Skip to content
View erndweinmanuel-cloud's full-sized avatar
:shipit:
Path to AZ-104
:shipit:
Path to AZ-104
  • Germany/Karlsruhe

Block or report erndweinmanuel-cloud

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Hi, I'm Manuel 👋

Azure Platform & Infrastructure Engineer

I build hands-on Azure infrastructure with a focus on Terraform, networking, governance, automation and secure cloud delivery.

My projects are designed around real implementation scenarios rather than isolated demos — including deployment, validation, failure recovery, least-privilege access and reproducible infrastructure lifecycles.


🛠️ Core Technologies

Azure Terraform GitHub Actions Git PowerShell

Azure: Networking · Entra ID · RBAC · Policy · Automation · Monitor · Log Analytics
Infrastructure: Terraform · Azure CLI · Bicep · Remote State · OIDC
Engineering: Git · GitHub Actions · CI/CD · IaC validation · Security scanning


🚀 Featured Projects

☁️ Azure Hub-Spoke Networking with Terraform

Terraform · Azure Networking · GitHub Actions · OIDC · Checkov · Observability

A reproducible Azure infrastructure environment built around a Hub-and-Spoke architecture with a controlled infrastructure lifecycle.

Highlights

  • Hub-and-Spoke topology with App and Data spokes
  • Linux NVA with UDR-based inter-spoke routing
  • Azure Bastion for private administration
  • No public IP addresses on workload VMs
  • NSGs and Application Security Groups
  • Microsoft Entra ID-based SSH access
  • Network Watcher, Flow Logs and Traffic Analytics
  • Terraform remote state in Azure Blob Storage
  • Separate persistent bootstrap and destroyable workload states
  • GitHub Actions authentication through OIDC
  • Terraform CI with Checkov security scanning
  • Controlled Apply → Validate → Destroy lifecycle
  • Terraform import and state recovery scenarios

Explore the project


🛡️ Azure FinOps & Governance Guardrails

Azure Policy · RBAC · Automation · Managed Identity · FinOps · Event-Driven Governance

An evolving Azure governance platform that started with cost protection and is being expanded into layered preventive and event-driven guardrails.

Implemented

  • Subscription budget alerts
  • Tag-based nightly VM AutoStop
  • Managed Identity automation
  • Custom least-privilege RBAC
  • Azure Policy tag governance
  • Preventive VM-size restrictions
  • Public IP denial
  • Required workload tags
  • Governance tag auditing
  • Group-based workload access
  • Platform / workload separation

Current evolution

Visibility
    ↓
Automation
    ↓
Least Privilege
    ↓
Governance
    ↓
Prevention
    ↓
Event-Driven Attribution
    ↓
Reusable Terraform Platform

Currently building resource attribution through:

Activity Log
    ↓
Event Grid
    ↓
Azure Function
    ↓
CreatedBy / CreatedByType

Explore the project


🔐 Terraform Azure Backend + OIDC

Terraform · Azure Storage · GitHub Actions · Microsoft Entra ID · RBAC

A secure Terraform delivery foundation focused on state management and secretless CI/CD authentication.

Highlights

  • Azure Blob Storage remote backend
  • Terraform state migration
  • Blob lease state locking validation
  • Private backend container
  • Versioning and soft delete
  • Azure AD backend authentication
  • GitHub Actions → Azure federation
  • OpenID Connect instead of client secrets
  • Scoped workload and backend RBAC
  • Reproducible implementation runbooks
  • Documented troubleshooting and failure scenarios

Explore the runbook


🧭 Engineering Focus

The principles I try to apply across my projects:

Infrastructure as Code
        +
Least Privilege
        +
Private-by-default Networking
        +
Automation
        +
Observable Infrastructure
        +
Reproducible Deployments
        +
Evidence-based Validation

I prefer building infrastructure that can answer:

  • Who is allowed to deploy it?
  • Should the resource be allowed to exist?
  • How is it deployed reproducibly?
  • How is access scoped?
  • How is its lifecycle controlled?
  • How is it monitored?
  • Can the deployment be validated?
  • Can it be safely destroyed and rebuilt?

🎓 Certifications & Learning

  • ✅ Microsoft Azure Fundamentals — AZ-900
  • ✅ Google Cloud Digital Leader
  • 🚧 Microsoft Azure Administrator — AZ-104
  • 🔬 Current technical focus: Azure Platform Engineering, Terraform and Governance

🔨 Currently Building

Event-Driven Resource Attribution

Extending the Azure FinOps & Governance platform with automatic creator attribution for newly deployed resources.

Entra ID
   ↓
Group-based RBAC
   ↓
Azure Policy
   ↓
Resource Deployment
   ↓
Activity Log
   ↓
Event Grid
   ↓
Azure Function
   ↓
CreatedBy / CreatedByType

The goal is to combine identity, authorization, prevention, attribution and automation into one governance workflow.


📫 Connect

Interested in Azure infrastructure, Terraform, platform engineering, cloud governance and automation.

GitHub: @erndweinmanuel-cloud

Pinned Loading

  1. azure-hub-spoke-networking-tf azure-hub-spoke-networking-tf Public

    Azure Hub-Spoke networking lab built with Terraform, GitHub Actions and OIDC. Includes NVA routing, Bastion, Flow Logs, remote state and a tested Apply/Destroy lifecycle.

    HCL

  2. azure-finops-governance-guardrails azure-finops-governance-guardrails Public

    CLI-first Azure FinOps & governance guardrails: budget alerts, tag-based VM auto-stop, inherited tag governance, custom RBAC, and Azure Policy baseline to prevent risky lab resources.

    Shell

  3. terraform-azure-backend-oidc-runbook terraform-azure-backend-oidc-runbook Public

    Runbook: Azure Terraform remote state (azurerm backend) + GitHub Actions OIDC CI/CD (no secrets), step-by-step with proofs.

    HCL

  4. azure-vmss-autoscale-cli azure-vmss-autoscale-cli Public

    azure-vmss-autoscale-cli

  5. azure-vm-basics-cli azure-vm-basics-cli Public

    azure-vm-basics-cli

    1

  6. azure-networking-basics-cli azure-networking-basics-cli Public

    azure-networking-basics-cli