Learning in public — documenting my step-by-step journey through Linux, multi-cloud platforms, enterprise productivity suites, DevSecOps, and more hands-on practice.
This repository documents my hands-on learning journey through Linux administration, multi-cloud computing (Microsoft Azure, Amazon Web Services), enterprise productivity & identity platforms (Google Workspace, Microsoft 365), containerization, and DevSecOps. Every topic is accompanied by practical labs, notes, and real-world projects, helping me build a strong foundation in modern infrastructure, automation, and secure software delivery — on the path from Lead Developer to DevSecOps Engineer.
| Day | Date | Topic | Notes |
|---|---|---|---|
| Day 01 | May 14, 2026 | Linux Basics | View → |
| Day 02 | May 15, 2026 | File Management, Links & I/O Redirection | View → |
| Day 03 | May 18, 2026 | User Management, Groups & SSH | View → |
| Day 04 | May 19, 2026 | SSH Deep Dive & File Permissions | View → |
| Day 05 | May 20, 2026 | Special Permissions, umask & Apache Server | View → |
| Day 06 | May 21, 2026 | WordPress on LAMP Stack (Full Deployment) | View → |
| Day 07 | May 25, 2026 | Job Scheduling (at & cron) & Disk Management | View → |
| Day 08 | May 26, 2026 | Storage Partitioning & Process Management | View → |
| Day 09 | May 27, 2026 | Linux Administration Lab — File Ops, Users, Permissions, Services, Apache, Bash & Cron | View → |
| Day 10 | Jun 08, 2026 | Azure VMSS, Snapshots & Load Balancer Lab | View → |
| Day 11 | Jun 10, 2026 | Azure VMSS Autoscaling Lab | View → |
| Day 12 | Jun 16, 2026 | Azure Storage Services & File Share Lab | View → |
| Day 13 | Jun 18, 2026 | Azure App Service, Function App & Logic Apps | View → |
| Day 14 | Jun 19, 2026 | Azure Application Hosting Services | View → |
| Day 15 | Jun 22, 2026 | Azure CLI Virtual Machine Administration Lab | View → |
| Day 16 | Jun 23, 2026 | Azure Container Registry (ACR) & Azure Container Instances (ACI) | View → |
| Day 17 | Jun 24, 2026 | Azure Container Services & Application Hosting Services | View → |
| Day 18 | Jun 25, 2026 | Azure Security Services | View → |
| Day 19 | Jun 26, 2026 | Azure Database Services (SQL, MySQL & PostgreSQL) | View → |
| Day 20 | Jun 30, 2026 | DevSecOps CI/CD Project – Azure Edition | View Project → |
| Day 21 | Jun 30, 2026 | AWS Billing, Budgets & IAM Fundamentals | View → |
| Day 22 | Jul 02, 2026 | AWS EC2 Administration & EBS Snapshots | View → |
| Day 23 | Jul 03, 2026 | AWS Elastic IP, Application Load Balancer & Auto Scaling | View → |
| Day 24 | Jul 06, 2026 | AWS Elastic File System (EFS) Administration | View → |
| Day 25 | Jul 07, 2026 | IIS Web Server Hosting on Windows Server | View → |
| Day 26 | Jul 08, 2026 | AWS RDS Administration (MariaDB & Microsoft SQL Server) | View → |
| Day 27 | Jul 09, 2026 | Amazon DocumentDB & Apache Web Server Administration | View → |
