<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Portfolio</title><description>DevOps, SRE, Platform Engineering, and AI-driven delivery — by Haggai Philip Zagury.</description><link>https://portfolio.hagzag.com/</link><language>en</language><item><title>Anthroipcs announcement, a Brake Pedal, or a Press Release?</title><link>https://portfolio.hagzag.com/blog/2026-06-06-brake-pedal-or-press-release/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-06-06-brake-pedal-or-press-release/</guid><description>Anthropic wants the option to pause frontier AI development. A platform engineer reads the data behind the &apos;recursive self-improvement&apos; warning — and the timing.</description><pubDate>Sat, 06 Jun 2026 16:36:28 GMT</pubDate><category>agentic-ai</category><category>ai-safety</category><category>recursive-self-improvement</category><category>platform-engineering</category><category>devops</category><category>anthropic</category><category>ai-governance</category></item><item><title>The Knowledge Bill Comes Due</title><link>https://portfolio.hagzag.com/blog/2026-05-30-the-knowledge-bill-comes-due/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-05-30-the-knowledge-bill-comes-due/</guid><description>A follow-up to The AI Headcount Panic. The numbers crossed 150,000, and the first codebases gutted of senior engineers are starting to break. The bill arrives on a lag.</description><pubDate>Sat, 30 May 2026 23:34:00 GMT</pubDate><category>ai</category><category>layoffs</category><category>platform-engineering</category><category>institutional-knowledge</category><category>engineering-management</category><category>technical-debt</category></item><item><title>The AI Headcount Panic, Bad Bets, and Lost Knowledge</title><link>https://portfolio.hagzag.com/blog/2026-05-27-the-ai-headcount-panic/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-05-27-the-ai-headcount-panic/</guid><description>Companies across the globe—and Israeli high-tech especially—are mass-laying off in the name of AI. But is AI really the reason, or just the best available excuse?</description><pubDate>Wed, 27 May 2026 08:00:00 GMT</pubDate><category>ai</category><category>layoffs</category><category>platform-engineering</category><category>developer-productivity</category><category>israeli-tech</category><category>organizational-change</category><category>agentic-ai</category><category>knowledge-management</category></item><item><title>Cilium in Practice — A Three-Part Series on eBPF Networking, EKS, and FedRAMP</title><link>https://portfolio.hagzag.com/blog/reading-lists/cilium-in-practice/2026-05-15-cilium-series-introduction/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/cilium-in-practice/2026-05-15-cilium-series-introduction/</guid><description>Three forces pushed Cilium onto my roadmap: a VPC-CNI silent-drop bug, a FedRAMP project, and a pattern in every recent breach I&apos;ve reviewed. Here&apos;s the series.</description><pubDate>Fri, 15 May 2026 10:00:00 GMT</pubDate><category>cilium</category><category>ebpf</category><category>kubernetes</category><category>network-policy</category><category>eks</category><category>fedramp</category><category>fips</category></item><item><title>FedRAMP, From the Platform Side — Glossary: NIST SP 800-53 Control Families</title><link>https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-14-fedramp-platform-side-glossary-copy/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-14-fedramp-platform-side-glossary-copy/</guid><description>A quick-reference glossary of NIST SP 800-53 control families referenced throughout the FedRAMP series — RA, CM, SA, AC, AU, SI — and what each one means for platform engineers.</description><pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate><category>fedramp</category><category>nist-sp-800-53</category><category>compliance</category><category>platform-engineering</category><category>risk-assessment</category><category>configuration-management</category><category>system-acquisition</category><category>access-control</category><category>audit</category></item><item><title>FedRAMP, From the Platform Side — Part 4: Drawing the Boundary</title><link>https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-12-fedramp-platform-side-part-4/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-12-fedramp-platform-side-part-4/</guid><description>Drawing the FedRAMP authorization boundary is the most consequential platform decision in the program — what&apos;s in, what&apos;s leveraged, what&apos;s external, and how 20x turns the boundary from a Visio diagram into a data structure.</description><pubDate>Tue, 12 May 2026 11:00:00 GMT</pubDate><category>fedramp</category><category>fedramp-20x</category><category>authorization-boundary</category><category>compliance</category><category>platform-engineering</category><category>devops</category><category>shared-responsibility</category><category>govcloud</category></item><item><title>The Infrastructure Wall: Why Your Agent Demo Died in Production</title><link>https://portfolio.hagzag.com/blog/2026-05-12-the-infrastructure-wall-agents-in-production/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-05-12-the-infrastructure-wall-agents-in-production/</guid><description>Everyone prototypes an AI agent in a weekend. Almost nobody ships it cleanly. Here&apos;s the wall you&apos;re about to hit — and how the platform is evolving to remove it.</description><pubDate>Tue, 12 May 2026 06:00:00 GMT</pubDate><category>agentic-ai</category><category>platform-engineering</category><category>devops</category><category>cloud-native</category><category>llm-ops</category><category>cloud-managed-agents</category><category>production-readiness</category></item><item><title>FedRAMP, From the Platform Side — Part 3: Where FIPS Lives Inside FedRAMP</title><link>https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-12-fedramp-platform-side-part-3/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-12-fedramp-platform-side-part-3/</guid><description>FIPS-validated crypto is a hard requirement inside a FedRAMP boundary — not a best practice. A practitioner&apos;s walkthrough of where FIPS lands across 800-53 control families, and how the Building for Compliance supply-chain work maps onto it.</description><pubDate>Tue, 12 May 2026 06:00:00 GMT</pubDate><category>fedramp</category><category>fips</category><category>fips-140-3</category><category>compliance</category><category>platform-engineering</category><category>cryptography</category><category>supply-chain-security</category><category>containers</category></item><item><title>FedRAMP, From the Platform Side — Part 2: The Basics</title><link>https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-02-fedramp-platform-side-part-2/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-05-02-fedramp-platform-side-part-2/</guid><description>A platform engineer&apos;s plain-English walkthrough of what FedRAMP actually is — impact levels, the document set (SSP, SAR, POA&amp;M), the ATO process, and how Rev5 and 20x change the picture in 2026.</description><pubDate>Sat, 02 May 2026 06:00:00 GMT</pubDate><category>fedramp</category><category>fedramp-20x</category><category>compliance</category><category>platform-engineering</category><category>devops</category><category>nist-800-53</category><category>ato</category><category>oscal</category></item><item><title>SOC 2 for ISVs — A 2026 Refresh of the Series</title><link>https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2026-04-30-soc2-series-2026-refresh/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2026-04-30-soc2-series-2026-refresh/</guid><description>A short note on why I refreshed the 5-part SOC 2 for ISVs series in 2026 — modernized imagery, and a reset of my own field knowledge from +-5-7 years of customer engagements.</description><pubDate>Wed, 29 Apr 2026 04:00:00 GMT</pubDate><category>soc2</category><category>compliance</category><category>isv</category><category>series-update</category><category>retrospective</category></item><item><title>FedRAMP, From the Platform Side — Part 1: Why You Probably Need a Partner</title><link>https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-04-28-fedramp-platform-side-part-1/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/fedramp-journey/2026-04-28-fedramp-platform-side-part-1/</guid><description>A platform engineer&apos;s take on starting the FedRAMP journey from outside the US — why a third-party partner matters, and what the &apos;90 days&apos; promise really means in 2026.