blog.
Sometimes I write about things that I've worked on, and sometimes I write about things that I've learned.
Infrastructure as code
Terragrunt Is Not a Silver Bullet: The Real Operational Trade-offs of Scaling Terraform Across Environments
Terragrunt ends copy-pasted environments and drift, but adds a layer of its own to operate. Where it pays off and when to skip it.
All articles
Everything I have written, newest first.
16 articles
Security
Your pipeline has more access than any engineer on your team
A 60-second check of your GitHub Actions workflows for the patterns CI supply-chain attacks rely on: pull_request_target, movable tags, long-lived keys and default token permissions.
Security
The frontend is not a security boundary
Notes on AWS Builder Center’s frontend security article: enforcement belongs behind the frontend, not in it.
Databases & reliability
Zero-Downtime Database Migrations Are Usually a Lie
Dual-write migrations often cost more than a short, planned maintenance window. When each approach is actually worth it.
AI infrastructure
Dynamic LoRA swapping enables multi-tenant LLM serving without cold-starts
Serving many fine-tuned models from one resident base model by hot-swapping adapters, and the memory and storage trade-offs.
CI/CD
The Autonomous CI/CD: Setting Up Self-Healing Codebases in 2026
A narrow loop from telemetry to patch to canary: what self-healing pipelines need, and where they break.
AI infrastructure
The Free API Stack That Quietly Changed AI Side Projects
How generous free tiers made AI side projects viable, and where the operational cost moves instead.
Security
Stop treating SSH as just a remote terminal; it’s actually the most versatile encrypted transport layer in your stack
SSH tunnels as a lightweight alternative to VPNs and public exposure for databases, dashboards and staging.
Kubernetes & containers
The HPA Connection Tax: Why Horizontal Scaling Is Crashing Your Database
Autoscaled pods can exhaust database connections and cascade into an outage. Pooling and scaling guardrails that prevent it.
Infrastructure as code
You Don’t Need DynamoDB for Terraform State Locking Anymore
Terraform 1.10+ can lock state natively in S3, so the DynamoDB table is optional. When to migrate, and the trade-offs.
Kubernetes & containers
Everything Docker!!
From Basic Containers to Multi-Stage Builds
Infrastructure as code
From ClickOps to Terraform: what we measured
How we cut MTTR and why state files deserve respect.
Automation
Running LinkedIn automation without losing your mind (or API limits)
n8n, idempotency, and state in Supabase—patterns from ZabeSync.
Observability
Observability that on-call actually uses
Prometheus + Grafana SLIs: alerts humans can act on.
Observability
Setting Up Seq Logging Alerts Across Multiple Channels
How to set up Seq logging alerts across multiple channels
CI/CD
Access Jenkins running on EC2 with only private IP on web
How to access Jenkins running on EC2 with only private IP on web
New articles land on Medium first.
Follow along there, or say hello on LinkedIn if one of these saved you a late night.