| Day 28 | Jul 09, 2026 | Hosting a Website on Ubuntu Server using Apache | View → |
| Day 29 | Jul 10, 2026 | Amazon S3 Static Website Hosting | View → |
| Day 30 | Jul 13, 2026 | AWS Elastic Beanstalk Application Deployment | View → |
| Day 31 | Jul 15, 2026 | AWS Backup, Recycle Bin, Lambda & AWS Batch | View → |
| Day 32 | Jul 23, 2026 | Internship Task 3 — Hosting & Publishing a DB-Backed Website on AWS (RHEL 10, Nginx, SELinux, Certbot) | View Project → |
| Day 33 | Jul 14, 2026 | AWS Backup Administration | View → |
| Day 34 | Jul 16, 2026 | Amazon Recycle Bin Administration | View → |
| Day 35 | Jul 17, 2026 | AWS Lambda & Serverless Computing | View → |
| Day 36 | Jul 18, 2026 | AWS Batch Administration | View → |
| Day 37 | Jul 18, 2026 | Amazon Lightsail WordPress Deployment | View → |
| Day 38 | Jul 21, 2026 | Amazon Elastic Container Registry (Amazon ECR) | View → |
| Day 39 | Jul 22, 2026 | Amazon Elastic Kubernetes Service (Amazon EKS) | View → |
| Day 40 | Jul 23, 2026 | Amazon Athena Serverless Query Service | View → |
| Day 41 | Jul 23, 2026 | AWS Amplify Frontend Web Application Deployment | View → |
| Day 42 | Jul 24, 2026 | Amazon Simple Notification Service (SNS) | View → |
| Day 43 | Jul 24, 2026 | Amazon Simple Queue Service (SQS) | View → |
| Day 44 | Jul 24, 2026 | Amazon Simple Email Service (SES) | View → |
| Day 45 | Jul 25, 2026 | Automated S3-to-SNS Event Notification | View → |
| Day 46 | Jul 26, 2026 | Amazon Managed Service for Prometheus | View → |
| Day 47 | Jul 27, 2026 | Grafana Monitoring on AWS EC2 | View → |
| Day 48 | Jul 28, 2026 | Amazon ECS with AWS Fargate | View → |
| Day 49 | Jul 29, 2026 | AWS CloudTrail Monitoring and Governance | View → |
| Day 50 | Jul 06, 2026 | Amazon S3 Glacier & Lifecycle Management | View → |
| Day 51 | Jul 07, 2026 | Amazon RDS MySQL Administration | View → |
| Day 52 | Jul 08, 2026 | Amazon RDS PostgreSQL Administration | View → |
| Day 53 | Jul 09, 2026 | Amazon Aurora MySQL-Compatible Database | View → |
| Day 54 | Jul 09, 2026 | Amazon Neptune Graph Database | View → |
| Day 55 | Jul 09, 2026 | Amazon RDS MariaDB Administration | View → |
| Day 56 | Jul 09, 2026 | Amazon RDS Microsoft SQL Server Administration | View → |
| Day 57 | Jul 09, 2026 | Amazon DynamoDB Administration | View → |
| Day 58 | Jul 22, 2026 | Amazon WorkSpaces Virtual Desktop | View → |
| Day 59 | Aug 12, 2026 | Google Workspace Admin Fundamentals — OUs, Users, Groups, Resources & Buildings | View → |
| Day 60 | Aug 13, 2026 | Internship Task 6 — WaslaSoft POS Deployment (SQL Server, Windows, .NET WinForms) | View Project → |
| Day 61 | Aug 18, 2026 | Google Workspace Device & Application Management — MDM, App Controls & Audit Logs | View → |
| Day 62 | Aug 18, 2026 | Google Workspace Studio Email Automation — AI Summarization, Sheets Logging & Email Follow-Up | View → |
More sessions will be added as I progress.
