Alerting & On-Call 1
▼
Understands SLI, SLO, SLA concepts and their application in cloud services. Knows SLA of major cloud providers (AWS 99.99% for S3, 99.95% for EC2). Monitors basic SLIs — availability, latency, error rate through CloudWatch dashboards.
Defines SLI/SLO for cloud services: availability (successful requests / total), latency (p50, p95, p99), throughput. Configures error budget tracking, burn rate alerts in Prometheus/CloudWatch. Understands multi-window multi-burn-rate alerts and their configuration.
Designs SLO framework for cloud platform: composite SLOs for distributed systems, dependency-aware SLOs, SLO-based deployment gates. Introduces error budget policies — automated rollback on budget exhaustion, feature freeze processes. Integrates SLO with incident management.
Defines organizational SLO culture: SLO review process, error budget governance, SLA negotiations with clients. Introduces tooling (Sloth, Google SLO Generator) and standards for all cloud services. Balances reliability requirements and delivery speed based on error budgets.
Algorithms & Data Structures 2
▼
Understands the fundamentals of Algorithms & Complexity at a basic level. Applies simple concepts in work tasks using Python/HCL. Follows recommendations from senior developers when solving problems.
Independently applies algorithmic thinking in cloud engineering: evaluates resource scheduling strategies, understands auto-scaling algorithm behavior, selects load balancing algorithms for traffic distribution. Analyzes cost/performance trade-offs of infrastructure provisioning approaches.
Applies algorithmic thinking to cloud infrastructure: resource scheduling algorithms for cost optimization, auto-scaling algorithms based on demand prediction, load balancing algorithms across availability zones. Designs efficient infrastructure provisioning algorithms minimizing deployment time and blast radius.
Evaluates algorithmic complexity of cloud solutions: cost of resource traversal through API, pagination when working with thousands of instances, Lambda cold start optimization. Defines performance budgets for IaC pipelines and automates degradation detection during infrastructure scaling.
Understands the fundamentals of Data Structures at a basic level. Applies simple concepts in work tasks using Python/HCL. Follows recommendations from senior developers when solving problems.
Independently selects appropriate data structures for IaC: Terraform module input/output structures, resource tagging schemas, variable type constraints for configuration validation. Understands trade-offs between nested vs flat infrastructure data models for maintainability.
Selects optimal data structures for cloud infrastructure: state file structures in Terraform for efficient plan/apply cycles, resource dependency graphs for provisioning order, tag taxonomies for resource organization. Optimizes infrastructure data models for multi-region consistency. Designs efficient configuration structures for scalable cloud resource management.
Defines standards for cloud infrastructure configuration storage and structuring: hierarchical Terraform state files, resource dependency DAGs, graph models for network topologies. Reviews data structure choices for CloudFormation stacks and Helm charts.
Application Security 1
▼
Knows about OWASP Top 10. Understands main vulnerabilities: SQL injection, XSS, CSRF. Uses parameterized queries. Does not store passwords in plaintext.
Applies security headers (CORS, CSP, X-Frame-Options). Protects against SSRF, path traversal, mass assignment. Uses input validation and sanitization. Configures rate limiting. Conducts basic security code review.
Designs application security architecture. Conducts threat modeling (STRIDE). Introduces security testing in CI (SAST/DAST). Designs secure defaults. Runs vulnerability management process. Trains the team on secure development.
CI/CD 1
▼
Creates simple GitHub Actions workflows for cloud projects: lint Terraform/CloudFormation, validate configurations, run tests. Understands workflow file structure, triggers (push, pull_request), uses existing actions for AWS CLI, Docker build and push.
Designs CI/CD pipelines for infrastructure: terraform plan in PR with result comment, automated apply after merge, matrix builds for multi-environments. Configures OIDC federation with AWS/GCP for secure authentication without long-lived credentials.
Develops reusable workflows and composite actions for infrastructure pipelines: standardized IaC pipeline (validate→plan→approve→apply), automated module updates, scheduled drift detection. Integrates security scanning (tfsec, checkov) and cost estimation.
Defines CI/CD strategy for all infrastructure repositories: standard workflow templates, self-hosted runners in private networks, secrets management through OIDC. Introduces governance — required reviews, environment protection rules, audit trail for infrastructure changes.
Cloud Providers 4
▼
Works with core AWS services: EC2, S3, RDS, IAM, VPC. Creates and configures resources through Console and CLI. Understands Shared Responsibility model, IAM policy basics, and account structure. Deploys simple applications on EC2/ECS.
