Hari Paruchuri
Senior DevOps, Cloud Automation, and Infrastructure Engineering professional with 8+ years of experience designing, automating, securing, and operating cloud, Kubernetes, and platform infrastructure.
I work across infrastructure as code, CI/CD platforms, Kubernetes, automation controllers, Linux operations, policy-as-code, and cloud security. My focus is building repeatable engineering systems that reduce manual work, improve auditability, and make infrastructure delivery safer at scale.
Core Engineering Areas
| Area | Focus |
|---|---|
| Cloud Infrastructure | AWS infrastructure design, private connectivity, IAM, EC2, S3, VPC endpoints, encrypted storage, and controlled network access. |
| Multi-Cloud Engineering | AWS-first automation with working knowledge of GCP, GKE, Azure, and cross-cloud delivery patterns. |
| Kubernetes Platforms | Kubernetes, Amazon EKS, Google Kubernetes Engine, container runtimes, cluster operations, and platform delivery workflows. |
| Infrastructure as Code | Terraform modules, live repositories, remote state, reusable module patterns, release workflows, and policy-governed deployments. |
| Automation Platforms | AWX / Ansible Automation Platform configuration-as-code, execution environments, job templates, credentials, inventories, and team onboarding patterns. |
| Linux Automation | Ansible-based Linux operations, RHEL/Rocky hardening, CIS baselines, observability agents, service configuration, and operational runbooks. |
| CI/CD Engineering | GitLab CI/CD shared templates, protected workflows, validation stages, controlled apply/destroy jobs, artifact handling, and release automation. |
| Security and Governance | Checkov, OPA/Rego, secret scanning, least-privilege access, encrypted state, security baselines, and auditable change control. |
Current Platform Work
I am building a GitLab-based infrastructure automation portfolio that models an enterprise platform engineering structure.
Current work includes:
- Terraform module catalog under
tf-modules/aws - Terraform live deployments under
tf-live - AWS IPAM, VPC, security group, VPC endpoint, KMS, IAM, ECR, CloudWatch, and EKS modules
- EKS live foundation stack for governed Kubernetes platform infrastructure
- GitLab CI pipelines with validation, Rego policy checks, Checkov scanning, and release workflows
- AWX automation for private AWS EC2 management through AWS Systems Manager Session Manager
- AWX execution environment builds for AWS SSM and Kubernetes operations
- AWX EKS operations automation for runtime kubeconfig generation, validation, namespace bootstrap, and controlled Helm actions
- Ansible automation for Linux operations, RHEL 9 CIS hardening, observability, and lab infrastructure
- Kubernetes and container platform patterns for future EKS/GKE-based platform delivery
- GitLab group profile documentation for cloud, platform, bootstrap, infrastructure, AWX, and Ansible automation domains
The current repositories are still being developed and organized, but the target model is clear: reusable modules, governed pipelines, auditable automation, and scalable ownership boundaries.
Featured GitLab Groups
| Group | Focus |
|---|---|
| bootstrap_automation | Platform bootstrap automation, Terraform backend foundation, root encryption, and first-run control-plane setup. |
| cloud_automation | Terraform module catalog and live AWS infrastructure deployments for EC2, S3, VPC endpoints, and future cloud domains. |
| infra_automation | Infrastructure operations automation, including Ansible, AWX/AAP, Linux operations, and configuration management patterns. |
| platform_automation | Shared CI/CD pipelines, policy-as-code, runtime images, and platform delivery standards. |
Technical Stack
Cloud and Infrastructure
- AWS
- Google Cloud Platform
- Azure
- Terraform
- GitLab-managed Terraform state
- IAM, EC2, S3, VPC endpoints, KMS
- GKE, EKS, VPC networking, private connectivity
- Private infrastructure patterns with SSM-based access
Kubernetes and Containers
- Kubernetes
- Amazon EKS
- Google Kubernetes Engine
- Docker
- Podman
- Helm
- Argo CD patterns
- Container registries and execution environments
Automation and Configuration
- Ansible
- AWX / Red Hat Ansible Automation Platform
- Ansible execution environments
- AWS Systems Manager Session Manager
- Linux operations and hardening automation
- Automation Hub / collection-based automation patterns
CI/CD and Platform Tooling
- GitLab CI/CD
- GitHub Actions
- Docker / container registries
- Shared pipeline templates
- Protected branches and controlled promotion workflows
- Release automation and semantic versioning
- Pipeline policy enforcement
Security and Policy
- OPA / Rego
- Checkov
- Secret detection
- Least-privilege IAM
- Encrypted Terraform state
- CIS-aligned Linux hardening patterns
- Vault-oriented secret management patterns
- DevSecOps validation gates
Operating Systems
- RHEL
- Rocky Linux
- Linux platform administration
Advanced Automation Tooling
- Terraform module release workflows
- AWX/AAP controller configuration-as-code
- Ansible collections and execution environments
- OPA/Conftest policy checks
- Checkov IaC scanning
- GitLab container registry integration
- AWS SSM Session Manager automation
Engineering Principles
- Automate repeatable work instead of documenting manual steps forever.
- Keep infrastructure and configuration separated by clear ownership boundaries.
- Build modules as reusable internal products with examples, docs, validation, and releases.
- Prefer private, least-privilege, auditable access patterns over broad network exposure.
- Make CI/CD the control plane for validation, approval, deployment, and rollback evidence.
- Treat security, policy, and operational readiness as part of the delivery path, not afterthoughts.
- Design Kubernetes and cloud automation with repeatable platform patterns instead of one-off cluster or environment changes.
Representative Architecture Patterns
Developer / Platform Engineer
|
v
GitLab Repository
|
v
Shared CI/CD Pipeline
|
v
Terraform fmt / validate / plan
|
v
Checkov + OPA/Rego Policy Checks
|
v
Manual Approval
|
v
Terraform Apply
|
v
AWS Infrastructure and Kubernetes Platform Outputs
|
v
AWX Inventory / Job Template
|
v
Ansible Execution Environment
|
v
Private EC2 Management Through AWS SSM / EKS Operations Through Kubernetes APIWhat I Build For
- Repeatable cloud delivery
- Secure infrastructure defaults
- Clear operational ownership
- Auditable CI/CD workflows
- Scalable Terraform module design
- Practical automation that can survive real operations
Contact
For professional networking or infrastructure automation discussions:
Personal projects
View all- Loading