
🛠️ DevOps & SRE · Flowchart
How infrastructure changes are made safely with Terraform: plan on pull request, policy checks, approval, apply and drift detection.
Drawing diagram…
Terraform workflow: an engineer opens a pull request; CI runs terraform fmt, validate and plan, and posts the plan as a comment. Policy checks (OPA) block public S3 buckets and open security groups. After approval and merge, apply runs with a state lock. A nightly job runs plan against production and alerts if it finds drift.
flowchart TD
A[Open pull request] --> B[terraform fmt and validate]
B --> C[terraform plan]
C --> D[Post plan as PR comment]
D --> E{Policy checks pass?}
E -->|No| X[Block merge with reason]
E -->|Yes| F[Review and approve]
F --> G[Merge to main]
G --> H[Lock state]
H --> I[terraform apply]
I --> J[Unlock state]
J --> K[Nightly drift check]
K --> L{Drift found?}
L -->|Yes| M[Alert platform team]
L -->|No| N[No action]How a code change reaches production with GitOps: CI builds and tests, the image tag is written to a config repo, and Argo CD syncs the cluster to match Git.
A complete observability setup: OpenTelemetry collects metrics, logs and traces from services, which are stored separately and viewed together in Grafana with alerting.
The stages of a production incident from the first alert to the postmortem, with severity escalation along the way.
Who does what when production breaks: monitoring pages the on-call engineer, an incident channel is opened, customers are updated and the fix is rolled out.
A blue-green setup where a new version is deployed next to the live one and traffic is switched only after it passes checks, allowing instant rollback.
A self-service platform for developers: a Backstage portal with templates that create repos, pipelines and environments without tickets to the ops team.