Achmad Nurul Fauzie
DevOps & Infrastructure Engineer
Results-oriented DevOps Engineer with comprehensive expertise in architecting Cloud Native solutions and orchestrating Self-Managed Kubernetes clusters (Kubeadm) on AWS and GCP. Expert in driving DevSecOps adoption by integrating secret management (Vault) and security hardening standards into the deployment lifecycle.
Core Skills
Technologies & tools I work with every day
Experience
My professional journey
Eliminated critical kubelet disk pressure outages by re-architecting eviction settings and implementing proactive monitoring thresholds.
Migrated artifact storage from Nexus to a dedicated Harbor registry, reducing cluster storage bottlenecks significantly.
Executed zero-downtime migration from Longhorn to NFS for Persistent Volume Claims (PVC).
Engineered robust CI/CD pipelines using Jenkins and GitHub Actions, standardizing clone-build-deploy workflows with automated notifications.
Hardened HTTP security headers across all web assets and established secure site-to-site administration using NetBird (WireGuard) VPNs.
Architected a bespoke Vanilla Kubernetes cluster on AWS EC2 using Kubeadm, with custom VPC topology and public/private subnet isolation.
Deployed hybrid load balancing with AWS ALB (Layer 7) and HAProxy (Layer 4), integrated with MetalLB for internal service exposure.
Implemented HPA for dynamic workload management and conducted rigorous stress testing with K6 to validate cluster stability.
Built a full monitoring stack with Prometheus and Node Exporter, visualized via custom Grafana dashboards.
Managed complex Kubernetes objects (Deployments, Services, Ingress, Secrets) and standardized 100% of deployments using custom Helm Charts.
Configured Istio Service Mesh (Gateway, VirtualService) for sophisticated traffic routing and secured secret management using HashiCorp Vault.
Built and maintained Jenkins pipelines for Development and Production environments with automated kubeconfig wiring for secure deployments.
Operated GCP resources (GKE, Load Balancing, Cloud Armor) and managed DNS via Cloudflare. Deployed MinIO and Redis Sentinel via Helm.
Enforced enterprise security standardization across endpoint infrastructure, ensuring alignment with banking regulatory protocols.
Administered hybrid Linux/Windows environments, resolving complex connectivity, database, and server hardware issues.
Managed mail server configurations and maintained detailed technical documentation for incident resolution and ticket management.
Certifications
Professional credentials and training
Education
Recent Projects
Latest articles & project write-ups
Get In Touch
Open to new opportunities and collaborations