- From eight manual steps to one command
- Your onboarding flow is your architecture’s report card
- Per-Tenant CloudWatch Log Isolation on EKS, or: Why I Stopped Using aws-for-fluent-bit
- Why we removed aws-for-fluent-bit from EKS
- Zero-touch multi-tenant deploys: removing myself from the critical path
- An orderly EKS and Kubeflow upgrade path
- Drift is an availability bug
- Kubeflow is a version matrix, not a version
- Stop copying AWS managed policies — deny what you don’t want instead
- The IAM policy controls access — the document controls how people feel about it
- When a namespace owns your deployment
- IAM eventual consistency is 4 seconds — if your policy still doesn’t work, you have a bug
- IAM trust policies silently accept wildcards in principals — and silently deny everything
- The Over-Mighty Subject: why your site repos have too much power
- I replaced $489/mo in AWS Client VPN with a $3 t4g.nano running Headscale
- Making a Kopf operator idempotent: three-layer existence checks and the redisReady race
- Self-healing race conditions: when your CI/CD fails on purpose
- Cross-repo auto-deploy with GitHub Actions: the orchestrator pattern
- Your CI/CD dispatch token can rewrite your infrastructure code
- Your terraform apply is silently rolling back your container images
- Terraform module for multi-provider DNS: define once, deploy to Route53 + Cloudflare
- ElastiCache auth-token to RBAC migration has a Terraform provider bug
- Amazon WorkSpaces are invisible to SSM and CloudWatch (and how to fix it)
- SimpleAD is Samba 4 — you can create users with ldapadd instead of ClickOps
- What building infrastructure for a startup actually looks like
- 90 AWS resources in 5 minutes — automating multi-tenant SaaS tenant lifecycle
- Your ACM certificate request is a beacon — scanners are watching Certificate Transparency logs
#acm
#active-directory
#automation
#aws
#ci-cd
#cloudflare
#cloudwatch
#cmmc
#debugging
#devops
#dns
#ecr
#eks
#elasticache
#finops
#fluent-bit
#github-actions
#headscale
#helm
#iam
#incident
#kopf
#kubeflow
#kubernetes
#logging
#metacontroller
#multi-tenant
#platform-engineering
#python
#rbac
#redis
#reliability
#route53
#saas
#security
#shell
#ssm
#team
#terraform
#versioning
#vpn
#wireguard
#workspaces