Skip to content
View Steeve-devops's full-sized avatar
🎯
Focusing
🎯
Focusing
  • SSLABS
  • POLAND

Block or report Steeve-devops

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Steeve-devops/README.md

⚡ Meet Stephen OMOWUMI


🧠 WHO AM I?

I'm a DevOps Engineer building toward the next generation of cloud and platform engineering.

My focus isn't simply on deploying applications.

It's on engineering environments where:

        CODE
          ↓
      AUTOMATION
          ↓
     INFRASTRUCTURE
          ↓
        CLOUD
          ↓
      SECURITY
          ↓
       IDENTITY
          ↓
    OBSERVABILITY
          ↓
      RESILIENCE

Everything should be automated, reproducible, observable, secure and scalable.

I work across the boundary between development, infrastructure and cybersecurity, using DevOps and DevSecOps principles to transform manual infrastructure into reliable engineering platforms.

⚡ My Engineering Philosophy

If it can be automated → automate it. If it can be measured → observe it. If it can be secured → secure it by design. If it can fail → engineer for resilience.


🧬 ENGINEERING DNA

☁️ CLOUD

Azure AWS Cloud Architecture Networking Storage

⚙️ DEVOPS

CI/CD Git Automation Release Engineering Platform Engineering

🏗️ IaC

Terraform Infrastructure Provisioning Configuration Automation

🔐 SECURITY

DevSecOps IAM Zero Trust Secrets Cloud Security

📊 OPERATIONS

Monitoring Logging Observability Reliability Resilience


🚀 THE PLATFORM MINDSET

I think beyond individual deployments.

The goal is to create repeatable engineering platforms that allow teams to ship faster without sacrificing security or reliability.

              ┌─────────────────────┐
              │      DEVELOPERS      │
              └──────────┬──────────┘
                         │
                         ▼
              ┌─────────────────────┐
              │    DEVELOPER        │
              │     PLATFORM        │
              └──────────┬──────────┘
                         │
        ┌────────────────┼────────────────┐
        ▼                ▼                ▼
   ┌─────────┐      ┌─────────┐      ┌─────────┐
   │   CI/CD │      │   IaC   │      │  CLOUD  │
   └────┬────┘      └────┬────┘      └────┬────┘
        │                │                │
        └────────────────┼────────────────┘
                         ▼
                ┌─────────────────┐
                │    DEVSECOPS    │
                └────────┬────────┘
                         ▼
                ┌─────────────────┐
                │ IAM • SECURITY  │
                └────────┬────────┘
                         ▼
                ┌─────────────────┐
                │ OBSERVABILITY   │
                └────────┬────────┘
                         ▼
                ┌─────────────────┐
                │   RESILIENCE    │
                └─────────────────┘

🛠️ MY TOOLBOX

Cloud • Containers • Kubernetes • IaC • CI/CD • Automation • Linux • Scripting


🔄 EVERYTHING AS CODE

Infrastructure should be versioned, repeatable and reproducible.

Infrastructure as Code
        │
        ├── Terraform
        ├── Configuration
        ├── Networking
        ├── Identity
        ├── Security
        └── Deployment
                 │
                 ▼
          Git-based workflow
                 │
                 ▼
             CI/CD
                 │
                 ▼
        Automated validation
                 │
                 ▼
          Cloud deployment

Current focus

Terraform · Azure · AWS · GitHub Actions · Azure DevOps · Automation


🔐 DEVSECOPS BY DESIGN

Security isn't a final pipeline stage.

It's part of the architecture.

PLAN
 ↓
CODE
 ↓
BUILD
 ↓
TEST
 ↓
SECURITY
 ↓
PACKAGE
 ↓
DEPLOY
 ↓
OBSERVE
 ↓
IMPROVE
 ↺

Security layer

🔐 Secrets Management 🛡️ Vulnerability Management 🔎 Security Testing 🐳 Container Security ☁️ Cloud Security 🔑 IAM 📦 Dependency Security ⚙️ Secure CI/CD 📊 Security Monitoring


🔑 IDENTITY IS THE NEW PERIMETER

Modern infrastructure requires modern identity.

