How to read this portfolio: These projects demonstrate independent hands-on engineering. They are intentionally separated from the professional delivery case studies based on organization work.
01

Secure Multi-AZ VPC Foundation

Networking, private access, observability and cost-aware egress

A reusable Terraform network foundation with public ingress subnets, private application subnets, isolated data subnets, controlled outbound routing, VPC Flow Logs, an S3 gateway endpoint and private Systems Manager endpoints.

TerraformAWS VPCSubnetsRoute TablesNAT Gateway
Evidencefmtinitvalidate
02

Highly Available Three-Tier AWS Platform

HTTPS ingress, private compute, Auto Scaling and isolated PostgreSQL

A Terraform design for an HTTPS Application Load Balancer, private EC2 Auto Scaling application tier and private PostgreSQL RDS database tier distributed across two Availability Zones.

TerraformAmazon EC2Auto ScalingApplication Load BalancerAmazon RDS
Evidencefmtinitvalidate
03

Private ECS Fargate Application Platform

Immutable delivery, private tasks, autoscaling and observable deployments

A Terraform platform for an ECS Fargate service behind an Application Load Balancer, with ECR image controls, private tasks, CloudWatch logs, Container Insights, rolling deployments and target-tracking autoscaling.

TerraformAmazon ECSAWS FargateAmazon ECRApplication Load Balancer
Evidencefmtinitvalidate
04

Private Amazon EKS Platform Foundation

Private cluster access, managed nodes, KMS and controlled upgrades

A Terraform foundation for a private-endpoint Amazon EKS cluster with managed nodes, KMS envelope encryption, control-plane logging, core managed add-ons and controlled rolling node updates.

TerraformAmazon EKSKubernetesManaged Node GroupsAWS KMS
Evidencefmtinitvalidate
05

Reliable Serverless Event-Driven Platform

Durable event buffering, retries, dead-letter handling and bounded concurrency

An event-driven Terraform design where S3 object-created events pass through EventBridge to an encrypted SQS queue, Lambda processes bounded batches, failed messages reach a DLQ and CloudWatch alarms notify through encrypted SNS.

TerraformAmazon S3Amazon EventBridgeAmazon SQSAWS Lambda
Evidencefmtinitvalidate
06

IAM Governance and Cross-Account Access

Permission boundaries, explicit trust, MFA and access analysis

A Terraform IAM governance lab demonstrating a permission boundary, cross-account read-only role with MFA and an external ID, one-hour sessions, IAM Access Analyzer, a strict password policy and CloudTrail log-role preparation.

TerraformAWS IAMAWS STSPermission BoundariesMFA
Evidencefmtinitvalidate
07

AWS Multi-Account Landing Zone Blueprint

Organizations, preventive guardrails and centralized audit logging

A safety-first Terraform blueprint for organizational units, an example regional Service Control Policy, centralized organization CloudTrail, KMS-encrypted versioned log storage and lifecycle retention around a Control Tower-managed landing zone.

TerraformAWS OrganizationsAWS Control TowerService Control PoliciesAWS CloudTrail
Evidencefmtinitvalidate