Kathmandu, Nepal · Cloud Computing & Cybersecurity Student

Building Invisible Cloud
Architecture.

Hi, I'm Ritik Sah. I study Cloud Computing & Cybersecurity at KFA Business School & IT. I focus on deploying static websites via AWS CloudFront CDN & S3, building multi-region Auto-Scaling infrastructures, configuring hardened Linux servers, and writing Terraform code.

AWS

Cloud Practitioner Certified

ISC²

Certified in Cybersecurity

LPI

Linux Essentials Certified

Ritik Sah

Ritik Sah

Cloud & Security Engineer

KFA BUSINESS SCHOOL & IT
Primary Focus AWS / Linux / DevOps
Key AWS Skills CloudFront, S3, EC2, RDS
GitHub Handle @hritiksah00
Location Kathmandu, Nepal
Technical Domains

MY ENGINEERING EXPERTISE.

I focus on cloud infrastructure, web deployment pipelines, server security, and system automation. Here is how I build modern web applications and infrastructure.

View AWS Project Showcase

AWS CloudFront & S3 Deployment

CDN & Static Site Hosting

Deploying static websites using Amazon S3 bucket origin storage, AWS CloudFront global edge caching, Route 53 custom domain management, and ACM SSL certificates.

AWS High Availability

Auto-Scaling & Multi-AZ

Architecting multi-region EC2 Auto Scaling Groups, Application Load Balancers, Route 53 latency routing, and RDS database replication to ensure maximum uptime.

Terraform & CI/CD Pipelines

Infrastructure as Code

Writing modular Terraform code with Amazon S3 state storage, DynamoDB lock keys, and automated GitHub Actions workflows for zero-drift deployments.

Linux Hardening & Security

Ubuntu 24 & CIS Benchmarks

Applying Level 1 CIS Benchmark security controls to Ubuntu servers: UFW firewall configuration, Fail2ban brute-force protection, Auditd log management, and Lynis auditing.

My Engineering Workflow

How I Deploy Projects

A structured process for building reliable cloud infrastructure.

1
Step One

Architecture Planning

Defining system requirements, choosing AWS resources (S3, CloudFront, EC2, RDS), and drafting network subnets.

2
Step Two

Terraform & Code Setup

Writing clean, modular Terraform IaC modules or Docker Compose definitions to automate resource creation.

3
Step Three

Deployment & Hardening

Deploying static assets to S3 + CloudFront CDN, configuring SSL/TLS certificates via ACM, and hardening Linux servers with UFW and Fail2ban.

4
Step Four

Testing & Verification

Testing global CDN latency, verifying Route 53 DNS records, running Lynis vulnerability scans, and monitoring logs.

My Engineering Portfolio

Selected Projects & AWS Deployments

AWS FEATURED PROJECT · CLOUDFRONT & S3

Global Website Deployment via AWS S3 & CloudFront CDN

Deployed and secured a high-performance, globally distributed static website on AWS. Configured an Amazon S3 bucket for origin asset storage, created an AWS CloudFront CDN distribution with Origin Access Control (OAC) to block direct public access to S3, linked a custom domain via Amazon Route 53, and provisioned SSL/TLS certificates using AWS Certificate Manager (ACM). Achieved sub-50ms latency across global edge locations.

AWS ARCHITECTURE DIAGRAM S3 + CloudFront CDN + ACM SSL + Route 53
Users / Clients Route 53 DNS AWS CloudFront CDN Global Edge Cache ACM SSL / TLS Encryption Amazon S3 Origin
AWS CloudFront Amazon S3 ACM SSL Route 53
✓ Live Project
AWS CLOUD TRAINEE · SERVERLESS

Serverless Cloud Resume

Role: AWS Cloud Trainee

  • Overview & Hosting: Designed and deployed a highly available, serverless static resume website hosted on Amazon S3 to demonstrate foundational cloud capabilities.
  • Security & IAM: Authored custom JSON bucket policies and IAM access rules to enable secure public read access while restricting backend resource settings.
  • Core Learnings: Gained hands-on experience in cloud storage architecture, object-level security management, and AWS console resource provisioning.
Amazon S3 AWS IAM HTML/CSS
✓ Deployed
AWS CLOUD · EC2 & RDS

AWS Multi-Region Auto-Scaling Stack

Multi-region web infrastructure utilizing EC2 Auto Scaling Groups, Application Load Balancers (ALB), Route 53 health check failover, and RDS Multi-AZ replication.