| Date | Project | Description | Repository |
|---|---|---|---|
| May 2026 | SSH Security Checker | Bash-based SSH security auditing tool for Linux hardening. | View → |
| Jun 2026 | WordPress LAMP Deployment | Complete WordPress deployment on a Linux LAMP stack. | View → |
| Jun 2026 | Secure DevSecOps Pipeline v2.0 | Production-style DevSecOps CI/CD pipeline featuring Docker, GitHub Actions, Ruff, Pytest, Bandit, pip-audit, Gitleaks, Trivy, GitHub Container Registry (GHCR), and automatic deployment to Azure Container Apps. | GitHub → |
| Jul 2026 | Terraform EC2 Lab | Infrastructure as Code (IaC) project demonstrating automated AWS EC2 provisioning using Terraform, including IAM authentication, Security Groups, SSH access, troubleshooting, and infrastructure lifecycle management. | GitHub → |
| Jul 2026 | SecureTrack — Cloud Deployment (Internship Task 3) | Full-stack MERN app (MongoDB, Express, React, Node.js) hosted end-to-end on AWS EC2 (RHEL 10): Nginx reverse proxy, self-hosted MongoDB with auth hardening, PM2 process management, SELinux troubleshooting, and a free SSL certificate via Certbot/Let's Encrypt on a No-IP dynamic domain. | GitHub → |
| Aug 2026 | WaslaSoft POS — Windows/SQL Server Deployment (Internship Task 6) | Deployed a commercial .NET WinForms POS system on Windows: SQL Server install/version troubleshooting (2014 → 2022 pivot after a Windows 11 24H2 prerequisite removal), SSMS database restore, Mixed Mode auth, and client configuration. Vendor code/data intentionally excluded — process and troubleshooting documented only. | View → |
cloud-linux-learning-journey/
├── README.md ← You are here
├── linux/
│ ├── day-01-basics.md ← Core commands, users, file ops
│ ├── day-02-file-management.md ← cp, mv, rm, links, I/O, grep, pipes
│ ├── day-03-users-groups-ssh.md ← useradd, groups, sudo, SSH keygen
│ ├── day-04-ssh-permissions.md ← SSH deep dive, chmod, chown
│ ├── day-05-permissions-apache.md ← SUID, SGID, sticky bit, umask, Apache
│ ├── day-06-wordpress-lamp.md ← Full LAMP stack + WordPress deployment
│ ├── day-07-scheduling-disk.md ← at, cron, df, du, lsblk, partitioning
│ ├── day-08-storage-processes.md ← fdisk, fstab, ps, kill, top, nice, jobs
│ ├── day-09-linux-admin-lab.md ← Consolidation lab: file ops, users, chmod, systemctl, Apache, bash scripts
│ └── assets/ ← Screenshots from lab sessions
├── cloud/
│ ├── azure/ ← Microsoft Azure (Day 10-19)
│ │ ├── day-10-azure-vmss-load-balancer.md ← VMSS, snapshots, load balancer & HA web lab
│ │ ├── day-11-vmss-autoscaling.md ← VMSS creation, autoscaling, stress testing
│ │ ├── day-12-azure-storage-services.md ← Azure storage services and file share lab
│ │ ├── day-13-app-service-function-logic-apps.md ← Azure App Service, Function App & Logic Apps
│ │ ├── day-14-azure-application-hosting-services.md ← Azure Application Hosting Services
│ │ ├── day-15-azure-cli-vm-lab.md ← Azure CLI VM creation, networking, NSG, SSH access
│ │ ├── day-16-azure-containerization-lab.md ← Azure Container Registry, Docker Images & Azure Container Instances
│ │ ├── day-17-azure-container-services-hosting.md ← Azure Container Services, AKS, Container Apps & Hosting Services
│ │ ├── day-18-azure-security-services.md ← Azure security, identity, networking & governance services
│ │ └── day-19-azure-database-services.md ← Azure SQL, MySQL & PostgreSQL Administration Labs
│ ├── aws/ ← Amazon Web Services (Day 21-58)
│ │ ├── day-21-aws-budgets-iam.md ← AWS Billing, Budgets, IAM Users
│ │ ├── day-22-aws-ec2-ebs.md ← EC2 Windows/Linux Administration & EBS Snapshots
│ │ ├── day-23-aws-networking-load-balancing.md ← Elastic IP, Auto Scaling Groups & Application Load Balancer
│ │ ├── day-24-aws-efs.md ← Elastic File System (EFS) Administration
