Skip to content
View sadvi11's full-sized avatar

Block or report sadvi11

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sadvi11/README.md

Sadhvi Sharma

AI Engineer — Agentic Systems, RAG and Python on AWS · Calgary, Alberta, Canada

I build agentic and retrieval-augmented systems in Python on AWS — RAG written against raw APIs rather than a framework, and agent constraints enforced in code before a request leaves the machine, so they cannot be prompted away.

Before that I spent 2.5 years keeping Bell Canada's, T-Mobile US's and Orange's 5G core running against a 99.9% SLA. Per-session state machines and deterministic transitions — which turns out to be the same problem as a multi-turn conversation, with different primitives.

Open to AI Engineering · Agentic Systems · Applied AI · Platform · SRE roles. Calgary · remote across Canada · open to relocation. Permanent Resident — no sponsorship required. Available immediately.

Canadian data residency written as policy that fails a build, not as a paragraph in a wiki — PIPEDA, provincial FIPPA and health legislation, and OSFI B-13 for federally regulated institutions. Enforced at the AWS Organizations root in aws-multi-account-governance and scanned pre-merge in iac-security-guardrails.

31 public repositories · every one green in CI · 3 services live right now

🌐 sadvi11.github.io — portfolio, with every claim carrying the evidence it was checked against 📄 Résumé (PDF) · 📧 sadhvisharma763@gmail.com · 💼 LinkedIn


Why my background is different

Most cloud engineers learn high availability from a course. I learned it on call, on a telecom core network, where the failure mode isn't a red build — it's someone's call dropping mid-sentence.

At Nokia I operated Cloud-Native 5G Core network functions — AMF, SMF, UPF, CBIS, CBAM, NRF — as containerized workloads on Kubernetes and OpenStack, across deployments for international operators. Zero-downtime rolling upgrades were a contractual requirement, not an aspiration. I delivered a wave-based multi-site 4G→5G migration with zero subscriber downtime. (Nokia appreciation award.)

Then I noticed the thing that made everything since easier: 5G Service-Based Architecture and cloud microservices are the same patterns wearing different names. Service discovery, horizontal scaling, event streaming, container lifecycle.


Three things worth your time

Everything here is public. These three are where the AI engineering actually is.

Every repository on this profile has a passing CI badge. Not a decoration — several stand up real infrastructure in CI and assert against it, and a few deliberately break their own safety checks to prove the tests can go red. A green suite that has never failed is not evidence.

1. Amazon Connect contact-centre RAG agent — the whole conversational stack, offline

Amazon Connect chat → Lex V2 → FastAPI/Lambda → hybrid RAG. Custom chunking, rank fusion, reranking, and context packed to a token budget.

What makes it different: abstention is enforced in code, not asked of the model — a retrieval score below threshold returns a handoff, not a guess. 91 tests run offline with no AWS account, and 15 controls are broken on purpose in CI to prove the tests can go red. Nothing deployed, $0 billed, and it still demonstrates the full path.


2. terraform-guard-mcp — an MCP server that refuses to bless a dangerous plan

A Model Context Protocol server that reads a Terraform plan and declines to approve one that would destroy data. The verdict is a Python comparison, so no wording in the plan can argue it down — deterministic control flow wrapped around a non-deterministic component. Tool contracts as JSON Schema.

34 tests; CI removes each of the three guards deliberately and fails if the suite still passes. I found and fixed a security weakness in my own tool two hours after publishing it.


3. bedrock-rag-app — RAG with the economics measured

Document question-answering built directly on the Bedrock API over an HTTP client, no orchestration framework, so every retrieval and generation step stays inspectable.

Instrumented per stage: 195 ms embedding, 225 ms retrieval, 1.53 s generation, $0.0003 per query. Prompt and retrieval changes get evaluated against cost and latency, not only output quality. Grounded, so it reports missing context instead of inventing a number.


The rest, sorted by what you are hiring for

Thirty-one public repositories is more than anyone will read, so this is grouped by role rather than alphabetically. Bold is where I would start.

