Available for Cloud & DevOps roles

Samuel Akosa Onyejekwe

Cloud & DevOps Engineer

Cloud & DevOps Engineer who designs, automates and secures production-grade cloud infrastructure on AWS and Azure. Hands-on building containerised microservices on Kubernetes (EKS), provisioning infrastructure as code with Terraform, and delivering CI/CD pipelines with GitHub Actions and Jenkins. Practises DevSecOps end-to-end — shift-left security scanning, least-privilege IAM, and full observability with Prometheus and Grafana. Backed by 9+ years of engineering in high-reliability offshore environments, bringing an automation mindset, operational rigour and strong problem-solving to every deployment.

Limassol, Cyprus EU work-authorised (Cypriot work permit) samuelonyejekwe852@gmail.com +357 95713273
Capabilities

Technical skills

The full toolchain I work with day to day — every item below is demonstrated in a project or a documented lab on this site, not just listed.

Cloud Platforms

AWS EC2S3LambdaEKSECRAPI GatewayRDS / AuroraDynamoDBCloudFrontALB / NLBRoute 53ACMVPCIAMCloudWatchRekognitionEventBridgeCloudFormationSystems Manager (SSM)Azure App ServiceAzure SQLBlob StorageAzure FunctionsVNet / NSGEntra IDAzure RBACKey Vault

Containers & Orchestration

DockerDocker ComposeDocker SwarmKubernetes (EKS)HelmKustomizeKEDAHPAcert-managerArgo CD (GitOps)Kyverno policy engine

Infrastructure as Code

TerraformTerraform remote state (S3 + DynamoDB locking)AWS CloudFormationImmutable infrastructureModular IaCEC2 user-data bootstrapping

CI/CD & Automation

GitHub ActionsJenkins (freestyle, pipeline, multibranch)JenkinsfileGitOps deliveryWebhook-driven buildsImmutable image tagsManual production approval gatesGit branching, PRs & code review

DevSecOps & Security

Trivy image / filesystem / IaC scanningGitleaks secret scanningShift-left security gatesLeast-privilege IAMIRSA (pod-level IAM)IMDSv2Kubernetes NetworkPolicies (default-deny)mTLSDocker Content TrustSecrets management (Key Vault, K8s/Swarm secrets, External Secrets)Non-root & read-only root filesystemsRBACSecurity-group chaining

Observability & Reliability

PrometheusGrafana (35-panel dashboard)CloudWatchSLOs & error budgetsMulti-window burn-rate alertingDead-letter & retry queuesIdempotency (Redis)Multi-AZ high availabilityAuto ScalingTested DR runbooks (RTO < 2h)

Programming & Data

Python (boto3, FastAPI, Flask)Bash / LinuxSQLRabbitMQRedisPostgreSQLMongoDB / GridFSMySQL / AuroraDynamoDBReact / ViteNode.jsPHP

Ways of Working

Cross-functional collaborationTechnical documentation & runbooksArchitecture decision recordsTechnical training deliveryStakeholder communicationFinOps / cost optimisation
Portfolio

Flagship projects

Four end-to-end builds, ordered from focused infrastructure automation through to a full production-grade Kubernetes platform. Each links to its source repository and a complete engineering report.

01 Project 01

Terraform S3 Automation with GitHub Actions

Infrastructure as Code · CI/CD · AWS

A production-grade Infrastructure-as-Code workflow that provisions a hardened Amazon S3 bucket entirely through CI/CD. Every change is reviewed as a pull request, planned automatically, and applied only on merge to main — no console clicking, no drift.

  • Terraform module provisioning S3 with versioning, server-side encryption, full public-access block, lifecycle rules, access logging and a production tagging standard.
  • Remote state on S3 with DynamoDB state locking — safe concurrent runs across a team.
  • GitHub Actions pipeline running fmt → validate → plan on every pull request and apply only on merge to main.
  • AWS credentials injected through GitHub Actions Secrets — zero credentials in source control.
  • Jenkinsfile included so the same IaC ships through either orchestrator.
02 Project 02

CityMart Online — Highly Available 3-Tier AWS Architecture

High availability · Network segmentation · AWS

A fault-tolerant three-tier e-commerce platform spanning two Availability Zones in eu-west-2, with every tier isolated in its own subnet and no single point of failure. Built once by hand to prove the architecture, then re-provisioned as Terraform IaC.

