Cloud Engineer · In Progress

Building cloud infrastructure
one layer at a time.

I came from mobile development and decided to go deep into cloud engineering — not through courses alone, but by building real infrastructure with my hands and understanding the why behind every decision I make.

This site documents that journey. Not a finished product — a record of what I've built, what I've broken, and what I've learned from both.

Most people learn cloud by following tutorials and getting things to work. I am more interested in understanding why things work — and more importantly, why they break.

"Never just hand over commands without understanding what they do first."

Every resource I deploy, I can explain from first principles. Every tool I use, I understand the problem it solves. I believe the engineers who build the most reliable systems are the ones who spent time deliberately breaking things in controlled environments before touching anything that matters.

month 1 — foundations
Week 1 — Networking & Compute EC2, Nginx, Security Groups, VPC from scratch, intentional misconfiguration
done
Week 2 — Storage & IAM S3 versioning, bucket policies, IAM roles, EC2 to S3 without hardcoded credentials
done
Week 3 — Static Website on AWS S3 + CloudFront + OAC + Route 53 + ACM — this site runs on this stack
done
Week 4 — Linux & Scripting Process management, log monitoring, bash scripting, AWS CLI automation
done
month 2 — automation
Week 5 — Terraform Infrastructure as code — rebuilt the entire VPC architecture in config files
done
Week 6 — CI/CD Pipelines GitHub Actions — push code, site deploys automatically, cache invalidated
done
Week 7 — Docker & Containers Container fundamentals, custom images, Dockerfile best practices, layer caching
done
Week 8 — First Backend API Python REST API, containerised with Docker, deployed on EC2
done
month 3 — real architecture
Week 9 — Databases RDS PostgreSQL in a private subnet, connected to the API, data persists across restarts
done
Week 10 — Serverless Lambda, S3 triggers, API Gateway
in progress
Week 11 — Monitoring CloudWatch dashboards, alarms, structured logging
upcoming
Week 12 — Capstone: Digital Product Delivery System Full cloud-native system for selling and delivering digital products — S3, CloudFront, API, database, Lambda, CI/CD
upcoming
This Website
Hosted on S3, served globally via CloudFront, HTTPS enforced with ACM, custom domain via Route 53. Deployed automatically on every git push via GitHub Actions. Zero manual steps to publish changes.
S3 CloudFront Route 53 ACM GitHub Actions
Custom VPC Architecture
Built a full VPC from scratch — public and private subnets, internet gateway, route tables, security groups. First manually to understand every layer, then rebuilt entirely in Terraform as infrastructure as code.
VPC EC2 Terraform Networking
Secure S3 Access Pattern
EC2 instance reading from S3 using IAM roles and instance profiles — no hardcoded credentials anywhere. Bucket policies, versioning, and the metadata endpoint all understood and configured correctly.
IAM S3 EC2 Security
Notes REST API with Database
Python REST API built with FastAPI, containerised with Docker, deployed on EC2. Connected to RDS PostgreSQL in a private subnet — data persists across container restarts. Entire infrastructure provisioned automatically via Terraform with zero manual server configuration after terraform apply.
Python FastAPI Docker EC2 RDS SQLAlchemy Terraform
URLSync
A self-hosted alternative to Brave Sync — one small VPS, Postgres, and Tailscale, built to practice the parts of cloud infrastructure that don't show up in a tutorial: adopting a server that already exists, and debugging tools that quietly stop working.
Python FastAPI Docker Linode VPS PostgreSQL Terraform
less more
    email curious@iluvi.xyz github github.com/geocyt site iluvi.xyz based available remotely