My IAM focus includes:

Microsoft Entra ID

→ Identity & Access → RBAC → Conditional Access → Managed Identities → Service Principals → Authentication → Authorization → Least Privilege → Identity Governance → Zero Trust

USER
 ↓
IDENTITY
 ↓
AUTHENTICATION
 ↓
AUTHORIZATION
 ↓
POLICY
 ↓
RESOURCE
 ↓
AUDIT

☁️ CLOUD ARCHITECTURE

Microsoft Azure

Azure DevOps · Azure Networking · Azure Monitor · Azure Container Apps · Azure Storage · Entra ID

AWS

IAM · EC2 · VPC · S3 · CloudWatch · Cloud-native architecture


🐳 CONTAINER & PLATFORM ENGINEERING

I'm interested in the evolution from:

Servers → Virtual Machines → Containers → Kubernetes → Platforms

Current playground

🐳 Docker ☸️ Kubernetes ☁️ Azure Container Apps 🏗️ Terraform ⚙️ CI/CD 🔐 Container Security 📊 Observability


📡 OBSERVABILITY

You can't operate what you can't see.

My observability mindset:

           ┌────────────┐
           │   METRICS  │
           └─────┬──────┘
                 │
┌──────────┐     ▼     ┌──────────┐
│   LOGS   │ → SYSTEM ← │  TRACES  │
└──────────┘     │     └──────────┘
                 ▼
             ALERTING
                 │
                 ▼
          INCIDENT RESPONSE
                 │
                 ▼
            IMPROVEMENT

Azure Monitor • Log Analytics • Metrics • Logs • Alerts • Dashboards


🏦 ENGINEERING FOR FINANCIAL SERVICES

My engineering interests are strongly influenced by the security and resilience requirements of banking and financial technology environments.

Financial systems require infrastructure that is:

Secure

Highly available

Auditable

Observable

Resilient

Automated

Controlled

That means DevOps cannot operate independently from security and governance.

             DEVOPS
                │
                ▼
             SECURITY
                │
                ▼
               IAM
                │
                ▼
             RESILIENCE
                │
                ▼
             AUDITABILITY
                │
                ▼
              TRUST

Areas of interest include:

Cloud Security · IAM · DORA · ISO 27001 · NIST · PCI DSS · Operational Resilience


🧪 ENGINEERING LABS

☁️ Secure Cloud Platform

Building cloud environments using:

Terraform + Azure + CI/CD + IAM + Monitoring


🔐 DevSecOps Pipeline

Experimenting with:

GitHub Actions → Security Checks → Container Build → Deployment → Monitoring


🏦 Financial Services Security Lab

Exploring:

IAM → Cloud Security → Risk → Controls → Auditability → Resilience


🤝 OPEN SOURCE CONTRIBUTIONS

I contribute to public cloud, FinOps and DevOps projects. My changes go through the normal fork → feature branch → pull request → review → merge workflow.

💰 cloudcost-cli

An open-source, provider-neutral FinOps data platform with Arrow-based pipelines, SQL-first governance policies, and DuckDB, Postgres and BigQuery destinations.

✅ PR #24: Report command, webhook notifications, PyPI release automation and idle Azure checks

  • Added a report command to the CLI that writes cost findings as an HTML report.
  • Added Slack/webhook notifications so findings can be pushed to team channels.
  • Added PyPI package metadata and a PyPI publish step to the GitHub Actions release workflow.
  • Wrote three new SQL cost policies that detect idle Azure API Management, Azure Kubernetes Fleet Manager and Azure Managed HSM resources.
  • Covered every change with pytest tests: 8 new test files across the policies, the report, notifications, packaging and the release workflow.
  • +417 lines across 13 files. Reviewed, approved and merged by the maintainer.

🔗 Pull Request: raphgm/cloudcost-cli#24


📍 PinPoint Pro

An open-source, context-aware digital workspace that works with any AI provider, with Azure OpenAI preferred.

✅ PR #46: Contributor record and repository hygiene

  • Added myself to CONTRIBUTORS.md as a project contributor.
  • Added a standard .gitignore so that local environment variables and OS-generated files are not committed.
  • Reviewed, approved and merged by the maintainer.

