I'm a Cloud Infrastructure & DevOps Engineer based in Poland with 6+ years in tech (since 2020), designing, securing and operating infrastructure for large-scale enterprise environments on Microsoft Azure. I specialise in Azure networking, identity and governance, container platforms, Infrastructure as Code and automated delivery pipelines, turning manual, error-prone operations into repeatable, auditable processes.
I believe good infrastructure is only as strong as its documentation. The repositories here are reference implementations and runbooks, written the way I'd hand them over to a team: reproducible, verified and easy to operate.
- Design and operate secure Azure infrastructure: networking, identity, governance and monitoring
- Containerise and deploy workloads with Docker and Kubernetes
- Provision infrastructure as code with Terraform
- Build and maintain CI/CD pipelines with GitHub Actions and Azure DevOps
- Publish technical guides for engineers on dev.to
- Infrastructure Automation: Automated VM and Application Gateway provisioning with Terraform and CI/CD pipelines, cutting environment setup time from 2 days to 30 minutes.
- Secure Networking: Designed hub-spoke network architectures with private endpoints across 5 Azure subscriptions.
- Edge Security: Protected web workloads with Azure Application Gateway WAF, combining Microsoft-managed rule sets with custom rules and rate limiting to block malicious and abusive traffic.
- Cost Optimisation: Reduced compute spend by putting idle virtual machines on deallocation and shutdown schedules, so non-production capacity is paid for only when it's used.
- Product Engineering: Hardened and operated KONTA, a production AI platform on Google Cloud Run with 98 automated test files and 70+ merged pull requests.
- Azure Administration: Compute, storage, resource governance and day-to-day management tasks.
- Identity & Access: Microsoft Entra ID, RBAC and Active Directory Domain Services.
- Security, Monitoring & Compliance: Secure storage (Azure Files and Blob Storage), Azure Monitor, cloud security operations, and Microsoft Purview retention and eDiscovery.
- Azure Networking: Virtual networks, hybrid connectivity, load balancing, network security and private access to PaaS services.
- DevOps & CI/CD: Source control strategy, branching and pull-request workflows, build and release pipelines, and DevSecOps practices.
- Containers: Writing Dockerfiles, multi-container stacks with Docker Compose, and Kubernetes manifests.
- Infrastructure as Code & Automation: Terraform, YAML, Bash scripting and Makefile automation.
- Linux Administration: Day-to-day operations, shell tooling and troubleshooting.
| Domain | Tools & Platforms |
|---|---|
| Cloud | Microsoft Azure, Azure CLI, Azure Monitor, Microsoft Entra ID, Google Cloud Run, Secret Manager, Firestore, Cloudflare Pages |
| Automation | Power Automate, Bash, Makefile |
| Containers & Orchestration | Docker, Docker Compose, Kubernetes |
| Infrastructure as Code | Terraform, tflint, Trivy, YAML |
| CI/CD & Version Control | GitHub Actions, Azure DevOps, Git, GitHub |
| OS & Directory Services | Linux (Ubuntu), Active Directory Domain Services |
| Web & Apps | TypeScript, React, Node.js / Express, Python, Astro, Nginx, MySQL, WordPress |
An AI-assisted business ledger for small businesses, run from a web dashboard or WhatsApp
KONTA tracks sales, orders, inventory, customers, debtors and expenses. Merchants can send a WhatsApp text or voice note, and AI turns it into a proposal. Nothing changes in the books until a person confirms it, and the change itself is made by deterministic code.
- Platform: Containerised with a multi-stage Docker build (non-root runtime and health check) and deployed on Google Cloud Run. A least-privilege service account reads secrets from Secret Manager, and Firestore is locked down with deny-all rules, so all data access goes through the server.
- Security hardening: WhatsApp webhook HMAC verification, API rate limiting, request size limits, CSP/HSTS security headers, input validation before building Firestore paths, and phone numbers masked in logs.
- Reliability: Idempotent webhook processing, bounded timeouts on AI and messaging calls with safe retry rules, durable inbound and outbound message logs, and transactional ledger writes with concurrency isolation.
- Engineering practice: 98 automated test files running against both an in-memory database and the Firestore emulator. Every change ships through a pull request (70+ merged).
- Tech Stack:
TypeScript,React,Node.js / Express,Firestore,Google Cloud Run,Secret Manager,Docker,Gemini AI,WhatsApp Cloud API
A private-by-default Azure network, changed only through a reviewed pipeline
A hub VNet with central Private DNS and an optional Azure Firewall, a workload spoke behind Application Gateway WAF_v2, and a data spoke whose storage is reachable only through a private endpoint. Changes go through GitHub Actions: plan on every pull request, apply only after an approval gate, authenticated with OIDC federated credentials and no client secrets.