Designs AWS infrastructure: multi-AZ architecture, Auto Scaling Groups, ALB/NLB, Route 53 for DNS. Configures VPC peering, Transit Gateway, Security Groups and NACLs. Works with managed services — RDS, ElastiCache, SQS, SNS for building resilient systems.
Designs complex AWS architectures: multi-account strategy (AWS Organizations, Control Tower), landing zones, cross-account access. Optimizes costs through Reserved Instances, Savings Plans, Spot Fleet. Introduces Well-Architected Framework and conducts architectural reviews.
Defines organizational AWS strategy: account vending machine, service control policies, centralized networking (Transit Gateway Hub). Manages enterprise support, cost allocation, budgets and alerts. Introduces FinOps practices and optimizes costs at the company level.
Understands core GCP services: Compute Engine, Cloud Storage, VPC, and IAM. Uses gcloud CLI for basic resource provisioning. Follows project structure and labeling conventions.
Independently configures and manages Google Cloud Platform. Writes IaC for common tasks. Understands networking and security basics.
Designs infrastructure solutions with Google Cloud Platform. Optimizes cost and performance. Introduces best practices and security hardening.
Defines infrastructure strategy with Google Cloud Platform. Establishes IaC standards. Conducts architecture review. Optimizes FinOps.
Understands core Azure services: VMs, Storage Accounts, VNets, and Resource Groups. Navigates Azure Portal and CLI for basic provisioning. Follows tagging and naming conventions.
Independently configures and manages Microsoft Azure. Writes IaC for common tasks. Understands networking and security basics.
Designs infrastructure solutions with Microsoft Azure. Optimizes cost and performance. Introduces best practices and security hardening.
Defines infrastructure strategy with Microsoft Azure. Establishes IaC standards. Conducts architecture review. Optimizes FinOps.
Understands basic Yandex Cloud concepts. Uses existing configurations. Performs simple operations under senior guidance.
Independently configures and manages Yandex Cloud. Writes IaC for common tasks. Understands networking and security basics.
Designs infrastructure solutions with Yandex Cloud. Optimizes cost and performance. Introduces best practices and security hardening.
Defines infrastructure strategy with Yandex Cloud. Establishes IaC standards. Conducts architecture review. Optimizes FinOps.
Code Review 1
▼
Participates in infrastructure code reviews: checks Terraform plan output, pays attention to security groups, IAM policies. Leaves constructive comments and asks questions about unfamiliar resources. Learns from senior colleagues' review feedback.
Conducts quality review of IaC code: checks naming conventions, tagging compliance, resource sizing, security best practices. Analyzes Terraform plan for destructive changes, drift and unexpected dependencies. Provides recommendations on cost optimization and architecture.
Conducts deep architectural review of infrastructure changes: evaluates blast radius, cross-service impact, compliance implications. Reviews modular structure, state management, security posture. Mentors colleagues through review and establishes IaC code quality standards.
Defines review process for infrastructure changes: review checklist, mandatory approvals by severity (production = 2+ approvals), automated policy checks. Builds a culture of quality review — knowledge sharing, not gate-keeping. Balances speed and safety.
Container Security 1
▼
Understands basic Container Security Scanning concepts. Uses existing configurations. Performs simple operations under senior guidance.
Independently configures container security scanning in CI/CD pipelines with Trivy, Snyk Container, or Aqua. Implements admission controllers for vulnerability gates. Manages base image registries with automated vulnerability patching workflows.
Designs infrastructure solutions with Container Security Scanning. Optimizes cost and performance. Introduces best practices and security hardening.
Defines infrastructure strategy with Container Security Scanning. Establishes IaC standards. Conducts architecture review. Optimizes FinOps.
Containerization 1
▼
Builds Docker images for simple services, writes basic Dockerfiles. Understands image layers, build caching, difference between CMD and ENTRYPOINT. Uses docker-compose for local development and can view container logs.
Optimizes Docker images: multi-stage builds, layer minimization, selecting alpine/distroless base images. Configures health checks, resource limits, graceful shutdown. Works with private registries (ECR, GCR, ACR) and configures vulnerability scanning.
Designs containerization strategy for cloud services: standardized base images, build pipeline with CI caching, runtime configuration through environment variables and secrets. Optimizes cold start for serverless containers (Fargate, Cloud Run).
Defines containerization standards for the organization: golden base images, security hardening guidelines, image scanning policies. Introduces automation for base image updates and patch management for container runtime.