AWS Multi-Region Architecture
Route 53 Latency Routing ➔ ALB ➔ EC2 Auto Scaling (us-east-1 & us-west-2) ➔ RDS Replication
EC2 ASG ALB RDS Multi-AZ
Case Study
DEVOPS / IAC · TERRAFORM

Terraform AWS GitOps Pipeline

Automated Terraform IaC project provisioning AWS VPC subnets, Security Groups, and EC2 instances with S3 remote state storage and GitHub Actions CI/CD workflows.

Terraform IaC Pipeline
GitHub Commit ➔ Actions CI/CD ➔ Checkov Scan ➔ S3 State Lock ➔ AWS Provision
Terraform S3 State GitHub Actions
Case Study
LINUX SECURITY · 2026

CIS Hardened Ubuntu 24.04 Server

Security hardening script applying CIS Level 1 benchmarks on Ubuntu Linux: UFW firewall posture, Fail2ban SSH protection, Auditd system auditing, and Lynis compliance reporting.

Ubuntu UFW Lynis
Case Study
GITHUB REPO · SHELL

server-health-monitor

Automated Bash script to monitor server health metrics, check disk usage, verify web service uptime, and trigger automated system alerts.

Shell / Bash Script View on GitHub ↗
GITHUB REPO · PYTHON

PFM — Personal Finance Manager

Personal finance tracking application built in Python to log transactions, compute monthly category spending, and export analytics.

Interactive Planning Tool

Cloud Architecture Resource Estimator

2 Nodes
25K RPM

Estimated Resource Scope

Selected Scope Static CDN Deployment
Compute Nodes 2 Nodes
Base Setup Cost $300
Selected Add-ons $0
Total Estimated Budget $650/mo
Contact Me About This Stack

*Estimated monthly cost based on AWS resource pricing & configuration.

Academic & Professional Credentials

Industry Certifications & Skills

AWS

AWS Cloud Practitioner

Amazon Web Services · 2025

✓ Official Verified Badge
ISC²

Certified in Cybersecurity (CC)

ISC² Security Council · 2025

✓ Official Verified Badge
LPI

Linux Essentials Certificate

Linux Professional Institute · 2024

✓ Official Verified Badge

Technical Skillset & Technologies

Skill Area Tools & Technologies Proficiency Years
AWS Cloud Services CloudFront, S3, EC2, VPC, Route 53, ALB, RDS, Lambda
2 Yrs
Linux Administration Ubuntu 24.04, UFW, Fail2ban, Auditd, Bash Shell Scripting
3 Yrs
Infrastructure as Code Terraform, GitHub Actions CI/CD, Checkov, TFLint
1.5 Yrs
Containers & Web Servers Docker, Docker Compose, Nginx Reverse Proxy, Redis
2 Yrs
Network Security Nmap, Wireshark, Lynis Auditing, WireGuard VPN
2 Yrs
Common Questions

Frequently Asked Questions

How did you set up static website deployment on AWS CloudFront & S3?
I hosted static website files in an Amazon S3 bucket, blocked public S3 access, configured AWS CloudFront CDN with Origin Access Control (OAC), provisioned a free SSL/TLS certificate via ACM, and routed custom DNS records using Amazon Route 53.
What Linux security hardening steps do you apply?
I follow CIS Level 1 benchmarks on Ubuntu Linux: disabling root SSH logins, configuring strict UFW firewall policies, enabling Fail2ban SSH brute-force protection, setting sysctl kernel parameters, and running Lynis security audits.
What institution are you studying at?
I am currently studying Cloud Computing and Cybersecurity at KFA Business School & IT in Kathmandu, Nepal.
Are you available for internships, full-time roles, or projects?
Yes! I am open to Cloud Engineer, DevOps, and Systems Infrastructure roles, internships, and project collaborations.
Get In Touch

Let's Connect & Collaborate

Whether you have an inquiry about cloud infrastructure, DevOps deployment, or career opportunities, feel free to send me a message.

Academic Base & Location

Ritik Sah · KFA Business School & IT · Kathmandu, Nepal.
Available for remote roles and projects worldwide.

Direct Contact Channels

Feel free to connect via any of my personal links below.

Personal Email

hritiksah38@gmail.com

GitHub Profile

github.com/hritiksah00

Response time: Within 24 hours.

Let's Build Something Resilient Together.

Open for Cloud Infrastructure, DevOps, and Cybersecurity roles and project collaborations.

Send Me A Message
Email Ritik
LinkedIn