Hello from the cloud.

You're viewing my resume through a containerized Node.js app on Google Cloud Run — built, pushed, and deployed with Pulumi on GCP. Kubernetes is a separate lab; this page is Cloud Run.

To Maria and Max — thank you for the love, patience, and joy that make every project (and this one) worth sharing.

Michael Solla · Cloud Platform Engineer · Download resume (PDF)

Pulumi GCP Cloud Run Docker GitLab CI + WIF GKE Autopilot lab
Cloud Run — live (this page) GKE Autopilot lab — offline by default

Architecture

flowchart LR
  Human[Human] --> GH[GitHub]
  Agent[Cloud agent] --> GH
  GH --> Copy[GitHub Action copies git to GitLab]
  Copy --> GL[GitLab CI + WIF]
  GL --> CR[Cloud Run]
  CR --> DNS[resume.solla.app]
  GH -.-> Kind[kind — local lab]
  GH -.-> GKE[GKE Autopilot — on demand]
        

A person or a cloud agent lands work on GitHub. A GitHub Action copies the same git branch to GitLab. GitLab CI runs Pulumi against GCP. GitHub Actions never deploys.

Why these trade-offs

Security

GCP is keyless WIF — no service-account JSON in CI. Pulumi Cloud uses a GitLab PULUMI_ACCESS_TOKEN (masked, not Protected) so feature-branch preview can log in. That is acceptable on a solo personal repo; a team would typically use Pulumi OIDC/ESC and protected branches. The token lives only on GitLab.