Terraform module patterns for multi-environment cloud estates
Reusable Terraform module boundaries, environment composition, state management, and hand-off patterns for repeatable cloud platforms.
Practical notes from cloud architecture, platform engineering, security, and production operations.
Featured
Reusable Terraform module boundaries, environment composition, state management, and hand-off patterns for repeatable cloud platforms.
Why VPC and VNet models diverge more than any other control across AWS, Azure, GCP, and Alibaba Cloud, and how to decide what to standardise versus what to leave provider-native.
Role design, automation identities, access review, and break-glass controls for auditable production access across shared cloud estates.
An operating model for Packer golden images: bake vs configure boundaries, promotion pipelines, launch-template enforcement, and automatable hardening checks across AWS, Azure, and GCP.
All notes
Reusable Terraform module boundaries, environment composition, state management, and hand-off patterns for repeatable cloud platforms.
A systematic approach to diagnosing slow WordPress admin. Covers all common causes: plugin outbound HTTP calls, WP_HTTP_BLOCK_EXTERNAL, Heartbeat API, autoloaded options, WP-Cron, PHP version, OPcache, object cache, and slow database queries.
Why VPC and VNet models diverge more than any other control across AWS, Azure, GCP, and Alibaba Cloud, and how to decide what to standardise versus what to leave provider-native.
Role design, automation identities, access review, and break-glass controls for auditable production access across shared cloud estates.
An operating model for Packer golden images: bake vs configure boundaries, promotion pipelines, launch-template enforcement, and automatable hardening checks across AWS, Azure, and GCP.
An operating model for right-sizing, reserved capacity, and cost ownership across AWS, Azure, and GCP without compromising production reliability.
A migration operating model for landing zones, ownership boundaries, IaC baselines, cutover planning, and cost control before workloads move to the target cloud.
Use iptables string matching to block specific outbound HTTP paths, understand HTTPS limits, and choose safer egress controls when needed.
A real case: Modern Events Calendar (MEC) was responsible for 28 out of 31 outbound HTTP calls and 16 seconds of additional latency on every WordPress admin request. How it was found and stopped.
Fix Nginx 404 errors on .well-known/acme-challenge during Let's Encrypt HTTP-01 validation with webroot config and renewal checks.
Get in touch
I take on a small number of engagements at a time. Tell me what you are working on and I will tell you honestly if I am the right fit.
Start a conversation