πŸš€ Automating Infrastructure at Scale

Hi, I'm
Rohit Vishwakarma

I am a |

Building scalable infrastructure and automating deployments
LinkedIn
Profile
●Available for Freelance Work
β˜…1.8 Years Exp
πŸ’Ό
1.8
Years Experience
πŸš€
10+
Projects Completed
☁️
10+
Cloud Deployments
πŸ“œ
3+
Certifications

Recent Achievements

Recent problems solved, lessons learned, and features shipped.

πŸš€
ShippedAug 17 β€’ 3:37 PM
Automated EventBridge & CloudWatch Monitoring System for ECS & RDS

Architected comprehensive infrastructure monitoring and event-driven alert systems across ECS, RDS, ALB, and ElastiCache Redis services.

Key Implementations:

  • Configured EventBridge event pattern rules to trigger real-time SNS notifications during ECS deployment rollbacks and container state changes.
  • Built standardized alarm modules for ECS CPU/Memory utilization, ALB 5xx error rates, RDS storage thresholds, and ElastiCache Redis memory limits.
  • Integrated SNS topics with subscriber endpoints for immediate engineering team notification upon critical infrastructure failures.

Outcome: Reduced Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) for infrastructure outages, providing instant visibility into deployment rollbacks and resource exhaustion.

AWSCloudWatchEventBridgeSNSMonitoringDevOps
βš™οΈ
ImprovedAug 14 β€’ 1:48 PM
AWS WAF Web Application Firewall Integration & Active Threat Defense

Implemented AWS WAF v2 perimeter protection across application load balancers to defend infrastructure against web-based exploits and automated attacks.

Key Implementations:

  • Deployed AWS WAF v2 Web ACLs operating in active BLOCKING mode protecting ingress Application Load Balancers.
  • Configured managed rule sets for OWASP Top 10 vulnerabilities, SQL Injection (SQLi), Cross-Site Scripting (XSS), and IP rate limiting.
  • Attached automated CloudWatch metrics and alarm thresholds to track blocked requests and detect layer-7 DDoS attempts in real time.
  • Standardized WAF module architecture for seamless reuse across Dev, QA, Stage, and Production environments.

Outcome: Established active perimeter defense protecting production application services from malicious web traffic, SQL injection attacks, and HTTP flood attempts.

AWS WAFSecurityALBOWASPPerimeter DefenseCloudWatch
βœ…
SolvedAug 12 β€’ 8:47 PM
Zero-PII Leakage Database Audit Logging & Parameterized KMS Encryption

Implemented PII-compliant database logging controls and KMS encryption parameterization for PostgreSQL RDS instances across production and staging environments.

Key Implementations:

  • Configured PostgreSQL RDS custom parameter groups enforcing log_statement = ddl across production (prod, prod-bayer) and staging environments.
  • Prevented sensitive user PII from leaking into CloudWatch logs by restricting logging strictly to DDL schema modifications (excluding DML queries containing user data).
  • Parameterized KMS encryption key aliases to enable strict cryptographic isolation between core production and enterprise client environments (prod-bayer).
  • Enabled automated RDS snapshot tag copying and RDS Performance Insights for proactive database health monitoring.

Outcome: Ensured strict compliance with data privacy regulations (GDPR/HIPAA) by preventing sensitive customer PII exposure in logs while preserving full schema auditability.

AWSRDSPostgreSQLData PrivacyKMSCompliance
βœ…
SolvedAug 05 β€’ 10:34 PM
Zero-Trust Network Isolation & ECS Application Migration to Private Subnets

Redesigned multi-environment ECS application infrastructure to transition from public container execution to a Zero-Trust private subnet deployment model.

Key Implementations:

  • Migrated ECS application and frontend containers into isolated VPC private subnets across Dev, QA, Stage, and Production environments.
  • Configured public Application Load Balancers (ALB) as ingress proxies with strict security group egress/ingress rules, completely eliminating direct Internet exposure for ECS tasks.
  • Configured ECS deployment circuit breakers to automatically detect and roll back failed container deployments without service downtime.
  • Standardized strict HTTP 200 OK target group health check matchers across all ALB modules to ensure immediate traffic routing away from unhealthy tasks.

Outcome: Eliminated Internet attack surfaces for core container workloads, ensuring application tasks run securely within private network boundaries while maintaining zero-downtime deployment resilience.

AWSECSVPCNetworkingDockerSecurity

Core Technologies

My preferred stack for building robust and scalable solutions

Kubernetes
Kubernetes
GitHub
GitHub
Git
Git
Jenkins
Jenkins
Terraform
Terraform
AWS
AWS
Docker
Docker
PostgreSQL
PostgreSQL
MySQL
MySQL
Bash
Bash
Python
Python
πŸ’Ό

Experience

Explore my professional journey, roles, and key achievements across different companies.

View Timeline
πŸŽ“

Education

Check out my academic background, degrees, and professional certifications.

View Credentials
⚑

Skills

Dive into my technical arsenal, tools, and proficiency levels.

View Arsenal
πŸš€

Projects

Browse through my portfolio of projects, applications, and solutions.

View Portfolio
πŸ“œ

Certifications

View my professional certifications, courses, and internships.

View Credentials