Deployment Strategies 2
▼
Understands the fundamentals of Blue/Green Deployment. Applies basic practices in daily work. Follows recommendations from the team and documentation.
Independently creates and maintains Blue/Green Deployment. Configures CI/CD pipelines. Automates routine operations.
Designs CI/CD architecture with Blue/Green Deployment. Optimizes pipeline speed and reliability. Introduces progressive delivery.
Defines DevOps strategy with Blue/Green Deployment. Establishes CI/CD standards. Introduces platform engineering approaches.
Understands the fundamentals of Canary Deployment. Applies basic practices in daily work. Follows recommendations from the team and documentation.
Independently creates and maintains Canary Deployment. Configures CI/CD pipelines. Automates routine operations.
Designs CI/CD architecture with Canary Deployment. Optimizes pipeline speed and reliability. Introduces progressive delivery.
Defines DevOps strategy with Canary Deployment. Establishes CI/CD standards. Introduces platform engineering approaches.
DNS & Networking 3
▼
Configures basic CDN distributions using cloud provider consoles. Understands caching headers, TTL, and cache invalidation concepts. Deploys simple edge functions following team templates.
Implements CDN configurations with custom cache policies and origin failover using IaC. Deploys edge computing workloads for request transformation and A/B testing. Optimizes cache hit ratios and reduces origin load.
Designs infrastructure solutions with CDN and Edge Computing. Optimizes cost and performance. Introduces best practices and security hardening.
Defines CDN and edge computing strategy across multi-cloud environments. Establishes caching standards, edge security policies, and FinOps optimization for content delivery. Conducts architecture reviews for global content distribution.
Understands basic load balancing concepts in cloud: ALB/NLB in AWS, Azure Load Balancer, and health check configurations. Follows team guidelines for setting up target groups and SSL termination in managed load balancer services.
Independently configures cloud load balancing: multi-AZ ALB with path-based routing, weighted target groups for canary deployments, and WAF integration. Implements auto-scaling policies triggered by load balancer request metrics.
Designs infrastructure solutions with Load Balancing. Optimizes cost and performance. Introduces best practices and security hardening.
Defines load balancing strategy for cloud platform: multi-region traffic management, failover automation, and cost-optimized balancer selection. Establishes IaC standards for load balancer provisioning and conducts architecture reviews.
Understands basic VPN and network isolation concepts: site-to-site tunnels, IPSec/WireGuard protocols, and VPC peering fundamentals. Uses existing configurations to provision VPN connections in cloud environments. Follows team guidelines for network segmentation and firewall rule management.
Independently configures VPN solutions and network isolation in multi-cloud environments: AWS VPN Gateway, Azure VPN, GCP Cloud VPN with BGP routing. Implements network segmentation using VPC service controls, private endpoints, and transit gateway architectures. Understands zero-trust network access patterns.
Designs infrastructure solutions with VPN and Network Isolation. Optimizes cost and performance. Introduces best practices and security hardening.
Defines VPN and network isolation strategy for cloud infrastructure: establishes connectivity standards, transit architecture patterns, and zero-trust network policies. Conducts architecture reviews for multi-cloud network designs. Optimizes network costs through traffic engineering and interconnect planning.
Git & Workflows 1
▼
Works with Git for IaC code management: clones repositories, creates branches, makes commits and pull requests. Understands gitflow for infrastructure changes, writes meaningful commit messages describing infrastructure modifications.
Uses Git for team infrastructure work: feature branches for Terraform changes, interactive rebase for clean history, cherry-pick for hotfixes. Configures git hooks for pre-commit validation (terraform fmt, tflint) and pre-push security scanning.
Designs Git workflow for infrastructure repositories: monorepo vs polyrepo for Terraform modules, branching strategy for multi-environments, automated changelog generation. Introduces conventional commits, semantic versioning for IaC modules and CODEOWNERS for review.
Defines IaC repository management strategy: repo topology, access control, branch protection rules, mandatory reviews for production changes. Introduces GitOps workflow — infrastructure changes only through PR with automated plan and manual approve for apply.
GitOps 1
▼
Understands basic ArgoCD concepts including Application CRDs, sync policies, and GitOps workflow fundamentals. Follows team guidelines for viewing application sync status and checking deployment health in the ArgoCD UI. Uses existing ArgoCD Application manifests to deploy cloud infrastructure services.
