Cloud engineer working across platform infrastructure, networking, security, and automation.
I build and operate cloud systems with an emphasis on infrastructure as code, predictable change, operational resilience, and clear engineering boundaries.
- 🏗️ Cloud & Platform: Azure, AWS, and GCP infrastructure, Kubernetes, containers, CI/CD, and repeatable platform patterns
- 🌐 Networking: Routing, hybrid connectivity, secure ingress/egress, load balancing, traffic engineering, and network security
- 🔐 Security & Identity: Least privilege, JIT access, identity federation, policy-driven controls, and workload security
- ⚙️ Infrastructure as Code: Terraform, Bicep, PowerShell, YAML, GitHub Actions, and Azure DevOps
- 📊 Operations: Observability, validation, controlled cutovers, rollback, incident readiness, and operational runbooks
- ✍️ Engineering Practice: Reversible change, explicit failure modes, automation, and documentation designed for handover
I also explore AI-assisted automation and event-driven systems where they provide useful interfaces to infrastructure and operational workflows.
Infrastructure patterns spanning cloud platforms, containers, orchestration, delivery pipelines, and infrastructure as code.
| Project | Description | Stack |
|---|---|---|
| Production Cloud Network Platform | Synthetic cloud infrastructure platform modelling secure ingress, egress, tiered segmentation, route control, and offline Terraform validation. | 🏗️ Terraform · Azure · Networking · Testing |
| AKS GitOps | GitOps deployment pattern for AKS using declarative configuration and automated reconciliation across Kubernetes environments. | ☸️ Kubernetes · AKS · GitOps · YAML |
| GKE Production Platform | GKE platform pattern covering workload deployment, platform controls, and operational conventions in Google Cloud. | ☸️ Kubernetes · GCP · GKE · Operations |
| Container Apps CI/CD Starter | Container deployment pattern demonstrating CI/CD wiring and a minimal cloud-native application lifecycle. | 📦 Containers · Azure · CI/CD · DevOps |
Patterns for deterministic traffic flow, secure connectivity, explicit routing, controlled egress, and predictable failure modes across cloud and hybrid environments.
| Project | Description | Stack |
|---|---|---|
| Fortinet SD-WAN + IPsec | SD-WAN and IPsec architecture covering HA, BGP routing, MTU tuning, and operational validation. | 🧱 Fortinet · Azure · SD-WAN · IPsec |
| Cloud-Secure Egress Policy | Centralised outbound control using policy enforcement and explicit routing to remove uncontrolled Internet egress. | 🔐 Network Security · Firewall · Azure |
| Azure Firewall Multi-Site Publishing | Controlled ingress pattern for publishing multiple internal applications through Azure Firewall with backend isolation and reversible cutover. | 🔥 Azure Firewall · Networking · Security |
| Hub-Spoke Hybrid Routing | Hybrid routing architecture using UDRs, gateway transit, and scoped prefix steering for partner connectivity. | 🌐 Routing · Azure · Hybrid |
| Azure VPN Patterns | VPN deployment and troubleshooting patterns covering authentication, DNS behaviour, and connectivity hardening. | 🌐 VPN · Azure · DNS · Troubleshooting |
Identity and security patterns centred on reducing standing privilege, making access time-bound, and keeping security controls auditable.
| Project | Description | Stack |
|---|---|---|
| Access Governance Request Platform | Identity-driven access governance managing time-bound permissions through request workflows, approvals, expiry, and audit evidence. | 🔐 Identity · Governance · Automation |
| Cloud Access Broker — JIT | Multi-cloud JIT access pattern providing temporary privilege across Azure and AWS with approval, revocation, and audit controls. | ☁️ AWS · Azure · IAM · JIT |
| AWS JIT Access | Temporary AWS privilege model using Identity Center and workflow-driven access with revocation and auditability. | ☁️ AWS · 🐍 Python · IAM · JIT |
| Azure Access Automation | RBAC lifecycle and JIT automation for time-bound entitlement approvals and access management. | 🔐 Azure · RBAC · PowerShell |
| Time-Bound Geo Bypass Access | Time-bound access-control pattern for geo-based policy exceptions with explicit expiry and operational traceability. | 🔐 Identity · Security · Automation |
| GCP External Security Pipelines | Security automation and pipeline controls in GCP covering identity, validation, and operational guardrails. | ☁️ GCP · Security · Pipelines |
Architecture and migration work focused on controlled transitions, operational constraints, validation, and maintainable target states.
