GitHub Actions, Argo CD, Helm, and automated release paths — from commit to production with repeatable CI/CD workflows.
AWS Certified Solutions Architect DevOps AWS Cloud Engineer
DevOps & AWS Cloud Engineer — secure, automated delivery from code to production.
AWS Certified Solutions Architect — DevOps & AWS Cloud Engineer focused on automated delivery on AWS.
I build EKS GitOps pipelines, serverless architectures, event-driven systems, and Terraform infrastructure. Every project includes architecture diagrams and documented tradeoffs.
GitHub Actions, Argo CD, Helm, and automated release paths — from commit to production with repeatable CI/CD workflows.
Docker, Kubernetes (EKS), Terraform, and AWS platform services wired into secure, scalable delivery pipelines.
Three focused security repositories — Network Firewall threat detection, IAM Access Analyzer reviews, and Lambda-driven security group automation.
Prometheus, Grafana, CloudWatch, and fault-tolerant design — metrics, alerting, and resilience built into every delivery path.
Secure CI/CD from GitHub to CloudFront — the pipeline running this site.
A push to main starts the GitHub Actions workflow — the single source of truth for AWS production and GitHub Pages backup.
GitHub OIDC assumes an AWS IAM deployment role. STS issues temporary credentials per run — no permanent access keys or GitHub Secrets.
Static assets sync to a private S3 bucket with stale-file cleanup. CloudFront OAC is the only read path to the origin.
CloudFront invalidation refreshes the CDN cache and publishes the live portfolio worldwide within seconds.
Four hands-on tracks with independent Credly verification.
Trained — Hands-on cloud architect
Verify on CredlyTrained — Hands-on cloud security
Verify on CredlyTrained — Hands-on serverless
Verify on CredlyTrained — Hands-on cloud networking
Verify on CredlyThe standards applied to every build and delivery path here.
Cost, availability, and complexity tradeoffs written for each architecture — so design intent survives beyond the initial build.
Multi-AZ placement, autoscaling thresholds, and fault boundaries defined before go-live — not patched in after an incident.
CloudFront and API Gateway expose only the edge — application and data tiers stay in private subnets with no direct inbound path.
Terraform modules, remote state locking, and GitOps-style promotion — environments advanced through version control, not console changes.
Twelve AWS builds across DevOps, Serverless, IaC, Security, and core AWS architecture — each with diagrams, tradeoffs, and GitHub repos.
End-to-end GitOps delivery for a Go web app on Amazon EKS — CI, Docker, Helm, and Argo CD with NGINX Ingress.
GitOps and Helm add deployment flexibility but introduce cluster sync lag and chart versioning overhead compared to direct kubectl deploys.
3-tier blog platform on Amazon EKS with DevOps CI, Terraform, GitOps, and Prometheus/Grafana observability.
Layered security scanning and NetworkPolicies improve posture but lengthen CI runtime and add operational complexity.
Highly available web, application, and database tiers on AWS — Multi-AZ subnets, Auto Scaling, ALB, and private RDS.
Multi-tier separation improves resilience and blast-radius control but adds networking and operational complexity versus a single-tier design.
Production-grade Amazon EKS cluster in a custom VPC — Terraform IaC with multi-AZ subnets, managed node groups, IRSA, and CloudWatch logging.
Terraform IaC enables full repeatability but adds state management overhead.
Provisioned isolated VPC and EC2 web servers across dev, stage, and prod using Terraform Workspaces. Each environment uses dedicated networking, environment-specific variables, and remote state in S3 with DynamoDB locking.
Workspaces simplify multi-environment deploys but require careful workspace and variable selection.
Built a production-style Terraform remote backend using S3 for state storage and DynamoDB for apply locking. Includes a dedicated state-backend stack and workspace-based dev/prod deployments with SSM Parameter Store.
Remote state enables safe team collaboration but adds backend infrastructure to provision before workloads deploy.
Built a serverless messaging pipeline to ensure reliable and asynchronous communication between services. Designed to handle traffic spikes without data loss.
Adds latency and requires handling message duplication and ordering.
Designed an event-driven system to enable asynchronous communication and reduce tight coupling between services, improving scalability and flexibility.
Debugging and tracing events becomes more complex. Eventual consistency.
Implemented deep packet inspection and traffic filtering to detect and control malicious network activity.
Enhances network security, but increases latency and requires complex rule management.
Automated dynamic security group rule updates to enforce consistent network access and reduce manual intervention.
Improves operational efficiency, but incorrect automation logic can lead to unintended access or service disruption.
Analyzed network access paths to identify unintended exposure and validate secure connectivity across resources.
Provides visibility into access paths, but requires manual remediation and does not enforce changes automatically.
Accelerated global content delivery using CDN edge locations and caching strategies to reduce latency and improve performance.
Improves global performance, but adds cache invalidation complexity and additional cost.
AWS platform services and DevOps delivery tooling — from infrastructure to observability.
Open to full-time and hybrid DevOps & AWS Cloud Engineering roles.
Open to full-time and hybrid opportunities in DevOps and AWS Cloud Engineering.