Senior DevSecOps Engineer with 8+ years operating cloud infrastructure across AWS, Azure, and GCP in regulated, PCI DSS environments. This repository captures hands-on implementations of the tools and practices I work with daily.
| # | Project | Stack | Highlights |
|---|---|---|---|
| 01 | Terraform — Azure Basics | Terraform, Azure | Resource Group, providers, variables, outputs |
| 03 | Terraform — Azure Container Deployment | Terraform, ACR, App Service | ACR + App Service Plan + Web App for Containers, Checkov scan |
| 12 | Terraform — AWS Multi-Cloud Baseline | Terraform, AWS | VPC, subnets, security groups, IAM instance role, encrypted S3 |
| # | Project | Stack | Highlights |
|---|---|---|---|
| 02 | GitHub Actions CI/CD | GitHub Actions, Python, Docker | Unit tests, Docker build, Snyk scan, Trivy scan |
| 13 | Azure DevOps Pipeline | Azure DevOps, ACR, App Service | 5-stage pipeline, approval gate, slot swap blue/green deploy |
| # | Project | Stack | Highlights |
|---|---|---|---|
| 08 | DevSecOps Security Pipeline | Gitleaks, Snyk, Trivy, Checkov | 4-stage shift-left: secrets → SAST → container → IaC |
| 07 | HashiCorp Vault Secrets Management | Vault, Docker, Python | KV v2, least-privilege policy, AppRole auth, no env-var secrets |
| 11 | PCI DSS Compliance-as-Code | Checkov, OPA/Conftest, GitHub Actions | PCI DSS v4.0 control mapping, weekly audit evidence artifacts |
| # | Project | Stack | Highlights |
|---|---|---|---|
| 04 | Docker Compose — Microservices | Docker Compose, Flask, Redis | Web + worker + Redis, async job processing, hardened Dockerfiles |
| 06 | Kubernetes — Helm Chart | Helm, Kubernetes | Flask deployment, service, ingress, configurable replicas |
| # | Project | Stack | Highlights |
|---|---|---|---|
| 09 | Prometheus + Grafana Stack | Prometheus, Grafana, Flask | SLO-based alerting rules, pre-built dashboard, P95 latency tracking |
| # | Project | Stack | Highlights |
|---|---|---|---|
| 10 | Ansible — Config Management | Ansible | Security baseline, Docker role, monitoring agent, SSH hardening |
| 05 | Automation Scripts | Python | File scanner, JSON reporting, CLI tooling |
Cloud: AWS · Azure · GCP
IaC & Automation: Terraform · Ansible · Python · Bash · PowerShell
CI/CD: GitHub Actions · Azure DevOps
Security: Snyk · Checkov · Trivy · Gitleaks · HashiCorp Vault · OPA/Conftest
Containers: Docker · Docker Compose · Kubernetes · Helm
Observability: Prometheus · Grafana
Compliance: PCI DSS v4.0 controls mapped to IaC and container policies
Mustafa S — Senior DevSecOps Engineer
GitHub: github.com/espnguy