Azure Cloud Portfolio · AZ-104

Gerard Ostebovik

From billing support to building production-grade cloud infrastructure on Azure — one real deployment at a time.

15 PROJECTS.
ONE SUBSCRIPTION.
ZERO SHORTCUTS.

This portfolio documents a deliberate journey through Azure infrastructure — no tutorials nor sandboxes. Only production-pattern deployments built from scratch using Azure CLI, Bicep, and GitHub Actions.

Every project here reflects a real architectural decision: why this service over that one, what the tradeoffs are at scale, and what I would do differently next time. The lessons learned sections are honest.

Currently pursuing the AZ-104 Microsoft Certified: Azure Administrator certification, with AI, Security and Identity specializations planned next.

14
Projects deployed
4
Azure skill domains
40+
Resources in production
1
Certification in progress

Skill Domains

IaaS · PaaS Foundation

Identity &
Governance

Role-based access control, Entra ID configuration, Azure Policy enforcement, and Management Group hierarchy — the security and compliance layer everything else runs on.

RBACEntra IDAzure PolicyZero TrustManagement Groups
View projects
IaaS

Networking

Hub-spoke VNet architecture, NSG design, load balancing, private endpoints, DNS, Application Gateway with WAF, and Bastion — production network topology built from scratch.

VNetNSGPrivate EndpointsApp GatewayWAFBastion
View projects
IaaS · PaaS

Compute &
Storage

Windows and Linux VMs, App Service, Container Registry and Container Apps, blob storage, backup, and site recovery — the full compute and data tier.

Virtual MachinesApp ServiceContainer AppsACRBlob Storage
View projects
IaC

Infrastructure
as Code

Modular Bicep deployments, Key Vault with managed identity for zero-credential architecture, CI/CD pipelines, and parameterized multi-environment deployments.

BicepKey VaultManaged IdentityCI/CDGitHub Actions
View projects
PaaS

Monitoring &
Security

Log Analytics workspaces, KQL queries, Application Insights, diagnostic settings, Microsoft Defender for Cloud, and alert rules — full observability across the stack.

Log AnalyticsKQLApp InsightsDefenderDCR
View projects
PaaS · AI

AI &
Automation

Azure OpenAI, AI-integrated monitoring, Copilot-assisted infrastructure, and intelligent automation pipelines. Coming next.

Azure OpenAICopilotAutomation
Coming soon