| Project | Description | Stack |
|---|---|---|
| AWS Modernisation Architecture | AWS architecture mapping a legacy data platform through transition states, migration sequencing, and operational controls. | ☁️ AWS · Architecture · Migration · Security |
| Enterprise CRM/ERP Platform Deployment | CRM/ERP deployment pattern covering hardened Linux, NGINX reverse proxying, TLS automation, mail flow, and operational runbooks. | 🐧 Linux · NGINX · TLS · Operations |
| UniFi Controller Cloud Migration | Migration playbook for moving a UniFi controller from legacy hosting to cloud infrastructure with DNS cutover, hardening, and access controls. | ☁️ Azure · Linux · DNS · Migration |
| Azure Public IP Migration | Inventory-led migration framework for moving Basic SKU public IPs to Standard SKU with validation and rollback sequencing. | ☁️ Azure · PowerShell · Validation |
Engineering patterns for policy enforcement, repeatability, observability, operational control, and reducing manual infrastructure work.
| Project | Description | Stack |
|---|---|---|
| Azure Governance Baseline Framework | Governance baseline covering naming rules, tagging, policy-as-code, drift detection, and controlled remediation. | ☁️ Azure · Policy · PowerShell |
| Azure Cost & Tagging Governance | Policy and automation for enforcing cost-allocation tags and repairing configuration drift across subscription estates. | ☁️ Azure · Governance · Automation |
| LogicMonitor Hybrid Monitoring | Hybrid observability pattern providing monitoring, alerting, and operational visibility across multiple environments. | 📊 LogicMonitor · Monitoring · Hybrid |
| Grafana + Kibana Observability | Centralised metrics and log-analysis patterns for hybrid infrastructure and operational dashboards. | 📊 Grafana · Kibana · Observability |
| M365 Security Alerts to Teams | Workflow aggregating security alerts into Teams with enrichment and operational triage context. | 🔐 Security · Logic Apps · Automation |
Exploring event-driven and AI-assisted systems as an extension of infrastructure and operational automation.
| Project | Description | Stack |
|---|---|---|
| AI Voice Agent Platform | Event-driven voice agent platform covering enquiry intake, outbound workflows, structured data capture, and operational automation. | 🤖 AI · Azure Functions · Event-Driven |
- Cloud infrastructure and platform engineering across multiple cloud environments
- Kubernetes, containers, infrastructure as code, and automated delivery
- Deterministic networking, traffic engineering, and secure ingress/egress
- Identity-first security and least-privilege access models
- Observability, operational resilience, and predictable failure modes
- Controlled change, validation, rollback, and incident readiness
- Repeatable engineering patterns designed for long-term operational ownership
- Reduced standing privilege through identity-driven elevation models across cloud environments.
- Delivered production migrations and cutovers with defined validation and rollback paths.
- Standardised infrastructure, network, and access patterns to reduce operational drift.
- Built automation replacing manual provisioning and configuration workflows.
- Produced operational runbooks supporting predictable handover, support, and incident response.
- Design for rollback first.
- Prefer small, reversible changes over high-risk deployments.
- Treat identity as a primary security boundary.
- Document systems so someone else can operate them at 3am.
- Automate only after the manual process is fully understood.
- Identity over network trust.
- Short-lived access over standing privilege.
- Evidence over assumptions.
- Safe defaults over permissive convenience.
- Production systems should fail predictably.
- Internal infrastructure platforms and reusable platform abstractions
- Kubernetes and cloud-native infrastructure patterns
- Workload identity and cross-cloud security models
- Zero-trust segmentation and cloud traffic-control patterns
- Policy-as-code and automated infrastructure governance
- AI-assisted infrastructure operations
🧾 Public projects use synthetic or redacted information where appropriate.
No employer or customer confidential information, secrets, private tenant identifiers, or sensitive production configuration is intentionally included.

