
Terraform AWS Reference Architecture
Progressive Terraform examples from a single EC2 instance to a full VPC with private RDS, reusable modules, remote state, CI-validated.
32 projects, runnable open-source reference implementations alongside production work delivered for clients.
32 projects

Progressive Terraform examples from a single EC2 instance to a full VPC with private RDS, reusable modules, remote state, CI-validated.

A collection of 5 AI-powered agents for cloud operations, DevOps, Cost, Security, Incident, and IaC Review, built on AWS Bedrock with production guardrails.

Reusable GitHub Actions workflows, build/test, security scan, build-push-sign (cosign), deploy, with a sample app that uses them.

Metrics, logs, and traces as code: Prometheus, Grafana, Loki, Tempo, Alertmanager via Docker Compose, plus Helm values for Kubernetes.

ArgoCD app-of-apps delivering a Helm sample app to Kubernetes, with a local kind bootstrap, Git as the single source of truth.

HashiCorp Vault in HA mode with integrated Raft storage and Kubernetes auth, deployed via Helm, with a secret-injection example.

Drop-in security tooling, pre-commit, gitleaks, Trivy, tfsec, checkov, hadolint, wired into one CI pipeline.

Production-grade Google Cloud landing zone, resource hierarchy, shared VPC + Cloud NAT, IAM, and org-policy guardrails.

Control-tower-style AWS foundation, Organizations, OUs, member accounts, Service Control Policies, and central CloudTrail.

An umbrella Helm chart that ships an app together with its ServiceMonitor and PrometheusRule, observable by default.

A platform-engineering reference, Backstage service catalog, golden-path scaffolder templates, and a paved-road developer experience.

Battle-tested runbooks, an SLO/error-budget framework, and blameless postmortem + comms templates for production systems.

A containerized Flask app with a complete GitHub Actions pipeline, test, build, Trivy scan, GHCR push, and deploy.

A Jenkins declarative pipeline that dockerizes an app, runs tests, pushes to a registry, and sends Slack notifications.

End-to-end CI/CD: Jenkins (in Docker) builds a Go app, pushes to a local registry, and deploys to Minikube, fully local, no cloud account needed.

Production static hosting on AWS, private S3 + CloudFront (OAC), ACM TLS, and Route 53, fully provisioned with Terraform.

Kubernetes Gateway API on GKE, path and header routing across services, TLS via cert-manager, and a troubleshooting runbook.

Production Node-RED on Kubernetes, PVC-backed flows, a bcrypt-hashed admin password in a Secret, and TLS Ingress.

Reference architecture: a containerized app on Google Cloud Run behind Cloudflare (CDN/WAF/TLS), with Terraform and a Cloud Build CI/CD pipeline.

Lambda + API Gateway + DynamoDB CRUD API, provisioned with Terraform, least-privilege IAM, unit-tested, scale-to-zero.

Order-fulfilment pipeline, EventBridge routing + Step Functions orchestration + Lambda, with a saga/compensation path. Terraform, tested.

End-to-end distributed tracing across gateway → backend → worker with OpenTelemetry, HTTP and async trace-context propagation, exported to Tempo and viewed in Grafana.

A Cloud Operations tool: monitors every CloudWatch log group in real-time for leaked secrets (AWS keys, passwords, JWTs, tokens), emits custom metrics + alarms, and routes rate-limited alerts via SNS, with a Flask dashboard for triage.

Reference Terraform for using core AWS services the right way, Secrets Manager, least-privilege IAM, CodeConnections (no stored tokens), customer-managed KMS, and a one-command account security baseline.

Built and launched a full-stack lost-and-found platform, FastAPI backend (107 endpoints), Flutter mobile app, React web app, live on AWS with mobile money payments and smart matching.

Designed and operate a serverless hosting platform on Google Cloud Run, fronted by Cloudflare, 5,000+ sites, global CDN, WAF/DDoS, load-tested to scale further.

Production EKS platform serving 50+ microservices and 1M+ requests/day with GitOps, service mesh, and full observability.

Migrated 100+ Jenkins pipelines to GitHub Actions, cutting average build time 60% and lifting deployment frequency 300%.

Full-stack metrics/logs/traces for 100+ services, cutting mean time to detection from 30 minutes to 2.

Automated scanning and compliance across 200+ repos, reaching SOC 2 Type II in 3 months.

Unified AWS + GCP provisioning with reusable Terraform modules and Ansible, cutting provisioning from days to hours.

Re-architected a monolith to AWS Lambda + EventBridge, cutting cost 70% and scaling to 10K req/s.