resume ─── sultan ahmad
Sultan Ahmad
Education
ICS — Intermediate with Computer Science
[REDACTED] · 95%+ in CS subjects
Experience
Streaming Infrastructure — Backend Engineer
Self / Freelance
- Streaming Backend: Built high-throughput HLS stream resolution and content delivery backends in Rust/Axum with multi-tier caching — Cloudflare edge cache, Redis session store, and in-process Moka LRU cache. Stress-tested under 20k+ concurrent streamers with sub-50ms p99 latency.
- Error Rate Reduction: Reworked retry logic and failover routing across redundant upstream sources, cutting downstream error rates. Implemented structured tracing with
tracing-subscriberand Sentry panic capture to identify and close failure loops. - Load Balancing: Multi-node Axum deployments on Fly.io ([REDACTED]) with automatic machine scaling, health-check routing, and blue-green rollouts via Docker multi-stage builds.
Proxy & Bypass Engineering
Self / Freelance
- Rotating Proxy Pipelines: Engineered async rotating IP proxy pools to bypass geo-locks and IP-rate-limits on third-party sources. Wrote a standalone
proxy_scan.rsbinary to validate and rank live proxies from sourced lists with concurrency-limited reqwest workers. - Client Fingerprint Spoofing: Built custom Axum middleware for header injection — User-Agent cycling, TLS JA3 mitigation strategies, cookie passthrough chains, and Referer spoofing. Used
wreqwith SOCKS5 support for per-request proxy binding. - Cryptographic Pipeline: Implemented ChaCha20, AES-CTR, HMAC-SHA256, and base64 encode/decode pipelines for inter-service token obfuscation and content integrity checks.
Infrastructure & Multi-Node Deployment
Self / Freelance
- Multi-Node Orchestration: Manages containerised service clusters with Docker Swarm and Fly.io rolling deployments across multiple regions. Services include Postgres (SQLx migrations), Redis, Moka in-memory caches, and Cloudflare Workers for edge passthrough.
- Microservice Management: Operates multiple independent Rust binaries behind Nginx reverse proxies with upstream failover, rate limiting, and TLS termination. Each service ships as a stripped release binary (
lto=true, strip=true) in a minimal Docker image. - Frontend Integration: Next.js frontends deployed on Vercel, consuming Axum APIs over HTTPS with Cloudflare in front for DDoS mitigation and cache layering.
Auth System & User Account Management
ReedStreams Backend
- Authentication: Full auth flows in Axum — registration, bcrypt/argon2 password hashing, JWT issuance and refresh, role-based route middleware guards. UUID v4 primary keys, chrono-stamped audit rows, compile-time checked SQLx queries against Postgres.
- Live Viewer System: WebSocket-backed real-time viewer count tracking via DashMap shared state, with live broadcast to connected clients and Redis-backed persistent counters across node restarts.
- Admin & Content Routing: User, profile, playlist, chat, admin, and source management route groups. Override system synced from Redis with configurable TTL for zero-downtime source switching.
Skills
LanguagesRust, JavaScript, TypeScript, SQL, Bash, HTML/CSS
Rust EcosystemTokio, Axum, Tower, SQLx, reqwest, wreq, Moka, Serde, Tracing, DashMap
InfrastructureDocker, Docker Swarm, Fly.io, Cloudflare, Nginx, Redis, Postgres
CryptographySHA-256, HMAC, AES-CTR, ChaCha20, argon2, bcrypt, JWT, base64
FrontendNext.js, React, Vite, CSS, Canvas API
ToolsKali Linux, Arch Linux, Git, Neovim, k6 load testing, Sentry
note: location & institutional details redacted for privacy. credentials available via imhackax@gmail.com.