AI, agents & RAG ⭐

Project One line Stack
amazon-connect-rag-agent Contact-centre chat → Lex V2 → FastAPI → hybrid RAG with abstention enforced in code. 91 tests offline, 15 controls broken on purpose Amazon Connect · Lex · FastAPI · Bedrock
terraform-guard-mcp MCP server that refuses to approve a plan that destroys data — the verdict is a Python comparison, so it cannot be argued down MCP · Python · Terraform
aws-ec2-read-only-agent Allowlist on botocore's request hook, so a persuaded model still cannot call a mutating API. 36 tests, no credentials needed Claude tool use · boto3
smart-ai-agent Agent with tool use, persistent memory and RAG, plus an eval suite for prompt injection and SQL injection Claude API · pgvector · Flask
bedrock-rag-app RAG over financial documents — measured at 195 ms embedding, 225 ms retrieval, ~$0.0003/query. Grounded, so it reports missing context instead of inventing a number Bedrock · Titan V2 · pgvector
azure-sentiment-containerapp The Azure half of the both-clouds comparison. Bicep, scales to zero Container Apps · Bicep
structured-test-agent Forced tool choice against a strict JSON Schema, with tests asserting the schema stays strict rather than advisory Claude API · JSON Schema
canadian-financial-sentiment End-to-end SageMaker pipeline — train, deploy, serve, tear down SageMaker · S3 · Flask
ai-chatbot-with-memory Cross-session memory in DynamoDB, with a circuit breaker around the model API FastAPI · DynamoDB
f1-telemetry-pipeline Event-driven telemetry — producer, SQS, consumer, DynamoDB, CloudWatch dashboard SQS · Lambda · DynamoDB
aws-python-automation boto3 across EC2, S3, Lambda, CloudWatch, DynamoDB and API Gateway — ships the AST auditor that found ten unpaginated AWS calls in it Python · boto3 · botocore Stubber

Kubernetes & containers

Project One line Stack
eks-ecommerce-microservices 8 microservices, 5 languages, Terraform + Helm. CI proves the cart survives a pod restart Terraform · Helm · EKS
gitops-argocd-kubernetes Pull-based delivery with no cluster credential in CI. The pipeline scales prod down by hand and fails unless Argo CD heals it — self-heal confirmed in ~10s every run Argo CD · Kustomize · kind
mlops-sentiment-eks HPA on Prometheus metrics; CI gates the build on cross-validated model accuracy EKS · FastAPI · Terraform
flask-ecs-fargate-cicd Containerized API on Fargate, SHA-tagged images, OIDC — no stored AWS keys · live demo (free tier: ~13s to wake) ECS Fargate · ECR · Actions
docker-flask-ai-app Test-gated CI/CD where the Trivy scan fails the build on HIGH/CRITICAL rather than reporting and moving on Docker · Trivy · ECR

Infrastructure as code

Project One line Stack
aws-multi-account-governance 6 SCPs, permission boundaries, 44 tests — including the region restriction that silently breaks IAM org-wide Terraform · Organizations
aws-hybrid-network-terraform Transit Gateway. 12 assertions, mostly negatives — prod cannot reach nonprod Terraform · TGW · VPN
nokia-5g-to-aws-migration 7 modules mapping carrier 5G network functions onto AWS, with SOC 2 and PCI DSS control mappings Terraform · ECS · Kinesis
aws-cloudformation-stacksets Org-wide security baseline. 17 assertions run in both directions CloudFormation · StackSets
multi-cloud-terraform One codebase, two clouds — and the three places they stop being interchangeable Terraform · AWS · Azure
aws-vpc-terraform Multi-tier VPC across two AZs — NAT, tiered security groups, NACLs, least-privilege IAM Terraform · AWS · IAM

Security & governance

Project One line Stack
terraform-guard-mcp An MCP server any AI assistant can call — it reads a Terraform plan and refuses to bless a dangerous one. The verdict is a Python comparison, so no wording in the plan argues it down. 34 tests; each of the three guards removed on purpose in CI to prove the suite goes red MCP · Python · Terraform
iac-security-guardrails Checkov + custom Rego for Canadian data residency and cost tags. Tested in both directions — which caught a policy that had silently stopped matching anything OPA · Rego · Checkov
azure-devops-pipelines Multi-stage pipelines with environment gates that live outside the repo, so a developer cannot bypass production approval by editing YAML Azure DevOps · templates
azure-finops-guardrails Seven detectors for resources that cost money and do nothing — unattached disks, orphaned IPs, VMs stopped but not deallocated. Forecasts month-end using median absolute deviation, so one spike cannot hide inside it Azure · Bicep · Python

Observability & SRE

Project One line Stack
sre-incident-practice Blameless postmortems from my own real incidents, an SLO with an error-budget policy, and the argument for 99.5% over 99.9% because the architecture cannot hold the higher number SRE · SLO · runbooks
prometheus-monitoring-stack Pull-model observability, deliberately isolated from what it watches — a watcher that dies with its host never alerts Prometheus · Grafana

Open source

31 public repositories, all MIT licensed — every one of them usable, forkable and adaptable by anyone, and every one passing its automated tests. Several exist because the thing they do did not exist yet: an MCP server that refuses to bless a destructive Terraform plan, a read-only AWS agent whose guard is enforced at the client layer, and policy-as-code for Canadian data residency across both AWS and Azure.

aquasecurity/trivy-checks #602 — an open pull request against the security scanner used across the industry, allowing TLS 1.3 in a policy that incorrectly rejected it. Submitted 18 August, awaiting maintainer review.


