THE AUTOMATION WORKSHOP

Design the loop.
Know the next action.

Six cloud and platform blueprints. Follow the trigger, inspect the evidence and understand the verification gate before a system acts.

Explore the blueprints
REFERENCE DESIGNS

These pages document intended workflows. They do not start jobs, connect accounts or run hosted automations. Implementation and service access are separate prerequisites.

CHOOSE A USE CASE

A blueprint for the work at hand.

6 blueprints

SecurityBLUEPRINT 01

IAM Drift Sentinel

Design intent

Watches CloudTrail for over-permissive policy writes, reasons against 90 days of real access, and opens a scoped Terraform PR — verified in the IAM simulator first.

Starts with
IAM policy change
Produces
least-privilege PR
FinOpsBLUEPRINT 02

Cost Anomaly Digest

Design intent

Separates real cost anomalies from weekday noise and new workloads, then writes the digest a human actually reads: top 3 movers, why, one-line fix.

Starts with
daily 07:00 IST
Produces
Slack digest + PDF
IncidentsBLUEPRINT 03

Postmortem Drafter

Design intent

On incident resolution, pulls the Slack war-room and PagerDuty timeline, drafts a blameless postmortem with open questions flagged — never publishes on its own.

Starts with
PagerDuty resolved
Produces
draft postmortem doc
KubernetesBLUEPRINT 04

K8s Deprecation Radar

Design intent

When a new EKS/GKE minor goes GA, scans every cluster for deprecated API usage and files one migration issue per team with the exact manifest fixes.

Starts with
new EKS minor GA
Produces
migration issue + fixes
SecurityBLUEPRINT 05

TF Plan Explainer

Design intent

Turns a 400-line plan into six lines of plain English: what's destroyed, what's risky, what's cosmetic — so reviewers read the diff that matters.

Starts with
terraform plan in CI
Produces
PR comment
SecurityBLUEPRINT 06

Expiry Sweep

Design intent

Weekly sweep of ACM certs, KMS keys, and service-account tokens nearing expiry. Opens the rotation PR itself and pings the owner — before the pager does.

Starts with
Mon 09:00 weekly
Produces
rotation PR + alert

HOW TO USE A BLUEPRINT

Start with one bounded workflow.

  1. Read the prerequisites. Identify services, permissions and data sources your implementation would need.
  2. Inspect each transition. Separate the trigger, reasoning, verification and external action.
  3. Test with fixtures first. Treat configuration and output blocks as illustrative reference material, then validate an implementation in an approved environment.