Transit Gateway · VNet peering · PSC
Cloud networking
Hub-and-spoke on AWS, Azure and GCP: shared gateway, WAF, CDN and NAT in the hub, private spokes for Kubernetes and databases. Workloads have no direct internet exposure.
I design and automate cloud platforms on AWS, Azure and GCP: secure hub-and-spoke networks, private Kubernetes, and pipelines that build a full environment in one click.
Brief history
I work at Ksolves India in Noida, where I build and run the platform layer for client products: networks, Kubernetes clusters, secrets, observability and the pipelines that create them. The design I've built most is hub-and-spoke, which I've implemented on all three major clouds with Terraform.
Before that I set up Docker Swarm, GitLab CI and Vault for a startup, and before that I studied mechanical engineering, which is where my habit of drawing a system before building it comes from.
What I do
Transit Gateway · VNet peering · PSC
Hub-and-spoke on AWS, Azure and GCP: shared gateway, WAF, CDN and NAT in the hub, private spokes for Kubernetes and databases. Workloads have no direct internet exposure.
Terraform · Ansible · Helm
40+ Terraform modules and one blueprint reused across three clouds. Environment provisioning is 60% faster and every change goes through code review.
Azure DevOps · GitLab CI · GitHub Actions
A 3-stage pipeline (hub → self-hosted agent → spoke) that builds a full environment with no manual steps, and build → test → deploy pipelines for 3 product squads.
EKS · GKE · AKS · Istio · Docker
15+ Helm releases on private EKS and GKE with Istio and HPA. Earlier, 8 microservices on Docker Swarm with zero-downtime deploys; dev setup went from 2 days to under 2 hours.
Vault · Workload Identity · Trivy · Gitleaks
Removed long-lived cloud keys with Workload Identity Federation, moved secrets into Vault with TTL rotation, and added Trivy, Gitleaks and SonarQube gates to delivery pipelines.
Prometheus · Grafana · OpenTelemetry
Metrics, dashboards and distributed tracing with Prometheus, Grafana, Jaeger and OpenTelemetry, plus scheduled off-hours shutdown to cut non-production spend.
The journey
Noida
Noida
Ganga Institute of Technology & Management (MDU)
Pusa Institute of Technology (BTE)
Selected work
AWS · Terraform
Spokes have no internet gateway. All traffic goes through Transit Gateway to Network Firewall and NAT in the hub, with a domain allowlist. Private EKS with IRSA, deployed by GitHub Actions over OIDC.
Azure · Terraform
AKS egress forced through the hub firewall with user-defined routes. Local accounts disabled, Entra ID RBAC, workload identity, and Key Vault reachable only over a private endpoint.
GCP · Terraform
Public APIs through Apigee with no VPC peering and no proxy VMs. The spokes connect only through Private Service Connect. Cloud Armor WAF, deny-by-default egress, keyless CI via Workload Identity Federation.
AWS · AI agent
An AI agent built on Claude that diagnoses failed ECS/Fargate deployments from CloudWatch logs, explains the root cause in plain English and proposes a fix. Fixes run only after human approval, under a tightly scoped IAM role, with a full audit trail in RDS. Average time to resolve went from ~45 minutes to under 10.
Tricks of the trade
TrivyImage scanning
GitleaksSecret scanningI'm open to DevOps, platform and cloud infrastructure roles. The quickest way to reach me is email. I usually reply within a day.