</description><pubDate>Tue, 28 Apr 2026 06:00:00 GMT</pubDate><category>fedramp</category><category>compliance</category><category>platform-engineering</category><category>devops</category><category>soc2</category><category>fips</category><category>3pao</category><category>fedramp-20x</category></item><item><title>Stop Storing Secrets in GitHub and GitLab: OIDC + External Secrets Managers for CI/CD</title><link>https://portfolio.hagzag.com/blog/2026-04-27-ci-secrets-oidc-external-secrets-manager/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-04-27-ci-secrets-oidc-external-secrets-manager/</guid><description>Why masked CI variables and GitHub encrypted secrets are not enough — and how to replace them with OIDC-based access to HashiCorp Vault, AWS Secrets Manager, or GCP Secret Manager.</description><pubDate>Mon, 27 Apr 2026 08:00:00 GMT</pubDate><category>secrets-management</category><category>oidc</category><category>github-actions</category><category>gitlab-ci</category><category>hashicorp-vault</category><category>aws-secrets-manager</category><category>gcp-secret-manager</category><category>ci-cd</category><category>security</category><category>zero-trust</category></item><item><title>My Personal Blog Stack: Astro + GitHub Pages = Zero Excuses Not to Write</title><link>https://portfolio.hagzag.com/blog/2026-04-24-blogging-with-astro/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-04-24-blogging-with-astro/</guid><description>How I set up my personal blog and portfolio using Astro and GitHub Pages — zero cost, full control, and a git push away from publishing.</description><pubDate>Fri, 24 Apr 2026 05:00:00 GMT</pubDate><category>astro</category><category>github-pages</category><category>static-site</category><category>blog</category><category>portfolio</category><category>github-actions</category><category>tailwindcss</category><category>markdown</category><category>developer-experience</category></item><item><title>Zero Trust Network Access in CI/CD: Cloudflare WARP for Private Endpoint Connectivity in GitHub Actions</title><link>https://portfolio.hagzag.com/blog/2026-04-23-cloudflare-warp-ci-private-endpoints-terragrunt/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/2026-04-23-cloudflare-warp-ci-private-endpoints-terragrunt/</guid><description>How to connect GitHub Actions runners to private infrastructure using Cloudflare Zero Trust WARP and a service account — enabling Terragrunt to reach private endpoints without IP allowlisting.</description><pubDate>Thu, 23 Apr 2026 08:00:00 GMT</pubDate><category>cloudflare</category><category>zero-trust</category><category>github-actions</category><category>gitlab-ci</category><category>terragrunt</category><category>terraform</category><category>networking</category><category>ci-cd</category><category>warp</category><category>security</category></item><item><title>Rebuilding for Compliance, Part 4: From Signed Image to Verified Pipeline</title><link>https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-4-from-signed-image-to-verified-pipeline/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-4-from-signed-image-to-verified-pipeline/</guid><description>Wiring a signed Wolfi toolchain image into a real consumer pipeline, verifying it at deploy time with Sigstore policy-controller, and digest-pinning with Renovate — the series finale.</description><pubDate>Tue, 21 Apr 2026 10:00:00 GMT</pubDate><category>supply-chain-security</category><category>cosign</category><category>sigstore</category><category>kubernetes</category><category>admission-control</category><category>github-actions</category><category>renovate</category><category>wolfi</category><category>terraform</category><category>semantic-release</category></item><item><title>The Reverse Tunnel: ngrok, Cloudflare Tunnel, and the Service That Dials Out</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/the-reverse-tunnel/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/the-reverse-tunnel/</guid><description>ngrok, cloudflared, Tailscale Funnel, frp — a practitioner&apos;s map of reverse tunnels: how they work, when they&apos;re production-grade, and how they fit the Zero Trust picture.</description><pubDate>Tue, 21 Apr 2026 10:00:00 GMT</pubDate><category>ngrok</category><category>cloudflare-tunnel</category><category>cloudflared</category><category>tailscale</category><category>frp</category><category>reverse-tunnel</category><category>zero-trust</category><category>remote-access</category><category>dns</category></item><item><title>Compliance, Cloud, and Consulting from Anywhere</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/compliance-cloud-and-consulting-from-anywhere/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/compliance-cloud-and-consulting-from-anywhere/</guid><description>The finale of the Zero Trust series: where compliance frameworks meet ZTNA, how the hyperscalers ship it natively, and what twenty years of remote-access evolution means for working practitioners.</description><pubDate>Mon, 20 Apr 2026 18:00:00 GMT</pubDate><category>zero-trust</category><category>compliance</category><category>soc2</category><category>fips</category><category>aws-verified-access</category><category>beyondcorp</category><category>entra-id</category><category>consulting</category><category>remote-access</category><category>dns</category></item><item><title>Zero Trust Networking: Identity Meets the Network</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/zero-trust-networking-identity-meets-the-network/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/zero-trust-networking-identity-meets-the-network/</guid><description>ZTNA is what you get when you stop treating the network as the trust boundary and make every packet a policy decision against identity. A practitioner&apos;s map of the model, the vendors, and the DNS turn.</description><pubDate>Mon, 20 Apr 2026 16:00:00 GMT</pubDate><category>zero-trust</category><category>ztna</category><category>cloudflare</category><category>tailscale</category><category>beyondcorp</category><category>remote-access</category><category>dns</category><category>kubernetes</category><category>k3d</category></item><item><title>Identity Is the New Perimeter: AuthN, AuthZ, MFA, and Why They Matter</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/identity-is-the-new-perimeter/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/identity-is-the-new-perimeter/</guid><description>OAuth is authorization. OIDC is identity. MFA is necessary but not sufficient. A practitioner&apos;s map of AuthN, AuthZ, federation, and the DevOps use cases that live on top.</description><pubDate>Mon, 20 Apr 2026 14:00:00 GMT</pubDate><category>identity</category><category>oauth</category><category>oidc</category><category>saml</category><category>mfa</category><category>passkeys</category><category>zero-trust</category><category>keycloak</category><category>kubernetes</category></item><item><title>WireGuard: Why Simpler Won</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/wireguard-why-simpler-won/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/wireguard-why-simpler-won/</guid><description>WireGuard won because it&apos;s boring — a short config, a fixed crypto suite, and a kernel module the size of a caffeine habit. Here&apos;s the practitioner&apos;s case for it in 2026.</description><pubDate>Mon, 20 Apr 2026 12:00:00 GMT</pubDate><category>wireguard</category><category>vpn</category><category>remote-access</category><category>zero-trust</category><category>tailscale</category><category>dns</category><category>kubernetes</category><category>k3d</category></item><item><title>VPNs: OpenVPN, IPsec, and the TLS Tunnel</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/vpns-openvpn-ipsec-and-the-tls-tunnel/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/vpns-openvpn-ipsec-and-the-tls-tunnel/</guid><description>VPNs extended the trust boundary over the public internet — and preserved the flaw at the heart of it. A practitioner&apos;s tour of OpenVPN, IPsec, split-DNS, and the DPI blocking era.