Public ingress, without public compute
A hub-and-spoke landing-zone network: a public ALB fronting private ECS Fargate services over PrivateLink, plus a hardened SFTP-to-S3 bridge for external file exchange.
Cloud DevOps & platform engineer. I design cloud architecture and networks, wire pipelines that hold no credentials, and run the monitoring that keeps it all honest.
network design·terraform & cloudformation·oidc ci-cd·k8s / gitops·observability·multi-tenant saas
Open to new roles and freelance work: infrastructure, SaaS, landing pages·[email protected]
FIG. 01: system topology · the systems, by domain · ● = in production · each figure below details one
Every system in service, with its domain and current status.
| Fig | System | Domain | Status |
|---|---|---|---|
| FIG. 02 | Private ingress chain network · in production | network | in production |
| FIG. 03 | Zero-credential pipelines ci-cd · in production | ci-cd | in production |
| FIG. 04 | Fleet provisioning platform infra · in production | infra | in production |
| FIG. 05 | Zero-dependency monitoring observability · 222d uptime | observability | 222d uptime |
| FIG. 06 | Nested-stack CloudFormation platform infra · delivered | infra | delivered |
| FIG. 07 | 3-AZ shared VPC & module library network · in staging | network | in staging |
The engagements behind the systems, most recent first.
A hub-and-spoke landing-zone network: a public ALB fronting private ECS Fargate services over PrivateLink, plus a hardened SFTP-to-S3 bridge for external file exchange.
A solo-built, multi-tenant wedding-invitation platform (deliberately hand-built per client rather than self-serve SaaS) with four templated site designs, a shared row-level-secured Postgres layer, and a dispatched pipeline that provisions a new tenant end to end on Terraform and GitHub Actions.
Thin, versioned Terraform stacks consuming shared reference-architecture modules to run three internal application platforms on ECS Fargate with RDS PostgreSQL 17 behind RDS Proxy.