Practical Guides for Operational Reality
Deep-dive operational blueprints, architecture decision records, and FinOps guides on Azure, Kubernetes and DevOps, grounded in real production systems.
- Building AI-Powered Applications with Azure Database for PostgreSQL — A granular walkthrough of turning Azure Database for PostgreSQL into an AI application backend — pgvector embeddings, semantic search, in-database Azure OpenAI calls, a full RAG pipeline, and a simple generative agent.
- Configuring and Migrating to Azure Database for PostgreSQL — A granular DBA-level walkthrough — migrating a database with minimal downtime, configuring zone-redundant high availability, tuning query performance, and locking down identity and network access.
- Deploying Cloud-Native Apps with Azure Container Apps — A granular build: a secure, identity-based connection to Azure Container Registry, KEDA-based autoscaling rules, continuous deployment via Azure Pipelines, and safe revision management for zero-downtime rollouts.
- Containerizing MultiLangua for Azure Container Apps — A real migration, not a toy example — MultiLangua's Firebase Hosting deployment only serves static files, so its AI chat backend never actually runs in production. Containerizing it for Azure Container Apps is what makes the full app work end to end.
- Containerizing ORIN: From Docker to Azure App Service and a Plain VM — The same Express + Vite app, deployed two different ways — Azure App Service and a plain Azure VM — to see exactly what a managed PaaS product is buying you over doing it by hand, then automated end to end with GitHub Actions.
- Networking MYRIX: Hub-Spoke VNets, Bastion, and Load-Balancer Health on Azure — A containerized Flutter game deployed to a plain Azure VM with no public IP at all — reached only through a hub-spoke VNet, peered networks, Azure Bastion for management, and a Standard Load Balancer whose health probe is the actual first line of monitoring.
- Supabase vs. MongoDB vs. Firebase: A Real App, Three Backends — The same minimal notes app — signup, create a note, list notes — built three times against three real backends. One needed zero backend code. One needed a hand-written auth server. One rejected a write with a real 403 and exposed a genuine tooling limitation along the way.
- Building an EKS Security Baseline: RBAC, Pod Security Standards, and NetworkPolicy, Verified — A hub-spoke Transit Gateway network in Terraform, plus RBAC, Pod Security Standards, and NetworkPolicy applied to a real Kubernetes cluster — including a real NetworkPolicy bug caught only because the "allowed" connection failed for a different reason than the blocked one.
- Open Cloud Cost Intelligence: A Real FinOps Pipeline, Built and Run Against Real Billing Data — Ingestion, normalization, cost allocation, and an optimization engine — not against sample data, but against a real Azure resource group's real Cost Management API response. The result: a genuine finding (one service is 75% of daily spend) and a genuine gap (100% of that cost is currently unallocated by tag).
- A Monte Carlo Option Pricer, Checked Against the Closed Form — European option pricing via Monte Carlo simulation of GBM, validated against Black-Scholes — real spot price, real historical volatility, and a measured convergence curve instead of an asserted one.
- Testing My Own Multi-Cloud FinOps CLI Against a Real Azure Account — and Finding Two Real Bugs — A provider-neutral FinOps data platform I built — extraction, normalization, SQL-first governance policies. I pointed it at a real Azure Cost Management export and found the governance layer was completely broken against any live cloud source. Here is exactly what broke, why, and the fix.
- Testing a CloudLab Against a Real App: Deploying to Azure Container Apps — I ran the SKILL.SCH "Deploy Your Application to Azure Container Apps" CloudLab against a real Vite game instead of an app built to fit it. Mission 1 passed live; reviewing the rest turned up a Dockerfile that breaks every static frontend, a deploy command that fails with a private registry, and six smaller gaps, all now fixed in the lab.
- Zero Trust Network Architecture in Azure: Firewalls, Private Link & NSGs — A deep dive into perimeter-less networking, micro-segmentation, and central hub-and-spoke security enforcement.
- Automate Azure Load Testing Using GitHub Actions — Wiring Azure Load Testing into a GitHub Actions pipeline so every pull request gets an automated, pass/fail-gated performance test — based on the pattern in Microsoft's Automate Azure Load Testing Applied Skills path.