│ │ ├── day-25-iis-web-server.md ← IIS Web Server Hosting on Windows Server
│ │ ├── day-26-aws-rds.md ← Amazon RDS (MariaDB & Microsoft SQL Server)
│ │ ├── day-27-aws-documentdb-apache.md ← Amazon DocumentDB & Apache Web Server Administration
│ │ ├── day-28-ubuntu-apache-web-hosting.md ← Ubuntu Server, Apache2, Virtual Hosts & Static Website Deployment
│ │ ├── day-29-aws-s3-static-website-hosting.md ← Amazon S3 Static Website Hosting & Deployment
│ │ ├── day-30-aws-elastic-beanstalk.md ← AWS Elastic Beanstalk Application Deployment
│ │ ├── day-31-aws-backup-lambda-batch.md ← AWS Backup, Recycle Bin, Lambda & AWS Batch
│ │ ├── day-33-aws-backup.md ← AWS Backup Administration
│ │ ├── day-34-aws-recycle-bin.md ← Amazon Recycle Bin Administration
│ │ ├── day-35-aws-lambda.md ← AWS Lambda & Serverless Computing
│ │ ├── day-36-aws-batch.md ← AWS Batch Administration
│ │ ├── day-37-amazon-lightsail.md ← Amazon Lightsail WordPress Deployment
│ │ ├── day-38-aws-ecr.md ← Amazon Elastic Container Registry (Amazon ECR)
│ │ ├── day-39-amazon-eks.md ← Amazon Elastic Kubernetes Service (Amazon EKS)
│ │ ├── day-40-amazon-athena.md ← Amazon Athena Serverless Query Service
│ │ ├── day-41-aws-amplify.md ← AWS Amplify Frontend Web Application Deployment
│ │ ├── day-42-amazon-sns.md ← Amazon Simple Notification Service (SNS)
│ │ ├── day-43-amazon-sqs.md ← Amazon Simple Queue Service (SQS)
│ │ ├── day-44-amazon-ses.md ← Amazon Simple Email Service (SES)
│ │ ├── day-45-s3-sns-event-notification.md ← Automated S3-to-SNS Event Notification
│ │ ├── day-46-aws-prometheus.md ← Amazon Managed Service for Prometheus
│ │ ├── day-47-grafana-monitoring.md ← Grafana Monitoring on AWS EC2
│ │ ├── day-48-aws-ecs.md ← Amazon ECS with AWS Fargate
│ │ ├── day-49-aws-cloudtrail.md ← AWS CloudTrail Monitoring and Governance
│ │ ├── day-50-aws-s3-glacier.md ← Amazon S3 Glacier & Lifecycle Management
│ │ ├── day-51-aws-rds-mysql.md ← Amazon RDS MySQL Administration
│ │ ├── day-52-aws-rds-postgresql.md ← Amazon RDS PostgreSQL Administration
│ │ ├── day-53-amazon-aurora.md ← Amazon Aurora MySQL-Compatible Database
│ │ ├── day-54-amazon-neptune.md ← Amazon Neptune Graph Database
│ │ ├── day-55-aws-rds-mariadb.md ← Amazon RDS MariaDB Administration
│ │ ├── day-56-aws-rds-sql-server.md ← Amazon RDS Microsoft SQL Server Administration
│ │ ├── day-57-aws-dynamodb.md ← Amazon DynamoDB Administration
│ │ └── day-58-amazon-workspaces.md ← Amazon WorkSpaces Virtual Desktop
│ ├── gws/ ← Google Workspace (starting Day 59)
│ │ ├── day-59-gws-admin-fundamentals.md ← OUs, Users, Groups, Resources & Buildings admin lab
│ │ ├── day-61-gws-device-application-management.md ← Device management, MDM policies, app controls & audit logs
│ │ └── day-62-gws-studio-email-automation.md ← Gmail automation, AI summarization, Sheets logging & email follow-up
│ ├── m365/ ← Microsoft 365 (upcoming)
│ │ └── README.md ← Placeholder — sessions logged as they happen
│ └── assets/ ← Screenshots from lab sessions
└── projects/
├── ssh-security-checker/ ← SSH security auditing project
├── wordpress-lab-report/ ← Install and configure wordpress
├── secure-devsecops-pipeline/ ← DevSecOps project overview (links to external repository below)
├── terraform-ec2-lab/ ← Terraform EC2 Lab overview & external repository link
├── securetrack/ ← SecureTrack deployment overview & external repository link
└── waslasoft-pos-deployment/ ← WaslaSoft POS deployment case study (internship task 6, sanitized)
External Repositories
- Secure DevSecOps Pipeline: https://github.com/eshansahad/secure-devsecops-pipeline
- Terraform EC2 Lab: https://github.com/eshansahad/terraform-ec2-lab
- SecureTrack: https://github.com/eshansahad/securetrack
A hands-on Linux security project that audits SSH configurations and checks for common security weaknesses.
