Skip to content
View ej-east's full-sized avatar
馃殺
kubectl rollout restart deployment/elijah.fyi --selector=env=prod
馃殺
kubectl rollout restart deployment/elijah.fyi --selector=env=prod

Block or report ej-east

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don鈥檛 include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user鈥檚 behavior. Learn more about reporting abuse.

Report abuse
ej-east/README.md

Hey, I'm EJ

I build cloud platforms and compliance automation in FedRAMP High environments. I work across AWS, AWS GovCloud, Azure, and GCP. If it's hard and repetitive, I make it boring.

Website LinkedIn

What I do

  • Provision cloud infrastructure with Terraform across AWS, AWS GovCloud, Azure, and GCP
  • Deploy and manage Kubernetes workloads with Helm, Argo CD, and GitHub Actions
  • Build CI/CD pipelines that replace hour-long manual processes with repeatable automation
  • Add security controls with policy as code, vulnerability scanning, signed images, SBOMs, and attestations
  • Build and operate a Kubernetes homelab focused on security, secrets, and learning how things fail
  • If I do it twice, I automate it.

Projects

My third Kubernetes homelab iteration. Burns runs a three-node Ubuntu/K3s cluster with Terraform-managed Oracle Cloud infrastructure and Argo CD managing application deployments.

I use separate Traefik instances for public and private traffic. Tailscale handles private network access. Other services include Authentik, cert-manager, External Secrets, 1Password Connect, CloudNativePG, OpenSearch, and Fluent Bit.

A collection of hardened, reproducible container images and reusable GitHub Actions workflows.

The pipeline builds multi-architecture images, scans them with Trivy and OpenSCAP, signs them with Cosign, and publishes SBOM attestations with Syft. It currently produces SLSA Build Level 2 provenance.

What I work with

Cloud and infrastructure: AWS, AWS GovCloud, Azure, GCP, Terraform, Docker, Kubernetes, Linux

GitOps and delivery: Argo CD, Helm, GitHub Actions, ECR

Security: FedRAMP, NIST 800-53, OPA Gatekeeper, Wiz, Zscaler, Trivy, Cosign, Syft, OpenSCAP, SBOMs

Languages: Python, Bash, Rust

Certifications

AWS Cloud Practitioner 路 Google Associate Cloud Engineer 路 HashiCorp Terraform Associate 路 CompTIA Security+ 路 PCAP (Python)

Pinned Loading

  1. burns burns Public

    homelab cluster

    HCL

  2. redoubt redoubt Public

    Hardened container images and reusable CI workflows with cosign signing and SBOM attestation.

    Dockerfile 1

  3. lisa-cluster lisa-cluster Public archive

    GitOps-managed homelab Kubernetes cluster running on k3s with ArgoCD, Vault, Authentik SSO, Prometheus/Grafana, and automated certificate management.

    HCL 1