Skip to content

tunnel established · Bangalore, India

Aditya Ramguru

Software Engineer · Infrastructure & Zero-Trust

Infrastructure engineer at Aurm, a secure wealth-storage startup. I build zero-trust networks, harden clouds, wire up observability and run the AI developer platform across AWS and GCP.

ARHUB · 10.0.0.1traceroutecareercase-studieswhat I builtstacktoolsfootprintwhere it runsssh adicontact
hub-and-spoke · encrypted peers · click a node to tunnel in

wg-quick up adi0

handshake initiation

peer adi → you · UDP 51820

establishing… 0%

Career

traceroute to the current role

Five hops so far. Latency drops at every hop, which is roughly how it feels.

adi@portfolio: ~

$ traceroute adi --career --max-hops 30

traceroute to software-engineer.aurm, 30 hops max

  1. 1

    vit.vellore(Vellore, IN)9.53 ms· 2021 – 2025

    B.Tech CS (Bioinformatics) · CGPA 9.53 / 10

    • Merit Scholarship all four years
    • DSA, DBMS, Operating Systems, Computer Networks, Cryptography
  2. 2

    nus.singapore(Singapore)62.1 ms· Dec 2023 – Jan 2024

    Academic Intern · National University of Singapore

    • Big-data analytics and cloud computing on AWS
    • Led Verdict Hub, a six-person deep learning project predicting legal outcomes from historical cases, deployed on SageMaker
  3. 3

    aurm.intern(Bangalore, IN)4.2 ms· Feb 2025 – Aug 2025

    Technical Intern · Aurm

    • LLM + custom MCP server that turns hand-drawn vault plans into 3D rack layouts
    • Incident response platform: LiveKit, Google Chat, RTSP feeds, auto RCA and Jira
    • LLM triage agent for support email, WhatsApp Business automation for field sales
  4. 4

    aurm.jr-swe(Bangalore, IN)2.8 ms· Sep 2025 – Sep 2026

    Junior Software Engineer · Aurm

    • Built the zero-trust network from scratch: WireGuard/VyOS mesh, Teleport, Cloudflare
    • Cleared a CERT-In empanelled third-party cloud security audit
    • On-call rotations, RCAs, mentored an intern to a shipped production feature
  5. 5

    aurm.swe(Bangalore, IN)1.0 ms· Sep 2026 – now

    Software Engineer · Aurm

    • Leads infrastructure end to end: networking, cloud security and platform
    • Owns networking, cloud security, observability and the AI developer platform

--- trace complete · 0% packet loss

Case studies

Things I built and run

Each one comes with a small interactive model. Poke at them.

01 · Zero-trust networking

Secure access to every remote site, nothing on the public internet

Every remote site joins a private WireGuard/VyOS mesh back to AWS. Teleport checks identity per app, and Cloudflare WARP sits in front as another wall, so operators reach routers, hubs and robot controls without anything being exposed.

  • ›Automated peer registration with a REST integration layer on ECS
  • ›Domain-based split tunneling with dnsmasq, ipset and iptables policy routing
  • ›Highly available Teleport giving per-app, identity-based access to router, switch, Zigbee hub and robot UIs
  • ›Wrote a retry patch for Teleport’s app tunnel client, prepared for upstream
  • ›Cloudflare tunnels, virtual networks and Mesh, all as Terraform modules
WireGuardVyOSTeleportCloudflareTerraform

// toggle a layer, watch who gets through

engineer (enrolled, MFA) → robot-ui.node-17

attacker (stolen password) → robot-ui.node-17

Blocked at Cloudflare WARP. Two more walls behind it.

02 · AI developer platform

Claude Code for the whole team, with spend that can’t run away

I designed a LiteLLM gateway on ECS Fargate that routes every engineer’s Claude Code traffic to AWS Bedrock. It sits on a private network behind Cloudflare Access, with org-wide and per-engineer budgets enforced at the gateway, so the team gets AI coding without surprise bills or data leaving the cloud account.

  • ›Org-wide and per-engineer budgets enforced at the gateway, not by policy docs
  • ›Moved the AI code-review agent onto the same governed gateway
  • ›Built Claude Code skills and subagents for the core service, so agentic coding became the team’s default workflow
  • ›A self-improving loop: engineers log failure cases back into the skills, so the agents get better every week
  • ›Standardized DevPod + Mutagen remote workspaces on AWS
LiteLLMBedrockECS FargateClaude CodeDevPod

// illustrative: one engineer’s month on the gateway

user spend

$60

personal budget $150

gateway

200 OK

→ Bedrock

org-wide budget61% used

03 · Security & compliance

Critical vulnerabilities driven to near zero

Hardening work that cleared an independent CERT-In empanelled cloud security audit, with no incidents since rollout.

  • ›Read-only root filesystems enforced across production services
  • ›Non-root containers and dependency upgrades cut critical and high image findings to a handful
  • ›Automated AWS Security Hub remediation pipeline across S3, IAM, security groups and logging
  • ›Wazuh SIEM collecting runtime logs from customer sites alongside CrowdStrike Falcon
  • ›In-house secret management for every Teleport-exposed app and the edge bootstrap service
TrivySecurity HubWazuhCrowdStrikeECS

// trivy image scan, critical + high

CRITICAL0
HIGH3

near zero

critical CVEs

read-only

prod containers

audit

cleared

04 · Observability

A self-healing stack watching every node

Self-hosted Mimir, Loki, Grafana and Alloy on AWS with S3-backed storage and auto-scaling-group self-healing.

  • ›Watches every zero-trust node with per-identity labels
  • ›Separate views for edge, VyOS and Teleport hosts
  • ›Event-driven service layer on SQS for fault isolation downstream
GrafanaMimirLokiAlloySQS

zts nodes up

30 / 30

p95 tunnel latency

38 ms

loki ingest

1.2k lines/s

alerts firing

0

illustrative values · the real dashboards stay internal

Stack

What I reach for

Cloud & IaC

  • AWS
  • GCP
  • Terraform
  • Docker
  • ECS / Fargate
  • Bedrock

Network & Security

  • WireGuard
  • VyOS
  • Teleport
  • Cloudflare Zero Trust
  • iptables
  • Wazuh

Observability

  • Grafana
  • Mimir
  • Loki
  • Alloy
  • CloudWatch

AI tooling

  • Claude Code
  • LiteLLM
  • MCP servers
  • Claude API
  • n8n
  • LiveKit

Languages

  • Python
  • JavaScript / Node.js
  • Bash
  • SQL
  • C

Certified

AWS Certified Solutions Architect – Associate

status: valid

Footprint

Vellore → Singapore → Bangalore

Studied computer science and bioinformatics at VIT, picked up AWS and deep learning at NUS, and now run infrastructure across AWS and GCP from Bangalore. Next hop: bigger systems, where latency, failover and fault tolerance are the whole job.

  • ●Vellore · B.Tech, 2021–2025
  • ●Singapore · NUS, 2023–2024
  • ●Bangalore · Aurm, 2025–now
  • drag the globe to spin it

Contact

$ ssh adi@adityapoc.xyz

Let’s talk infrastructure.

Open to SDE, platform, SRE and infrastructure roles. The fastest route is email.