CI/CD standardisation across application teams
Reusable GitHub Actions workflows, Environment-scoped OIDC, and digest promotion so several teams ship without each inventing a private release path.
Practical notes from cloud architecture, platform engineering, security, and production operations.
Featured
Reusable GitHub Actions workflows, Environment-scoped OIDC, and digest promotion so several teams ship without each inventing a private release path.
Reusable Terraform module boundaries, environment composition, state management, and hand-off patterns for repeatable cloud platforms.
Why VPC and VNet models diverge more than any other control across AWS, Azure, GCP, and Alibaba Cloud, and how to decide what to standardise versus what to leave provider-native.
Role design, automation identities, access review, and break-glass controls for auditable production access across shared cloud estates.
An operating model for Packer golden images: bake vs configure boundaries, promotion pipelines, launch-template enforcement, and automatable hardening checks across AWS, Azure, and GCP.
All notes
Zero-downtime, rollback-safe database migrations with GitHub Actions. Expand, drain, contract: the schema, queue, and config changes a digest rollback cannot undo.
Reusable GitHub Actions workflows, Environment-scoped OIDC, and digest promotion so several teams ship without each inventing a private release path.
Reusable Terraform module boundaries, environment composition, state management, and hand-off patterns for repeatable cloud platforms.
A systematic approach to diagnosing slow WordPress admin. Covers all common causes: plugin outbound HTTP calls, WP_HTTP_BLOCK_EXTERNAL, Heartbeat API, autoloaded options, WP-Cron, PHP version, OPcache, object cache, and slow database queries.
Why VPC and VNet models diverge more than any other control across AWS, Azure, GCP, and Alibaba Cloud, and how to decide what to standardise versus what to leave provider-native.
Role design, automation identities, access review, and break-glass controls for auditable production access across shared cloud estates.
An operating model for Packer golden images: bake vs configure boundaries, promotion pipelines, launch-template enforcement, and automatable hardening checks across AWS, Azure, and GCP.
An operating model for right-sizing, reserved capacity, and cost ownership across AWS, Azure, and GCP without compromising production reliability.
A migration operating model for landing zones, ownership boundaries, IaC baselines, cutover planning, and cost control before workloads move to the target cloud.
Use iptables string matching to block specific outbound HTTP paths, understand HTTPS limits, and choose safer egress controls when needed.
Get in touch
Tell me what you are working on.
Start a conversation