- Architected scalable, multi-tenant Azure infrastructure using Terraform, enforcing cloud best practices, enterprise standards, repeatability, and secure network isolation via Private Endpoints and Azure Private Link with custom DNS configurations and private DNS zones.
- Implemented high availability and resilience with BCDR strategies, dockerized App Services (including blue/green deployments via deployment slots), SQL Servers with failover/replicas, and integrated services like ACR, ACI, Container Apps, Front Door, Key Vault, VMs, App Insights, and many more.
- Configured GitHub Actions CI/CD pipelines with self-hosted runners, reusable composite actions, centralized dispatchers (workflow_dispatch & repository_dispatch), OIDC federation to Azure Key Vault, manual approvals, automated PRs, and Postman validation for secure, automated IaC deployments across environments.
- Automated operational tasks and local Terraform workflows with Bash/PowerShell wrapper scripts supporting plan/apply/destroy/import/drift detection, consistent error handling, environment selection, and secure execution.
- Integrated AIOps in Microsoft Teams using an AI RAG agent to provision infrastructure and manage Terraform MCP Server deployments, boosting automation efficiency.
- Designed resilient workloads for the enterprise judicial system, meeting strict RTO/RPO requirements with reliable, secure, and maintainable architecture.
- Managed Microsoft Entra ID (Azure AD) configurations including users/groups, role assignments, conditional access policies, Managed Identities, Service Principals, and secure resource integration for robust authentication and authorization.
- Established comprehensive FinOps practices and cost governance, implementing Azure Cost Management budgets, tagging strategies, reserved instances, savings plans, and automated cost optimization recommendations, resulting in significant monthly cloud spend reduction while maintaining performance and compliance.
AzureTerraformGitHub ActionsCI/CDBash ScriptingPowershell ScriptingGitOpsSonarQubeVeracodeAIOpsMCP ServersAzure ADGrafana