Independently configures ArgoCD Applications and ApplicationSets for multi-environment cloud infrastructure deployments. Writes sync policies with automated self-healing, pruning strategies, and sync waves for ordered resource provisioning. Implements RBAC and project-level access controls for cloud team namespaces.
Designs ArgoCD architecture for multi-cluster cloud infrastructure management with ApplicationSets and cluster generators. Implements advanced GitOps patterns including progressive delivery integration, drift detection alerting, and secret management with Sealed Secrets or SOPS. Optimizes ArgoCD performance for large-scale cloud deployments with resource tracking and caching strategies.
Defines ArgoCD strategy and GitOps standards for the organization's cloud infrastructure fleet. Establishes multi-tenant ArgoCD governance with project structures, RBAC policies, and approval workflows. Conducts architecture reviews of ArgoCD configurations and drives adoption of declarative infrastructure delivery patterns across cloud engineering teams.
Incident Management 1
▼
Understands on-call basics for cloud infrastructure: alert triage procedures, runbook following for common incidents, and escalation paths. Participates in on-call rotations as secondary responder. Follows team practices for incident documentation and handoff procedures.
Participates in on-call rotation for cloud infrastructure. Configures PagerDuty/OpsGenie with escalation, responds to CloudWatch and Prometheus alerts. Classifies incidents by severity, performs initial diagnostics — checking metrics, logs, cloud provider status pages.
Designs on-call processes for cloud team: alert routing by services and severity, runbooks for common incidents (disk full, OOM, AZ failure), post-incident review process. Optimizes alert noise — deduplication, suppression rules, actionable alerts. Reduces toil through automation.
Defines on-call strategy for the cloud organization: follow-the-sun rotation, tier-1/tier-2 escalation, incident commander role. Introduces incident management process (ITIL/SRE), blameless postmortems, reliability metrics (MTTA, MTTR). Manages on-call load balancing and burnout prevention.
Infrastructure as Code 3
▼
Understands basic Ansible concepts including playbooks, inventory files, and module usage for cloud infrastructure provisioning. Follows team-provided playbooks for deploying and configuring cloud resources across AWS, GCP, or Azure environments. Uses ansible-playbook command to run existing automation tasks and reviews output for errors during cloud resource management.
Independently writes Ansible playbooks and roles for cloud infrastructure automation including VM provisioning, network configuration, and security group management. Implements dynamic inventory scripts for cloud providers and uses Ansible collections (amazon.aws, google.cloud, azure.azcollection) for idempotent resource management. Structures playbooks with roles, handlers, and templates for reusable cloud configuration patterns across environments.
Designs Ansible automation architecture for enterprise cloud infrastructure with multi-cloud support, encrypted secrets management via Ansible Vault, and CI/CD integration for infrastructure-as-code pipelines. Implements advanced patterns including custom modules for cloud-specific operations, Ansible Tower/AWX workflows for complex provisioning sequences, and idempotent drift detection playbooks. Optimizes Ansible execution performance for large cloud estates through parallelism tuning, fact caching, and connection pooling strategies.
Defines Ansible automation standards and best practices for cloud infrastructure teams across the organization. Establishes role and collection development guidelines, testing frameworks with Molecule, and Ansible Tower/AWX governance for self-service cloud provisioning. Conducts architecture reviews of automation codebases and drives adoption of standardized cloud provisioning patterns through reusable Ansible collections.
Understands basic Pulumi concepts: stacks, resources, and state management for cloud infrastructure. Deploys simple cloud resources using existing Pulumi programs in TypeScript or Python. Follows team conventions for stack organization, secret handling, and configuration management.
Independently writes Pulumi programs for multi-cloud deployments using component resources and stack references. Configures networking, IAM, and storage with proper secret encryption and environment management. Understands Pulumi policy-as-code with CrossGuard for compliance enforcement.
Designs infrastructure solutions with Pulumi. Optimizes cost and performance. Introduces best practices and security hardening.
Defines cloud infrastructure strategy with Pulumi: establishes IaC standards, module registry governance, and multi-environment promotion workflows. Conducts architecture reviews for cross-team Pulumi adoption. Optimizes FinOps through automated cost policies and resource lifecycle management.
Understands Terraform fundamentals: HCL syntax, provider configuration, resource blocks, and data sources. Works with terraform init/plan/apply workflow. Manages state files and understands locking. Creates basic cloud resources (VMs, networks, storage) from documentation examples.
