This site: static hosting on AWS with Terraform and OIDC
A personal site treated as a production system: private S3 behind CloudFront, two Terraform stacks and a single GitHub Actions pipeline with no stored AWS keys.
Open to DevOps/SRE opportunities
DevOps Engineer
Belo Horizonte, Brazil
DevOps Engineer building and running AWS infrastructure with Terraform, Kubernetes (EKS) and CI/CD. I automate deployments, observability and security.
A personal site treated as a production system: private S3 behind CloudFront, two Terraform stacks and a single GitHub Actions pipeline with no stored AWS keys.
Operated and evolved a Kubernetes-based logs and metrics platform: moved it to another AWS region, upgraded its core components and extended it to cover data pipelines.
Took public ingestion endpoints from an allow-all web ACL to layered WAF protection, validating every rule in count mode before blocking.
This site is served from a private S3 bucket through CloudFront, provisioned with Terraform and shipped by GitHub Actions over OIDC, with no AWS keys stored anywhere.
See the architecture →