
ARCH — Architecture Control Hub
A visual cloud architecture designer that emits reviewable Terraform for AWS, Azure and Google Cloud.
Gokul Upadhyay Guragaingocools
DevOps and MLOps Engineer
I build the delivery paths that get software into production and keep it there. Cloud infrastructure as code, pipelines that fail loudly, and observability that answers questions before anyone thinks to ask them.

Real profile media is served from R2.
At a glance
Positions
Interests
Grounded in the projects, skills, and community work published here.
Current focus
Building ARCH, an architecture-as-code control hub that turns a drawn cloud topology into reviewable Terraform. Reading about eBPF-based network observability. Preparing the next AWS Student Builder session at LBEF.
Read the latestWhat I build
The work divides cleanly. Everything else I do is in service of one of these.
Terraform as the primary artefact rather than documentation written afterwards. Composable modules, remote state with locking, and availability decided per failure domain with the cost written down.
Cloud notesPipelines that produce evidence as well as artefacts, deployments identified by image digest rather than a mutable tag, and a production gate that can actually say no.
DevOps notesAn inference service is a production service with one extra failure mode: it can be healthy, fast and wrong. Pipeline-driven training, metric-gated registration, and monitoring that pairs request metrics with prediction distribution.
MLOps notesSelected work

A visual cloud architecture designer that emits reviewable Terraform for AWS, Azure and Google Cloud.

A cloud learning platform with structured courses, practice examinations and certification tracks.

A writing and documentation workspace with grammar assistance, AI-text detection and document management.

GitLab CI pipelines for a HITRUST-regulated healthcare system, where every stage has to produce evidence as well as an artefact.
What I work with
Grouped by what the tool is for. Core means I have run it under real load and know how it fails.
Experience
Mar 2026 — Apr 2026
Delivery and MLOps work on a healthcare platform operating under HITRUST, where the pipeline is an audited control rather than convenience tooling.
May 2025 — Dec 2025
Containerised ML pipelines and K3s-hosted inference, instrumented so that a model service is treated as a production service with an extra failure mode.
Nov 2024 — Feb 2025
AWS architecture work where availability, cost and blast radius were treated as one conversation, and Terraform was the primary artefact rather than an afterthought.
Jun 2024 — Oct 2024
Structured cloud engineering training built around practical tasks rather than lecture material.
Writing
In a regulated environment a CI pipeline is not automation that happens to be convenient. It is the evidence that software reached production legitimately, and evidence has to outlive a log retention window.
The line that made model provenance tractable was not banning notebooks. It was deciding that nothing which reaches an endpoint may have originated in one.
Standard service monitoring tells you an inference endpoint is up and responsive. It cannot tell you the predictions stopped making sense three days ago.
Notes
Things I did not want to work out twice.
A convenience feature that mutates production is a blast-radius decision wearing a convenience costume.
A tag is a mutable pointer. Deploying by tag means you cannot state what is running.
Two engineers, one state file, no lock. The failure is exactly as bad as the documentation implies.
If there is no recorded way to accept a scan finding, engineers will find an unrecorded way.
Now
Building ARCH, an architecture-as-code control hub that turns a drawn cloud topology into reviewable Terraform. Reading about eBPF-based network observability. Preparing the next AWS Student Builder session at LBEF.
Contact
If any of this is close to a problem you are trying to solve, I would like to hear about it.