# Deependra Bhatta > Deependra (Dipendra) Bhatta is a Platform & DevOps Engineer based in Kathmandu, Nepal. I build the platform other engineers ship on, secrets, observability, and zero-trust CI/CD as code. Platform and DevOps engineer operating production infrastructure across AWS and a self-hosted Linux fleet. I own the secrets and identity platform built on HashiCorp Vault and Keycloak, the Prometheus/Loki/Grafana observability stack behind it, and the AWS infrastructure under client SaaS products. I work in the layer most teams postpone: least-privilege access, secrets-as-code, tested alerting, and backups proven restorable. Also written as: Dipendra Bhatta. Also known as: Cloud Infrastructure & Security Engineer. ## Profile - [Website](https://www.deependrabhatta.com.np): portfolio with projects, live sites and skills - [Resume (PDF)](https://www.deependrabhatta.com.np/Deependra-Bhatta-Resume.pdf): full resume - [GitHub](https://github.com/deependra-bhatta): code and labs - [LinkedIn](https://www.linkedin.com/in/deependra-bhatta-15a1ba203/): work history - [Blog](https://devopsdeependrabhatta.wordpress.com/): cloud and DevOps notes - Email: bhattadeependra05@gmail.com ## Current role Platform & DevOps Engineer at RippleBytes (Nov 2025 – Present, Nepal · Remote (AU & NP clients)). Own the shared platform layer across the engineering org: secrets and identity, fleet observability, and the AWS infrastructure behind client SaaS products. Around 950 commits across 48 repositories. ## Skills - Infrastructure as Code: AWS CDK (TypeScript), Terraform, Ansible, CloudFormation, Docker Compose, Make - AWS: IAM, KMS, VPC & VPC Endpoints, CloudFront, WAF, Aurora / RDS, ECS, Lambda, API Gateway, S3, SSM, ECR, SNS, CodeBuild, App Runner, Amplify, Route 53 - Security & Identity: HashiCorp Vault, Keycloak (OIDC), GitHub OIDC federation, Least-privilege IAM, Customer-managed KMS, Secrets-as-code, Semgrep, Trivy, Gitleaks, GPG, Security headers / CSP, Audit logging, fail2ban - Observability & Reliability: Prometheus, PromQL, Loki, Alertmanager, Grafana, Grafana Alloy, cAdvisor, promtool testing, CloudWatch, Dead-man’s switch, Meta-monitoring, Disaster recovery - CI/CD: GitHub Actions, AWS CodePipeline / CodeBuild, Jenkins, OIDC-based auth, Reusable workflows, Approval gates, Coverage reporting, Pre-commit hooks - Containers & Orchestration: Docker, Multi-stage builds, Docker Compose, Kubernetes, Helm, Traefik, Nginx, Harbor, ECR, Portainer, Dozzle - Languages & Scripting: Go, Python, TypeScript / Node.js, Bash, SQL, HCL, PromQL, YAML / Jinja2 - Data & Operations: PostgreSQL, Aurora, MongoDB, MySQL, Redis, Supabase, DuckDB, Prisma migrations, Encrypted backups, Restore verification, Glacier archival ## Platform projects ### Self-Hosted Observability, Identity & Secrets Platform 6 platform services, sole author. A rebuildable platform, with alerting that alerts on itself. - Problem: Hosted monitoring with no alert guarantees and no way to rebuild it. - Built: Self-hosted Prometheus, Loki, Grafana, Keycloak and Vault, one unit per layer. - Secured: One authenticated way in. Secrets isolated from the monitoring backends. - Result: Alerts survive losing the dashboards, and silence itself raises an alert. - Stack: Prometheus, PromQL, Loki, Alertmanager, Grafana OSS, Grafana Alloy, Traefik, Keycloak, HashiCorp Vault, Ansible, Docker Compose, promtool, fail2ban ### Secrets & Identity as Code: Vault + Terraform 18 Terraform stacks, one module. Zero long-lived CI credentials, deny-by-default access. - Problem: Secrets scattered in .env files, with no audit trail or rotation. - Built: 18 Terraform stacks sharing one reusable Vault module. - Secured: CI signs in with short-lived tokens. An empty grant list means no access. - Result: Every permission change is a one-line diff someone can review. - Stack: HashiCorp Vault, Terraform, HCL, Keycloak, Object storage, IAM, GitHub OIDC, JWT auth, Bash, Make ### AWS Platform for a Regulated Client SaaS 100% of the platform in AWS CDK. Infrastructure as code, in a compliance-bound account. - Problem: A regulated SaaS needed a cloud platform it could review and audit. - Built: The whole platform in AWS CDK, split so each layer deploys alone. - Secured: Customer-managed encryption keys and least-privilege deploy roles. - Result: Real errors page a human. Expected noise is counted, not paged. - Stack: AWS CDK, TypeScript, AWS, Infrastructure as Code, Observability, PostgreSQL, Docker ### Removing Standing Credentials from Client CI/CD 2 platforms moved to federated CI. Delete the standing credential, shrink the surface. - Problem: Two platforms deployed with broad, long-lived cloud keys stored in CI. - Built: Federated CI identity per environment, with edge and DNS config as code. - Secured: Least-privilege deploys. Secrets resolved at runtime, never baked into builds. - Result: Standing credentials deleted, leaving less surface to misconfigure. - Stack: AWS, GitHub OIDC, IAM, CDN + WAF, TLS/ACM, Serverless, Python, Node LTS, Infrastructure as Code ### grc_watcher: Concurrent Multi-Repo Security Scanner 3,225 lines of Go. Fan-out security scanning without Docker overhead. - Problem: Three scanners run by hand per repo, so scans got skipped. - Built: A Go CLI that clones and scans many repos in parallel. - Secured: Semgrep, Trivy and Gitleaks in one sweep across every repo. - Result: One de-duplicated report, so