<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Subhanshu Mohan Gupta</title>
  <subtitle>DevSecOps, platform engineering and cloud security. Long-form essays on the infrastructure that survives production.</subtitle>
  <link href="https://subhanshumg.com/atom.xml" rel="self" />
  <link href="https://subhanshumg.com/blogs" />
  <id>https://subhanshumg.com/</id>
  <updated>2026-08-24T21:26:10.000Z</updated>
  <author>
    <name>Subhanshu Mohan Gupta</name>
    <email>subhanshugupta0@gmail.com</email>
  </author>
  <entry>
    <title>Your rate limiter was designed for humans</title>
    <link href="https://blogs.subhanshumg.com/your-rate-limiter-was-designed-for-humans" />
    <id>https://blogs.subhanshumg.com/your-rate-limiter-was-designed-for-humans</id>
    <updated>2026-08-24T21:26:10.000Z</updated>
    <published>2026-08-24T21:26:10.000Z</published>
    <summary>Agent traffic does not get tired. Four layers of your stack assume it does.</summary>
    <category term="Devops" />
    <category term="api" />
    <category term="Security" />
    <category term="System Design" />
    <category term="AI" />
    <category term="Platform Engineering" />
    <category term="Cloud Computing" />
  </entry>
  <entry>
    <title>Prefill Is Compute, Decode Is Memory: The Architecture Shift Nobody Budgeted For</title>
    <link href="https://subhanshumg.com/blogs/prefill-is-compute-decode-is-memory" />
    <id>https://subhanshumg.com/blogs/prefill-is-compute-decode-is-memory</id>
    <updated>2026-06-26T00:00:00.000Z</updated>
    <published>2026-06-26T00:00:00.000Z</published>
    <summary>Every LLM request is two workloads with opposite appetites running on one chip. In 2025 the industry quietly stopped sharing the silicon. Here is the architecture, the economics, and the threshold where it pays.</summary>
    <category term="LLM Inference" />
    <category term="GPU Architecture" />
    <category term="Platform Engineering" />
    <category term="Systems Design" />
    <category term="Performance Optimization" />
  </entry>
  <entry>
    <title>The Data Plane Is the New Perimeter</title>
    <link href="https://subhanshumg.com/blogs/the-data-plane-is-the-new-perimeter" />
    <id>https://subhanshumg.com/blogs/the-data-plane-is-the-new-perimeter</id>
    <updated>2026-06-08T00:00:00.000Z</updated>
    <published>2026-06-08T00:00:00.000Z</published>
    <summary>A reference architecture for AI-native data security: making security a property of the platform, not a feature of the app.</summary>
    <category term="Security" />
    <category term="AI Infrastructure" />
    <category term="Platform Engineering" />
  </entry>
  <entry>
    <title>Trust the Silicon. They Said.</title>
    <link href="https://blogs.subhanshumg.com/teefail-broke-confidential-compute" />
    <id>https://blogs.subhanshumg.com/teefail-broke-confidential-compute</id>
    <updated>2026-05-24T22:34:35.416Z</updated>
    <published>2026-05-24T22:34:35.416Z</published>
    <summary>TEE.Fail did not kill confidential compute. It narrowed it. The threat model that excluded physical access stayed safe; the threat model that included it did not. Slatewatch Cyber rebuilt its workload</summary>
    <category term="GPU" />
    <category term="Environment" />
    <category term="#execution" />
    <category term="SGX" />
    <category term="Devops" />
    <category term="sev-snp" />
    <category term="gpu tee" />
    <category term="google cloud" />
    <category term="software development" />
    <category term="Security" />
    <category term="spire" />
    <category term="Machine Learning" />
  </entry>
  <entry>
    <title>The EU CRA countdown</title>
    <link href="https://blogs.subhanshumg.com/the-eu-cra-countdown" />
    <id>https://blogs.subhanshumg.com/the-eu-cra-countdown</id>
    <updated>2026-05-20T08:37:36.830Z</updated>
    <published>2026-05-20T08:37:36.830Z</published>
    <summary>Every product with digital elements sold in the EU after December 2027 must carry a CE conformity assessment.
