Zero-touch EKS cutover that retired 140 hand-rolled EC2 deploy scripts
NimbusPay’s payments edge lived on snowflake AMIs — no consistent IAM, secrets in env files, and PCI auditors flagged missing network segmentation.
Greenfield EKS with IRSA for pod identity, AWS Secrets Manager CSI, private subnets + NAT, Cluster Autoscaler + Karpenter, and Argo CD sync waves per bounded context.
- Pod Security Standards enforced in CI
- NetworkPolicy default-deny + curated allow lists
- Velero backup schedules + restore drills
- Cost allocation tags per team + namespace
- OTel collector DaemonSet → Grafana Cloud
- Runbooks for etcd pressure + node cordon