- Cloud Security and Monitoring in Azure: Defender for Cloud, Key Vault, Firewall, and Log Analytics — A granular, hands-on walkthrough of the four pillars a security engineer sets up first in Azure — workload protection with Defender for Cloud, key management with Key Vault, network filtering with Azure Firewall, and centralized monitoring with a Log Analytics workspace.
- FinOps for Kubernetes: Cost Optimization & Sizing on Azure AKS — Practical strategies to slash compute spend by 40% on AKS clusters using spot node pools, KEDA auto-scalers, and Azure Data Lake Gen2 tiering.
- FinOps in Practice: Stop Wasting Money on Idle Azure Resources — A practical guide to using Azure Resource Graph, Azure Policy, Azure Advisor, Cost Management, and automation to identify unused resources, reduce cloud waste, and establish sustainable FinOps governance.
- Alibaba Cloud for African Developers: Building a Low-Cost Cloud Architecture — How a small African startup can build a first production platform without over-engineering — a realistic reference architecture, and an honest account of which components to skip until you actually need them.
- Building Resilient Azure OpenAI Apps: Rate Limits, Fallbacks & Private Networking — A practical architectural guide to handling TPM/RPM throttling, regional failover, graceful degradation, and private connectivity for production-grade Azure OpenAI applications.
- Alibaba Cloud Observability Lab: Finding a Production Problem Before Users Do — A deliberately broken application, investigated end-to-end: metrics, logs, alerts, root-cause analysis, fix, and verification — an incident-response walkthrough, not a monitoring-tool tutorial.
- Disaster Recovery on Alibaba Cloud: Designing for Failure — A real disaster-recovery experiment — deliberately failing ECS, a container, and a data object, then measuring actual recovery time against target RTOs rather than assuming a runbook works.
- Building a DevSecOps Pipeline on Alibaba Cloud — Security folded into every stage of the delivery pipeline — code scanning, container image scanning, secrets management, and IAM controls — rather than a checklist run once before production.
- Docker Compose for Real Local Dev Parity — An app and a Postgres database, wired together with health-gated startup ordering and a named volume — torn all the way down and brought back up to prove the data actually survives, not just assumed to.
- GitOps on Alibaba Cloud ACK: Automating Kubernetes Deployments with Git — A full GitOps workflow on ACK with ArgoCD — repo structure, environment separation, automated sync — and a documented account of what happens, and how to recover, when a deployment fails.
- Rootless Containers: Converting a Real Image and Fixing What Breaks — Adding one USER line to a working Dockerfile is easy. Watching the container crash with a real EACCES error the moment it tries to write a file — and fixing it properly — is what actually teaches you why most images still run as root.
- Building a Secure Alibaba Cloud VPC: From Public Internet to Private Architecture — A realistic multi-tier network build — public frontend, private backend, database-tier isolation, bastion access, and the troubleshooting session that happens when a route table is wrong.
- BuildKit Cache Mounts: A Benchmark That Didn't Go the Way I Expected — I expected RUN --mount=type=cache to dramatically speed up repeated npm installs. I benchmarked it in a real GitHub Actions workflow instead of assuming, and the honest result was smaller than the hype — here's why, with the actual timing logs.
- Alibaba Cloud AI Infrastructure: Building an AI Application with ECS and PAI — What it actually takes to move an AI prototype into cloud infrastructure — ECS compute, Platform for AI (PAI) model serving, OSS-backed model artifacts, and the API layer that ties it together.
- Multi-Stage Builds: What Actually Gets Thrown Away — The same app, the same dependencies, built two ways — a naive single-stage Dockerfile and a real multi-stage one — measured byte-for-byte to see exactly what a second FROM line throws away.
- FinOps on Alibaba Cloud: Cost Visibility, Governance, and Optimization at Scale — Applying FinOps discipline — cost allocation, RI/Savings Plan strategy, and automated waste elimination — to Alibaba Cloud, for engineers extending a multi-cloud cost-optimization practice beyond Azure.
- Kubernetes on ACK: Cloud-Native Operations and Troubleshooting on Alibaba Cloud — A hands-on operational guide to Container Service for Kubernetes (ACK) — cluster provisioning, node pool autoscaling, ingress, and the diagnostic workflow for troubleshooting production incidents.
- Terraform on Alibaba Cloud: Building Repeatable Infrastructure as Code — A complete Terraform project on Alibaba Cloud — module structure, state management, CI/CD, drift detection, and the boundary where Terraform ends and configuration management begins.