CityMart three-tier AWS architecture diagramEnlarge
CityMart three-tier AWS architecture diagramEnlarge (2600×3900)Vector PDF
  • Custom VPC (10.0.0.0/16) with public, private-web, private-app and private-database subnets across two AZs; one NAT gateway per AZ to remove cross-AZ dependencies.
  • Web tier (Nginx) behind a public ALB, application tier (Apache/PHP) behind an internal ALB, data tier on Amazon RDS/Aurora MySQL Multi-AZ — strict security-group chaining between every hop.
  • Auto Scaling Groups keep both compute tiers self-healing; application code distributed from S3 so instances are fully ephemeral and replaceable.
  • Route 53 DNS with ACM TLS termination and an HTTP→HTTPS redirect; CloudFront in front for global cache and latency reduction.
  • Administrative access through SSM Session Manager — no bastion host and no open SSH port.
03 Project 03

Serverless Facial Recognition Platform

Serverless · Event-driven · AI on AWS

A fully serverless identity-verification system that replaces access cards and PINs with face-based authentication. Two independent workflows — event-driven registration and API-driven authentication — with zero servers to patch or scale.

Serverless facial recognition architecture on AWSEnlarge
Serverless facial recognition architecture on AWSEnlarge (2400×1440)
  • Registration: an S3 upload event triggers a Lambda that indexes the face with Amazon Rekognition and writes the face ID plus metadata to DynamoDB.
  • Authentication: React/Vite frontend → API Gateway → Lambda → Rekognition face comparison with similarity scoring, validated against DynamoDB.
  • Whole stack deployed from a single CloudFormation template (eu-west-1) — reproducible in one command.
  • Least-privilege IAM roles per function and CloudWatch logging across both workflows.
  • Pay-per-use cost model with automatic scaling and high availability, and no idle infrastructure.
Stack
AWS LambdaAmazon RekognitionAPI GatewayDynamoDBS3CloudFormationIAMCloudWatchReactVitePython
Video walkthroughs
04 Project 04 Flagship

VidCast — Video Processing Microservices on AWS EKS

Kubernetes · DevSecOps · GitOps · Flagship

A production-grade, event-driven platform converting video to podcast-ready MP3 on Amazon EKS. Built for a realistic client — a London podcast company whose manual FFmpeg workflow was consuming roughly £100,000 a year of producer time and scattering client content across personal drives and third-party sites.

~£198monthly run cost
94%budget headroom
< 2 htested RTO
0secrets in Git
VidCast EKS platform architectureEnlarge
VidCast EKS platform architectureEnlarge (1457×1607)
  • Five Python microservices (Gateway, Auth, Converter, Notification) plus a single-replica outbox relay on Kubernetes 1.29 (AWS EKS), fully provisioned with Terraform.
  • Store-and-queue pipeline: upload returns 202 in milliseconds and conversion happens asynchronously through RabbitMQ, with dead-letter and retry queues plus Redis deduplication for idempotency.
  • Event-driven autoscaling with KEDA on RabbitMQ queue depth (scale 0→N, then back to zero when idle) alongside HPA on the API tier.
  • 20+ GitHub Actions workflows and a Jenkins pipeline with a shift-left Trivy gate and Gitleaks secret scanning; Argo CD GitOps delivery behind a manual production approval gate.
  • Six layers of defence-in-depth: zero-trust default-deny NetworkPolicies, IRSA least-privilege pod IAM, hardened non-root read-only containers, mTLS via cert-manager, seven Kyverno admission policies, and IMDSv2.
  • Full observability — Prometheus metrics, a 35-panel Grafana dashboard, three SLOs backed by multi-window burn-rate alerting, and Kubecost for FinOps.
  • Nightly encrypted S3 backups with two tested recovery paths (app/config from Git via Argo CD, data from S3) documented in a runbook proven to restore in under two hours.
VidCast CI/CD and GitOps delivery pipelineEnlarge
VidCast CI/CD and GitOps delivery pipelineEnlarge (2400×1350)
Published write-up. The build was written up as a ~6,000-word engineering article, “We Replaced a £100k/Year Manual Workflow With a £198/Month Kubernetes Platform — Here’s How” (19 June 2026), co-authored by the four of us and published on a teammate’s Medium account. It walks through the client scenario, the architecture decisions and the cost model.
Team project. Delivered as a four-engineer team (Samuel Onyejekwe, John Babalola, Seun Okegbola, Chinedu Izuelu) for the Cloudboosta Advanced DevOps cohort, June 2026.
Stack
Kubernetes (EKS)TerraformHelmKustomizeArgo CDKEDAKyvernoDockerRabbitMQRedisPostgreSQLMongoDB/GridFSPrometheusGrafanaKubecostTrivyGitleakscert-managerGitHub ActionsJenkinsPython/FastAPIReactALBRoute 53ACM

