HomeExpertise02 · Cloud & Deployment

Cloud & Deployment

AWS architecture, deployment via Docker, secrets management. Or your own server, when that is the better math. This page shows what it fails on, how I built it, and what you can check it against.

Back to the last green release while the site stays reachable.Video · 21:9
Area
02 of 04
Stack
9 technologies
Reference
SnipeFlip
Terminal: every service healthy
The state the rollback restores.21:9

The situation: one person can deploy

In many teams, deployment is the step exactly one person can do. Secrets sit in env files in the repository, the bill goes up, and nobody can say which service is driving the cost.

Printed env file, redacted by handAI-generated
The secrets were in the repository. The redaction happened for this photograph.16:9
One machine, one person, one holiday. That is all the single point of failure needs.Video · 21:9

Way of working

Measure first, move second. The cheaper architecture is often not the more modern one: SnipeFlip handles 2,500 deals per day on a single VPS. Where Lambda wins, I use Lambda — the bill decides, not the fashion.

EvidenceBefore and after2 exhibits

Photo: infrastructure sketch with network boundaries and access pathsAI-generated

The reference project for this area

A capability with no project behind it is a list of technologies. This is the project — with the number it produced, and the case study where you can check it.

Sneaker deals · Automation

2,500

operations per day · one VPS

Deal tracking that handles 2,500 operations a day

Watch several marketplaces at once, score every find, push the hits straight to a phone — without anyone keeping tabs open.

Next.js React TypeScript PostgreSQL / Prisma WebSocket Cheerio DeepSeek PM2 VPS

Screenshot: monitoring on an ordinary day
The same case from inside: the monitoring16:9
Diagram: one VPS and everything running on it
The same case from outside: the machine behind it16:9

All reference projects

What I worked on

Four kinds of work, each with the one picture that makes it checkable. Numbered so they can be pointed at — not because one follows another: each stands on its own.

  • 01

    Setting up deployment pipelines and CI/CD

  • 02

    Containerizing existing applications

    Screenshot · A Dockerfile and the container it runs, side by side
  • 03

    Cutting cost without giving up operational safety

    Screenshot · Cost overview, two months compared
  • 04

    Cleaning up access and secrets management

The stack: AWS, Docker, CI/CD

After the situation and the way of working, nobody is still asking what is installed — they are asking whether any of it is real. The line stays; two frames below it answer.

AWS (S3, Lambda, ECS, EventBridge) Docker SSM-Tunneling Infisical Nginx PM2 Hetzner Gitea CI/CD

In use

Repeatable

Screenshot · the compose file and the Nginx block

Scale

A pipeline was usually up in a few days. A migration into the cloud or out of it took two to six weeks, depending on the legacy.

Small case
Pipeline · One clean runAI-generated
Commit, build, deploy — and it is live. Usually a matter of days.16:9
Large case
The work is in the legacy, not in the destination.Video · 16:9

Common questions

Five questions that keep coming up about this area — answered from the projects they came up in.

AWS or your own server — which is cheaper?
The load decides that, not the catalogue. SnipeFlip handles 2,500 deals a day on a single VPS; where Lambda wins, I use Lambda. The arithmetic comes first, not afterwards.
How long did it take to get a CI/CD pipeline running?
For an application with a clean build, a few days: build, tests, migrations, rollout, and the way back if something breaks. It took longer where the build used to run on a laptop.
Can an existing application be containerized?
As a rule, yes. The work rarely sits in the Dockerfile — it sits in the paths, cron jobs and credentials that have grown onto exactly one machine over years.
Where do the secrets live, if not in the repository?
In a secrets store the application and the pipeline pull from at runtime — for me, usually Infisical. Anyone who once held a password does not see it in the clear afterwards.
How much cost saving came out of it?
It depended on what was running before. The largest line item was almost never compute, it was services nobody had cancelled. That is why this started with a measurement and not with a promise.

Contact

Half a minute, and you know more.

Half a minute on what I work on and how. If a question is left, write to me — an answer within one working day.

Four areas

Cloud & Deployment rarely stands alone — in most projects this area reaches into at least one of the others. That is why the chain belongs together.

One change running through four layers: interface, API, database, cloud — with a timestamp at each stationAI-generated
One change, four layers — why the areas belong together21:9
An order list and its detail view side by side: ORD-4418 selected, net, VAT and total beside itAI-generated

01

Full-stack development

React and Next.js frontends with SSR and Server Components. Backends with TypeScript, Python and PostgreSQL.

AI image · test questions on cards, answers beside themAI-generated

03

AI integration

RAG pipelines, embeddings and vector search with pgvector. Production-ready and live in use — not as a demo.

Sync run 4471: 3,184 records, one mismatch — ERP 214 against shop 209, decision HOLDAI-generated

04

System integration

Middleware between systems that don't talk to each other. Marketplace connections, stock and order data synchronization.

All four areas