Key Skills
- Linux Administration
- SSH Hardening
- Bash Scripting
- System Auditing
- DevSecOps Fundamentals
| Component | Details |
|---|---|
| Cloud Provider | AWS EC2 |
| OS | Red Hat Linux |
| Access Method | SSH from Windows CMD |
| Shell | Bash |
An end-to-end DevSecOps project built with Python, Flask, Docker, and GitHub Actions. The project demonstrates a secure CI/CD workflow integrating automated testing, security scanning, containerization, and container publishing.
Repository
https://github.com/eshansahad/secure-devsecops-pipeline
Highlights
- Multi-job GitHub Actions workflow
- Ruff code quality analysis
- Pytest automated testing
- Bandit SAST scanning
- pip-audit dependency scanning
- Gitleaks secret detection
- Docker containerization
- Trivy container security scanning
- GitHub Container Registry (GHCR)
- Azure Container Apps deployment
- Continuous Deployment (CD)
Skills Practiced
- DevSecOps
- Continuous Integration (CI)
- Continuous Deployment (CD)
- GitHub Actions
- Docker
- Container Security
- Microsoft Azure
- Azure Container Apps
- Secure Software Development
- Shift-Left Security
| Component | Details |
|---|---|
| Project | Secure DevSecOps Pipeline |
| Programming Language | Python 3.10 |
| Framework | Flask |
| Code Editor | Visual Studio Code |
| Version Control | Git & GitHub |
| Containerization | Docker & Docker Compose |
| CI/CD | GitHub Actions |
| Code Quality | Ruff |
| Unit Testing | Pytest |
| SAST | Bandit |
| Dependency Scanning | pip-audit |
| Secret Detection | Gitleaks |
| Container Security | Trivy |
| Container Registry | GitHub Container Registry (GHCR) |
| Operating System | Windows 11 |
| Future Deployment | Azure Container Apps / Azure Kubernetes Service (AKS) |
A hands-on Infrastructure as Code (IaC) project that provisions an Amazon EC2 instance using Terraform. The project demonstrates automated infrastructure deployment, secure AWS authentication, custom security group configuration, SSH connectivity, and infrastructure lifecycle management.
Repository
https://github.com/eshansahad/terraform-ec2-lab
Highlights
- Infrastructure as Code (IaC) using Terraform
- AWS CLI authentication with IAM user
- Automated EC2 instance provisioning
- Security Group creation and configuration
- Terraform variables and outputs
- SSH connectivity to Amazon Linux 2023
- Infrastructure planning with
terraform plan - Automated deployment using
terraform apply - Clean resource removal using
terraform destroy - Troubleshooting real-world Terraform deployment and AWS configuration issues
Skills Practiced
- Terraform
- Infrastructure as Code (IaC)
- Amazon EC2
- AWS IAM
- AWS CLI
- Security Groups
- SSH Administration
- Infrastructure Automation
- Cloud Resource Management
- AWS CLI
- Infrastructure Lifecycle Management
| Component | Details |
|---|---|
| Project | Terraform EC2 Lab |
| Cloud Provider | Amazon Web Services (AWS) |
| IaC Tool | Terraform |
| Compute Service | Amazon EC2 |
| Operating System | Amazon Linux 2023 |
| Authentication | AWS CLI (IAM User Access Keys) |
| Security | Security Groups |
| Access Method | SSH |
| Version Control | Git & GitHub |
| Development Environment | Windows 11 + PowerShell |
A full-stack MERN application (IT asset & incident tracker) deployed end-to-end on a self-managed AWS EC2 instance — source code, dependency installation, database hardening, web server configuration, domain setup, and SSL, documented as internship deployment task 3.
