<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: bernardo jose</title>
    <description>The latest articles on Forem by bernardo jose (@bernymack90).</description>
    <link>https://forem.com/bernymack90</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3672308%2Fe3aca2c6-b0df-4485-86fc-f17847e976f3.png</url>
      <title>Forem: bernardo jose</title>
      <link>https://forem.com/bernymack90</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/bernymack90"/>
    <language>en</language>
    <item>
      <title>Sharing my hands-on Enterprise Cloud Platform project</title>
      <dc:creator>bernardo jose</dc:creator>
      <pubDate>Fri, 16 Jan 2026 18:08:11 +0000</pubDate>
      <link>https://forem.com/bernymack90/sharing-my-hands-on-enterprise-cloud-platform-project-45i1</link>
      <guid>https://forem.com/bernymack90/sharing-my-hands-on-enterprise-cloud-platform-project-45i1</guid>
      <description>&lt;p&gt;I'm Bernardo, a Cloud &amp;amp; Network Engineer excited to join this DevOps community. I wanted to introduce myself by sharing a hands-on project I'm currently building that addresses real enterprise cloud challenges.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Problem:&lt;/strong&gt; Organizations face common pain points when adopting public cloud:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Security Misconfigurations&lt;/li&gt;
&lt;li&gt;Excessive Permissions &amp;amp; Privilege Escalation&lt;/li&gt;
&lt;li&gt;Security Alert Fatigue &amp;amp; Noise&lt;/li&gt;
&lt;li&gt;Lack of Unified Visibility&lt;/li&gt;
&lt;li&gt;Infrastructure Configuration Drift&lt;/li&gt;
&lt;li&gt;Governance &amp;amp; Policy Enforcement Gaps&lt;/li&gt;
&lt;li&gt;Compliance &amp;amp; Audit Overhead&lt;/li&gt;
&lt;li&gt;Network Segmentation Complexity&lt;/li&gt;
&lt;li&gt;Slow Incident Response&lt;/li&gt;
&lt;li&gt;Container &amp;amp; Kubernetes Security Gaps&lt;/li&gt;
&lt;li&gt;Data Exposure &amp;amp; Breach Risks&lt;/li&gt;
&lt;li&gt;Identity Sprawl &amp;amp; Credential Management&lt;/li&gt;
&lt;li&gt;Unpredictable Cloud Costs &amp;amp; Waste&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;My Solution:&lt;/strong&gt; A secure, multi-account Enterprise Cloud Platform on AWS built on security-by-design principles.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Architecture Components:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Foundation:&lt;/strong&gt; AWS Organizations with Service Control Policies (SCPs) for governance, IAM Identity Center for centralized access, and a multi-account strategy (Management, Security, Network, Prod, Dev, Monitor).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security Operations:&lt;/strong&gt; Centralized detection using GuardDuty and Security Hub, automated incident response via EventBridge/Lambda, and proactive compliance monitoring with AWS Config.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Zero-Trust Network:&lt;/strong&gt; Hub-and-spoke model using Transit Gateway with a centralized inspection VPC and Network Firewall. All traffic between Prod and Dev is blocked by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Full Automation:&lt;/strong&gt; Everything is defined as code via Terraform modules, with GitOps-driven application deployment using ArgoCD to EKS clusters.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unified Observability:&lt;/strong&gt; Central monitoring account with AWS Managed Prometheus and Grafana for infrastructure, application, and security metrics.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What I'd Love to Discuss:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Infrastructure Lifecycle:&lt;/strong&gt; CI/CD strategies for Terraform across multiple accounts, including state management, automated drift detection, and promotion workflows between environments&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitOps at Scale:&lt;/strong&gt; Experiences with multi-cluster ArgoCD synchronization, managing application sets, and handling rollbacks in production EKS environments&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Security Shift-Left:&lt;/strong&gt; Integrating IaC scanning (Checkov/tfsec) into pipelines and implementing policy-as-code before deployment&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network Patterns:&lt;/strong&gt; Zero-trust architectures for microservices in EKS, service mesh implementations, and managing VPC endpoints in automated environments.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Platform Engineering:&lt;/strong&gt; Building internal developer platforms that maintain security guardrails while enabling developer self-service through Terraform modules and GitOps&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Observability Integration:&lt;/strong&gt; Correlating deployment events (from ArgoCD) with application performance and security findings in centralized dashboards&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I'll be posting weekly progress updates as I work through the architecture diagrams and implementation phases so it would greatly appreciate any feedback on the approach!&lt;/p&gt;

&lt;p&gt;I'd be grateful for any insights, suggestions, or experiences you might share from similar implementations. Also happy to answer questions about any part of the architecture!&lt;/p&gt;

&lt;p&gt;Looking forward to learning from and contributing to this community.&lt;/p&gt;

</description>
      <category>aws</category>
      <category>devops</category>
      <category>security</category>
      <category>networking</category>
    </item>
    <item>
      <title>working on a Enterprise Cloud Platform with AI-Powered Security in AWS any recommendation on which phase of IR would AI integration be most impactful.</title>
      <dc:creator>bernardo jose</dc:creator>
      <pubDate>Fri, 16 Jan 2026 17:39:51 +0000</pubDate>
      <link>https://forem.com/bernymack90/working-on-a-enterprise-cloud-platform-with-ai-powered-security-in-aws-any-recommendation-on-which-53ld</link>
      <guid>https://forem.com/bernymack90/working-on-a-enterprise-cloud-platform-with-ai-powered-security-in-aws-any-recommendation-on-which-53ld</guid>
      <description></description>
      <category>ai</category>
      <category>aws</category>
      <category>discuss</category>
      <category>security</category>
    </item>
  </channel>
</rss>
