Portfolio

Projects

Real infrastructure problems, real solutions. Each project is documented end-to-end with architecture decisions, implementation details, and lessons learned.

9 projects

Production EKS Cluster with Terraform - VPC, Node Groups & IRSA from Scratch cover
01Infrastructure

Production EKS Cluster with Terraform - VPC, Node Groups & IRSA from Scratch

  • Terraform
  • AWS EKS
  • Kubernetes
  • AWS VPC
  • Helm
  • IRSA
  • Cluster Autoscaler
  • AWS Load Balancer Controller

A production-grade EKS cluster provisioned with Terraform — Custom VPC with private subnets across 3 AZs, separate system and application node groups, VPC endpoints for private AWS traffic, AWS Load Balancer Controller, and Cluster Autoscaler. The infrastructure foundation for all Kubernetes deployments.

    EKS Platform Engineering — Deploying and Scaling Applications cover
    02DevOps / Platform

    EKS Platform Engineering — Deploying and Scaling Applications

    • Kubernetes
    • Helm
    • AWS EKS
    • HPA
    • ALB
    • AWS Secrets Manager
    • Docker
    • ECR

    Deploying a Node.js API on EKS using Helm charts, HPA for pod autoscaling, ALB Ingress for traffic routing, and AWS Secrets Manager for zero-secret-in-Git configuration management.

      EKS Platform Engineering — Part 3: Cost Optimization with Karpenter & Spot Instances cover
      03Infrastructure

      EKS Platform Engineering — Part 3: Cost Optimization with Karpenter & Spot Instances

      • Karpenter
      • AWS EKS
      • Spot Instances
      • Kubernetes
      • AWS SQS
      • Helm

      Replaced the Cluster Autoscaler and managed node groups on EKS with Karpenter for intelligent, cost-aware node provisioning. Spot instances with automatic interruption handling, node consolidation within 30 seconds, and 40% compute cost reduction — with no changes to application code.

        Kubernetes RBAC Hardening — Least Privilege, Kyverno Enforcement, and Automated Auditing cover
        04DevOps / Platform

        Kubernetes RBAC Hardening — Least Privilege, Kyverno Enforcement, and Automated Auditing

        • Kubernetes
        • RBAC
        • EKS
        • AWS CloudWatch
        • Pod Security Standards
        • kyverno
        • Alerts
        • SNS

        Simulated and fixed excessive cluster-admin access on EKS — reduced bindings from 8 to 1, added Kyverno policies to block regression at the API level, and built a weekly automated audit with Slack notifications. Zero disruptions.

          Kubernetes Security — Pod Security Standards & Network Policies cover
          05DevOps / Platform

          Kubernetes Security — Pod Security Standards & Network Policies

          • Kubernetes
          • Pod Security Standards
          • Network Policies
          • EKS
          • DevSecOps

          Enforced Pod Security Standards (restricted profile) and Network Policy microsegmentation on a production-style EKS environment — containers cannot run as root or escalate privileges, and pods communicate only on explicitly permitted paths. Validated with both positive and negative traffic tests.

            Full Observability Stack — Prometheus, Grafana, Loki & Alertmanager on Kubernetes cover
            06Observability

            Full Observability Stack — Prometheus, Grafana, Loki & Alertmanager on Kubernetes

            • Prometheus
            • Grafana
            • Loki
            • Alertmanager
            • Kubernetes
            • Helm

            Deployed a complete observability platform on EKS using Helm — Prometheus for metrics, Grafana for dashboards, Loki for log aggregation, and Alertmanager routing alerts to Slack. MTTR reduced from 15 min to under 3 min.

              GitOps CI/CD — GitHub Actions + Argo CD with Multi-Environment Promotion cover
              07DevOps / Platform

              GitOps CI/CD — GitHub Actions + Argo CD with Multi-Environment Promotion

              • GitHub Actions
              • Argo CD
              • Docker
              • AWS ECR
              • Kubernetes
              • GitOps

              Built on top of EKS Platform Engineering — Deploying and Scaling Applications. The application, Helm chart, and EKS cluster from that project are what this pipeline builds, scans, and deploys.

                AWS Multi-Account Landing Zone — Organizations, IAM Identity Center & SCPs cover
                08Cloud Architecture

                AWS Multi-Account Landing Zone — Organizations, IAM Identity Center & SCPs

                • AWS Organizations
                • IAM Identity Center
                • SCPs
                • CloudTrail
                • GuardDuty
                • Terraform

                Designed and implemented an enterprise AWS multi-account structure — management account, security account, shared services, and workload accounts. SSO via IAM Identity Center, guardrails via SCPs, centralised CloudTrail and Config.

                  Cloud Cost Optimisation — Datadog and AWS Spend Reduction cover
                  09Cost Optimisation

                  Cloud Cost Optimisation — Datadog and AWS Spend Reduction

                  • Datadog
                  • AWS
                  • APM
                  • Log Management
                  • Cost Analysis
                  • Savings Plans

                  Systematic cost reduction across Datadog and AWS — cutting observability spend by 15% ($800+/month) through log retention tuning, APM sampling, orphaned resource cleanup, and Savings Plan commitment. All changes made without reducing production visibility.