Supporting repositories

Additional DevOps and cloud repositories on my GitHub that back the labs and projects above.

Evidence

Documented labs & assignments

Every lab and assignment from the Cloudboosta Cloud Computing and Advanced DevOps programmes — 34 write-ups totalling 1,207 pages, each with the objective, the steps taken, the commands run and screenshot evidence of the result. Filter by technology, then open any PDF to verify the work.

Showing 34 of 34 documented labs

Networking on Cloud · Class 2

Linux Command-Line Fundamentals

Create, inspect, concatenate and manage files and directories from the shell — the foundation every deployment script rests on.

LinuxUbuntuBash 6 pages · 1 Mar 2026Open PDF
Networking on Cloud · Class 2

Custom Dual-Stack VPC with EC2 Apache Web Server

Build a custom IPv4/IPv6 VPC (10.0.0.0/16) with public and private subnets, NACLs, route tables and an internet gateway, then provision an EC2 instance running Apache.

VPCSubnetsNACLSecurity GroupsRoute TablesIGWEC2IPv6 14 pages · 1 Mar 2026Open PDF
Networking on Cloud · Class 2

Jenkins Server Provisioning on a Custom VPC

Provision a custom VPC and launch an EC2 instance to host a Jenkins automation server, opening only the ports the service actually needs.

JenkinsVPCEC2Security GroupsPort 8080 18 pages · 1 Mar 2026Open PDF
Microsoft Azure Intro · Class 3

Azure Blob Storage — Containers, Tags, Locks & Monitoring

Organise files in blob containers and protect the storage account with tags and resource locks, then read Azure's usage and access telemetry.

AzureBlob StorageStorage AccountResource LocksTagsMonitoring 28 pages · 10 Mar 2026Open PDF
Microsoft Azure Intro · Class 3

Static Website Hosting on Azure Blob Storage

Publish a static website straight from Azure Blob Storage and serve it on a public endpoint — no web server to run or patch.

AzureBlob StorageStatic HostingPublic Endpoint 12 pages · 10 Mar 2026Open PDF
Python Intro · Class 4

Python Fundamentals — Variables, Types & f-strings

Set up a Python environment in VS Code and work through variables, arithmetic, type conversion and formatted output.

PythonVS CodeUbuntuf-stringsType conversion 6 pages · 17 Mar 2026Open PDF
Python Intro · Class 4

Python Lists, Slicing & Dictionaries

Build and slice lists, construct dictionaries and navigate the official Python documentation to solve problems independently.

PythonListsSlicingDictionariesPython docs 6 pages · 17 Mar 2026Open PDF
High Availability · Class 4

Application Load Balancer + Auto Scaling for High Availability

Deploy an internet-facing ALB and an Auto Scaling Group across two Availability Zones so the infrastructure recovers from instance failure with no manual intervention.

ALBAuto ScalingMulti-AZTarget GroupsHealth ChecksVPC 53 pages · 17 Mar 2026Open PDF
High Availability · Class 4

Secure 3-Tier AWS Architecture — Web, App & Database Tiers

Design and deploy a segmented three-tier architecture — public web tier, private app tier and private RDS MySQL — with two NAT gateways for zone-local egress and strict tier-to-tier security groups.

3-TierVPCNAT GatewayALBAuto ScalingRDS MySQLSecurity Groups 70 pages · 17 Mar 2026Open PDF
Azure App Service · Class 5

Azure Secure HR Portal — VNet, NSG, Entra ID & RBAC

Stand up an HR web portal isolated in a VNet, restrict access with NSG rules, and replace shared passwords with Entra ID identities and RBAC role assignments.