</description><pubDate>Mon, 20 Apr 2026 11:00:00 GMT</pubDate><category>vpn</category><category>openvpn</category><category>ipsec</category><category>remote-access</category><category>zero-trust</category><category>dns</category><category>kubernetes</category><category>k3d</category></item><item><title>Rebuilding for Compliance, Part 3: Building Secure Containers on Wolfi</title><link>https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-3-building-secure-containers-on-wolfi/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-3-building-secure-containers-on-wolfi/</guid><description>Part 3 — how I put Wolfi, syft, grype, and cosign to work in hagzag/tools: a CI toolchain image with SBOM validation, keyless signing, and a single-command local loop.</description><pubDate>Mon, 20 Apr 2026 10:00:00 GMT</pubDate><category>wolfi</category><category>chainguard</category><category>containers</category><category>sbom</category><category>syft</category><category>grype</category><category>cosign</category><category>supply-chain-security</category><category>terraform</category><category>terragrunt</category><category>github-actions</category></item><item><title>SSH and the Cryptographic Turn</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/ssh-and-the-cryptographic-turn/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/ssh-and-the-cryptographic-turn/</guid><description>SSH replaced telnet in a few years and still runs everything three decades later. Here&apos;s why &apos;SSH is solved&apos; is the most dangerous sentence in your runbook.</description><pubDate>Mon, 20 Apr 2026 10:00:00 GMT</pubDate><category>ssh</category><category>remote-access</category><category>zero-trust</category><category>certificates</category><category>bastion</category><category>openssh</category><category>kubernetes</category><category>k3d</category></item><item><title>From Trusted Wires to the Open Internet</title><link>https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/from-trusted-wires-to-the-open-internet/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/path2zerotrust/from-trusted-wires-to-the-open-internet/</guid><description>Why telnet, rsh, and finger made sense once — and why every modern remote-access control traces back to the moment the wire stopped being trusted.</description><pubDate>Mon, 20 Apr 2026 09:00:00 GMT</pubDate><category>remote-access</category><category>networking</category><category>zero-trust</category><category>history</category><category>osi-model</category><category>dns</category><category>kubernetes</category><category>k3d</category></item><item><title>Rebuilding for Compliance, Part 2: Rebuilding on Wolfi OS</title><link>https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-2-building-on-wolfi-os/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-2-building-on-wolfi-os/</guid><description>Wolfi OS, apko, melange, and Chainguard&apos;s daily rebuild model — a practitioner&apos;s evaluation of the open-source path to low-CVE, FIPS/FedRAMP-ready images.</description><pubDate>Sun, 19 Apr 2026 10:00:00 GMT</pubDate><category>wolfi</category><category>chainguard</category><category>containers</category><category>apko</category><category>melange</category><category>supply-chain-security</category><category>cve</category><category>fips</category><category>fedramp</category><category>kubernetes</category></item><item><title>Rebuilding for Compliance, Part 1: A Supply Chain Security Primer</title><link>https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-1-a-supply-chain-security-primer/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/building-complient-software/rebuilding-for-compliance-part-1-a-supply-chain-security-primer/</guid><description>SBOM, provenance, SLSA, cosign — and how FIPS 140-2/3 and FedRAMP land on your container images. A practitioner&apos;s map before the rebuild begins.</description><pubDate>Sat, 18 Apr 2026 10:00:00 GMT</pubDate><category>supply-chain-security</category><category>sbom</category><category>slsa</category><category>cosign</category><category>sigstore</category><category>fips</category><category>fedramp</category><category>containers</category><category>compliance</category></item><item><title>From API to Owned: MiniMax M2.7, Gemma 4, and the Case for Running Models on Your Laptop</title><link>https://portfolio.hagzag.com/blog/medium/from-api-to-owned-minimax-m2-7-gemma-4-and-the-case-for-running-models-on-your-laptop/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/from-api-to-owned-minimax-m2-7-gemma-4-and-the-case-for-running-models-on-your-laptop/</guid><description>Two major open-source model releases in one week signal a tipping point. Here&apos;s why I&apos;m running capable agent models on my own hardware — and how you can too.</description><pubDate>Tue, 14 Apr 2026 05:00:00 GMT</pubDate><category>ollama</category><category>k3d</category><category>kubernetes</category><category>gemma</category><category>minimax</category><category>open-source-llm</category><category>local-ai</category><category>platform-engineering</category><category>agent-cost-wars</category></item><item><title>ClawJacked, Axios, and the Autonomous Agent Problem</title><link>https://portfolio.hagzag.com/blog/medium/autonomous-agent-p1-clawjacked-axios-and-the-autonomous-agent-problem/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/autonomous-agent-p1-clawjacked-axios-and-the-autonomous-agent-problem/</guid><description>A practitioner&apos;s field notes on March 2026: OpenClaw&apos;s CVE flood, the Axios npm RAT, and why self-hosted autonomous agents are standing in the blast zone.</description><pubDate>Fri, 10 Apr 2026 10:00:00 GMT</pubDate><category>autonomous-agents</category><category>security</category><category>supply-chain</category><category>openclaw</category><category>prompt-injection</category><category>agentic-ai</category><category>devsecops</category></item><item><title>I Want a Personal Agent. I&apos;m Not Running One Yet — Here&apos;s What Would Change That</title><link>https://portfolio.hagzag.com/blog/medium/autonomous-agent-p2-i-want-a-personal-agent-im-not-running-one-yet-here-s-what-would-change-that/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/autonomous-agent-p2-i-want-a-personal-agent-im-not-running-one-yet-here-s-what-would-change-that/</guid><description>Part 2: sandboxing with agent-sandbox, evaluating nanobot and nanoclaw, prompt injection realities, and the pre-flight checklist before I trust an autonomous agent.</description><pubDate>Thu, 09 Apr 2026 11:00:00 GMT</pubDate><category>autonomous-agents</category><category>security</category><category>sandboxing</category><category>agent-sandbox</category><category>nanobot</category><category>prompt-injection</category><category>agentic-ai</category><category>devsecops</category></item><item><title>Andrej Karpathy Just Made RAG Obsolete — And All You Need Is Three Folders</title><link>https://portfolio.hagzag.com/blog/medium/andrej-karpathy-just-made-rag-obsolete-and-all-you-need-is-three-folders/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/andrej-karpathy-just-made-rag-obsolete-and-all-you-need-is-three-folders/</guid><description>Andrej Karpathy dropped a paradigm-shifting gist on building personal knowledge bases with LLMs — no vector DB, no embeddings, just raw/wiki/output folders. Here&apos;s what it means for the rest of us.</description><pubDate>Tue, 07 Apr 2026 08:00:00 GMT</pubDate><category>karpathy</category><category>rag</category><category>llm</category><category>knowledge-management</category><category>obsidian</category><category>platform-engineering</category><category>agentic-ai</category><category>vibe-coding</category><category>autoresearch</category></item><item><title>The Agent Cost Wars — Updated: GLM-5, M2.7, and What the Leaderboard Actually Tells Us</title><link>https://portfolio.hagzag.com/blog/medium/cost-of-intelligence-02/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/cost-of-intelligence-02/</guid><description>A follow-up to my MiniMax M2.5 piece — challenging my own assumptions with fresh Artificial Analysis data, GLM-5, M2.7, and what this means for coders in 2026.</description><pubDate>Tue, 31 Mar 2026 08:00:00 GMT</pubDate><category>llm-pricing</category><category>minimax</category><category>glm-5</category><category>claude-opus</category><category>artificial-analysis</category><category>agentic-ai</category><category>cost-optimization</category><category>coding-agents</category><category>devops</category></item><item><title>The View from Outside the Glass: Why Growing Organizations Need the Outsider&apos;s Mirror</title><link>https://portfolio.hagzag.com/blog/medium/why-growing-organizations-need-the-outsiders-mirror/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/why-growing-organizations-need-the-outsiders-mirror/</guid><description>How a consultant&apos;s external perspective helps scaling organizations shift from reactive execution to intentional alignment — and why staying silent is the real failure.