I will write production terraform modules for aws eks with argocd gitops
Senior DevOps and Network Security Engineer and Linux Expert
About this Gig
I've been writing Terraform since 0.11. The difference between "it works on my machine" and "it works in production for 3 years" is modules, state management, and GitOps.
What you get:
Production-grade modules VPC (public/private/subnet), EKS (managed node groups, IRSA, encryption), RDS (encrypted, backup, read replica), S3 (versioned, lifecycle, replication), IAM (least privilege, OIDC)
Terraform Cloud/Enterprise Workspaces per env, run triggers, policy checks (Sentinel/OPA), private registry, drift detection
GitOps with ArgoCD App-of-Apps pattern, auto-sync + prune + self-heal, Kustomize/Helm, declarative secrets (SealedSecrets/External Secrets + Vault)
CI/CD for Terraform GitHub Actions: fmt validate plan policy check apply (manual approval on prod)
Policy as Code OPA/Kyverno: required tags, no public SG, encrypted volumes, approved AMIs only
Disaster Recovery Velero backups to S3 (cross-region), scheduled + on-demand, tested restore runbook
FinOps Infracost on every PR, Kubecost in cluster, tagging enforcement, rightsizing recommendations
Documentation Auto-generated (terraform-docs), architecture diagrams, runbooks, onboarding guide
Stack: Terraform, Terragrunt, AWS..
My Portfolio
Other DevOps Engineering Services I Offer
FAQ
How do you handle state locking & team collaboration?
Terraform Cloud (free tier supports 500 resources) or S3 + DynamoDB backend. Workspaces per env (dev/staging/prod). Run triggers for dependent stacks. PR workflow: plan in PR comment → manual approve → apply.
Can you migrate existing console-click infrastructure?
Yes. terraform import for existing resources, then refactor into modules. I'll generate configs with terraformer/aws2tf, review with you, then cut over with zero downtime.
What about secrets in GitOps?
Never in Git. Options: 1) SealedSecrets (Bitnami), 2) External Secrets Operator + Vault/AWS Secrets Manager/1Password, 3) SOPS/age encrypted files. ArgoCD manages only sealed/encrypted resources.