Repository
https://github.com/eshansahad/securetrack
Highlights
- AWS EC2 provisioning (Red Hat Enterprise Linux 10, t3.micro, Free Tier)
- SELinux troubleshooting — context labeling, booleans,
nameidiagnosis (chosen over the more commonly tutorialized Ubuntu path) - firewalld configuration for HTTP/HTTPS/SSH
- Self-hosted MongoDB 7.0 with authentication enabled and least-privilege users
- Nginx reverse proxy + static file serving
- PM2 process management with boot persistence
- Free dynamic DNS (No-IP) after troubleshooting a DuckDNS resolution failure
- SSL via Certbot / Let's Encrypt with verified auto-renewal
- Swap provisioning to resolve an out-of-memory frontend build on a 1GB RAM instance
- Found and fixed a self-registration privilege-escalation bug before hosting
Skills Practiced
- AWS EC2 Administration
- Red Hat Enterprise Linux (RHEL)
- SELinux
- firewalld
- Nginx Reverse Proxy Configuration
- MongoDB Administration & Hardening
- PM2 Process Management
- Certbot / Let's Encrypt SSL
- Dynamic DNS Configuration
- Full-Stack Deployment Troubleshooting
| Component | Details |
|---|---|
| Project | SecureTrack — IT Asset & Incident Tracker |
| Cloud Provider | AWS EC2 (Free Tier) |
| Operating System | Red Hat Enterprise Linux 10 |
| Web Server | Nginx (reverse proxy + static hosting) |
| Application Runtime | Node.js 18 + Express, managed by PM2 |
| Database | MongoDB 7.0 (self-hosted, authentication enabled) |
| Domain | No-IP free dynamic DNS |
| SSL | Let's Encrypt via Certbot, auto-renewal enabled |
| Version Control | Git & GitHub |
A commercial .NET WinForms POS system (Restaurant & Retail editions) deployed on a clean Windows machine as internship deployment task 6 — SQL Server installation and version troubleshooting, database restore, client configuration, and a documented pivot when the originally-specified SQL Server version turned out to be incompatible with the current Windows build. Vendor installer, source code, database backups, and license/API credentials are intentionally excluded from this write-up; see the note at the top of the linked page.
Documentation
Highlights
- SQL Server 2014 setup blocked by a fully-removed Windows PowerShell 2.0 dependency on Windows 11 24H2+
- Pivoted to SQL Server 2022 Express + SSMS rather than force an unsupported engine version
- Database restore via SSMS's Restore Files and Filegroups workflow
- Mixed Mode (SQL + Windows) authentication configuration
- Restaurant edition blocked by vendor license expiry after a successful DB connection — pivoted to Retail edition to keep validating the deployment path
- POS client configuration: printer roles, menu/table layout, user roles, catalog import
Skills Practiced
- Microsoft SQL Server Administration
- SQL Server Management Studio (SSMS)
- Windows Prerequisite & Compatibility Troubleshooting
- .NET WinForms Client Configuration
- Database Restore & Recovery
- POS Application Configuration
- Root-Cause Troubleshooting & Deployment Pivoting
| Component | Details |
|---|---|
| Project | WaslaSoft POS — Restaurant & Retail Deployment |
| Application Type | .NET WinForms |
| Database Engine | SQL Server 2022 Express (pivoted from SQL Server 2014) |
| DB Tooling | SQL Server Management Studio (SSMS) |
| Authentication Mode | Mixed Mode (SQL + Windows) |
| Operating System | Windows 11, 24H2 |
| Version Control | Git & GitHub (documentation only) |
A structured overview of completed and pending topics across Linux, multi-cloud platforms (Azure, AWS), enterprise productivity suites (Google Workspace, Microsoft 365), DevSecOps, and related infrastructure skills.