Writes modular Terraform configurations for multi-tier cloud architectures. Creates reusable modules with input variables, outputs, and documentation. Manages multi-environment setups using workspaces or directory structures. Implements remote state with locking (S3+DynamoDB, GCS). Configures IAM policies and security groups through Terraform.
Designs modular Terraform architecture: reusable modules for VPC, EKS, RDS, remote state with locking, workspaces for multi-environments. Introduces Terragrunt for DRY configurations and automates plan/apply through CI/CD with review process.
Defines organizational IaC standards: repository structure, naming conventions, tagging strategy, module registry. Introduces policy-as-code through Sentinel/OPA, drift detection, cost estimation (Infracost). Trains teams on Terraform best practices.
Infrastructure Security 1
▼
Understands basic Secrets Management concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
Integrates HashiCorp Vault with cloud infrastructure: dynamic secrets for AWS/GCP, PKI engine for TLS certificates, transit engine for encryption. Configures auth methods (AWS IAM, Kubernetes) and policies for secure service access to secrets.
Designs secrets management architecture: Vault cluster in HA configuration, auto-unseal through KMS, audit logging. Introduces secret rotation for database credentials and API keys. Integrates with Terraform through Vault provider and External Secrets Operator in Kubernetes.
Defines secrets management strategy for the organization: Vault vs AWS Secrets Manager vs GCP Secret Manager, namespace hierarchy for multi-tenancy, emergency break-glass procedures. Introduces compliance controls and automated audit of secrets access.
Kubernetes & Orchestration 3
▼
Installs and upgrades applications using existing Helm charts. Understands Helm chart structure: templates, values, and Chart.yaml. Customizes deployments by overriding values files under senior guidance.
Authors reusable Helm charts with parameterized templates and dependency management. Implements Helm hooks for migration and initialization workflows. Integrates Helm deployments into CI/CD pipelines with automated testing.
Designs infrastructure solutions with Helm. Optimizes cost and performance. Introduces best practices and security hardening.
Defines Helm chart standards and library charts for organization-wide Kubernetes deployments. Establishes chart review processes, security scanning, and versioning governance. Drives adoption of GitOps workflows with Helm and ArgoCD or Flux.
Understands Kubernetes resource types (Deployments, Services, ConfigMaps). Uses kubectl to inspect pod status, view logs, and apply existing manifests in cloud environments.
Configures Kubernetes RBAC, network policies, and Ingress controllers for multi-tenant cloud environments. Writes Helm charts and manages cluster upgrades with zero-downtime strategies.
Designs infrastructure solutions with Kubernetes Advanced. Optimizes cost and performance. Introduces best practices and security hardening.
Defines multi-cluster Kubernetes strategy across cloud providers. Establishes GitOps workflows with ArgoCD/Flux, implements service mesh policies, and optimizes cluster costs with FinOps practices.
Understands core Kubernetes concepts: Pod, Deployment, Service, ConfigMap, Secret. Can deploy applications via kubectl, view pod logs, perform port-forward for debugging. Knows basic cluster architecture — control plane and worker nodes.
Configures production-ready deployments: resource requests/limits, liveness/readiness probes, HPA, PDB. Works with Ingress controllers, NetworkPolicy, RBAC. Understands scheduling, taints/tolerations and affinity rules for load distribution.
Designs production Kubernetes clusters: choosing between managed (EKS/GKE/AKS) and self-managed, namespace strategy, quota management. Configures cluster autoscaler, spot/preemptible instances, node groups. Introduces GitOps approach to resource management.
Defines Kubernetes standards for the organization: cluster provisioning through IaC, security baseline (CIS benchmarks), cluster health monitoring. Introduces platform engineering approach — internal developer platform based on Kubernetes.
Logging 1
▼
Uses JSON format for cloud service logs. Includes request_id, service_name, environment, cloud region in logs. Understands the importance of structured logging for CloudWatch Insights and OpenSearch filtering. Avoids logging sensitive data (secrets, PII).
Implements unified log format for cloud workloads: standard fields (trace_id, span_id, account_id, resource_arn), log levels convention. Configures CloudWatch Insights queries for analysis, creates metric filters for automated log-based monitoring.
Designs structured logging standard for cloud platform: unified schema for Lambda/ECS/EKS, correlation through X-Ray trace ID, enrichment with cloud context (region, AZ, instance type). Automates compliance — PII masking, data classification in logs.
Defines organizational logging standards: mandatory fields, log levels policy, sensitive data handling. Introduces automated log validation in CI/CD, standards compliance monitoring. Trains teams on best practices and reviews logging configurations.