</description><pubDate>Tue, 31 Mar 2026 06:00:00 GMT</pubDate><category>consulting</category><category>thought-leadership</category><category>platform-engineering</category><category>organizational-patterns</category><category>agentic-sdlc</category><category>engineering-culture</category><category>team-topology</category></item><item><title>The $1,892 Agent: MiniMax M2.5 and the Dawn of Always-On Intelligence</title><link>https://portfolio.hagzag.com/blog/medium/cost-of-intelligence-01/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/cost-of-intelligence-01/</guid><description>MiniMax M2.5 achieves near-Opus 4.6 performance at 3% the cost. What this means for always-on agents, the SWE-bench, and the falling cost of intelligence.</description><pubDate>Sun, 22 Mar 2026 06:00:00 GMT</pubDate><category>minimax-m2.5</category><category>always-on-agents</category><category>swe-bench</category><category>llm-cost</category><category>agentic-ai</category><category>opencode</category><category>platform-engineering</category><category>mixture-of-experts</category></item><item><title>AWS KMS Best Practices: Securing the Secret Ingredients of Your Infrastructure</title><link>https://portfolio.hagzag.com/blog/medium/aws-kms-key-strategy/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/aws-kms-key-strategy/</guid><description>AWS KMS gives you three flavors of encryption keys. For anything resembling production, CMKs are the only real choice. This post covers key granularity, aliases, ransomware shields, and cross-account access patterns.</description><pubDate>Fri, 20 Mar 2026 05:00:00 GMT</pubDate><category>aws</category><category>kms</category><category>encryption</category><category>security</category><category>infrastructure-as-code</category><category>terraform</category></item><item><title>AWS Landing Zone Accelerator — When Multi-Account Governance Gets Real</title><link>https://portfolio.hagzag.com/blog/medium/aws-landing-zone-accelerator-multi-account-governance/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/aws-landing-zone-accelerator-multi-account-governance/</guid><description>How AWS Landing Zone Accelerator (LZA) turns YAML configs into governed multi-account environments with Transit Gateway isolation, NACLs, and HIPAA-ready networking.</description><pubDate>Thu, 19 Mar 2026 08:00:00 GMT</pubDate><category>aws</category><category>landing-zone-accelerator</category><category>control-tower</category><category>transit-gateway</category><category>multi-account</category><category>hipaa</category><category>infrastructure-as-code</category><category>cdk</category><category>network-architecture</category><category>compliance</category></item><item><title>Declarative IaC with Terraform &amp; Terragrunt — A 2026 Series Recap</title><link>https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2026-03-10-declarative-iac-series-recap/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2026-03-10-declarative-iac-series-recap/</guid><description>A recap of the 5-part series on production Terraform &amp; Terragrunt patterns — module versioning, multi-account OIDC, CI/CD pipelines — updated March 2026 with tooling comparisons and field notes.</description><pubDate>Tue, 10 Mar 2026 08:00:00 GMT</pubDate><category>terraform</category><category>terragrunt</category><category>iac</category><category>aws</category><category>oidc</category><category>github-actions</category><category>gitlab-ci</category><category>multi-account</category><category>ci-cd</category><category>series-recap</category></item><item><title>DNS Series Glossary — The Terms That Keep Showing Up</title><link>https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-03-04-dns-series-glossary/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-03-04-dns-series-glossary/</guid><description>A practical glossary for the DNS Evolution in Practice series: core DNS records, service discovery terms, traffic management concepts, and DNS security vocabulary.</description><pubDate>Wed, 04 Mar 2026 05:00:00 GMT</pubDate><category>dns</category><category>networking</category><category>service-discovery</category><category>security</category><category>platform-engineering</category></item><item><title>DNS — The Internet&apos;s Quiet Backbone: A Series Introduction</title><link>https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-03-03-dns-series-introduction/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-03-03-dns-series-introduction/</guid><description>Why I&apos;m writing a four-part DNS series in 2026. Notes from 25 years of teaching the topic that most engineers — and most curricula — quietly underestimate.</description><pubDate>Tue, 03 Mar 2026 04:21:32 GMT</pubDate><category>dns</category><category>platform-engineering</category><category>teaching</category><category>infrastructure</category><category>service-discovery</category><category>high-availability</category></item><item><title>DNS, Part 4 — When DNS Lies: Cache Poisoning, Spoofing, and How to Defend Yourself</title><link>https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-15-dns-part-4-when-dns-lies/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-15-dns-part-4-when-dns-lies/</guid><description>How DNS attacks actually work — Kaminsky, Sea Turtle, MyEtherWallet, DigiNotar — and the layered defenses that hold up: DNSSEC, DoH, CAA, registrar lock.</description><pubDate>Sun, 15 Feb 2026 18:53:55 GMT</pubDate><category>dns</category><category>dnssec</category><category>security</category><category>infrastructure</category><category>platform-engineering</category><category>incident-response</category></item><item><title>DNS, Part 3 — DNS as a Load Balancer: AWS, GCP, Azure and the L3-to-L7 Stack</title><link>https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-11-dns-part-3-dns-as-a-load-balancer/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-11-dns-part-3-dns-as-a-load-balancer/</guid><description>How DNS sits in front of cloud load balancers, what each LB tier actually sees, and the brutal truth about TTLs in multi-region high availability.</description><pubDate>Wed, 11 Feb 2026 18:53:55 GMT</pubDate><category>dns</category><category>load-balancing</category><category>high-availability</category><category>aws</category><category>gcp</category><category>azure</category><category>route53</category></item><item><title>DNS, Part 2 — DNS at Scale: Service Discovery with Consul and CoreDNS</title><link>https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-07-dns-part-2-service-discovery-consul-coredns/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-07-dns-part-2-service-discovery-consul-coredns/</guid><description>How ephemeral cloud-native workloads broke traditional DNS, and how Consul and CoreDNS rebuilt it as a real-time service catalog.</description><pubDate>Sat, 07 Feb 2026 18:53:55 GMT</pubDate><category>dns</category><category>kubernetes</category><category>consul</category><category>coredns</category><category>service-discovery</category><category>cloud-native</category></item><item><title>DNS, Part 1 — From /etc/hosts to BIND-9: The Origin Story Every SRE Should Know</title><link>https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-03-dns-part-1-from-hosts-file-to-bind-9/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/dns-evolution-in-practice/2026-02-03-dns-part-1-from-hosts-file-to-bind-9/</guid><description>A practitioner&apos;s tour of DNS — from the hosts file era and BIND at Berkeley to CoreDNS in Kubernetes — and the record types every engineer should actually understand.</description><pubDate>Tue, 03 Feb 2026 18:53:55 GMT</pubDate><category>dns</category><category>bind</category><category>networking</category><category>infrastructure</category><category>platform-engineering</category><category>service-discovery</category></item><item><title>Cilium, Part 1 — Hands-On With eBPF Network Policies on k3d</title><link>https://portfolio.hagzag.com/blog/reading-lists/cilium-in-practice/2025-11-08-cilium-part-1-k3d-lab/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/cilium-in-practice/2025-11-08-cilium-part-1-k3d-lab/</guid><description>A practitioner&apos;s k3d lab for Cilium: install it next to your laptop, walk a CiliumNetworkPolicy progression from default-deny to L7 HTTP filtering, and read the drops in Hubble.