Standardising CI/CD pipelines across teams
Reusable GitHub Actions workflows, Environment-scoped OIDC, and digest promotion so several teams ship without each inventing a private release path.
Practical notes from cloud architecture, platform engineering, security, and production operations.
Featured
Reusable GitHub Actions workflows, Environment-scoped OIDC, and digest promotion so several teams ship without each inventing a private release path.
Terraform module boundaries, environment roots, isolated state per account, and pinned promotion, so teams can extend a cloud estate without breaking it.
Why VPC and VNet models diverge across AWS, Azure, GCP, and Alibaba Cloud, and how to decide what to standardise versus what to leave provider-native.
Role design, OIDC for pipelines, SSO for people, access reviews, and time-boxed break-glass: production access that stays auditable across cloud accounts.
Packer golden images: bake vs configure boundaries, promotion pipelines, launch-template enforcement, and baseline hardening checks across AWS, Azure, and GCP.
All notes
Get in touch
Send a note to start a conversation, or reach out directly by email.
Contact