Building a Production-Grade Personal Blog with AWS, Terraform, and Hugo
Motivation As a DevOps engineer, your personal website is your portfolio. It should demonstrate not just what you know but what you build. This blog is itself an example of a production-grade cloud architecture - every decision documented, every tradeoff explained. Architecture Overview The stack: Layer Technology Content Markdown → Hugo static site CI/CD (Infra) GitHub Actions - PR plan, merge apply CI/CD (Content) GitHub Actions - build, sync, invalidate State Mgmt S3 backend, concurrency-gated at pipeline level Origin S3 (private, versioned, encrypted, CloudFront OAC only) CDN CloudFront with HTTPS, Brotli/Gzip, security headers DNS Route 53 alias records (A / AAAA, root + www) TLS ACM certificate (auto-renewal, TLSv1.2_2021) Auth OIDC - no AWS access keys stored anywhere Monitoring CloudWatch dashboard + error rate alarm Cost Control AWS Budgets alert (direct email) Key Design Decisions 1. Two Separate Pipelines Infrastructure changes and content changes have different risk profiles and review requirements. They’re handled by separate workflows: ...