What I work with

Cloud — AWS (EKS, ECS Fargate, Lambda, VPC, ECR, S3, DynamoDB, Kinesis, SQS, SNS, IAM, CloudWatch, Bedrock, SageMaker) · Azure (Container Apps, ACR, Bicep, managed identity, Log Analytics, workload identity federation)

Infrastructure as code — Terraform · Bicep · Helm · Kustomize · Docker · Kubernetes · OpenStack

CI/CD & delivery — GitHub Actions · Azure DevOps · Argo CD (GitOps) · OIDC federation

Security & governance — OPA/Rego policy-as-code · Checkov · Trivy · IRSA · least-privilege IAM · SOC 2 / PCI DSS control mapping

Observability & SRE — Prometheus · Grafana · CloudWatch · SLOs and error budgets · blameless postmortems · production on-call

AI/ML — Bedrock · SageMaker · Claude API · RAG · pgvector · agent tool use · LLM evaluation, prompt-injection testing

Languages — Python (boto3, FastAPI, Flask, scikit-learn) · Bash · HCL · SQL

Telecom — Nokia 5G Core (AMF, SMF, UPF, NRF, PCF, UDM) · CBIS/CBAM · CNFs on Kubernetes · 3GPP SBA · ETSI MANO


Background

AI Hardware & Technology Specialist — Meta (via Influence Marketing), Calgary · Oct 2025 – present Technical enablement on Meta AI products and XR hardware. Built and delivered training for 50+ retail staff, reducing escalated issues ~30%. The infrastructure work above is built outside working hours.

Solution Engineer, Cloud Core Network — Nokia, Delhi · Dec 2022 – Jul 2025 5G core in carrier production at 99.9% SLA on OpenStack and Kubernetes, for Bell Canada, T-Mobile US and Orange. Wave-based multi-site 4G→5G migration with zero subscriber downtime. Production on-call with structured root cause analysis.

RF & Systems Engineer — AA Electro Magnetic Test Labs, India · 2018 – 2020

Education — M.Tech, Electronics & Communication Engineering, University of Delhi (full merit scholarship) · B.Tech, Shri Mata Vaishno Devi University

Certifications — Microsoft Azure Fundamentals (AZ-900) · AWS Solutions Architect Associate — studying now, sitting September 2026


Get in touch

I'm looking for a Cloud, DevOps, Platform or SRE role where infrastructure is treated as a product rather than a cost centre. If the work above looks relevant to what your team is building, I'd like to hear from you.

📧 sadhvisharma763@gmail.com 💼 linkedin.com/in/sadhvi-sharma-5789a6249 📍 Calgary, Alberta · Permanent Resident, no sponsorship required · open to relocation

Pinned Loading

  1. azure-sentiment-containerapp azure-sentiment-containerapp Public

    Scales to zero and pulls from ACR with a managed identity scoped to AcrPull, so there is no registry password — sentiment API on Container Apps, Bicep IaC, OIDC deploys

    Python

  2. gitops-argocd-kubernetes gitops-argocd-kubernetes Public

    CI breaks production on purpose and fails unless Argo CD heals it — pull-based GitOps with no cluster credential in the pipeline. Self-heal confirmed in ~10s every run

    Makefile

  3. iac-security-guardrails iac-security-guardrails Public

    A deliberately insecure fixture must be REJECTED, not just a secure one accepted — Checkov plus 12 custom Rego rules including Canadian data residency. Tested in both directions

    HCL

  4. mlops-sentiment-eks mlops-sentiment-eks Public

    CI gates the build on cross-validated model accuracy, so a worse model cannot ship — FastAPI on EKS with HPA on Prometheus metrics and Terraform IaC

    Python

  5. nokia-5g-to-aws-migration nokia-5g-to-aws-migration Public

    Explicit that the user plane does NOT map cleanly, because a UPF forwarding packets at line rate is not an ECS task — 7 Terraform modules mapping carrier 5G functions to AWS, with SOC 2 and PCI DSS…

    HCL

  6. sre-incident-practice sre-incident-practice Public

    Real postmortems from incidents I actually hit, with the open action items left open — a metrics disclosure, a control that failed open, an OIDC trust mismatch. CI enforces the document shape

    Python