Built by a practitioner who was tired of the gap.
CloudSentri isn't a research project dreamed up in the abstract — it's the tool its founder kept wishing existed, every time he stood up cloud operations for a team that couldn't hire the bench it needed.
Every SME needs a FinOps analyst, an SRE, and a security engineer. Almost none can hire that team.
CloudSentri started from a pattern repeated across nearly every cloud environment its founder has worked in as a Senior Cloud Security & Platform Architect: teams running production infrastructure on a patchwork of tools that alert, but never act — and no realistic path to hiring the specialists who'd otherwise close that loop by hand.
The platform is being built part-time, alongside ongoing work in cloud security and platform engineering, because the gap is real, it's expensive, and it's solvable with the same agentic reasoning now reshaping how engineering teams work.
Ali Armaghan
Senior Cloud Security & Platform Architect
Cloud Architecture · DevSecOps · Platform Engineering · Site Reliability Engineering
Ali is a Senior Cloud Security & Platform Architect with 7+ years designing, securing, and operating production-grade infrastructure across Azure, AWS, and GCP. He architects multi-region Kubernetes platforms with secure-by-default golden paths, embeds DevSecOps controls — SAST, DAST, secrets scanning, policy-as-code, supply-chain security — directly into CI/CD, and designs the cloud-native observability and SLO frameworks that keep mission-critical workloads at 99.9% uptime.
He's Microsoft, AWS, and Google certified, has led platform and security teams across 20+ engineers, and has spent much of the last several years translating frameworks like SOC 2, ISO 27001, CIS, and NIST from compliance checklists into day-to-day engineering practice. CloudSentri is the product of that experience — an attempt to package what a great platform, security, and FinOps team does, so more SMEs can actually have one.
Seven years in production, not slideware.
Architected a secure-by-default platform integrating SAST, DAST, secrets scanning, and SBOM generation into CI/CD across Azure and DigitalOcean, and automated continuous SOC 2 / ISO 27001 compliance.
Designed an enterprise-grade multi-region Kubernetes platform with GitOps delivery, zero-trust networking, and observability-by-default across 50+ microservices.
Led an AWS-to-Azure migration for multi-region Kubernetes workloads, cutting cloud spend ~25% while improving scalability and business continuity.
Integrated DevSecOps controls into CI/CD, reducing critical production vulnerabilities ~50% and enabling self-service infrastructure via policy-as-code.
Led the DevOps function and rebuilt CI/CD across 8 services, achieving 2× deployment frequency and a ~60% drop in failed deploys.
Optimized AWS infrastructure for cost and scale, cutting monthly spend ~30% and automating 15+ hours/week of manual operational work.
Managed a Linux server fleet and deployed VPNs, firewalls, and IDS/IPS, strengthening perimeter security across critical services.
Verified credentials, not just claims.
All certifications are verifiable at credly.com/users/ali-armaghan.