Production Runbooks / Muhammad Ibtisam Iqbal CKA · CKAD

Production infrastructure, documented from the trenches.

I don't chase buzzwords. I look for broken systems and redesign them until they become reliable, predictable, and calm under pressure. Step-by-step procedures, cloud migrations, and cluster configurations — documented upon live execution.

⚡ runbook.sh active
prod
$ runbook status --verified
✓ gitops/eks-boutique · ArgoCD, Gateway API, 10 microservices
✓ cloud/java-monolith · 4 compute targets (ASG ➔ ECS ➔ EKS)
✓ helmfile/retail-store · 3 targets (Bare-Metal ➔ Amazon EKS)
[ok] 3 production topologies validated & repeatable.
01 / PLATFORMS
4 Targets
EC2 Auto Scaling ➔ ECS Fargate ➔ Bare-Metal K8s ➔ Amazon EKS
02 / MICROSERVICES
5 Runtimes
Polyglot microservices stack with 5 databases orchestrated via Helmfile
03 / DEVSECOPS
14 Stages
Jenkins & GitHub Actions CI with SonarQube quality gates & Trivy scans
04 / DOMAINS
15+ Verified
HA Kubernetes, Gateway API, WireGuard Mesh, and full telemetry
Tailored Navigation

Choose Your Focus

Whether you are an engineering leader evaluating technical capability, a fellow SRE looking for battle-tested configs, or a developer exploring infrastructure systems.

Platform Engineering ● Production Verified
Terraform Amazon EKS ArgoCD Gateway API ExternalDNS Prometheus Elastic Stack

Event-Driven GitOps: Polyglot Microservices on Amazon EKS

Architected a production-grade GitOps platform on Amazon EKS for Google's 10-service Online Boutique. Engineered 3 automated CI pipelines with change detection, Trivy container security scanning, automated Helm packaging to GHCR, and zero-touch continuous delivery using ArgoCD Image Updater.

Continuous Delivery Zero-touch ArgoCD Image Updater via GHCR
Traffic Ingress Kubernetes Gateway API + Route 53 ExternalDNS
Telemetry Stack Kube-Prometheus, Grafana, AlertManager & Elastic
DevSecOps & Cloud ● Production Verified
Java 21 Spring Boot 3.4 EC2 ASG Amazon ECS Fargate Amazon EKS Jenkins GitHub Actions Trivy

BankApp: Evolutionary Cloud Migration Across 4 Compute Targets

Orchestrated an end-to-end DevSecOps strategy for a 3-tier Java Spring Boot banking monolith. Executed codebase modernization, multi-stage Docker containerization, 14-stage CI pipelines in Jenkins and GitHub Actions with SonarQube & Trivy gates, and deployed the identical artifact across four increasingly scalable compute paradigms.

Compute Targets EC2 Auto Scaling ➔ ECS Fargate ➔ Bare-Metal K8s ➔ EKS
Security Gates Trivy layered scan (OS vs Lib) + SonarQube quality gate
Artifact Stores Nexus Snapshot Repo, Amazon S3, ECR & GHCR
Platform & Orchestration ● Production Verified
Helmfile Amazon EKS ALB Ingress EBS CSI gp3 DynamoDB AWS SQS Lambda

Multi-Target Polyglot Microservices: Bare-Metal to Amazon EKS

Engineered multi-environment declarative orchestration for AWS's retail store application (5 independent services, 5 runtimes, 5 databases). Decoupled upstream Helm charts via layered values-*.yaml overrides and automated 1-command deployments across ephemeral bare-metal, persistent bare-metal, and Amazon EKS.

Declarative Tooling 3 Helmfile targets with strict dependency ordering
Cloud Integrations ALB Ingress, EBS CSI, DynamoDB, SQS, SNS & Lambda
Portability Severed cloud dependencies for zero-drift bare-metal runs
War Stories & Post-Mortems

What Broke & How I Fixed It

Production engineering is measured by how you diagnose and remediate failure. Here are actual debugging hurdles resolved during live system implementations.

SEV-1 · Ingress & Probes Resolved ✓
ALB Health Check Cascade Failure on Spring Boot 302 Redirect
Root Cause / Symptom: Deploying the BankApp monolith behind an AWS Application Load Balancer caused instances to enter a termination loop; Spring Security intercepted root / with a 302 Found redirect to /login, which the default ALB health check flagged as unhealthy.
Engineering Remediation: Reconfigured Target Group matcher to accept 200,302, deployed dedicated /actuator/health probes, and configured native X-Forwarded-Proto handling to eliminate HTTPS redirect loops.
View ALB post-mortem & runbook →
SEV-2 · Traffic Ingress Resolved ✓
Gateway API Listener Port Conflicts
Root Cause / Symptom: Deploying Envoy Gateway on bare-metal caused listener binding clashes with existing NodePort services and host port bindings.
Engineering Remediation: Decoupled L4 traffic via MetalLB Layer 2 ARP IP address pools, standardizing HTTPRoute attachment rules with explicit sectionName bindings.
View Gateway API runbook →
SEV-1 · Cluster Bootstrap Resolved ✓
EKS Worker Nodes Stuck 'Unauthorized' on API Server
Root Cause / Symptom: Nodes booted via launch templates failed API registration with err="Unauthorized" due to IAM authenticationMode mismatch between EKS access entries and sandbox SCP policies.
Engineering Remediation: Extracted InstanceProfileArn via IMDS (169.254.169.254), patched cluster to API_AND_CONFIG_MAP, and mapped the node role to system:bootstrappers & system:nodes.
View EKS bootstrap runbook →
Engineering System

The 4-Tier Knowledge Pipeline

How research translates into operational field notes, reusable infrastructure artifacts, and distilled technical essays.

Infrastructure Directory

Operational Domains

Systematic reference documentation organized across core infrastructure disciplines.

Engineering Collaboration

Let's build reliable, calm systems.

Engineered by Muhammad Ibtisam Iqbal (CKA & CKAD Certified). Based in Islamabad, Pakistan. Available for platform engineering, cloud migration, and SRE infrastructure discussions.