The challenge
Keeping control of settings spread across several consoles: defining them, reviewing changes before application and spotting drift.
What I did
Cloudflare: publishing and protection
DNS and zone settings, tunnels and service publishing, WAF rules, Zero Trust access and WARP profiles, cache and redirects. Each configuration domain has its own management scope; existing resources are imported before changes.
GitHub and NetBird: shared rules
GitHub security settings and workflow permissions; NetBird groups, network policies and nameservers. Automated change previews and drift checks, with guards for resources and vital traffic flows.
Dokploy, Infisical and R2: controlled delivery
Pulumi providers for Dokploy configuration and deployments, including this portfolio and the Codbip EDR cockpit. Secrets read from Infisical at execution time, encrypted Pulumi state on R2 and verification of the version actually served after deployment.
What it can bring you
Infrastructure that can be reviewed and reproduced: code, change previews and drift checks provide concrete evidence for a review or audit.
Related expertise · Automation & reliability
What you get
- Infrastructure described and versioned as code
- CI/CD with deployment evidence
- Tested backups
- Operations runbooks
