Skip to content
View prmaddi6233's full-sized avatar

Block or report prmaddi6233

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
prmaddi6233/README.md
Pradeep Maddi — the control plane at the centre of a cloud platform topology

Portfolio LinkedIn Email

01 · WHOAMI


Cloud Platform Engineer · FinOps  ·  Calgary, Canada 🇨🇦  · 


I make cost, security, and reliability enforceable — not aspirational.

My work sits where platform engineering, FinOps, and governance meet: guardrails that fail closed, evidence that survives an audit, and automation that takes humans out of the critical path.


Platform Engineering FinOps Kubernetes at Scale Governance


🚀 Currently shipping → cloud-finops-agent — tiered, fail-closed cost validation with production canaries and SARIF findings. Read why →


Principles I build by
Principle Why it holds
Policy engines over runbooks SCPs and Kyverno enforce; documents get forgotten
Fail closed or it isn't safety If the system can't verify, it stops — no silent pass
Document why-not, not just how Rejected options are what stop repeated mistakes
Evidence over assertion A claim without a check is a hope, not a control

02 · SCOPE & IMPACT


150+ AWS accounts · $500K+/yr identified savings · 100% IaC-managed

150+ AWS accounts · $500K+/yr identified savings · 100% IaC-managed


🏢 150+ AWS accounts — Control Tower + AFT, policy-gated vending, cost attribution from day one.

Kubernetes at scale — Multi-tenant EKS with Karpenter, Kyverno guardrails, per-namespace budgets.

💰 $500K+/yr savings — RI/SP coverage, Graviton, gp2→gp3, storage lifecycle — each with a proof step.

🛡️ Org-wide security — IAM Identity Center, SCPs, GuardDuty + Security Hub + Config across all accounts.

⚙️ Fail-closed automation — SARIF findings, OIDC-scoped access, production canaries.


03 · SELECTED WORK



🛠️ cloud-finops-agent

Tiered validation — math, metrics, production canary. SARIF findings. Fail-closed. OIDC.

Python · SARIF · GitHub Actions

📝 Blog · 📐 ADRs



☁️ aws-platform-control-plane

Self-service account lifecycle. Policy-gated. Step Functions. Audit trail.

Python · Step Functions · DynamoDB



🏭 aws-aft-account-factory-blueprint

Secure, cost-attributed account vending. Control Tower + AFT.

Terraform · Control Tower · AFT



☸️ eks-cost-governance-toolkit

Kyverno guardrails + budgeted namespaces. Multi-tenant EKS cost governance.

Kubernetes · Kyverno · Helm



04 · TECH STACK


☁️ Cloud & Platform

AWS Azure GCP Control Tower Organizations IAM Identity Center VPC Route 53 CloudFront

☸️ Containers & Orchestration

Kubernetes EKS Docker Helm Karpenter Kyverno ArgoCD OpenCost Istio

📜 Infrastructure as Code

Terraform OpenTofu CloudFormation Spacelift Terragrunt Ansible Packer

🚀 CI/CD & Automation

GitHub Actions Jenkins CodePipeline Step Functions EventBridge

💰 FinOps & Cost Engineering

FOCUS 1.2 CUR 2.0 Athena QuickSight Cost Explorer Savings Plans Graviton

🛡️ Security & Governance

IAM SCPs OIDC GuardDuty Security Hub AWS Config KMS WAF

📊 Observability

Grafana Prometheus CloudWatch Datadog ELK

💻 Languages & Data

Python Go Bash SQL HCL DynamoDB S3 Lambda Bedrock


05 · CREDENTIALS

CKA FinOps AWS SAA

06 · FIELD NOTES

Piece Theme
📡 Why Sandbox Benchmarks Don't Validate What They Claim FinOps · Validation
📐 The Agent Is Not the Control Plane Security · Architecture
📐 Tiered Validation Model Systems Design

07 · ESTABLISH LINK

Open to Principal / Senior Cloud Platform Engineering, AWS Architecture, and FinOps roles.

LinkedIn Portfolio Email


GitHub Streak

Open to Principal / Senior Cloud Platform Engineering · AWS · FinOps

Pinned Loading

  1. cloud-finops-agent cloud-finops-agent Public

    Evidence-based cloud cost optimization: deterministic rules, real production metrics, canary validation with automated rollback

    Python

  2. aws-platform-control-plane aws-platform-control-plane Public

    Self-service AWS account lifecycle control plane — policy-gated provisioning, decommissioning, DynamoDB persistence, Step Functions workflow, least-privilege IAM, and deterministic audit trail. No …

    Python

  3. eks-cost-governance-toolkit eks-cost-governance-toolkit Public

    Cost-aware, well-governed EKS: Kyverno policy-as-code guardrails, budgeted team namespaces (ResourceQuota/LimitRange), and a Helm chart. Sanitized.

    Shell

  4. aws-aft-account-factory-blueprint aws-aft-account-factory-blueprint Public

    Sanitized AFT (Account Factory for Terraform) blueprint — automated, secure, cost-aware AWS account vending. Spans platform engineering, security/governance, and FinOps.

    HCL