DriftGuard
Self-healing GitOps platform on AWS EKS with under 2-minute drift correction and canary rollouts
Self-healing GitOps infrastructure platform on AWS EKS. Terraform provisions the AWS substrate (VPC, EKS, IAM/IRSA, ECR, DNS, KMS), installs ArgoCD once, then steps back. ArgoCD owns all in-cluster state and continuously reconciles from Git. If someone mutates a resource out of band, the platform detects drift within seconds and self-heals within two minutes. The demo workload deploys through Argo Rollouts with a canary strategy: five weight steps (20% through 100%), each with Prometheus-backed analysis. Error rate above 5% or p95 latency above 500ms aborts the rollout automatically. OPA/Gatekeeper admission policies reject privileged containers. Falco monitors runtime behavior. The full LGTM observability stack (Prometheus, Grafana, Loki, Tempo, OpenTelemetry) provides metrics, logs, and traces. CI uses GitHub OIDC federation for short-lived credentials with no static AWS keys anywhere.