</description><pubDate>Sat, 08 Nov 2025 10:00:00 GMT</pubDate><category>cilium</category><category>ebpf</category><category>kubernetes</category><category>k3d</category><category>network-policy</category><category>hubble</category><category>platform-engineering</category></item><item><title>AI Chaos and Productivity How to Choose Your Core Tool Stack (and Stop the FOMO) </title><link>https://portfolio.hagzag.com/blog/medium/ai-chaos-and-productivity-how-to-choose-your-core-tool-start-and-stop-the-fomo/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/ai-chaos-and-productivity-how-to-choose-your-core-tool-start-and-stop-the-fomo/</guid><pubDate>Wed, 20 Aug 2025 05:00:00 GMT</pubDate><category>pre-commit</category><category>python</category><category>git</category><category>devex</category><category>Development</category><category>Tools</category></item><item><title>Taming the AI Beast: The Role of the LLM Gateway</title><link>https://portfolio.hagzag.com/blog/medium/taiming-the-ai-beast-wtih-llm-gw/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/taiming-the-ai-beast-wtih-llm-gw/</guid><pubDate>Wed, 20 Aug 2025 05:00:00 GMT</pubDate><category>pre-commit</category><category>python</category><category>git</category><category>devex</category><category>Development</category><category>Tools</category></item><item><title>The Cost of Conversations</title><link>https://portfolio.hagzag.com/blog/medium/the-cost-of-coversation/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/the-cost-of-coversation/</guid><pubDate>Wed, 20 Aug 2025 05:00:00 GMT</pubDate><category>ai</category><category>llm</category><category>llm-pricing</category><category>cost-optimization</category><category>agent-cost-wars</category></item><item><title>AI Usage: Are You Vibing or Building? Your Wallet Might Know</title><link>https://portfolio.hagzag.com/blog/medium/vibiing-or-building/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/vibiing-or-building/</guid><pubDate>Wed, 20 Aug 2025 05:00:00 GMT</pubDate><category>ai</category><category>LLM</category><category>devex</category><category>Development</category><category>Tools</category><category>Productivity</category></item><item><title>From smoke to sanity: how I unintentionally used Pomodoro and rebuilt my focus after quitting</title><link>https://portfolio.hagzag.com/blog/med-from-bad-habbits-to-clarity/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/med-from-bad-habbits-to-clarity/</guid><pubDate>Sun, 27 Jul 2025 07:00:00 GMT</pubDate><category>Productivity</category><category>Engineering</category><category>Habbits</category><category>A.I Driven DevOps</category><category>devops</category><category>agentic-ai</category></item><item><title>Tikal&apos;s DevOps Squad (Hebrew)</title><link>https://portfolio.hagzag.com/blog/youtube/pel-q2ydcwo/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/pel-q2ydcwo/</guid><pubDate>Sat, 24 May 2025 09:21:00 GMT</pubDate><category>Webinar</category><category>12-15 factors</category><category>Youtube</category><category>devex</category></item><item><title>CI/CD Pipelines for Terragrunt: GitLab CI</title><link>https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-05-24-declarative-iac-part5-gitlab-ci/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-05-24-declarative-iac-part5-gitlab-ci/</guid><description>GitLab CI for Terragrunt: web_identity_token keyless AWS auth, YAML anchor job templates, static-per-environment pipeline structure, and the one rule that&apos;s never negotiable — destroy is always manual.</description><pubDate>Sat, 24 May 2025 08:00:00 GMT</pubDate><category>gitlab-ci</category><category>terragrunt</category><category>terraform</category><category>ci-cd</category><category>oidc</category><category>aws</category><category>shared-templates</category><category>web-identity-token</category></item><item><title>SOC 2 for ISVs, Part 5: Surviving the Audit and What Comes After</title><link>https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-05-12-soc2-surviving-the-audit/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-05-12-soc2-surviving-the-audit/</guid><description>Choosing an auditor, surviving the Type II observation window, common findings, and how SOC 2 becomes the foundation for ISO 27001, HIPAA, and FedRAMP.</description><pubDate>Mon, 12 May 2025 20:45:00 GMT</pubDate><category>soc2</category><category>compliance</category><category>audit</category><category>iso-27001</category><category>hipaa</category><category>fedramp</category><category>isv</category><category>devops</category></item><item><title>From Prompts to Agents — a DevOps Engineer navigating the AI Landscape</title><link>https://portfolio.hagzag.com/blog/medium/ai-driven-devops-1/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/ai-driven-devops-1/</guid><pubDate>Mon, 05 May 2025 05:00:00 GMT</pubDate><category>ai</category><category>A.I Driven DevOps</category><category>devops</category><category>agentic-ai</category></item><item><title>Building Production-Ready AI Agent Workflows: MCP Integration and Operational Excellence</title><link>https://portfolio.hagzag.com/blog/medium/ai-driven-devops-2/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/ai-driven-devops-2/</guid><pubDate>Mon, 05 May 2025 05:00:00 GMT</pubDate><category>ai</category><category>A.I Driven DevOps</category><category>devops</category><category>agentic-ai</category></item><item><title>SOC 2 for ISVs, Part 4: Continuous Compliance — Making SOC 2 a Byproduct, Not a Project</title><link>https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-05-03-soc2-continuous-compliance/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-05-03-soc2-continuous-compliance/</guid><description>How to turn SOC 2 from a yearly fire drill into a byproduct of how you build — AWS SCPs, GCP Org Policies, OPA, drift detection, and automated evidence collection.</description><pubDate>Sat, 03 May 2025 20:15:00 GMT</pubDate><category>soc2</category><category>compliance</category><category>policy-as-code</category><category>scp</category><category>aws-organizations</category><category>opa</category><category>rego</category><category>gitops</category><category>devops</category><category>platform-engineering</category></item><item><title>CI/CD Pipelines for Terragrunt: GitHub Actions</title><link>https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-05-03-declarative-iac-part4-github-actions/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-05-03-declarative-iac-part4-github-actions/</guid><description>Building a smart GitHub Actions pipeline for Terragrunt: hierarchical HCL change detection, dynamic matrix plans posted as PR comments, and apply-on-merge — no Atlantis, no Terraform Cloud.</description><pubDate>Sat, 03 May 2025 08:00:00 GMT</pubDate><category>github-actions</category><category>terragrunt</category><category>terraform</category><category>ci-cd</category><category>oidc</category><category>aws</category><category>change-detection</category><category>matrix</category></item><item><title>SOC 2 for ISVs, Part 3: From Zero to Audit-Ready — The Technical Foundation</title><link>https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-05-02-soc2-technical-foundation/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-05-02-soc2-technical-foundation/</guid><description>How to map SOC 2 controls to your AWS, GCP, and Kubernetes stack — IAM, logging, encryption, change management, and what auditors actually want to see.</description><pubDate>Fri, 02 May 2025 19:45:00 GMT</pubDate><category>soc2</category><category>compliance</category><category>aws</category><category>gcp</category><category>kubernetes</category><category>iam</category><category>devops</category><category>platform-engineering</category></item><item><title>Terragrunt Live — Structure, Dependencies, and Multi-Account</title><link>https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-04-05-declarative-iac-part3-tf-live/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-04-05-declarative-iac-part3-tf-live/</guid><description>The account/region/env directory hierarchy that replaces Terraform workspaces, Terragrunt&apos;s built-in navigation functions, OIDC hub-and-spoke multi-account auth, and the one-time bootstrap that sets it all up.