You're viewing my resume through a containerized Node.js app on Google Cloud Run — built, pushed, and deployed with Pulumi on GCP. Kubernetes is a separate lab; this page is Cloud Run.
To Maria and Max — thank you for the love, patience, and joy that make every project (and this one) worth sharing.
flowchart LR
Human[Human] --> GH[GitHub]
Agent[Cloud agent] --> GH
GH --> Copy[GitHub Action copies git to GitLab]
Copy --> GL[GitLab CI + WIF]
GL --> CR[Cloud Run]
CR --> DNS[resume.solla.app]
GH -.-> Kind[kind — local lab]
GH -.-> GKE[GKE Autopilot — on demand]
A person or a cloud agent lands work on GitHub. A GitHub Action copies the same git branch to GitLab. GitLab CI runs Pulumi against GCP. GitHub Actions never deploys.
pulumi up. GitHub Actions never deploys.
GCP is keyless WIF — no service-account JSON in CI. Pulumi Cloud uses a GitLab
PULUMI_ACCESS_TOKEN (masked, not Protected) so feature-branch
preview can log in. That is acceptable on a solo personal repo; a team would
typically use Pulumi OIDC/ESC and protected branches. The token lives only on GitLab.