AzureVNetNSGEntra IDRBACLeast privilegeUbuntu VM 46 pages · 22 Mar 2026Open PDF
Azure App Service · Class 5

Azure App Service + Key Vault with Managed Identity

Remove secrets from code entirely — store the database connection string in Key Vault and let a system-assigned managed identity read it, so stolen source code grants no database access.

Azure App ServiceKey VaultManaged IdentityRBACSecrets 38 pages · 22 Mar 2026Open PDF
Azure App Service · Class 5

Azure SQL Database + HTTP-Triggered Azure Functions

Model a four-table order schema in Azure SQL and process real orders with a serverless function that runs only when an order arrives.

Azure SQLAzure FunctionsHTTP triggerBusiness logic 31 pages · 22 Mar 2026Open PDF
Serverless Computing & Database · Class 6

AWS Lambda — Blueprint and From-Scratch Functions

Create Lambda functions both from a blueprint and from scratch, drive them with test events, and debug and fix runtime errors.

AWS LambdaTest eventsDebuggingPython 15 pages · 1 Apr 2026Open PDF
Serverless Computing & Database · Class 6

EC2 + Amazon RDS MySQL with Layered Security Groups

Provision a WordPress-ready architecture — an application security group for internet traffic and a separate database security group permitting only MySQL from the app tier.

EC2RDS MySQLSecurity GroupsEndpoints 22 pages · 1 Apr 2026Open PDF
Serverless Computing & Database · Class 6

WordPress Deployment on EC2 with an RDS Backend

Install and configure Apache and WordPress on EC2 and point it at a managed Amazon RDS database rather than a local one.

EC2ApacheWordPressRDSSSHSession Manager 16 pages · 1 Apr 2026Open PDF
Serverless Computing & Database · Class 6

Lambda-Driven EC2 Lifecycle Automation with boto3

Write Lambda functions that stop, start and terminate EC2 instances programmatically, backed by a purpose-built IAM role.

AWS Lambdaboto3IAM rolesEC2Python 23 pages · 1 Apr 2026Open PDF
Serverless Computing & Database · Class 6

Lambda + EventBridge Cron — Scheduled Cost Automation

Provision EC2 from Lambda, tag instances with AutoSchedule=True, and drive start/stop on an EventBridge cron schedule to cut spend on idle compute.

AWS LambdaEventBridgeCronTaggingFinOpsboto3 36 pages · 1 Apr 2026Open PDF
Serverless Computing & Database · Class 6

S3-Triggered Lambda — Automated Thumbnail Pipeline

Build an end-to-end event-driven pipeline: an upload to the source bucket fires a Lambda that resizes the image and writes the thumbnail to a destination bucket.

S3 eventsAWS LambdaIAMCloudWatch LogsImage processing 23 pages · 1 Apr 2026Open PDF
Git & GitHub · Class 7

Git & GitHub — Branching, Pull Requests & Collaboration

Run the full version-control loop — init, stage, commit, push, branch, invite a collaborator, raise a pull request, review, merge and synchronise.

GitGitHubBranchingPull requestsCode reviewMerge 33 pages · 1 Apr 2026Open PDF
GitHub Actions · Class 1

GitHub Actions — Workflows, Triggers & Branch Testing

Author workflow YAML from scratch, define triggers and jobs, monitor execution logs, and validate behaviour across multiple branches.

GitHub ActionsYAMLWorkflow triggersJobsRunnersBranch strategy 75 pages · 30 Apr 2026Open PDF
Repositories
GitHub Actions · Class 1

Terraform IaC + GitHub Actions CI/CD to AWS

Provision an S3 bucket with Terraform through a GitHub Actions pipeline, store AWS credentials as encrypted secrets, then ship a versioning change via a branch and pull request.

TerraformGitHub ActionsGitHub SecretsS3VersioningPull requests 84 pages · 30 Apr 2026Open PDF
Repository
Jenkins 1 · Lab 1

Jenkins on AWS EC2 — Install & Parameterised Freestyle Jobs

Bootstrap Jenkins on Ubuntu EC2 via user data, complete first-run setup, then build parameterised freestyle jobs and validate their console output.

