Cloud Native EKS Landing Zone & GitOps Pipeline
- Designed and provisioned a production-ready Amazon EKS landing zone using Terraform with secure VPC peering, public/private subnets, and IAM Roles for Service Accounts (IRSA).
- Established automatic cert provisioning and TLS termination using Traefik and Cert-Manager, ensuring secure external endpoints.
- Built multi-environment GitOps CD pipelines via GitHub Actions and Helm, supporting rollback mechanics and lint checks.
- Secured cluster networking with WireGuard VPN for private API access and automated secret injection from AWS Secrets Manager.