Networking 1
▼
Understands basic networking concepts for cloud infrastructure — VPC configuration, subnet addressing, security groups, and route tables. Follows team guidelines for provisioning network resources and troubleshooting connectivity between cloud services.
Designs network architecture: multi-tier VPC with public/private/isolated subnets, VPC Peering, Transit Gateway for VPC connectivity. Configures DNS (Route 53/Cloud DNS) with health checks and failover. Works with Site-to-Site VPN and Direct Connect for hybrid environments.
Designs enterprise network architecture: hub-and-spoke topology through Transit Gateway, shared VPC, PrivateLink for inter-service communication. Introduces network firewall, traffic mirroring for analysis, IPv6 dual-stack. Optimizes latency and data transfer costs.
Defines organizational networking strategy: centralized networking account, IP address management (IPAM), segmentation standards. Introduces service mesh for microservices, zero-trust networking. Manages network changes through IaC with automated compliance.
Serverless 2
▼
Understands serverless container services: AWS Fargate, Cloud Run, and Azure Container Instances. Deploys containerized applications without managing infrastructure. Configures basic scaling and networking.
Independently configures and manages Serverless Containers. Writes IaC for common tasks. Understands networking and security basics.
Designs infrastructure solutions with Serverless Containers. Optimizes cost and performance. Introduces best practices and security hardening.
Defines infrastructure strategy with Serverless Containers. Establishes IaC standards. Conducts architecture review. Optimizes FinOps.
Understands basic serverless concepts: AWS Lambda, Azure Functions, Google Cloud Functions. Deploys simple functions using CLI or console. Follows existing event trigger configurations and IAM policies.
Independently designs and deploys serverless architectures with API Gateway, SQS, and event-driven triggers. Configures cold start mitigation, concurrency limits, and VPC connectivity. Writes Terraform/CloudFormation for serverless stacks.
Designs infrastructure solutions with Serverless Functions. Optimizes cost and performance. Introduces best practices and security hardening.
Defines serverless-first infrastructure strategy across the organization. Establishes IaC standards for function deployment, monitoring, and cost governance. Conducts architecture reviews of serverless solutions and optimizes FinOps for compute spend.
System Design 3
▼
Understands basic capacity planning concepts for cloud infrastructure: instance sizing, auto-scaling groups, and resource quotas. Follows team guidelines for monitoring cloud resource utilization and cost allocation dashboards.
Applies capacity planning for cloud workloads: right-sizing instances, configuring HPA/VPA in Kubernetes, and implementing auto-scaling policies. Analyzes resource utilization trends and forecasts capacity needs for cloud services.
Designs capacity planning architecture for multi-cloud environments. Implements predictive scaling with ML-based forecasting, cost optimization strategies, and reserved capacity management. Makes ADR decisions on scaling patterns and resource allocation.
Defines product architectural strategy with Capacity Planning. Establishes architecture guidelines. Conducts architecture review.
Understands basic architectural concepts of High Load Architecture. Follows team architectural decisions. Understands main patterns.
Designs cloud architectures for medium loads: Auto Scaling Groups with custom metrics, caching through ElastiCache/Memorystore, async processing through SQS/Pub-Sub. Understands trade-offs between vertical and horizontal scaling of managed services.
Designs high-load cloud systems: multi-region deployments, global database (Aurora Global, Spanner), CDN for latency reduction. Optimizes throughput through connection pooling, read replicas, event-driven architectures. Introduces load testing and chaos engineering.
Defines architectural standards for high-load cloud-native systems: reference architectures, performance budgets, scalability review checklist. Conducts architecture review, identifies bottlenecks through load testing and designs capacity planning processes.
Understands basic cloud architecture concepts: VPC networking design, compute/storage/database service selection, and availability zone placement strategies. Follows team architectural decisions for cloud resource organization and landing zone patterns.
Designs cloud-native systems: 12-factor apps, microservices on managed services (Lambda, ECS, Cloud Run), event-driven architecture with SQS/EventBridge. Chooses between managed and self-hosted solutions considering cost, operational overhead and vendor lock-in.
Designs complex distributed systems in cloud: saga pattern for distributed transactions, CQRS with DynamoDB Streams/Change Data Capture, multi-tenant architecture. Documents architectural decisions through ADR and conducts system design review.
Defines organizational architectural standards: technology radar, reference architectures for common scenarios (REST API, event processing, data pipeline). Establishes architecture review process and trains teams on cloud-native design patterns.