JenkinsEC2User dataFreestyle jobsBuild parametersConsole output 45 pages · 6 May 2026Open PDF
Jenkins 1 · Lab 2

Jenkins ↔ GitHub — PAT, SSH Keys & Webhooks

Wire Jenkins to GitHub three ways — personal access token, SSH key pair and webhook triggers — with post-build commit status reporting.

JenkinsGitHub PATSSH keysWebhooksCredentialsBuild status 32 pages · 6 May 2026Open PDF
Repository
Jenkins 1 · Lab 3

Jenkins AWS Plugins & Credentials Configuration

Install the AWS plugin set, store AWS credentials inside Jenkins, set the target region, and prepare a pipeline project for AWS deployments.

JenkinsAWS pluginsCredentialsRegionsPipeline project 30 pages · 6 May 2026Open PDF
Cloud Computing · Assignment 1

AWS CloudFormation — VPC, Subnets & RDS Subnet Groups

Author a CloudFormation template that provisions a production-style VPC with public, application and database subnets, deploy it from S3, and validate the stack events, resources and outputs.

CloudFormationYAMLVPCNAT GatewayRoute tablesS3Aurora MySQLStack outputs 89 pages · 6 May 2026Open PDF
Cloud Computing · Assignment 2

Amazon RDS Oracle Multi-AZ Deployment & SQLPlus Administration

Deploy a Multi-AZ Oracle RDS instance with custom parameter and option groups, reach it from an EC2 command host over SSM Session Manager, and create tables with SQLPlus.

RDS OracleMulti-AZParameter groupsOption groupsSSM Session ManagerSQLPlus 44 pages · 6 May 2026Open PDF
Jenkins 2 · Assignment 1

Jenkins CI/CD Environment on a Custom VPC with NAT Gateway

Build the whole CI/CD environment from the network up — VPC with public and private subnets, IGW and NAT gateway, Jenkins on EC2, AWS credentials, Java/Maven toolchain and GitHub webhook integration.

JenkinsVPCNAT GatewayIGWJavaMavenGlobal Tool ConfigWebhooks 49 pages · 14 May 2026Open PDF
Repository
Jenkins 2 · Assignment 2

Jenkins CI & CD Pipelines from SCM with Webhook Automation

Run continuous integration and continuous deployment as separate pipeline jobs driven by a Jenkinsfile in source control, triggered by webhook and gated by a deployment approval step.

Jenkins pipelineJenkinsfilePipeline from SCMWebhooksDeployment stagesApproval gate 23 pages · 14 May 2026Open PDF
Repository
Jenkins 2 · Assignment 3

Jenkins Secrets Management & Role-Based Access Control

Store secrets in Jenkins' credential store, bind them into pipelines so they are masked in logs, and enforce least privilege with the Role-Based Authorization Strategy plugin.

Jenkins credentialsSecret textCredential bindingsMaskingRBACRole strategyUser accounts 36 pages · 14 May 2026Open PDF
Jenkins 2 · Assignment 5 of 5 · Week 3

Jenkins + Terraform Pipeline to Amazon EKS & ECR

Stand up Terraform remote state on S3 with DynamoDB locking, provision ECR and an EKS cluster, and drive container build and deployment from a Jenkins pipeline.

TerraformS3 backendDynamoDB lockingECREKSELBJenkinsDocker pipelineGitHub PAT 84 pages · 19 May 2026Open PDF
Repository
Docker 1 · Lab 1 · Week 4

Docker Engine on EC2 — Image Build & Containerised Deployment

Bootstrap Docker on Ubuntu 24.04 via EC2 user data, write a Dockerfile for a Node.js app, build the image and run the container with port mapping.

Docker EngineDocker ComposeDockerfileNode.jsPort mappingVS Code Remote SSHUbuntu 24.04 23 pages · 23 May 2026Open PDF
Docker 1 · Lab 2 · Week 4

Docker Hub Registry, Image Tagging & Container Lifecycle

Authenticate to Docker Hub from the CLI, tag and push images to a cloud registry, and demonstrate ENTRYPOINT behaviour and the running/exited container lifecycle.

