ENTERPRISE IDENTITY • PKI • CLOUD INFRASTRUCTURE
IdentityForge
An enterprise identity and PKI platform for NexaBank, built as a four-discipline capstone. As part of the Cloud Team, I work on the AWS infrastructure that runs and connects the identity, certificate, API gateway and security platform components.
Infrastructure
Provisioning the platform infrastructure with Terraform and remote state, including AWS networking, load balancing and supporting services.
Identity platform
Supporting a highly available Keycloak deployment backed by PostgreSQL, with the administrative interface restricted through the bastion architecture.
PKI & trust
Running the certificate infrastructure on EC2 and supporting the device-trust layer, including KMS protection for the issuing CA private key and revocation infrastructure.
API gateway
Supporting the API gateway layer that terminates mTLS, validates device certificate chains and passes verified certificate identity to the NexaBank API.
Security & operations
Applying security-group controls, HTTPS/ACM, infrastructure-as-code practices and an ongoing cost/right-sizing plan for a platform intended to remain live after the cohort.
Architecture goal
The platform must prove that access requires both a valid Keycloak identity and a trusted device certificate, with certificate revocation demonstrated within 60 seconds.