whoami

Leonardo Marques Lima
Cloud Engineer

I build production-grade infrastructure on AWS with Terraform — networks, containers, CI/CD pipelines.

Available for hire & freelance AWS SAA · CCNA
Leonardo Marques Lima

01.About

Cloud infrastructure engineer with a network engineering background. I write Terraform that provisions clean, reviewable, repeatable AWS environments — and I treat infrastructure code with the same care as any other production codebase.

My background is in networking — CCNA-certified — which gave me a strong foundation in how traffic actually moves between environments. I've taken that into the cloud, where I now design and ship AWS infrastructure end-to-end with Terraform.

I care about the parts of cloud work that are easy to skip: solid CI/CD with PR reviews, OIDC instead of long-lived keys, security scanning in the pipeline, and READMEs that someone other than me can actually follow.

I'm currently looking for a full-time Cloud / DevOps Engineer role and I take on freelance infrastructure projects on the side. If you're a small team that needs a Terraform foundation laid down properly, that's exactly the work I love doing.

02.Stack

The tools I reach for, day to day.

Terraform
AWS
VPC / Networking
ECS Fargate
RDS
S3 + CloudFront
IAM / OIDC
Route 53
GitHub Actions
Checkov
Linux
Bash / Python

03.Featured Projects

All Terraform. All on AWS. All with full READMEs and architecture diagrams in the repo.

Hub-and-spoke network architecture on AWS. Centralized hub VPC with multiple spoke VPCs connected via Transit Gateway — the standard pattern for organizations that need to keep workloads isolated but still share egress, DNS, and on-prem connectivity through a single point. Clean, modular Terraform.

Terraform Transit Gateway VPC Networking Multi-account ready

Static website with full CI/CD pipeline. S3 + CloudFront fronted infrastructure managed by Terraform, with GitHub Actions running terraform plan on every PR (posted as a comment) and terraform apply on merge to main. OIDC-based AWS auth — no long-lived secrets in GitHub.

Terraform S3 CloudFront GitHub Actions OIDC Checkov

Three-tier application on ECS Fargate + RDS. Serverless containers behind an Application Load Balancer, talking to a private RDS database in a multi-AZ VPC. Public, app, and data subnets cleanly separated — exactly the layered design you'd run in production.

Terraform ECS Fargate RDS ALB VPC Multi-AZ

See all repositories →

04.Freelance & Contract Work

Available for short and medium-term cloud infrastructure projects. If you're a small team that needs Terraform laid down properly the first time — or someone to clean up infrastructure that grew faster than the docs did — let's talk.

AWS Foundations in Terraform

Greenfield setup: VPCs, IAM, state backend, environments. Done right from day one.

CI/CD Pipeline Build-out

GitHub Actions + OIDC auth, PR-based plan/apply, security scanning. No manual applys.

Container Workloads

ECS Fargate or EKS, ALB, autoscaling, RDS — production-ready, multi-AZ.

Network Architecture

Hub-and-spoke, Transit Gateway, VPC peering, hybrid connectivity. Coming from a CCNA background.

Static Site Hosting

S3 + CloudFront + Route 53, fully Terraform-managed, deploy-on-merge.

Code & Cost Review

Audit your Terraform, find drift, tighten IAM, surface unused resources.

Get in touch →

Let's build something

Hiring for a Cloud / DevOps role, or have a project that needs Terraform on AWS? I'd love to hear about it.