</description><pubDate>Sat, 05 Apr 2025 08:00:00 GMT</pubDate><category>terraform</category><category>terragrunt</category><category>aws</category><category>oidc</category><category>multi-account</category><category>iam</category><category>blast-radius</category><category>hcl</category></item><item><title>SOC 2 for ISVs, Part 2: The Five Trust Service Criteria, Demystified</title><link>https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-03-29-soc2-trust-service-criteria-demystified/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-03-29-soc2-trust-service-criteria-demystified/</guid><description>What the five SOC 2 Trust Service Criteria actually mean, which are mandatory, and how to scope your audit so it doesn&apos;t sprawl. Part 2 of 5.</description><pubDate>Sat, 29 Mar 2025 19:15:00 GMT</pubDate><category>soc2</category><category>compliance</category><category>trust-service-criteria</category><category>isv</category><category>audit-scoping</category><category>aws</category><category>gcp</category></item><item><title>SOC 2 for ISVs, Part 1: The Price of Admission to the Enterprise</title><link>https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-03-28-soc2-for-isvs-price-of-admission/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/soc2-complience/2025-03-28-soc2-for-isvs-price-of-admission/</guid><description>Why SOC 2 has become non-negotiable for ISVs selling to enterprises — and what it actually costs to skip it. Part 1 of a 5-part series.</description><pubDate>Fri, 28 Mar 2025 18:45:00 GMT</pubDate><category>soc2</category><category>compliance</category><category>isv</category><category>enterprise-sales</category><category>aws</category><category>gcp</category><category>devops</category></item><item><title>Building a Data Platform over Cloud Native Environments (Webinar 26/3/25- Hebrew)</title><link>https://portfolio.hagzag.com/blog/youtube/w2sxocnydbq/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/w2sxocnydbq/</guid><pubDate>Tue, 25 Mar 2025 09:21:00 GMT</pubDate><category>Webinar</category><category>12-15 factors</category><category>Youtube</category><category>devex</category><category>Dagster</category><category>Aibyte</category></item><item><title>From 12-15 Factors (Hebrew)</title><link>https://portfolio.hagzag.com/blog/youtube/7frxsgeops4/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/7frxsgeops4/</guid><pubDate>Mon, 24 Mar 2025 09:21:00 GMT</pubDate><category>Webinar</category><category>12-15 factors</category><category>Youtube</category><category>devex</category></item><item><title>App-Driven-IaC with Crossplane | Meetup slides</title><link>https://portfolio.hagzag.com/blog/presentations/app-driven-iac-with-crossplane/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/presentations/app-driven-iac-with-crossplane/</guid><pubDate>Wed, 19 Mar 2025 09:00:00 GMT</pubDate><category>crossplane</category><category>app-driven-iac</category><category>meetup</category></item><item><title>Terraform Modules — Versioning, Scanning, and Distribution</title><link>https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-03-08-declarative-iac-part2-tf-modules/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-03-08-declarative-iac-part2-tf-modules/</guid><description>How to treat Terraform modules as versioned libraries: semantic-release git tags, Dependabot drift detection, terraform-docs auto-generation, and tfsec/Trivy in CI — on both GitHub and GitLab.</description><pubDate>Sat, 08 Mar 2025 08:00:00 GMT</pubDate><category>terraform</category><category>semantic-release</category><category>ci-cd</category><category>tfsec</category><category>trivy</category><category>github-actions</category><category>gitlab-ci</category><category>modules</category><category>dependabot</category></item><item><title>Why Declarative IaC and Where Terragrunt Fits</title><link>https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-02-15-declarative-iac-part1-why-terragrunt/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/declerative-iac/2025-02-15-declarative-iac-part1-why-terragrunt/</guid><description>How Terragrunt solves the DRY problem Terraform leaves behind: per-module state, a dependency graph, and run-all fan-out — without forking your modules or touching workspaces.</description><pubDate>Sat, 15 Feb 2025 08:00:00 GMT</pubDate><category>terraform</category><category>terragrunt</category><category>iac</category><category>aws</category><category>declarative</category><category>multi-account</category><category>dry</category></item><item><title>Using S3 as Local Storage on kubernetes with S3 CSI Driver</title><link>https://portfolio.hagzag.com/blog/medium/s3-csi-driver-eks/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/s3-csi-driver-eks/</guid><pubDate>Sat, 25 Jan 2025 05:00:00 GMT</pubDate><category>kubernetes</category><category>S3</category><category>EKS</category><category>S3 CSI Driver</category><category>Object Storage</category></item><item><title>Kubernetes Production Readiness Best Practices by Tikal DevOps</title><link>https://portfolio.hagzag.com/blog/youtube/5ngevnfgwnw/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/5ngevnfgwnw/</guid><pubDate>Wed, 31 Jul 2024 07:23:00 GMT</pubDate><category>Webinar</category><category>Production Readiness</category></item><item><title>There’s no place like K3d continued — 2 — scaling with KEDA</title><link>https://portfolio.hagzag.com/blog/medium/scaling-with-keda/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/scaling-with-keda/</guid><description>A hands-on lab using K3d and KEDA to demonstrate horizontal scaling patterns for event-driven workloads.</description><pubDate>Sun, 14 Jul 2024 06:50:56 GMT</pubDate><category>kubernetes</category><category>KEDA</category><category>Event Driven Architecture</category></item><item><title>Planning a production ready kubernetes with fundamental Controllers &amp; Operators — Part 5 — Scheduling</title><link>https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-07-08-5-prod-readyness-scheduling/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-07-08-5-prod-readyness-scheduling/</guid><description>Why scheduling, resource requests, and controller loops matter when designing a production-ready Kubernetes platform.</description><pubDate>Mon, 08 Jul 2024 05:00:00 GMT</pubDate><category>Production Readiness</category><category>sre</category><category>kubernetes</category></item><item><title>Planning a production ready kubernetes with fundamental Controllers &amp; Operators — Part 4</title><link>https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-23-4-prod-readyness-ingress/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-23-4-prod-readyness-ingress/</guid><pubDate>Thu, 23 May 2024 05:00:00 GMT</pubDate><category>Production Readiness</category><category>sre</category><category>kubernetes</category></item><item><title>Planning a production ready kubernetes with fundamental Controllers &amp; Operators — Part 3 — DNS &amp; Service discovery</title><link>https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-17-3-prod-readyness-dns-service-discovery/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-17-3-prod-readyness-dns-service-discovery/</guid><pubDate>Fri, 17 May 2024 05:00:00 GMT</pubDate><category>Production Readiness</category><category>sre</category><category>kubernetes</category></item><item><title>Planning a production ready kubernetes with fundamental Controllers &amp; Operators — Part 2 — Secrets</title><link>https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-10-2-prod-readyness-secrets/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-10-2-prod-readyness-secrets/</guid><pubDate>Fri, 10 May 2024 05:00:00 GMT</pubDate><category>Production Readiness</category><category>sre</category><category>kubernetes</category></item><item><title>Planning a production ready kubernetes with fundamental Controllers &amp; Operators — Part 1 — Intro</title><link>https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-05-1-prod-readyness-planning/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/reading-lists/production-ready-kubernetes/2024-05-05-1-prod-readyness-planning/</guid><pubDate>Sun, 05 May 2024 05:00:00 GMT</pubDate><category>Production Readiness</category><category>sre</category><category>kubernetes</category></item><item><title>Navigating the Complexity of Modern Development: Introducing the Self-Service Development Environment</title><link>https://portfolio.hagzag.com/blog/medium/self-service-devenv/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/self-service-devenv/</guid><description>Why self-service development environments matter for modern teams and how automation, standardization, and templates reduce onboarding friction.