🔗 Pull Request: raphgm/pinpointpro#46


📈 Impact

  • 2 merged pull requests, both reviewed and approved by the project maintainer.
  • Delivered features, cost-governance policies, CI/CD release automation and test coverage to a real FinOps codebase.
  • Comfortable with the full open-source collaboration workflow: issues, forks, branches, PRs, code review and merges.

Looking forward to contributing more to open-source Cloud, DevOps, FinOps and DevSecOps projects.


🏆 MICROSOFT APPLIED SKILLS

🔎 Explore Applied Skills
Area Applied Skill Credential
🤖 AI Resolve GitHub issues by using GitHub Copilot View Skill
🏢 Infrastructure Administer Active Directory Domain Services View Skill
⚙️ DevOps Implement security through a pipeline using Azure DevOps View Skill
☁️ Cloud Deploy cloud-native apps using Azure Container Apps View Skill
🔐 Identity Get started with identities and access using Microsoft Entra View Skill
🌐 Networking Configure secure access to your workloads using Azure networking View Skill
🛡️ Security Get started with cloud security and monitoring tasks View Skill
📊 Monitoring Deploy and configure Azure Monitor View Skill
⚙️ Management Get started with Azure management tasks View Skill
💾 Storage Secure storage for Azure Files and Azure Blob Storage View Skill

🎓 CERTIFICATIONS

📜 View credentials
  • ISO/IEC 27001:2022 Lead Implementer
  • ISO 27001 Lead Auditor
  • ISO 42001 Lead Auditor
  • ISO 27701 Lead Auditor
  • ISO 31000 Risk Management
  • CompTIA Security+
  • CompTIA CySA+
  • Proofpoint Certified Security Awareness Specialist
  • Certified Cybersecurity & Privacy Professional
  • Certified Governance, Risk & Compliance Auditor
  • Certified Privacy & Protection Specialist

🧭 THE LONG-TERM VISION

                    ┌───────────────┐
                    │   DEVELOPER   │
                    │   EXPERIENCE  │
                    └───────┬───────┘
                            │
                            ▼
                  ┌──────────────────┐
                  │ PLATFORM ENGINEER│
                  └────────┬─────────┘
                           │
             ┌─────────────┼─────────────┐
             ▼             ▼             ▼
          CLOUD         SECURITY       DATA
             │             │             │
             └─────────────┼─────────────┘
                           ▼
                  ┌──────────────────┐
                  │  INTELLIGENT     │
                  │  AUTOMATION      │
                  └────────┬─────────┘
                           ▼
                  ┌──────────────────┐
                  │ SELF-HEALING &   │
                  │ RESILIENT SYSTEMS│
                  └──────────────────┘

The long-term goal is to move beyond simply managing infrastructure toward engineering intelligent, secure and increasingly autonomous platforms.


⚡ BUILD PHILOSOPHY

        AUTOMATE
           ↓
        SECURE
           ↓
        DEPLOY
           ↓
        OBSERVE
           ↓
        LEARN
           ↓
        IMPROVE
           ↺

Engineering principles

Infrastructure should be reproducible.

Security should be continuous.

Identity should be explicit.

Observability should be built in.

Automation should remove friction.

Resilience should be engineered — not assumed.


⚡ AUTOMATE • 🔐 SECURE • ☁️ SCALE • 📊 OBSERVE

Engineering the infrastructure behind the next generation of secure digital platforms.

STEЕVE.DEVOPS

Popular repositories Loading

  1. devops-lab devops-lab Public

    Makefile

  2. Contribution-Repository Contribution-Repository Public

    Learning how to contribute to open source projects

  3. profile-readme-fork profile-readme-fork Public

    Forked from raphgab/raphgab

  4. devops-workstation devops-workstation Public

  5. cloud-data-ai-security-zero-to-hero cloud-data-ai-security-zero-to-hero Public

    Forked from PatrickWiloak/cloud-data-ai-security-zero-to-hero

    Cloud + Data + AI + Security from zero to hero. 122+ certs across 22 providers, 37 plain-English concepts, 15 hands-on builds, cross-cloud + AI service comparisons.

  6. pinpointpro pinpointpro Public

    Forked from raphgm/pinpointpro

    PinPoint Pro — Open-source context-aware digital workspace. AI provider-agnostic. Preferred: Azure OpenAI.

    TypeScript