Delivery portfolio
Project case studies
Representative programmes across cloud landing zones, data centre fabric automation, private cloud provisioning,
and intent-based security orchestration — delivered with Infrastructure-as-Code, policy guardrails, and CI/CD discipline.
Cloud & Security
Azure Hub-and-Spoke Landing Zone with Palo Alto VM-Series — Terraform & Ansible
Infrastructure-as-Code automation of a production-grade Azure hub-and-spoke network platform with Palo Alto Networks
VM-Series firewalls — replacing manual vNet, firewall, BGP, and SASE integration with repeatable, version-controlled
Terraform deployments, policy guardrails, and CI/CD orchestration across multi-region Active/Passive HA.
- Automated three-hub topology (Hub-CONN connectivity, Hub-OBEW east-west/outbound, Hub-INBO inbound DMZ) with zone-aware VM-Series HA pairs (UK South/UK West), Azure Route Server BGP peering (ASN 65515), ExpressRoute/VPN Gateway, Prisma Access SASE integration, VNet peering, NSG templates, private DNS zones, Key Vault, Log Analytics diagnostics, spoke onboarding (DNS, NTP, workload VNets), and micro-segmentation using modular Terraform HCL and the azurerm provider across dedicated HCP Terraform Cloud workspaces.
- End-to-end Azure DevOps pipeline suite (PR Validation → Security Scanning → Plan → Manual Approval → Apply → Post-Deploy Validation) with gitleaks secret scanning, mandatory tag/region policy gates, scheduled Terraform drift detection, state backup/migration, and Ansible Day-2 playbooks for PAN-OS syslog configuration and spoke NTP client hardening across Dev and Production environments with full Git version control, ADRs, and SIT/UAT/DR test evidence.
Technology
- Terraform HCL
- Palo Alto VM-Series (PAN-OS 11.x)
- Strata Cloud Manager (SCM)
- Prisma Access
- Azure Route Server
- ExpressRoute
- Ansible (paloaltonetworks.panos)
- Azure DevOps Pipelines
- HCP Terraform Cloud
- Azure Key Vault
- Log Analytics / Azure Monitor
- Bicep
- PowerShell/Bash
Data Centre IaC
Cisco Data Center Fabric Infrastructure Automation with Terraform & Python
Infrastructure-as-Code automation of Cisco UCS and Nexus data center fabric onboarding — replacing manual Intersight,
NX-OS CLI, and UCS Manager configuration with repeatable, version-controlled Terraform deployments, policy guardrails,
and CI/CD orchestration.
- Automated Nexus 9300-GX2 fabric (VPC domains, peer-links, port-channels, VLANs, SVIs, HSRP), UCS X-Series compute policies (BIOS, boot, disk, LAN connectivity, vNIC templates), and server profile template assignment using modular Terraform HCL with the CiscoDevNet/intersight and CiscoDevNet/nxos providers across multi-datacenter, multi-pod deployments.
- End-to-end Azure DevOps pipeline (Lint → Pre-Checks → Plan → Approve → Apply → Validate) with HashiCorp Sentinel and Checkov policy-as-code, scheduled drift detection, and Python Day-2 scripts for API reachability checks, post-deploy fabric health validation, and zero-touch blade/switch replacement across Dev and Production environments with full Git version control of all infrastructure changes.
Technology
- Terraform HCL
- Cisco UCS X-Series
- UCS 6454 Fabric Interconnects
- Nexus 9300-GX2
- Cisco Intersight
- Python
- Azure DevOps Pipelines
- HCP Terraform
- HashiCorp Sentinel
- Checkov
- tflint
Private Cloud IaC
VMware Cloud Foundation (VCF) Infrastructure Automation with Terraform & Ansible
Infrastructure-as-Code automation of VMware Cloud Foundation (VCF) private cloud provisioning — replacing manual vCenter,
NSX, and SDDC Manager configuration with repeatable, version-controlled Terraform deployments, policy guardrails,
and CI/CD orchestration.
- Automated workload domain, NSX overlay networking (segments, T1 gateways, NAT/DHCP), zero-trust micro-segmentation (DFW), vSAN storage policies, VM lifecycle, and Tanzu Kubernetes provisioning using modular Terraform HCL and the hashicorp/vsphere and vmware/nsxt providers.
- End-to-end Azure DevOps pipeline (Validate → Security → Plan → Approve → Apply) with HashiCorp Sentinel and OPA policy-as-code, scheduled drift detection, and Ansible Day-2 playbooks for OS hardening, compliance checks, and VCF stack health validation across Dev and Production environments with full Git version control of all infrastructure changes.
Technology
- Terraform HCL
- VMware Cloud Foundation 5.x
- vSphere 8
- NSX 4.x
- vSAN 8
- Ansible
- Azure DevOps Pipelines
- HCP Terraform
- HashiCorp Sentinel
- Open Policy Agent (OPA)
AI Firewall Automation
RuleForgeAI — Intent-Based Multi-Vendor Firewall Orchestration Platform
Intent-based firewall change automation platform — replacing manual, multi-day Palo Alto, FortiGate, Juniper, and Cisco FMC
rule changes with YAML-declared connectivity intents, AI-assisted translation, deterministic policy guardrails, dual-gate
human approval, and atomic multi-vendor commit with full audit traceability.
- Built end-to-end intent lifecycle pipeline (ingest → enrich → validate → AI resolve → guardrail gate → dry-run → InfoSec/NetEng approval → execute → post-commit traffic validation) with modular vendor adapters, Celery worker queues per vendor, mandatory dry-run enforcement, SHA-256 hash-chain audit ledger, and drift detection across Panorama, SCM, FortiGate, Juniper NETCONF, and Cisco FMC estates.
- Designed and deployed production Azure infrastructure (Container Apps, PostgreSQL Flexible Server, Redis, Key Vault, Log Analytics, Application Insights) via modular Terraform with HCP Terraform remote execution; implemented split CI/CD with GitHub Actions (lint, mypy, 400+ pytest suite, Bandit SAST, pip-audit/npm audit, PostgreSQL integration tests) and Azure DevOps CD (Terraform Plan → Approve → Apply → Docker build/push → Container Apps deploy → smoke test) with Prometheus alerting and ServiceNow/Tufin/SolarWinds integrations.
Technology
- Python 3.12
- FastAPI
- Celery
- Redis
- PostgreSQL
- React/TypeScript
- Terraform HCL
- Azure Container Apps
- Azure Key Vault
- HCP Terraform
- GitHub Actions
- Azure DevOps Pipelines
- Ollama (llama3.2)
- Palo Alto Panorama/SCM
- FortiGate
- Juniper SRX
- Cisco FMC
- Tufin SecureTrack
- SolarWinds Orion
- ServiceNow
- Prometheus