Portfolio
Projects
Real infrastructure problems, real solutions. Each project is documented end-to-end with architecture decisions, implementation details, and lessons learned.
9 projects
01InfrastructureProduction EKS Cluster with Terraform - VPC, Node Groups & IRSA from Scratch
- Terraform
- AWS EKS
- Kubernetes
- AWS VPC
- Helm
- IRSA
- Cluster Autoscaler
- AWS Load Balancer Controller
A production-grade EKS cluster provisioned with Terraform — Custom VPC with private subnets across 3 AZs, separate system and application node groups, VPC endpoints for private AWS traffic, AWS Load Balancer Controller, and Cluster Autoscaler. The infrastructure foundation for all Kubernetes deployments.
EKS Platform Engineering — Deploying and Scaling Applications
- Kubernetes
- Helm
- AWS EKS
- HPA
- ALB
- AWS Secrets Manager
- Docker
- ECR
Deploying a Node.js API on EKS using Helm charts, HPA for pod autoscaling, ALB Ingress for traffic routing, and AWS Secrets Manager for zero-secret-in-Git configuration management.
03InfrastructureEKS Platform Engineering — Part 3: Cost Optimization with Karpenter & Spot Instances
- Karpenter
- AWS EKS
- Spot Instances
- Kubernetes
- AWS SQS
- Helm
Replaced the Cluster Autoscaler and managed node groups on EKS with Karpenter for intelligent, cost-aware node provisioning. Spot instances with automatic interruption handling, node consolidation within 30 seconds, and 40% compute cost reduction — with no changes to application code.
04DevOps / PlatformKubernetes RBAC Hardening — Least Privilege, Kyverno Enforcement, and Automated Auditing
- Kubernetes
- RBAC
- EKS
- AWS CloudWatch
- Pod Security Standards
- kyverno
- Alerts
- SNS
Simulated and fixed excessive cluster-admin access on EKS — reduced bindings from 8 to 1, added Kyverno policies to block regression at the API level, and built a weekly automated audit with Slack notifications. Zero disruptions.
05DevOps / PlatformKubernetes Security — Pod Security Standards & Network Policies
- Kubernetes
- Pod Security Standards
- Network Policies
- EKS
- DevSecOps
Enforced Pod Security Standards (restricted profile) and Network Policy microsegmentation on a production-style EKS environment — containers cannot run as root or escalate privileges, and pods communicate only on explicitly permitted paths. Validated with both positive and negative traffic tests.
Full Observability Stack — Prometheus, Grafana, Loki & Alertmanager on Kubernetes
- Prometheus
- Grafana
- Loki
- Alertmanager
- Kubernetes
- Helm
Deployed a complete observability platform on EKS using Helm — Prometheus for metrics, Grafana for dashboards, Loki for log aggregation, and Alertmanager routing alerts to Slack. MTTR reduced from 15 min to under 3 min.
GitOps CI/CD — GitHub Actions + Argo CD with Multi-Environment Promotion
- GitHub Actions
- Argo CD
- Docker
- AWS ECR
- Kubernetes
- GitOps
Built on top of EKS Platform Engineering — Deploying and Scaling Applications. The application, Helm chart, and EKS cluster from that project are what this pipeline builds, scans, and deploys.
AWS Multi-Account Landing Zone — Organizations, IAM Identity Center & SCPs
- AWS Organizations
- IAM Identity Center
- SCPs
- CloudTrail
- GuardDuty
- Terraform
Designed and implemented an enterprise AWS multi-account structure — management account, security account, shared services, and workload accounts. SSO via IAM Identity Center, guardrails via SCPs, centralised CloudTrail and Config.
Cloud Cost Optimisation — Datadog and AWS Spend Reduction
- Datadog
- AWS
- APM
- Log Management
- Cost Analysis
- Savings Plans
Systematic cost reduction across Datadog and AWS — cutting observability spend by 15% ($800+/month) through log retention tuning, APM sampling, orphaned resource cleanup, and Savings Plan commitment. All changes made without reducing production visibility.