I build hands-on Azure infrastructure with a focus on Terraform, networking, governance, automation and secure cloud delivery.
My projects are designed around real implementation scenarios rather than isolated demos — including deployment, validation, failure recovery, least-privilege access and reproducible infrastructure lifecycles.
Azure: Networking · Entra ID · RBAC · Policy · Automation · Monitor · Log Analytics
Infrastructure: Terraform · Azure CLI · Bicep · Remote State · OIDC
Engineering: Git · GitHub Actions · CI/CD · IaC validation · Security scanning
Terraform · Azure Networking · GitHub Actions · OIDC · Checkov · Observability
A reproducible Azure infrastructure environment built around a Hub-and-Spoke architecture with a controlled infrastructure lifecycle.
- Hub-and-Spoke topology with App and Data spokes
- Linux NVA with UDR-based inter-spoke routing
- Azure Bastion for private administration
- No public IP addresses on workload VMs
- NSGs and Application Security Groups
- Microsoft Entra ID-based SSH access
- Network Watcher, Flow Logs and Traffic Analytics
- Terraform remote state in Azure Blob Storage
- Separate persistent bootstrap and destroyable workload states
- GitHub Actions authentication through OIDC
- Terraform CI with Checkov security scanning
- Controlled Apply → Validate → Destroy lifecycle
- Terraform import and state recovery scenarios
Azure Policy · RBAC · Automation · Managed Identity · FinOps · Event-Driven Governance
An evolving Azure governance platform that started with cost protection and is being expanded into layered preventive and event-driven guardrails.
- Subscription budget alerts
- Tag-based nightly VM AutoStop
- Managed Identity automation
- Custom least-privilege RBAC
- Azure Policy tag governance
- Preventive VM-size restrictions
- Public IP denial
- Required workload tags
- Governance tag auditing
- Group-based workload access
- Platform / workload separation
Visibility
↓
Automation
↓
Least Privilege
↓
Governance
↓
Prevention
↓
Event-Driven Attribution
↓
Reusable Terraform Platform
Currently building resource attribution through:
Activity Log
↓
Event Grid
↓
Azure Function
↓
CreatedBy / CreatedByType
Terraform · Azure Storage · GitHub Actions · Microsoft Entra ID · RBAC
A secure Terraform delivery foundation focused on state management and secretless CI/CD authentication.
- Azure Blob Storage remote backend
- Terraform state migration
- Blob lease state locking validation
- Private backend container
- Versioning and soft delete
- Azure AD backend authentication
- GitHub Actions → Azure federation
- OpenID Connect instead of client secrets
- Scoped workload and backend RBAC
- Reproducible implementation runbooks
- Documented troubleshooting and failure scenarios
The principles I try to apply across my projects:
Infrastructure as Code
+
Least Privilege
+
Private-by-default Networking
+
Automation
+
Observable Infrastructure
+
Reproducible Deployments
+
Evidence-based Validation
I prefer building infrastructure that can answer:
- Who is allowed to deploy it?
- Should the resource be allowed to exist?
- How is it deployed reproducibly?
- How is access scoped?
- How is its lifecycle controlled?
- How is it monitored?
- Can the deployment be validated?
- Can it be safely destroyed and rebuilt?
- ✅ Microsoft Azure Fundamentals — AZ-900
- ✅ Google Cloud Digital Leader
- 🚧 Microsoft Azure Administrator — AZ-104
- 🔬 Current technical focus: Azure Platform Engineering, Terraform and Governance
Extending the Azure FinOps & Governance platform with automatic creator attribution for newly deployed resources.
Entra ID
↓
Group-based RBAC
↓
Azure Policy
↓
Resource Deployment
↓
Activity Log
↓
Event Grid
↓
Azure Function
↓
CreatedBy / CreatedByType
The goal is to combine identity, authorization, prevention, attribution and automation into one governance workflow.
Interested in Azure infrastructure, Terraform, platform engineering, cloud governance and automation.
GitHub: @erndweinmanuel-cloud