each finding shows up once. - Stack: Go, Goroutines, Semgrep, Trivy, Gitleaks, Make, HTML reporting ### Encrypted Backup & Restore-Verification Pipeline ~4,900 lines · restores proven. An untested backup is not a backup. - Problem: Database backups existed, but nobody had ever restored one. - Built: Encrypted dumps to S3, restored into throwaway containers to prove them. - Secured: GPG encrypted before upload. Checksums verified before every restore. - Result: Every client backup is proven to come back, not assumed. - Stack: Bash, Python, boto3, GPG, SHA-256, PostgreSQL, MySQL, DuckDB, Docker Compose, AWS S3, Glacier, Cron ### PipelineWatch: CI/CD Deployment Observability 1 view for every pipeline. One dashboard for every pipeline, every repo. - Problem: Deploy status was scattered across dozens of repositories. - Built: A FastAPI and React app fed by GitHub webhooks. - Secured: Managed API keys. Webhook payloads validated when they arrive. - Result: One live view, and an alert the moment any pipeline fails. - Stack: FastAPI, Python, React, Vite, TypeScript, Docker Compose, Tailwind, ngrok ## Automation tools - Vault Operations Library: A shell library and helper set that makes Vault operations repeatable instead of remembered, pushing server credentials, converting .env files into KV paths, auditing group membership, and hydrating a developer shell. - Restore Verification Suite: The part most teams skip. Each client has a compose file and restore script that pulls the encrypted dump, verifies its SHA-256, decrypts it, and replays it into a disposable database container to prove the backup actually restores. - Encrypted Database Backup Pipeline: Scheduled dumps encrypted before leaving the host, integrity-checked with SHA-256 manifests, validated for freshness in S3 by a boto3 checker, and aged into Glacier by lifecycle policy. - DuckDB Database Drift Auditing: Compares production and development databases table by table, row counts and real on-disk sizes, using DuckDB over SSH tunnels, so environment drift is measured instead of assumed. - Host Monitoring & Alerting Daemon: A self-hosted monitoring agent that turns a Linux box into a machine you can trust remotely: event-driven power daemon plus scheduled health snapshots, with hardware auto-detection and alert hysteresis. - Makefile Platform Orchestration: Every platform operation is a Make target with local validation before anything touches a server, promtool, amtool and compose configs are checked first, and deploys are gated on explicit targets. - Reusable CI/CD Workflow Templates: Shared GitHub Actions build and deploy templates plus Vault secret-pull workflows, so a new service inherits a hardened pipeline instead of copying a broken one. - SMTP & Mail Deliverability Diagnostics: A diagnostic suite for debugging production mail delivery at the protocol level, raw SMTP conversations, deliverability checks and send-rate load testing, built while chasing real delivery failures. ## Labs - [Java Task Manager](https://github.com/deependra-bhatta/Simple_Java_TM/tree/harbor): Jenkins CI/CD with SonarQube, Trivy, Harbor, Ansible and Prometheus/Grafana. - [IDURAR ERP/CRM on Kubernetes](https://github.com/deependra-bhatta/mern_admin_nodejs_fullstack): MERN ERP on Kubernetes with Helm, Ingress, PVCs and a Trivy-gated GitHub Actions pipeline. - [MERN Task Manager](https://github.com/deependra-bhatta/Ansible_Project/tree/main): Jenkins pipeline pushing Trivy-scanned images to Harbor, delivered by Ansible. - [DevConnector (Django + React)](https://github.com/deependra-bhatta/Django_React_application): Django API and React UI behind Nginx on Docker Compose with automated migrations. ## Live production sites (17) - [app.businessreset.com.au](https://app.businessreset.com.au/): Platform & infrastructure owner - [portal.businessreset.com.au](https://portal.businessreset.com.au/portal/sign-in): Platform & infrastructure owner - [sbrsuccess.com.au](https://sbrsuccess.com.au): Cloud infrastructure, CDN & WAF owner - [start.businessreset.com.au](https://start.businessreset.com.au/): Serverless infrastructure & CI/CD security - [getgrc.tech](https://getgrc.tech/auth/login): Deployment, secrets & observability owner - [astro.aatmavedalab.com](https://astro.aatmavedalab.com/): Deployment & infrastructure - [devpulse.info](https://devpulse.info): Infrastructure owner, sole author of deployment repo - [aatmavedalab.com](https://aatmavedalab.com): Infrastructure owner, sole author of deployment repo - [southwestern.edu.np](https://southwestern.edu.np): Deployment & hosting - [swsc.edu.np](https://swsc.edu.np): Deployment & hosting - [dev.freightconx.com](https://dev.freightconx.com): Deployment & hosting - [aroannepal.com](https://aroannepal.com): Deployment & hosting - [cp.schoolsie.com](https://cp.schoolsie.com): Deployment & hosting - [cph.schoolsie.com](https://cph.schoolsie.com): Deployment & hosting - [rajendrakc.com](https://rajendrakc.com/): Deployment & hosting - [operation.ripplebytes.com](https://operation.ripplebytes.com/): Deployment & hosting - [fieldmate.theripplebytes.com](https://fieldmate.theripplebytes.com/): Deployment & hosting ## Education - B.Sc. IT, Cloud Engineering, Asia Pacific University (APU) (Sep 2024 – Present) - Mastering DevOps, TechAxis Nepal (Mar 2025 – Jul 2025) - In progress: CKA, Certified Kubernetes Administrator - In progress: AWS Solutions Architect Associate