- Linux basics — commands, users, file operations
- File management —
cp,mv,rm, hard/soft links, I/O redirection,grep, pipes - User & group management —
useradd,passwd,sudo, SSH key authentication - SSH deep dive & file permissions —
sshd_config, root login,chmod,chown - Special permissions & Apache — SUID, SGID, sticky bit,
umask,httpd - WordPress LAMP deployment — Apache, PHP 8.3, MariaDB, WordPress, SELinux, backups
- Job scheduling & disk management —
at,cron,df,du,lsblk,fdisk,fstab - Storage partitioning & process management —
fdisk,fstab,ps, kill signals,top,nice - Linux administration lab — file ops, user/group management,
chmod,systemctl, Apache, bash scripting, cron - Networking —
ip,ss,ping,curl,nmcli - SSH security checker — Bash-based SSH security auditing project
- LVM — Logical Volume Manager
- Shell scripting —
.shfiles, variables, loops, conditionals
- Azure fundamentals — ARM, RBAC, IAM, scopes, Microsoft Entra ID
- Azure CLI fundamentals
- Azure CLI virtual machine deployment
- Virtual networks & subnets using Azure CLI
- Network Security Groups (NSG)
- Linux VM administration via SSH
- Cloud architecture — real-world project
- Azure VM Scale Sets (VMSS) & autoscaling
- Azure VMSS, snapshots & load balancer lab
- Azure monitoring & CPU-based scaling rules
- Azure load testing with stress utility
- Storage accounts, blobs & file shares
- Storage explorer
- Storage migration tools
- Azure database fundamentals
- Docker fundamentals
- Container images & Dockerfile
- Container orchestration
- Azure Container Registry (ACR)
- Azure Container Instances (ACI)
- Azure Kubernetes Service (AKS)
- Deploy containers from Docker Hub
- Push images to Azure Container Registry
- Containerized application deployment
- Kubernetes fundamentals
- Kubernetes (AKS) — advanced
- Azure App Service
- Azure Function App
- Azure Logic Apps
- Azure Spring Apps
- Azure Container Apps
- Azure Static Web Apps
- Serverless computing basics
- Workflow automation with Azure Pipelines
- Hosting service comparison
- Microsoft Entra ID
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Azure Key Vault
- Azure Firewall
- Network Security Groups (NSG)
- Azure DDoS Protection
- Azure Web Application Firewall (WAF)
- Azure Bastion
- Azure Policy
- Azure Monitor
- Microsoft Purview
- Azure SQL Database
- Azure SQL Query Editor
- Azure Database for MySQL
- Azure Database for PostgreSQL
- Flexible Server
- Firewall rules
- Azure Cloud Shell
- SQL table creation
- Data insertion & retrieval
- Database administration
- Python Flask application
- Docker containerization
- Docker Compose
- GitHub Actions CI/CD
- Ruff code quality analysis
- Pytest unit testing
- Bandit static application security testing (SAST)
- pip-audit dependency scanning
- Gitleaks secret detection
- Trivy container vulnerability scanning
- GitHub Container Registry (GHCR)
- Release management (v2.0.0)
- Azure Container Apps deployment
- Continuous deployment using GitHub Actions
- AWS Account setup
- AWS Billing & Cost Management
- AWS Budgets
- Budget Alerts & Notifications
- IAM Users
- IAM Roles
- IAM Policies
- STS AssumeRole
- Principle of Least Privilege
- Amazon EC2 Linux Instance
- Amazon EC2 Windows Server
- SSH Connectivity
- RDP Connectivity
- EC2 Instance Connect
- AWS Systems Manager (SSM) Session Manager
- EC2 Serial Console
- Security Groups
- User Data Bootstrapping
- AWS Elastic Beanstalk
- Platform as a Service (PaaS)
- Application Deployment
- Environment Management
- AWS Lambda
- Serverless Computing
- Lambda Functions
- CloudWatch Logs
- AWS Batch
- Compute Environments
- Job Queues
- Job Definitions
- Batch Job Execution
- AWS Backup
- Backup Vaults
- Backup Plans
- Backup Scheduling
