GitOps, hardened pipelines and platform engineering done right.
DevOps stopped being about scripts long ago — it is about building a platform other engineers can ship on safely and fast. I design and operate exactly that in production at enterprise scale: GitOps delivery, pipelines hardened against supply-chain attacks, and isolation strong enough for untrusted workloads.
Articles in this hub
12 articles
AdvancedKubernetes 1.35 to 1.38: What Actually Changes in Production
Kubernetes 1.35, 1.36 and 1.37 changed far more than their release-note headlines suggest. A production-focused map of security defaults, autoscaling, AI scheduling, storage, control-plane resilience, upgrade traps, and the still-moving 1.38 release.
Read article
AdvancedKubernetes Autoscaling: Three Controllers That Do Not Talk to Each Other
HPA, VPA and the node autoscaler all read resource requests, none of them coordinate, and every one of them fails silently when requests are wrong. The mechanics that decide whether your cluster scales or just thrashes.
Read article
Intermediatek3s vs k0s vs MicroK8s vs RKE2: Which Kubernetes to Install When You Don't Need the Full One
A practical comparison of the four lightweight Kubernetes distributions that matter in 2026. Not a feature list: what each one actually removes, why k3s and k0s share the same database shim, which one isolates the control plane by default, and the Ingress NGINX end-of-life that just changed RKE2's defaults.
Read article
IntermediateDORA Metrics in 2026: Why Four Became Five (and What Most Dashboards Still Get Wrong)
DORA's four key metrics quietly became five in 2024, and one of them moved out of the category everyone still puts it in. A practical guide to what changed, why recovery time is now a throughput measure, how to compute each metric from your own Git and deployment data, and the ways these numbers break the moment they become someone's performance target.
Read article
IntermediateSBOM Won't Stop the Next Log4j — Here's What Actually Would
An SBOM is an inventory, not a defense. Generating one would not have stopped Log4Shell. What would: continuous CVE correlation, signed provenance, and VEX to kill the noise. A practical supply-chain security guide for 2026.
Read article
IntermediatePlatform Engineering on Kubernetes: What It Actually Is (and How to Build the Platform)
Platform engineering on Kubernetes, explained without the hype: what an Internal Developer Platform actually is, how it differs from DevOps and SRE, the anatomy of an IDP, golden paths, a comparison table, and an honest answer to whether you even need one.
Read article
IntermediateOpenTofu vs Terraform in 2026: Is the Fork Worth Switching To?
OpenTofu vs Terraform in 2026: why the fork happened, what actually differs (state encryption, provider for_each, licensing), a comparison table, and an honest verdict on switching.
Read article
IntermediatePodman in 2026: Rootless, Daemonless Containers Without Docker
A hands-on 2026 guide to Podman: why daemonless and rootless containers are safer, how user-namespace UID mapping works, and how Quadlet lets systemd run your containers instead of a background daemon.
Read article
AdvancedBuild a Tiny Linux Container without Docker in 2026
A hands-on 2026 walkthrough for building a tiny isolated Linux container with overlayFS, cgroups, namespaces, pivot_root, and kernel primitives instead of Docker.
Read article
AdvancedmicroVMs Explained: Firecracker vs gVisor for Secure Workloads in 2026
A practical 2026 comparison of Firecracker microVMs and gVisor for secure workload isolation: how each sandbox works, the security and performance trade-offs, and when to choose KVM-based VMs over a userspace kernel.
Read article
AdvancedSecure GitLab CI/CD in 2026: A Practical Hardening Playbook
A practical 2026 GitLab hardening playbook for protecting source code, secrets, runners, containers, artifacts, and CI/CD infrastructure from real-world attack paths.
Read article
IntermediateGitOps with Argo CD: Automated Kubernetes Deployments in 2026
A practical look at GitOps, Argo CD, and Kubernetes deployment automation: push vs pull models, kubectl, Kustomize, Helm, ApplicationSets, and a cleaner delivery workflow.
Read article
FAQ
What is your platform engineering background?
Are you available to hire?
How do we start working together?
Building a platform or hardening delivery?
From GitOps and Argo CD to CI/CD hardening and Kubernetes, I help teams ship faster without trading away security.
See platform engineering services →