</description><pubDate>Wed, 24 Apr 2024 18:54:59 GMT</pubDate><category>devex</category><category>devops</category></item><item><title>Why blog in 2024 ? | A Reflection on Diversity of thought and the Power of anecdotes</title><link>https://portfolio.hagzag.com/blog/medium/whyblog-2024/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/whyblog-2024/</guid><description>Personal reflections on writing, collaboration, and the value of storytelling in the 2024 tech community.</description><pubDate>Tue, 27 Feb 2024 00:00:00 GMT</pubDate><category>Productivity</category><category>Writing</category><category>Community</category></item><item><title>Free &amp; Secure Local Development: Bitwarden Secrets Manager with K3d + Walkthrough</title><link>https://portfolio.hagzag.com/blog/medium/secure-at-dev-k8s-and-bitwarden-sm-operator/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/secure-at-dev-k8s-and-bitwarden-sm-operator/</guid><description>This post will show you how to secure your local development environment by using Bitwarden Secrets Manager with K3d.</description><pubDate>Wed, 17 Jan 2024 00:01:00 GMT</pubDate><category>Secrets</category><category>kubernetes</category><category>Bitwarden</category><category>k3d</category></item><item><title>Infrastructure as Code: Navigating Declarative and Imperative Approaches</title><link>https://portfolio.hagzag.com/blog/medium/declerative-vs-imperative-or-programatic/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/declerative-vs-imperative-or-programatic/</guid><description>Explore the nuances of declarative and imperative Infrastructure as Code (IaC) approaches. Learn how to choose the right method for your team and project needs, with insights from real-world experiences using tools like Terraform, AWS CDK, and Pulumi.</description><pubDate>Mon, 15 Jan 2024 05:00:00 GMT</pubDate><category>IaC</category><category>Terraform</category><category>GitOps</category><category>CDK</category><category>Pulumi</category><category>Declarative</category><category>Imperative</category></item><item><title>Managing your dotfiles or ~/.config ...</title><link>https://portfolio.hagzag.com/blog/dot-files/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/dot-files/</guid><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>dotfiles</category><category>config</category><category>devex</category></item><item><title>Pre-commit hooks using python library pre-commit</title><link>https://portfolio.hagzag.com/blog/pre-commit/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/pre-commit/</guid><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>pre-commit</category><category>python</category><category>git</category><category>devex</category><category>Development</category><category>Tools</category></item><item><title>Doing literally anything with go-task and why should ya?</title><link>https://portfolio.hagzag.com/blog/task-files/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/task-files/</guid><description>Explore how go-task can transform your development workflow by providing a modern, cloud-native task runner alternative to traditional Makefiles.</description><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>dotfiles</category><category>config</category><category>devex</category><category>Tools</category></item><item><title>Building a Developer Platform: “Behind the Scenes” of application lifecycle management</title><link>https://portfolio.hagzag.com/blog/medium/alm-2-platform/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/alm-2-platform/</guid><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>dotfiles</category><category>config</category><category>devex</category></item><item><title>Kubernetes Control Loops: The Secret Sauce Behind Your Microservice Bliss</title><link>https://portfolio.hagzag.com/blog/medium/controloop/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/controloop/</guid><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>dotfiles</category><category>config</category><category>devex</category></item><item><title>IaC &amp; GitOps with EKS blueprints</title><link>https://portfolio.hagzag.com/blog/medium/iac-gitops-with-eks-blueprints/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/iac-gitops-with-eks-blueprints/</guid><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>IaC</category><category>Terraform</category><category>GitOps</category><category>EKS</category></item><item><title>Kubexperience for developers</title><link>https://portfolio.hagzag.com/blog/medium/kubexpereince-intro/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/kubexpereince-intro/</guid><description>A walkthrough of the Kubexperience workshop for developers, covering Kubernetes fundamentals, demos, and resources.</description><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>kubernetes</category><category>k3d</category></item><item><title>From yak shaving to mastering tasks</title><link>https://portfolio.hagzag.com/blog/medium/taskfile-yak-shaving/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/taskfile-yak-shaving/</guid><description>Discover how go-task can transform your development workflow by eliminating yak shaving and streamlining task management.</description><pubDate>Tue, 02 Jan 2024 05:00:00 GMT</pubDate><category>dotfiles</category><category>config</category><category>devex</category></item><item><title>12-factor application principles and How to build by-them</title><link>https://portfolio.hagzag.com/blog/12-factor/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/12-factor/</guid><pubDate>Tue, 14 Mar 2023 05:00:00 GMT</pubDate><category>15-factor</category><category>12-factor</category><category>cloud-native</category><category>microservices</category></item><item><title>Building a Cloud Native Platform Brick by Brick</title><link>https://portfolio.hagzag.com/blog/youtube/3azxwt1am64/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/3azxwt1am64/</guid><pubDate>Wed, 11 Jan 2023 07:23:00 GMT</pubDate><category>Chaos Engineering</category><category>devex</category></item><item><title>Introduction to Helm, The Kubernetes Package Manager</title><link>https://portfolio.hagzag.com/blog/youtube/hdjfyi8egvi/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/hdjfyi8egvi/</guid><pubDate>Wed, 11 Jan 2023 07:23:00 GMT</pubDate><category>Helm</category><category>kubernetes</category></item><item><title>Modern Monitoring, Tikal Knowledge</title><link>https://portfolio.hagzag.com/blog/youtube/xybc7mttge4/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/xybc7mttge4/</guid><pubDate>Wed, 11 Jan 2023 07:23:00 GMT</pubDate><category>Monitoring</category></item><item><title>Kube Security Shifting left, with Armo Security</title><link>https://portfolio.hagzag.com/blog/youtube/9ox5o0a0noi/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/9ox5o0a0noi/</guid><pubDate>Sun, 04 Dec 2022 09:21:00 GMT</pubDate><category>Production Readiness</category><category>Youtube</category><category>TechRadarCon</category><category>security</category></item><item><title>Dev Env Evolution: Seeking developers productivity, Webinar</title><link>https://portfolio.hagzag.com/blog/youtube/jybsn6ij1qc/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/jybsn6ij1qc/</guid><pubDate>Sun, 04 Dec 2022 09:21:00 GMT</pubDate><category>Webinar</category><category>Youtube</category><category>devex</category></item><item><title>Shorts working at Tikal</title><link>https://portfolio.hagzag.com/blog/youtube/s001/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/s001/</guid><pubDate>Sun, 04 Dec 2022 09:21:00 GMT</pubDate><category>YoutubeShorts</category></item><item><title>Have You built your Developer Platform yet? TechRadarCon Talk</title><link>https://portfolio.hagzag.com/blog/youtube/vzmda8qs3jw/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/vzmda8qs3jw/</guid><pubDate>Tue, 22 Nov 2022 09:21:00 GMT</pubDate><category>TechRadarCon</category><category>Production Readiness</category><category>Youtube</category><category>devex</category></item><item><title>IELF Forum | From Chaos 2 Platform Engineering - Backstage introduction</title><link>https://portfolio.hagzag.com/blog/ielf-forum-1/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/ielf-forum-1/</guid><pubDate>Fri, 04 Nov 2022 09:00:00 GMT</pubDate><category>software</category><category>microservices</category><category>dora-metrics</category><category>tech-talk</category></item><item><title>Why metrics are-important ?! | Meetup slides</title><link>https://portfolio.hagzag.com/blog/presentations/0001/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/presentations/0001/</guid><pubDate>Fri, 