| Azure platform engineering |
Landing zone, Terraform roots, governance, private platform, monitoring |
| Microsoft hybrid identity |
Active Directory, Entra ID, Entra Connect, Conditional Access, MFA |
| Modern endpoint management |
Intune, Autopilot, compliance, BitLocker, LAPS, device recovery |
| Infrastructure as Code |
Terraform root separation, backend/state hygiene, plan/apply workflows |
| CI/CD and secretless delivery |
GitHub Actions OIDC, workflow-controlled delivery, no routine local apply |
| Hybrid and multi-cloud networking |
Hub-spoke, firewall, FortiGate context, AWS branch integration, route validation |
| Automation and operations |
Ansible, AWX, monitoring, backup, alerting, evidence capture |
| Kubernetes platform engineering |
Private AKS, manifests, network policies, future GitOps roadmap |
| Security architecture |
Least privilege, private access, evidence redaction, policy boundaries |
| AI-assisted CloudOps |
O6 AI operations enclave and local-ai-lab-infra companion workflow |