- Security: Storage public network access and shared keys disabled, per-subnet NSGs with explicit deny, no public IP on the backend VM, and WAF in Prevention mode (DRS 2.1 + Bot Manager) with an admin-path block and rate limiting.
- Quality gates:
terraform fmt,validate, offlineterraform testagainst a mocked provider,tflint(azurerm ruleset) and atrivy configscan on every change. Six ADRs record the design decisions. - Cost controls: Optional firewall, App Gateway autoscaling from zero, a daily log ingestion cap and resource-group budgets.
- Tech Stack:
Terraform,Azure,Application Gateway WAF_v2,Azure Firewall,Private Endpoints,GitHub Actions,OIDC,tflint,Trivy
A static site rebuilt, checked and deployed by its own pipeline
An Astro site on Cloudflare Pages, rebuilt by GitHub Actions on every push and every night from the GitHub and dev.to APIs. The home page shows the site's own pipeline as a live diagram, and each case study includes an interactive architecture diagram generated at build time.
- Security: A strict Content Security Policy (
script-srcandstyle-srclimited to'self') with HSTS and other security headers. CI fails the build if any inline script or style appears. - Resilience: Every data source is optional. A failing API shows up as a warning on the diagram instead of breaking the site.
- Tech Stack:
Astro,TypeScript,Cloudflare Pages,GitHub Actions,Wrangler,GitHub API
A multi-container WordPress + MySQL stack with Docker Compose
Provisions, monitors and tears down a two-tier application with persistent volumes, service dependencies and port mapping. Every stage is verified with captured output.
- Tech Stack:
Docker Compose,MySQL 8.0,WordPress,Docker Desktop
Kubernetes Pod specification: structure and API contract
A reference Pod manifest that breaks down the Kubernetes API contract (apiVersion, kind, metadata and spec) and sets out conventions for clean, version-controlled manifests.
- Tech Stack:
Kubernetes,YAML,Nginx,Git
YAML patterns for DevOps & Cloud Engineering
A structured reference covering mappings, sequences, scalar types, multiline strings, anchors and aliases, followed by real-world GitHub Actions and app-config examples.
- Tech Stack:
YAML,GitHub Actions,VS Code
A lean Nginx image for serving static content
A minimal Alpine-based image with a clean web root and documented build directives, covering layer caching, port mapping and container-lifecycle troubleshooting.
- Tech Stack:
Docker,Nginx,Alpine Linux,HTML
An end-to-end team Git & delivery workflow
Implements feature branching, conventional commits, pull requests, applying code-review feedback, merging to main and triggering a CI/CD pipeline.
- Tech Stack:
Git,GitHub,Python,Bash
| Project | Description |
|---|---|
| devops-lab | A Node.js app containerised with Docker, with build and run automated through a Makefile |
| simple-container-lab | Container build-and-ship workflow for a Node.js service, from docker build to git push |
| DevOps-Workstation-Setup | A standardised DevOps workstation baseline: Git, Azure CLI, Docker, Terraform and VS Code |
| Project | Contribution |
|---|---|
| cloudcost-cli | Added a findings summary command that rolls up FinOps policy findings per Azure resource and ranks them by combined cost impact, so teams know which resource to fix first |
I publish practical Azure implementation guides for engineers and teams.
| Certification | Exam | Earned | Verify |
|---|---|---|---|
| Microsoft Certified: DevOps Engineer Expert | AZ-400 | Jun 2026 | 🔗 |
| Microsoft Certified: Azure Administrator Associate | AZ-104 | Feb 2026 | 🔗 |
| Microsoft Certified: Azure Network Engineer Associate | AZ-700 | Jun 2025 | 🔗 |
| Credential | Area |
|---|---|
| Configure secure access to your workloads using Azure networking | Networking |
| Secure storage for Azure Files and Azure Blob Storage | Storage & Security |
| Deploy and configure Azure Monitor | Observability |
| Get started with cloud security and monitoring tasks | Security |
| Get started with Azure management tasks | Administration |
| Get started with identities and access using Microsoft Entra | Identity |
| Administer Active Directory Domain Services | Identity |
| Implement retention, eDiscovery, and Communication Compliance in Microsoft Purview | Compliance |
| Create and manage automated processes by using Power Automate | Automation |
- Location: Poland 🇵🇱
- Website: forsythfamous.pages.dev
- Professional Networking: LinkedIn
- Technical Writing: dev.to/forsyth_famous_
- Microsoft Learn: learning profile (completed learning paths and modules)
- Open to: Cloud & DevOps collaboration, technical consulting and new opportunities
Building reliable cloud infrastructure, one automated step at a time.


