Home
Flagship Azure, AWS-connected, hybrid, and multi-cloud platform engineering portfolio with public evidence trail.
AzAWSLab is the flagship portfolio project: a staged technical platform built from a realistic Microsoft hybrid enterprise environment into Azure platform engineering, AWS-connected secure networking, automation, private platform services, operations, and AI governance.
Inside: Terraform-driven Azure platform roots, AWS branch routing, OIDC-based delivery, hybrid identity, Exchange Hybrid, private AKS, AVD, AWX automation, backup resilience, and the AI Operations Enclave, evidenced through O6.
Evidence route: Proof Gallery, Engineering Deep Dive, and Skills Matrix connect implementation claims to screenshots, CLI output, workflow logs, source files, design notes, and evidence folders.
Reviewers: Cloud engineers, platform engineers, infrastructure architects, security architects, DevOps/SRE reviewers, and technical hiring teams.
Platform Journey Engineering Deep Dive Proof Gallery Reviewer Pathways
Public portfolio status
Published through a public GitHub repository, custom domain, HTTPS, evidence folders, strict documentation checks, and role-based reviewer paths.
Platform architecture overview - view full diagram on GitHub
What this platform contains¶
-
Release 1: hybrid workplace, identity, endpoint security, and Microsoft 365 operations
Realistic Microsoft hybrid enterprise environment with Hyper-V, AD DS, Exchange Hybrid, Entra Connect, Conditional Access, Intune, Autopilot, BitLocker, Windows LAPS, Purview, Sentinel, Defender for Cloud, operational visibility, and Microsoft Graph PowerShell.
-
Release 2: platform engineering, secure networking, automation, private platform services, operations, and AI governance
Terraform-driven Azure platform roots, OIDC delivery, isolated state boundaries, Azure governance, hub-spoke networking, FortiGate inspection, BGP, AWS branch transit, AWX automation, backup resilience, private AKS, AVD secure workspace, and the AI Operations Enclave, evidenced through O6.
-
Release 3: multi-cloud Kubernetes, GitOps, and DevSecOps roadmap
Roadmap for AKS/EKS, Flux, Flagger, DevSecOps scanning, observability, resilience, and platform evolution.
Core architectural capabilities¶
-
OIDC-based IaC delivery
GitHub Actions OIDC and workflow-controlled Terraform delivery reduce reliance on long-lived credentials and keep deployment behaviour reviewable.
-
Hybrid and multi-cloud fabric
Hub-spoke routing, Azure Firewall, FortiGate NVA inspection, VPN, BGP, and AWS branch patterns validate the transit and inspection model.
-
Private platform services
Private AKS and secure AVD workspace patterns keep platform and operator access inside controlled network paths.
-
Automation and resilience
AWX job templates, governed runbooks, Recovery Services Vault controls, soft-delete handling, backup validation, and BCDR plans provide the operations evidence route.
-
AI operations boundary
The AI Operations Enclave, evidenced through O6, models policy-mediated tool use and human approval boundaries for AI-assisted platform operations.
Platform journey and evidence routes¶
-
Platform journey¶
flowchart LR R1["Release 1<br/>Hybrid workplace<br/>Microsoft 365 operations"] R2["Release 2<br/>Platform engineering<br/>AWS branch routing"] O6["O6<br/>AI Operations Enclave"] R3["Release 3<br/>Kubernetes<br/>GitOps and DevSecOps roadmap"] R1 --> R2 --> O6 --> R3Release 1 - Hybrid workplace, identity, endpoint security, and Microsoft 365 operations.
Release 2 - Azure platform engineering, AWS-connected secure networking, automation, private platform services, operations, and AI governance.
Release 3 - Multi-cloud Kubernetes, GitOps, and DevSecOps roadmap.
-
Featured evidence¶
Reviewer evidence dashboard for the major capability routes.
Capability-to-evidence map across Microsoft 365, Azure, AWS-connected networking, automation, Kubernetes, AVD, resilience, and AI governance.
Technical notes, implementation context, and evidence maps.
Implementation source, workflows, Terraform roots, manifests, diagrams, and evidence folders.
Choose your reviewer path¶
-
Fast skills scan, role alignment, priority evidence, and interview-ready talking points.
-
Business context, delivery ownership, risk reduction, and platform operating model.
-
IaC design, Terraform state boundaries, workflows, networking, AKS, AVD, and evidence routes.
-
Identity governance, endpoint controls, network inspection, private access, resilience, and AI governance.
-
OIDC-based delivery, automation governance, observability, backup resilience, and operational runbooks.
Source repository¶
The public GitHub repository contains the implementation, evidence folders, workflows, Terraform roots, Kubernetes manifests, diagrams, and Markdown documentation.
