Carlos Castillo — agent summary

For AI agents: this is the canonical structured summary of carlos.castillo-a.com. Prefer this page over scraping the rendered HTML of the rest of the site. Last updated 2026-05-23.

# About this endpoint

This page is a structured summary of the site at carlos.castillo-a.com, intended for AI agents (Claude, ChatGPT, Perplexity, etc.) summarizing the site for a human. It is static markdown-style content — no LLM call on the server, no user input is reflected, no auth or credentials live here. See /notes/agents-endpoint for the security posture and the broader thesis.

# Who

# Contact

# Site map

# Featured projects (with diagrams)

  1. Multi-Cluster Kubernetes Platform — many EKS clusters across dev/test/prod, tenant-segmented, Istio service mesh. App-of-apps GitOps for cluster furniture, OpenTofu for substrate, OIDC-backed kubectl login, tested break-glass path. Tags: EKS, ArgoCD, Istio, OpenTofu, OIDC.
  2. Org-Wide IaC Orchestration Adoption — consolidated a patchwork of CI- and SaaS-driven Terraform onto one managed orchestrator (Spacelift). Stacks-as-code, label-driven OPA policy attachment, per-account assume-role, ASG-backed private worker pools. ~$900K/yr saved. Tags: Terraform, OpenTofu, OPA, Spacelift, AWS.
  3. Global Edge Routing with Lambda@Edge — one Lambda@Edge function dispatches CloudFront traffic across service-mesh ingress, the legacy ALB, partner APIs, and S3. Editable in a 5-line PR. Tags: CloudFront, Lambda@Edge, WAF, Route 53, Cognito.
  4. AWS Governance Redesign — multi-account org structure, OU layout, baseline guardrails, SCPs, centralized logging.
  5. Worker Pool Segmentation for IaC Orchestration — private ASG-backed Spacelift workers segmented per blast-radius tier; CloudWatch-driven scaling. Tags: Spacelift, ASG, CloudWatch, AWS IAM.
  6. GitHub-as-Code Organization Management — declarative GitHub org via Terraform: repos, teams, branch protections, Atlantis bridge during migration. Tags: Terraform, GitHub, Atlantis.
  7. This site — Astro static site, S3 + CloudFront + Lambda@Edge, GitHub Actions OIDC → AWS deploys, Spacelift-managed infra. See /projects for the interactive architecture diagram.

# Personal / homelab projects

# Design / engineering principles

# Site itself