Internal Developer Platform
A golden-path platform that turned repository creation, delivery and environment provisioning into a single self-service workflow.
- Platform
- Cloud
- DevSecOps
- Kubernetes
- Argo CD
- Terraform
- Backstage
- GitHub Actions
iam.alan.abreu · DEVSECOPS
Secure by design. Built to evolve. DevSecOps, platform engineering, cloud and applied AI.
01
Golden paths, self-service environments and templates teams can read and fork.
02
Supply-chain controls and policy gates that run inside delivery, not beside it.
03
Declarative infrastructure with recoverable, auditable state.
04
SLO-driven alerting and instrumentation that makes service health legible.
05
Grounded retrieval over engineering knowledge, with citations and honest refusals.
—
Infrastructure, security, reliability and AI are one surface.
Core
Who I am, what I shipped and how it is designed.
A golden-path platform that turned repository creation, delivery and environment provisioning into a single self-service workflow.
Supply-chain controls, signed artifacts and policy gates embedded into delivery without turning security into a release blocker.
A shared SLO, alerting and instrumentation baseline that made service health legible across teams.
System diagrams, component models, data flows and the trade-offs behind them.
Launch stateThese entries are placeholders while the real case studies and experiment write-ups are prepared for publication.
A GitOps-based control plane that turns repository, delivery and environment concerns into self-service workflows.
A delivery pipeline where supply-chain controls, signing and policy gates run as part of the build contract.
Practice
Experiments and notes from the workbench.
Can retrieval over internal runbooks answer on-call questions without inventing steps that do not exist?
A local environment for writing, testing and dry-running admission policies before they ever reach a cluster.
Engineering notes, lab reports, how-tos and things learned while building systems.
Launch stateThese entries are placeholders while the real case studies and experiment write-ups are prepared for publication.
A note on the gap between a platform that is technically correct and one that teams actually adopt.
Early findings from building a retrieval system that answers operational questions only from cited runbooks.
Foundations
Decisions and the tools behind them.
Architecture Decision Records: context, options, choices and consequences.
Use declarative reconciliation from Git instead of imperative deployment pipelines to drive cluster state.
Answer operational questions by retrieving from runbooks rather than fine-tuning a model on internal incidents.
A snapshot of what is currently being built, explored, learned and tested.
Technologies in context: why they are chosen and where they show up.
The common substrate for platform workloads. I use it as a reconciliation target, not as the product itself.
Infrastructure as code for cloud resources and Kubernetes cluster lifecycle.
Delivery orchestration and the place where most security controls first touch the artifact.
Policy-as-code for admission control, delivery gates and configuration validation.
Instrumentation standard for metrics, traces and logs across services.
Default durable store for structured data and, with pgvector, a retrieval backend.
Ask about systems, decisions, trade-offs and experiments published here. Every answer is grounded in the site's own content — with citations, and an honest “not documented yet” when the record is silent.
Ask a questionAlan Abreu is an engineer working across Platform Engineering, DevSecOps, Cloud and Reliability, with a growing focus on Applied AI.
The through line is treating engineering itself as a system: delivery, security, infrastructure and operations are one connected surface, not separate departments handing work to each other.