AWS CDK Infrastructure Development
Budget: ₹600 – ₹1,500 INR
IaC (CDK – Python)
Author modular, reusable CDK stacks for: Amplify, AppStream, Route53, IAM, EC2, Lambda, AppSync (GraphQL), CloudFront, AWS WAF, ECS (Fargate/EC2), Docker, RDS Postgres, S3, DynamoDB, CodePipeline, CodeBuild.
Multi-env patterns (dev/test/prod) with context/config files, feature flags, and environment-specific parameters.
Implement tagging standards, removal policies, and drift detection; enforce least-privilege IAM.
CI/CD & Release Engineering
Design CodePipeline/CodeBuild workflows (synth, unit tests, cdk diff, cdk deploy, manual approval gates for prod).
Blue/green or canary deployments (Lambda aliases, AppSync resolvers, ECS service deployments).
Networking & Security
VPC with public/private subnets, NAT, VPC endpoints (S3, DynamoDB), security groups, NACLs.
CloudFront + WAF (rate limiting, OWASP managed rules, geo restrictions), Route53 (hosted zones, records, health checks), ACM certificates.
Secret handling via Secrets Manager/SSM, KMS encryption, RDS auth, RLS (where applicable).
Data & Observability
RDS Postgres (parameter groups, backups, Multi-AZ), DynamoDB (GSIs, autoscaling, PITR).
Centralized logs (CloudWatch Logs), metrics & alarms (CloudWatch), dashboards, X-Ray tracing; cost & usage reporting.
Developer Experience
Boilerplate templates, README & runbooks, golden paths for new services, and “one-click” environment creation.
Governance: PR checks (lint/type check/tests), security scans, policy-as-code (optional Guard/OPA).
Author modular, reusable CDK stacks for: Amplify, AppStream, Route53, IAM, EC2, Lambda, AppSync (GraphQL), CloudFront, AWS WAF, ECS (Fargate/EC2), Docker, RDS Postgres, S3, DynamoDB, CodePipeline, CodeBuild.
Multi-env patterns (dev/test/prod) with context/config files, feature flags, and environment-specific parameters.
Implement tagging standards, removal policies, and drift detection; enforce least-privilege IAM.
CI/CD & Release Engineering
Design CodePipeline/CodeBuild workflows (synth, unit tests, cdk diff, cdk deploy, manual approval gates for prod).
Blue/green or canary deployments (Lambda aliases, AppSync resolvers, ECS service deployments).
Networking & Security
VPC with public/private subnets, NAT, VPC endpoints (S3, DynamoDB), security groups, NACLs.
CloudFront + WAF (rate limiting, OWASP managed rules, geo restrictions), Route53 (hosted zones, records, health checks), ACM certificates.
Secret handling via Secrets Manager/SSM, KMS encryption, RDS auth, RLS (where applicable).
Data & Observability
RDS Postgres (parameter groups, backups, Multi-AZ), DynamoDB (GSIs, autoscaling, PITR).
Centralized logs (CloudWatch Logs), metrics & alarms (CloudWatch), dashboards, X-Ray tracing; cost & usage reporting.
Developer Experience
Boilerplate templates, README & runbooks, golden paths for new services, and “one-click” environment creation.
Governance: PR checks (lint/type check/tests), security scans, policy-as-code (optional Guard/OPA).