Hybrid Cloud Engineer | Azure · Terraform · Zero-Trust
Designing and automating compliance-ready infrastructure for cloud and on-prem environments. Focused on ISO 27001, NIS2, and KRITIS-grade blueprints.
- IaC & Automation: Terraform, Ansible, Packer
- Cloud: Microsoft Azure (AZ-104 certified)
- Containers & Orchestration: Kubernetes (k3s), ArgoCD, Helm, Traefik
- Networking & Security: MikroTik RouterOS, Zero-Trust NSGs, Private Link
- Virtualization: Proxmox VE
Production-ready, compliance-grade Azure blueprints — full source, no lock-in.
| Module | What it solves |
|---|---|
| Azure Hub & Spoke — Zero-Trust Edition | Zero-Trust NSGs, centralized Private DNS, DINE policy bypass |
| Azure Firewall — Forced Tunneling Edition | Cycle-error-free deploy, KMS & Azure AD bypasses, dynamic IP Groups |
| Azure Acmebot — Enterprise VNet Edition | Private Link isolation, Managed Identity, Let's Encrypt automation |
| Enterprise AI RAG — Zero-Trust Networking | Azure OpenAI + AI Search, automated Shared Private Link, RBAC chaining |
- homelab-infrastructure — Full homelab IaC: Proxmox, k3s, MikroTik — Terraform + Ansible, GitOps via Atlantis
Deep dives on Azure, Terraform, and homelab engineering → woitzik.dev/blog



