blog.
Sometimes I write about things that I've worked on, and sometimes I write about things that I've learned.
Infrastructure as code
Terragrunt Is Not a Silver Bullet: The Real Operational Trade-offs of Scaling Terraform Across Environments (opens on Medium in a new tab)
Terragrunt ends copy-pasted environments and drift, but adds a layer of its own to operate. Where it pays off and when to skip it.
All articles
Everything I have written, newest first.
16 articles
Security
Your pipeline has more access than any engineer on your team
A 60-second check of your GitHub Actions workflows for the patterns CI supply-chain attacks rely on: pull_request_target, movable tags, long-lived keys and default token permissions.
Security
The frontend is not a security boundary
Notes on AWS Builder Center’s frontend security article: enforcement belongs behind the frontend, not in it.
Databases & reliability
Zero-Downtime Database Migrations Are Usually a Lie (opens on Medium in a new tab)
Dual-write migrations often cost more than a short, planned maintenance window. When each approach is actually worth it.
AI infrastructure
Dynamic LoRA swapping enables multi-tenant LLM serving without cold-starts (opens on Medium in a new tab)
Serving many fine-tuned models from one resident base model by hot-swapping adapters, and the memory and storage trade-offs.
CI/CD
The Autonomous CI/CD: Setting Up Self-Healing Codebases in 2026 (opens on Medium in a new tab)
A narrow loop from telemetry to patch to canary: what self-healing pipelines need, and where they break.
AI infrastructure
The Free API Stack That Quietly Changed AI Side Projects (opens on Medium in a new tab)
How generous free tiers made AI side projects viable, and where the operational cost moves instead.
Security
Stop treating SSH as just a remote terminal; it’s actually the most versatile encrypted transport layer in your stack (opens on Medium in a new tab)
SSH tunnels as a lightweight alternative to VPNs and public exposure for databases, dashboards and staging.
Kubernetes & containers
The HPA Connection Tax: Why Horizontal Scaling Is Crashing Your Database (opens on Medium in a new tab)
Autoscaled pods can exhaust database connections and cascade into an outage. Pooling and scaling guardrails that prevent it.
Infrastructure as code
You Don’t Need DynamoDB for Terraform State Locking Anymore (opens on Medium in a new tab)
Terraform 1.10+ can lock state natively in S3, so the DynamoDB table is optional. When to migrate, and the trade-offs.
Kubernetes & containers
Everything Docker!! (opens on Medium in a new tab)
From Basic Containers to Multi-Stage Builds
Infrastructure as code
From ClickOps to Terraform: what we measured
How we cut MTTR and why state files deserve respect.
Automation
Running LinkedIn automation without losing your mind (or API limits)
n8n, idempotency, and state in Supabase—patterns from ZabeSync.
Observability
Observability that on-call actually uses
Prometheus + Grafana SLIs: alerts humans can act on.
Observability
Setting Up Seq Logging Alerts Across Multiple Channels (opens on Medium in a new tab)
How to set up Seq logging alerts across multiple channels
CI/CD
Access Jenkins running on EC2 with only private IP on web (opens on Medium in a new tab)
How to access Jenkins running on EC2 with only private IP on web
New articles land on Medium first.
Follow along there, or say hello on LinkedIn if one of these saved you a late night.