← Projects

This site: static hosting on AWS with Terraform and OIDC

A personal site treated as a production system: private S3 behind CloudFront, two Terraform stacks and a single GitHub Actions pipeline with no stored AWS keys.

View repository →

Context

I wanted a place to publish my resume, projects and notes, and I wanted the site itself to show how I work. So I built it the way I would build infrastructure for a team: everything in code, reviewed through pull requests and shipped by a pipeline.

What I did

Architecture

Visitor ──HTTPS──▶ Route 53 ──▶ CloudFront (TLS/ACM, CloudFront Function, security headers)
                                    │  Origin Access Control
                                    ▼
                              S3 (private bucket)

GitHub ──▶ GitHub Actions ──OIDC──▶ IAM roles (infra / deploy)

The pipeline detects whether a change touches infrastructure, the site or both. Infrastructure changes go through terraform fmt, validate, tflint and checkov; on pull requests the plan is posted as a comment, and on main it is applied. The site deploy only runs after a successful apply (or when infra did not change), so even the very first push creates the infrastructure and then publishes the site.

Results

More details are on the About this site page.