// insights
Deep-dives on AWS, Kubernetes, Terraform, and the craft of building systems that scale without breaking.
A practical look at the module layout that keeps dev, staging, and prod in sync without copy-paste drift.
Idle NAT gateways, over-provisioned RDS, forgotten EBS volumes — the usual suspects, and how to find them fast.
Full mutual TLS across your Kubernetes workloads using cert-manager and a sidecar pattern — no Istio required.
Stop storing long-lived AWS keys in GitHub Secrets. Here's how to use OIDC federation for short-lived credentials on every deploy.
We've run both in production. Here's an honest breakdown of cost savings, complexity, and when one is better than the other.
Public, private, and intra subnets across three AZs, with NAT gateway placement and CIDR sizing decisions explained.
One post a week. No noise. Unsubscribe anytime.