Skip to content

Home

Flagship Azure, AWS-connected, hybrid, and multi-cloud platform engineering portfolio with public evidence trail.

AzAWSLab is the flagship portfolio project: a staged technical platform built from a realistic Microsoft hybrid enterprise environment into Azure platform engineering, AWS-connected secure networking, automation, private platform services, operations, and AI governance.

Inside: Terraform-driven Azure platform roots, AWS branch routing, OIDC-based delivery, hybrid identity, Exchange Hybrid, private AKS, AVD, AWX automation, backup resilience, and the AI Operations Enclave, evidenced through O6.

Evidence route: Proof Gallery, Engineering Deep Dive, and Skills Matrix connect implementation claims to screenshots, CLI output, workflow logs, source files, design notes, and evidence folders.

Reviewers: Cloud engineers, platform engineers, infrastructure architects, security architects, DevOps/SRE reviewers, and technical hiring teams.

Platform Journey Engineering Deep Dive Proof Gallery Reviewer Pathways

Public portfolio status

Published through a public GitHub repository, custom domain, HTTPS, evidence folders, strict documentation checks, and role-based reviewer paths.

Platform hero diagram

Platform architecture overview - view full diagram on GitHub

What this platform contains

  • Release 1: hybrid workplace, identity, endpoint security, and Microsoft 365 operations

    Realistic Microsoft hybrid enterprise environment with Hyper-V, AD DS, Exchange Hybrid, Entra Connect, Conditional Access, Intune, Autopilot, BitLocker, Windows LAPS, Purview, Sentinel, Defender for Cloud, operational visibility, and Microsoft Graph PowerShell.

    Open Release 1 summary

  • Release 2: platform engineering, secure networking, automation, private platform services, operations, and AI governance

    Terraform-driven Azure platform roots, OIDC delivery, isolated state boundaries, Azure governance, hub-spoke networking, FortiGate inspection, BGP, AWS branch transit, AWX automation, backup resilience, private AKS, AVD secure workspace, and the AI Operations Enclave, evidenced through O6.

    Open Release 2 summary

  • Release 3: multi-cloud Kubernetes, GitOps, and DevSecOps roadmap

    Roadmap for AKS/EKS, Flux, Flagger, DevSecOps scanning, observability, resilience, and platform evolution.

    Open Release 3 roadmap

Core architectural capabilities

  • OIDC-based IaC delivery

    GitHub Actions OIDC and workflow-controlled Terraform delivery reduce reliance on long-lived credentials and keep deployment behaviour reviewable.

    Review OIDC delivery

  • Hybrid and multi-cloud fabric

    Hub-spoke routing, Azure Firewall, FortiGate NVA inspection, VPN, BGP, and AWS branch patterns validate the transit and inspection model.

    Review networking

  • Private platform services

    Private AKS and secure AVD workspace patterns keep platform and operator access inside controlled network paths.

    Review private platform

  • Automation and resilience

    AWX job templates, governed runbooks, Recovery Services Vault controls, soft-delete handling, backup validation, and BCDR plans provide the operations evidence route.

    Review automation control plane

  • AI operations boundary

    The AI Operations Enclave, evidenced through O6, models policy-mediated tool use and human approval boundaries for AI-assisted platform operations.

    Review AI operations

Platform journey and evidence routes

  • Platform journey

    flowchart LR
        R1["Release 1<br/>Hybrid workplace<br/>Microsoft 365 operations"]
        R2["Release 2<br/>Platform engineering<br/>AWS branch routing"]
        O6["O6<br/>AI Operations Enclave"]
        R3["Release 3<br/>Kubernetes<br/>GitOps and DevSecOps roadmap"]
    
        R1 --> R2 --> O6 --> R3

    Release 1 - Hybrid workplace, identity, endpoint security, and Microsoft 365 operations.

    Release 2 - Azure platform engineering, AWS-connected secure networking, automation, private platform services, operations, and AI governance.

    Release 3 - Multi-cloud Kubernetes, GitOps, and DevSecOps roadmap.

  • Proof Gallery

    Reviewer evidence dashboard for the major capability routes.

    Skills Matrix

    Capability-to-evidence map across Microsoft 365, Azure, AWS-connected networking, automation, Kubernetes, AVD, resilience, and AI governance.

    Engineering Deep Dive

    Technical notes, implementation context, and evidence maps.

    GitHub source repository

    Implementation source, workflows, Terraform roots, manifests, diagrams, and evidence folders.

Choose your reviewer path

  • Recruiter path

    Fast skills scan, role alignment, priority evidence, and interview-ready talking points.

  • Hiring manager path

    Business context, delivery ownership, risk reduction, and platform operating model.

  • Technical reviewer path

    IaC design, Terraform state boundaries, workflows, networking, AKS, AVD, and evidence routes.

  • Security architect path

    Identity governance, endpoint controls, network inspection, private access, resilience, and AI governance.

  • DevOps and SRE path

    OIDC-based delivery, automation governance, observability, backup resilience, and operational runbooks.

Source repository

The public GitHub repository contains the implementation, evidence folders, workflows, Terraform roots, Kubernetes manifests, diagrams, and Markdown documentation.

Open GitHub repository