 22 · sqlite / postgres · helm |
none listed |
| codex-imagegen-mcp | MCP server that generates and edits images through the Codex CLI on an existing ChatGPT subscription. One container by default, in-process queue, local storage; Helm chart with separate MCP and worker roles, Redis and S3 for multi-container setups. 30 to 140 s per image. | typescript · docker · helm |
MIT |
terraform-provider-sonatyperepo describes Nexus as Terraform resources. provider-nexus wraps that provider with Upjet so the same resources become Kubernetes CRDs reconciled by Crossplane: a repository, a blob store or a role is a manifest in Git, not a click in the Nexus UI. orbit-object-console sits in front of whatever S3 endpoint the platform exposes, most often MinIO or Ceph RGW on premises, and gives teams a browser without handing out static keys. codex-imagegen-mcp is an internal tool that was worth publishing: it turns an existing subscription into an MCP endpoint that Claude Code and other MCP clients can call.
Crossplane provider for Nexus:
apiVersion: pkg.crossplane.io/v1
kind: Provider
metadata:
name: provider-nexus
spec:
package: ghcr.io/tinyorbitvn/provider-nexus:v0.1.0Orbit Object Console and codex-imagegen-mcp both start with docker compose up -d; each README lists the environment variables, the OIDC client registration and the Helm values.
Issues and pull requests are open on every repository. Read the repository README before opening one, and reproduce a bug against the latest tag: the report should say what happened, on which version, and what you expected. Commit and pull request titles are sentence case, verb first, no trailing punctuation: Add namespaced ProviderConfig, Fix presigned URL expiry. Releases are tagged vMAJOR.MINOR.PATCH; images are published to ghcr.io/tinyorbitvn/<repository> under the same tag.
Report security issues to info@tinyorbit.vn, not in a public issue. Include the repository, the version and the steps.
The wordmark is the only permitted way to show the mark. Use the files in profile/assets/logo/ as supplied: never recolour, outline, stretch or rebuild it. Minimum height 20 px; clear space equal to the mark height.
| File | Use on |
|---|---|
tinyorbit-logo-navy.png |
White and light surfaces. Navy #000055, cyan #46c3d8. |
tinyorbit-logo-white.png |
Navy #000055 and dark surfaces. |
tinyorbit-logo-black.png |
Single-colour print and monochrome contexts. |
| Legal name | Công ty TNHH Công nghệ và Giải pháp TinyOrbit · TINYORBIT TECHNOLOGY AND SOLUTION COMPANY LIMITED · TINYORBIT CO.,LTD |
| Tax code | 0111138003 |
| Address | Số 316 Lê Trọng Tấn, Phường Phương Liệt, Thành phố Hà Nội, Việt Nam |
| Web | tinyorbit.vn |
| info@tinyorbit.vn |