04 Nov 2022 09:00:00 GMT</pubDate><category>software</category><category>microservices</category><category>dora-metrics</category><category>tech-talk</category></item><item><title>yalla! devops 2022 - building a cloud-native platform brick by brick</title><link>https://portfolio.hagzag.com/blog/youtube/2yvd6locxps/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/2yvd6locxps/</guid><pubDate>Tue, 26 Jul 2022 07:23:00 GMT</pubDate><category>Chaos Engineering</category><category>devex</category></item><item><title>DevPod - lightning talk</title><link>https://portfolio.hagzag.com/blog/devpod/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/devpod/</guid><pubDate>Mon, 04 Apr 2022 05:00:00 GMT</pubDate><category>software</category><category>microservices</category><category>dora-metrics</category></item><item><title>Dora Metrics - lightning talk</title><link>https://portfolio.hagzag.com/blog/dora-metrics/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/dora-metrics/</guid><pubDate>Mon, 04 Apr 2022 05:00:00 GMT</pubDate><category>software</category><category>microservices</category><category>dora-metrics</category></item><item><title>Mise en place approach in software development</title><link>https://portfolio.hagzag.com/blog/mise-en-place/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/mise-en-place/</guid><pubDate>Mon, 04 Apr 2022 05:00:00 GMT</pubDate><category>software</category><category>microservices</category><category>dora-metrics</category></item><item><title>ScoutSuite - lightning talk</title><link>https://portfolio.hagzag.com/blog/scoutesuite/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/scoutesuite/</guid><pubDate>Mon, 04 Apr 2022 05:00:00 GMT</pubDate><category>software</category><category>microservices</category><category>dora-metrics</category></item><item><title>DevEx | GitOps &amp; ArgoCD, Meetup Tikal &amp; Ownbackup</title><link>https://portfolio.hagzag.com/blog/youtube/sor8enm6anm/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/sor8enm6anm/</guid><pubDate>Wed, 30 Mar 2022 19:21:00 GMT</pubDate><category>meetup</category><category>Youtube</category><category>devex</category></item><item><title>👨🏼‍🔬 &gt; 🥷🏼 | UpSkillin’ the Dev in DevOps</title><link>https://portfolio.hagzag.com/blog/medium/upskillin-the-dev-in-devops/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/upskillin-the-dev-in-devops/</guid><description>Why DevOps engineers must deepen their software engineering craft and how to plan the skills journey.</description><pubDate>Sat, 26 Feb 2022 11:14:36 GMT</pubDate><category>devops</category><category>Career</category><category>Engineering</category></item><item><title>MockOps on Kubernetes, Meetup</title><link>https://portfolio.hagzag.com/blog/youtube/1comqo-im6w/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/1comqo-im6w/</guid><pubDate>Tue, 22 Feb 2022 09:21:00 GMT</pubDate><category>meetup</category><category>Youtube</category><category>devex</category><category>k3s</category><category>k3d</category></item><item><title>Chef &amp; Vagrant for Dev-in-DevOps, Meetup (Workshop)</title><link>https://portfolio.hagzag.com/blog/youtube/6iuxdfwkx0y/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/6iuxdfwkx0y/</guid><pubDate>Tue, 22 Feb 2022 09:21:00 GMT</pubDate><category>meetup</category><category>Youtube</category><category>devex</category><category>Vagrant</category><category>Chef</category></item><item><title>Developing a Webcam Arcade Controller using Deep Learning by TensorFlow &amp; Keras - part 1, Meetup</title><link>https://portfolio.hagzag.com/blog/youtube/lxxnwud6x3k/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/lxxnwud6x3k/</guid><pubDate>Tue, 22 Feb 2022 09:21:00 GMT</pubDate><category>meetup</category><category>Youtube</category><category>devex</category><category>Vagrant</category><category>Chef</category></item><item><title>Cloud Native Devs!, TechRadarCon Talk</title><link>https://portfolio.hagzag.com/blog/youtube/nakkz_qdzk4/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/nakkz_qdzk4/</guid><pubDate>Mon, 17 Jan 2022 09:21:00 GMT</pubDate><category>Production Readiness</category><category>Youtube</category><category>TechRadarCon</category></item><item><title>A CloudNative Dev Experience 🎯 | Tikal TechRadarCon 2021</title><link>https://portfolio.hagzag.com/blog/medium/decex-techradrdcon/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/medium/decex-techradrdcon/</guid><pubDate>Wed, 15 Dec 2021 05:00:00 GMT</pubDate><category>dotfiles</category><category>config</category><category>devex</category></item><item><title>Cloud Native Developer Experience | Reducing the TOIL</title><link>https://portfolio.hagzag.com/blog/webminar-03214/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/webminar-03214/</guid><pubDate>Tue, 20 Jul 2021 07:23:00 GMT</pubDate><category>toil</category><category>devex</category></item><item><title>Scaling I/O Bound Microservices</title><link>https://portfolio.hagzag.com/blog/youtube/5wqotc2mlim/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/5wqotc2mlim/</guid><pubDate>Wed, 04 Mar 2020 09:21:00 GMT</pubDate><category>Webinar</category><category>Production Readiness</category><category>Youtube</category></item><item><title>Intro to KubExperience</title><link>https://portfolio.hagzag.com/blog/youtube/7krxvtpb3to/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/7krxvtpb3to/</guid><pubDate>Wed, 04 Mar 2020 09:21:00 GMT</pubDate><category>Webinar</category><category>Production Readiness</category><category>Youtube</category></item><item><title>Terraform - the Defacto Tool for Infrastructure Provisioning</title><link>https://portfolio.hagzag.com/blog/youtube/kqrysdfevec/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/kqrysdfevec/</guid><pubDate>Sun, 28 Jul 2019 09:21:00 GMT</pubDate><category>Webinar</category><category>Production Readiness</category><category>Youtube</category></item><item><title>Chaos Engineering Intro, Tikal</title><link>https://portfolio.hagzag.com/blog/youtube/1jbl2l-mrl4/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/1jbl2l-mrl4/</guid><pubDate>Mon, 22 Jul 2019 07:23:00 GMT</pubDate><category>Chaos Engineering</category><category>devex</category></item><item><title>Chaos-Based Architectures for Distributed Password Cracking, with @SaloShp at GoogleCampus TLV</title><link>https://portfolio.hagzag.com/blog/youtube/ewsdhvc8f5m/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/ewsdhvc8f5m/</guid><pubDate>Mon, 22 Jul 2019 07:23:00 GMT</pubDate><category>Chaos Engineering</category><category>devex</category><category>meetup</category></item><item><title>Minkube Introduction, in my early days with Kubernetes &amp; Youtube</title><link>https://portfolio.hagzag.com/blog/youtube/ssphtus4tii/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/ssphtus4tii/</guid><pubDate>Mon, 19 Mar 2018 09:21:00 GMT</pubDate><category>Production Readiness</category><category>Youtube</category><category>minikube</category></item><item><title>Talk On Serverless, TechRadarCon Talk</title><link>https://portfolio.hagzag.com/blog/youtube/pxfkzhpyq0q/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/pxfkzhpyq0q/</guid><pubDate>Mon, 19 Mar 2018 09:21:00 GMT</pubDate><category>Production Readiness</category><category>Youtube</category><category>TechRadarCon</category></item><item><title>Getting Up &amp; Running with Kubernetes</title><link>https://portfolio.hagzag.com/blog/youtube/xzi16ltohmo/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/xzi16ltohmo/</guid><pubDate>Sat, 28 Mar 2009 07:23:00 GMT</pubDate><category>Webinar</category><category>Production Readiness</category></item><item><title>Raising the Bar: Docker native clustering with Swarm | Hebrew, Meetup</title><link>https://portfolio.hagzag.com/blog/youtube/0panapw7bui/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/0panapw7bui/</guid><pubDate>Wed, 04 Feb 2004 09:21:00 GMT</pubDate><category>meetup</category><category>Youtube</category><category>devex</category><category>Vagrant</category><category>Chef</category></item><item><title>Docking your services with Docker | Hebrew</title><link>https://portfolio.hagzag.com/blog/youtube/5z3ryoxr8tm/</link><guid isPermaLink="true">https://portfolio.hagzag.com/blog/youtube/5z3ryoxr8tm/</guid><pubDate>Wed, 04 Feb 2004 09:21:00 GMT</pubDate><category>meetup</category><category>Youtube</category><category>devex</category><category>Vagrant</category><category>Chef</category></item></channel></rss>