- Backup Recovery
- Amazon Recycle Bin
- Snapshot Protection
- Snapshot Recovery
- Amazon EBS
- EBS Snapshots
- Restore Volume from Snapshot
- Attach Additional EBS Volumes
- Amazon EFS
- Amazon RDS
- Amazon DocumentDB
- Amazon S3
- S3 Bucket Creation
- Static Website Hosting
- Bucket Policies
- Elastic IP
- Application Load Balancer (ALB)
- Target Groups
- Health Checks
- Auto Scaling Groups
- High Availability across Availability Zones
- Apache HTTP Server
- IIS Web Server
- Public Access Configuration
- Website Deployment using Amazon S3
- AWS Elastic Beanstalk
- MariaDB
- Microsoft SQL Server
- Amazon DocumentDB
- CRUD Operations
- Red Hat Enterprise Linux (RHEL) 10 administration
- SELinux — context labeling, booleans,
nameidiagnosis - firewalld configuration
- Nginx reverse proxy & static file serving
- Self-hosted MongoDB hardening (auth, least-privilege users, localhost binding)
- PM2 process management & boot persistence
- Certbot / Let's Encrypt SSL with auto-renewal
- Dynamic DNS configuration (No-IP)
- Swap provisioning for low-RAM build environments
- Full-stack MERN production deployment
- Microsoft SQL Server installation & administration (2014 and 2022 Express)
- SQL Server version/prerequisite troubleshooting on modern Windows builds
- SQL Server Management Studio (SSMS) — database restore, filegroups
- Mixed Mode authentication configuration
- .NET WinForms client-to-database configuration
- Commercial POS application configuration & deployment documentation
- Google Admin Console — organizational units, users, groups
- User lifecycle — provisioning, OU transfers, suspension & restoration
- Bulk user provisioning via CSV upload
- Google Groups — access levels, restricted mailing lists
- Buildings & resources — bookable equipment and meeting rooms
- Endpoint management — device registration, MDM policies & device security
- Google Workspace application management — core app access and OU-scoped settings
- Web & mobile application controls — allowed, blocked & OU-scoped access
- Third-party application access — API Controls and OAuth app review
- Reporting & audit logs — device and application activity
- Workspace Studio — Gmail event triggers and workflow automation
- AI-assisted email summarization — Gemini/Workspace AI workflow step
- Google Sheets automation — structured request logging
- Automated email follow-up — confirmation/reply workflow
- Identity & access — 2-Step Verification, SSO
- Gmail administration — routing, DKIM/SPF/DMARC, security settings
- Google Drive & Shared Drives — sharing policies, DLP
- Google Calendar administration (beyond resource booking)
- Google Meet administration & policies
- Google Vault — retention & eDiscovery
- Apps Script automation basics
- Microsoft 365 Admin Center — tenant setup, licensing
- Microsoft Entra ID user & group management in M365 context
- Exchange Online administration — mail flow, transport rules
- SharePoint Online & OneDrive administration
- Microsoft Teams administration & policies
- Conditional Access & Multi-Factor Authentication (MFA)
- Microsoft Purview — compliance & data governance
- Microsoft Defender for Office 365
- Intune — mobile device & app management
- Power Automate basics
- Terraform installation & configuration
- AWS provider authentication
- Terraform variables and outputs
- Infrastructure provisioning using Terraform
- Amazon EC2 deployment
- Security Group configuration
- SSH connectivity
- Terraform workflow (
init,plan,apply,destroy) - Infrastructure cleanup using
terraform destroy
Building things in public keeps me accountable. Every commit is a proof of effort — not just learning, but showing up consistently.
Started: May 2026 — Updated regularly