Production-critical projects — personally architected or executed.
Cloud
Multi-Tenant n8n Automation Platform
Architected and deployed a self-hosted n8n AI automation platform from scratch. Independently learned ECS Fargate, Aurora Serverless v2, EFS, ALB, and Terraform — shipped in production for the first time.
ECS FargateAurora PostgreSQLTerraformEFSn8n
Business-owned AI automation, zero MSP involvement
Email
Email Deliverability Infrastructure
Migrated SendGrid to AWS Route 53, configured CloudFront + ACM for HTTPS tracked links, hardened SPF/DKIM/DMARC to p=reject. Monitor sender reputation via SNDS. Business-critical for client campaigns.
SendGridRoute 53CloudFrontDMARCSNDS
Zero deliverability outages since taking ownership
Infrastructure
IIS Migration + 23-Domain Cloudflare Rollout
Zero-downtime IIS migration consolidating 46 sites and 50 app pools. All 23 domains moved to Cloudflare with WAF, DDoS, Full Strict SSL, and DMARC p=reject. Prevented an active client NS outage mid-migration.
IISCloudflareDNSSSL/TLSWAF
Prevented outage + avoided $7,500 in MSP fees
Cloud Cost
Azure CDN → Cloudflare Migration
Migrating email campaign image hosting from Azure Front Door to Cloudflare CDN. Eliminates per-GB egress charges on high-volume marketing image delivery.
Cloudflare CDNAzure Front DoorDNS
Projected $30,000–$36,000/year in savings
Security
SOC2 Type 2 — Sole Internal Owner
Full gap analysis, all IT policies authored, 50+ technical controls deployed across CC4–CC8. Passed 2024 and 2025 audits. 2026 audit in progress.
SOC2 CC4–CC8SentinelOneAWS Security HubKnowBe4
2 consecutive audit passes, solo
Side Project
Cafe Galang — Website & Network
Built the website and full Ubiquiti UniFi network for a local Vietnamese coffee shop — from bare hardware to live production, outside my day job.
Ubiquiti UniFiWeb DesignCloudflare
cafegalang.com — live and running