Completed training
IT infrastructure & Cloud
Infrastructure, identity and AWS in real environments.
I work on the operation and improvement of hybrid infrastructure and AWS, especially identity and automation. Here I explain what was in place, what I worked on and why we chose each solution.
- Production AWS since 2023
- Microsoft Entra ID and hybrid identity
- AWS Solutions Architect – Associate
Work areas
What I work on.
These are the areas I work with most often. In each project I explain what I did, what I did with other people and the current status.
Identity and access
SSO, enterprise applications, dynamic groups, user lifecycle and external collaboration with Microsoft Entra ID.
View identity projects → 02AWS
Architecture and operations, costs, storage, backups, IAM and documentation for existing environments or new applications.
View AWS projects → 03Automation
Processes between systems, validations and controlled changes with PowerShell and Python, mainly for identity work.
View automation projects → 04Infrastructure
On-premises and cloud systems that need to work together: Windows, Linux, VMware, networks and other corporate services.
View infrastructure projects →Projects
What was in place, what I worked on and why we chose this approach.
The main cases need more context. The others are smaller changes, but they also show problems I have solved or work that is still in progress.
Filter projects by area
One case may appear in more than one area.10 projects
Academic identity classification
A daily process that classifies around 18,000 identities from source data and applies the result to Active Directory in a controlled way.
- My role
- Logic, validation and deployment
- Scope
- Around 18,000 identities
- Status
- Active and monitored
Application integration with SAML
Migration from local LDAP authentication to Microsoft Entra ID, adapting attributes, certificates and user groups for each application.
- My role
- Configuration and validation
- Result
- Centralised authentication
- Environment
- SAML · Entra ID · AD
AWS architecture for a new application
Joint design and implementation of a test environment with ALB, Cognito, EC2, RDS MariaDB and technical access through SSM.
- My role
- Proposal and joint deployment
- Status
- Test environment running
- Access
- ALB · Cognito · SSM
S3 storage optimisation
Review of versions, lifecycle rules and replication that had built up unnecessary storage in several buckets.
- Result
- Several TB removed
- Reduction
- More than 80%
- My role
- Analysis and implementation
Tag-based AWS Backup
A common strategy that adds resources automatically to daily, weekly and monthly plans, with regional copies for production.
- My role
- Design and implementation
- Status
- Active
- Scope
- AWS resources
Other work
Smaller changes.
Blocking legacy authentication
Report-only mode, sign-in review and activation without impact.
View case → Entra B2BAccess for external collaborators
Guest identities, application assignment and manual removal when the work ends.
View case → AWS · SSMInstance access with SSM + SSH
Technical access without exposing port 22, ready for private instances behind the ALB.
View case → AzureCost and resource review
Inventory of resources, reservations and proposed actions to organise the environment.
View case → AWS · DocumentationAWS application documentation
Architecture, dependencies and operations brought together in one common document.
View case →Credentials
Certifications and technical training.
Profile
I’m Bru. I have worked in IT infrastructure since 2021.
Since 2023, I have mainly worked with production AWS, Microsoft Entra ID and hybrid infrastructure. I also manage systems and services that do not fit into one simple category, but still need to keep running.
I usually start by understanding how the environment is built, what depends on what and where the problem is. Then I try to make a clear improvement, document it and leave it as maintainable as possible.
Contact
Do you have a specific project?
Tell me what you have, what you want to improve and what you need. Email works best, so I can review the context before we talk.