Owning the Terraform Estate: 85k Lines, Six Providers, and a Live Migration to Scalr
The 85,000-line Terraform estate isn't just code — it's 75+ modules that encode how EarnIn's engineering organization provisions and manages infrastructure across AWS, Cloudflare, Databricks, Confluent, Datadog, and beyond. Currently leading its migration from Terraform Cloud to Scalr: PoC proven, migration plan documented, team executing without downtime.
Business impact: The estate encodes EarnIn's infrastructure patterns through 75+ purpose-built modules. The Scalr migration is designed for zero downtime — architectural thinking before execution planning.
TerraformTerraform CloudScalrHCLGitHub ActionsAWSCloudflareDatabricksConfluentDatadog6+ provider management
Key decisions
- Designed 75+ modules that encode organizational standards rather than just describing resources — teams can build consistently without consulting the architect for every decision
- Built the EKS modules on top of community modules adapted to org needs — leveraging upstream work while owning the org-specific layer
- Architected the Scalr migration as a PoC first — validated the pattern and documented the migration plan before putting the team into execution mode
- Designed the migration for zero downtime — state migration strategy, parallel operation windows, and rollback checkpoints before decommissioning Terraform Cloud
- Contributed to disaster recovery and business continuity by working with DB, data infrastructure, and product teams to establish IaC standards for high-uptime SLAs and SLOs across the estate
85k
lines of Terraform IaC owned and architected
75+
modules designed to guide org-wide infrastructure patterns
The Governance Layer: AWS Account Foundations, Zero-Trust Access, and EKS at Scale
Lead architect and owner of the organizational infrastructure every engineering team at EarnIn operates within — AWS Account Foundations that define the security baseline and account structure, an Account Vending Machine that makes provisioning self-service, EKS Vending Machine Networking that every Kubernetes deployment inherits from, and the full zero-trust connectivity and DNS layer (Cloudflare WARP/ZTNA, Route 53, Cloudflare DNS) wired into every account from day one. Built to hold under the kind of growth that turned 25 engineers into a thousand.
Business impact: The account foundations and vending machine provide the security, governance, and operational boundaries that every engineering team at EarnIn operates within — built once, relied on by the entire organization, with secure connectivity as a default property of every account rather than a follow-up ticket.
AWS OrganizationsControl TowerAccount Vending MachineEKSVPC networkingTransit GatewayIAMSecurity HubCloudflare WARPZTNARoute 53Cloudflare DNSTerraform
Key decisions
- Designed Account Foundations as the org's first security boundary — account structure, IAM baselines, security tooling, and governance guardrails are architectural decisions, not operational configurations
- Built the Account Vending Machine to be self-service from the start — engineering teams provision accounts through a standardized, automated workflow rather than a ticketing queue
- Wired zero-trust network access (Cloudflare WARP/ZTNA) and DNS architecture (Route 53, Cloudflare) into the account baseline itself — every new account is secure and reachable by design, with no follow-up networking ticket required
- Architected EKS Vending Machine Networking as a composable layer on top of the account networking baseline — EKS clusters inherit correct VPC layout and connectivity without team-by-team configuration
- Represents platform, security, SRE, IT, and compliance in the same conversation whenever a business unit's request touches cloud architecture, networking, security, or RBAC — infrastructure decisions that affect those teams are made with them, not handed to them after the fact
Lead
AWS Account Foundations, Account Vending Machine & zero-trust connectivity
5 teams
represented in cross-functional cloud architecture decisions
Six Years, Forty Times the Growth: Building the Cloud Infrastructure EarnIn Scales On
Present at EarnIn since fewer than 25 engineers — designing the IaC foundations, account governance, platform tooling, and cost accountability that a thousand-person fintech now depends on. The cloud estate didn't just grow with EarnIn. It was architected to accommodate growth before the growth arrived.
Business impact: EarnIn has grown into a 1,000-person company with a cloud estate that reflects deliberate architectural decisions rather than accumulated workarounds. The infrastructure Archana designed and owns is the foundation that hypergrowth ran on.
AWSTerraformKubernetes (EKS)GitHub ActionsArgo CDFluxCortexDatadogPagerDutySpinnakerPythonGoAnsible
Key decisions
- Built infrastructure foundations before hypergrowth demanded them — account foundations, module standards, and vending machines existed before the scale that required them made them urgent
- Expanded scope deliberately as company needs evolved — DevOps foundations to platform engineering, developer experience, SRE, PaaSOps, and Kubernetes without losing ownership of the foundational IaC estate
- Owns the multi-million dollar cloud bill as an engineering responsibility — cost management, attribution, and right-sizing treated with the same rigor as uptime and security
- Led and delivered cross-functional infrastructure projects to tight deadlines with architecturally tailored solutions — not generic implementations handed off to operations
- Built self-service, automated infrastructure capabilities that removed operational bottlenecks as the engineering team scaled — reducing the support burden without reducing quality
<25 → 1k
engineering org scaled during her tenure as cloud infrastructure owner
$M+
cloud spend managed, optimized, and attributed at scale
The Terraform Champions Program: Turning an Infrastructure Team Into an Infrastructure Platform
Founded and leads EarnIn's Terraform Champions program — a structured initiative to make the broader engineering organization IaC-literate, embedding infrastructure ownership into product teams instead of centralizing it entirely in platform. The program reflects a larger transition she has been steering: from a reactive service-desk infrastructure model, through self-service platform-as-a-service, to platform-as-a-product — and now into the AI-native era, where she is already building the Claude and Cursor coding-agent skills and plugins that extend the platform into engineers' preferred AI tooling.
Business impact: Distributed infrastructure literacy beyond platform team headcount — teams that once filed a ticket for infrastructure changes now operate within Terraform patterns they understand and can extend themselves. Positions EarnIn's platform to meet engineers where they already work: inside AI coding agents, not just inside a wiki.
TerraformTerraform Champions curriculumPlatform-as-a-Product strategyClaude Code skillsCursor rules/pluginsInternal enablement and trainingService catalog design
Key decisions
- Founded the Terraform Champions program to embed IaC literacy directly into product and feature teams, rather than centralizing all infrastructure knowledge inside the platform team
- Chose to teach infrastructure literacy rather than gatekeep it — a deliberate bet that distributed competence scales better than a single team's calendar
- Led the platform's evolution from a reactive service-desk model, through self-service platform-as-a-service, to platform-as-a-product — treating internal engineering teams as customers with a roadmap, not a ticket queue
- Started building Claude Code and Cursor skills and plugins early, so the platform's standards and guardrails live inside engineers' preferred AI coding tools instead of a wiki nobody reads
- Continues to represent platform, security, SRE, IT, and compliance in cross-functional discussions whenever a business unit's request touches cloud architecture, networking, security, or RBAC
Founder
Terraform Champions Program — org-wide IaC literacy
3 eras
led the platform through service desk → PaaS → platform-as-a-product