Docker HubRegistryImage taggingApacheENTRYPOINTContainer statesdocker push 19 pages · 23 May 2026Open PDF
Docker 2 · Lab 1 · Week 5

Docker Swarm — Multi-Node Orchestration, Scaling & HA

Initialise a Swarm cluster across manager and worker EC2 nodes, deploy a multi-container stack, scale services, then drain a node and prove containers reschedule automatically.

Docker SwarmManager/Worker nodesStack deployService scalingLoad balancingNode drainRescheduling 40 pages · 30 May 2026Open PDF
Docker 2 · Lab 2 · Week 5

Docker Swarm Hardening — Trivy, Content Trust & Secrets

Harden a Swarm environment end-to-end: scan images with Trivy, sign them with Content Trust, cap CPU and memory, drop unnecessary Linux capabilities, and manage secrets with mutual TLS and certificate rotation.

TrivyVulnerability scanningDocker Content TrustImage signingResource limitsLinux capabilitiesSwarm secretsmTLSCertificate rotation 38 pages · 30 May 2026Open PDF
Verified

Credentials & awards

Academy certification, graded performance reports and academic degrees — all downloadable.

Most Consistent Student Award

Most Consistent Student Award

Cloudboosta Academy · 2026 Cohort 1
20 June 2026

Awarded for sustained consistency and engagement across the full programme.

Professional Diploma — Cloud Computing & DevOps

Professional Diploma — Cloud Computing & DevOps

Cloudboosta Academy
2026

Core curriculum: AWS, Microsoft Azure, Terraform, Kubernetes, Docker, CI/CD, Linux and Python automation.

A+90.38% overall

Final Performance Report — Cloud Computing & DevOps

Cloudboosta Academy · overall programme grade
17 weeks · issued 3 July 2026
A+ · 90.38%

The cumulative assessment across both the Cloud Computing and Advanced DevOps cohorts — 1,324 of 1,465 points spanning attendance, labs, assignments, quizzes, video posts and two project presentations (80.00% and 88.89%). Soft skills scored 22/25, with full marks for consistency, resilience and class engagement. Cloudboosta's pass mark is B- (60%); A+ requires 85%+.

Cloud Computing Cohort 1 — Interim Report

Cloudboosta Academy
First 9 weeks

The foundation-stage report covering AWS and Azure core services, networking, Linux, Python and serverless — superseded by the final overall report above.

MSc, Offshore Engineering — Distinction

MSc, Offshore Engineering — Distinction

University of Port Harcourt, Nigeria
2014

Postgraduate research in high-reliability offshore systems.

BEng, Mechanical Engineering — Second Class Upper

BEng, Mechanical Engineering — Second Class Upper

Federal University of Technology, Owerri
2010

Foundation in engineering analysis, systems thinking and design.

Background

Professional experience

Nine years of engineering in high-reliability offshore environments — where automation, documentation and operational rigour are not optional.

Engineering Consultant / Training Coordinator

Apr 2020 – Present
Subsener Ltd · Petrocarbon Engineers Ltd — Lagos, Nigeria
  • Design and deliver technical training and onboarding programmes for engineers at major clients including Shell and Saipem, producing reusable course material and process documentation.
  • Coordinate cross-functional delivery and knowledge transfer on specialised engineering software — programme authenticated by IMarEST.

Subsea Structural Engineer

Aug 2019 – Mar 2020
International Energy Services Ltd (IESL) — Lagos, Nigeria
  • Delivered rigorous analysis and detailed technical documentation, improving reliability by 20% and cutting project review times by 25% through repeatable, well-documented processes.

Asset Integrity Engineer

Oct 2017 – Oct 2018
Fadfae Engineering / Innospection Ltd — Lagos, Nigeria
  • Planned and ran inspection projects with Gantt scheduling, backlog management and risk assessment — delivering 15% ahead of schedule with zero safety incidents.

Mechanical / Project & Structural Engineer

2015 – 2019
Petrohob Ltd · Petrocarbon Engineers Ltd — Lagos, Nigeria
  • FEA/CFD simulation, automation of engineering workflows and multidisciplinary project coordination in high-reliability offshore environments.
Get in touch

Let's build something reliable

I am open to Cloud, DevOps, Platform and SRE roles across the EU and remote. I hold a Cypriot work permit, so there is no visa sponsorship to arrange.

Limassol, Cyprus · EU work-authorised (Cypriot work permit)