That is the EU CRA. The scope is broader than GDPR. The documentation trail is non-trivial</summary>
    <category term="Regulations" />
    <category term="DevSecOps" />
    <category term="Devops" />
    <category term="conformity" />
    <category term="Security" />
    <category term="engineering" />
    <category term="technology" />
    <category term="EU CRA" />
    <category term="CEMarking" />
    <category term="countdown" />
  </entry>
  <entry>
    <title>Crypto inventory: the platform workstream nobody scoped</title>
    <link href="https://blogs.subhanshumg.com/crypto-inventory-the-platform-workstream-nobody-scoped" />
    <id>https://blogs.subhanshumg.com/crypto-inventory-the-platform-workstream-nobody-scoped</id>
    <updated>2026-05-15T09:06:52.737Z</updated>
    <published>2026-05-15T09:06:52.737Z</published>
    <summary>Ironway Materials ran a crypto audit in 2024 and shipped two years of new TLS code on top of it. The 2026 audit found seventeen new libraries, three of them in the hot path, all of them invisible to t</summary>
    <category term="crypto" />
    <category term="PQC" />
    <category term="Platform Engineering " />
    <category term="Devops" />
    <category term="supply chain" />
    <category term="idp" />
    <category term="falcon" />
    <category term="spire" />
    <category term="#sigstore" />
    <category term="AWS" />
    <category term="GCP" />
    <category term="Azure" />
    <category term="Security" />
  </entry>
  <entry>
    <title>The agentic SOC is here</title>
    <link href="https://blogs.subhanshumg.com/the-agentic-soc-is-here" />
    <id>https://blogs.subhanshumg.com/the-agentic-soc-is-here</id>
    <updated>2026-05-11T10:38:26.907Z</updated>
    <published>2026-05-11T10:38:26.907Z</published>
    <summary>Three vendor agentic-SOC platforms in Q1 2026. One platform-engineering charter that decides whether they work.

Microsoft Sentinel AI shipped. Splunk Agentic SOC launched at RSAC. Google SecOps and T</summary>
    <category term="agentic-soc" />
    <category term="agentic AI" />
    <category term="AI" />
    <category term="SecOps" />
    <category term="Security" />
    <category term="Platform Engineering " />
    <category term="Devops" />
    <category term="DevSecOps" />
    <category term="SOC" />
    <category term="OpenTelemetry" />
    <category term="Open Source" />
    <category term="AWS" />
    <category term="Cloud" />
  </entry>
  <entry>
    <title>The distributed monolith tax</title>
    <link href="https://blogs.subhanshumg.com/the-distributed-monolith-tax" />
    <id>https://blogs.subhanshumg.com/the-distributed-monolith-tax</id>
    <updated>2026-05-06T03:17:08.047Z</updated>
    <published>2026-05-06T03:17:08.047Z</published>
    <summary>We collapsed 47 microservices to 8. Deploy time went up, latency went down, and on-call went silent. Here&apos;s what the microservices evangelists didn&apos;t tell you about Dunbar&apos;s number for services.




M</summary>
    <category term="DevSecOps" />
    <category term="System Design" />
    <category term="monolithic architecture" />
    <category term="Microservices" />
    <category term="architecture" />
    <category term="Devops" />
    <category term="Kubernetes" />
    <category term="AWS" />
    <category term="production" />
    <category term="ci-cd" />
    <category term="software development" />
    <category term="engineering" />
    <category term="leadership" />
  </entry>
  <entry>
    <title>Short-lived OIDC for CI: kill every long-lived GitHub Actions token</title>
    <link href="https://blogs.subhanshumg.com/short-lived-oidc" />
    <id>https://blogs.subhanshumg.com/short-lived-oidc</id>
    <updated>2026-05-03T05:31:09.663Z</updated>
    <published>2026-05-03T05:31:09.663Z</published>
    <summary>GitHub OIDC to AWS/GCP/Azure federated credentials killed the need for long-lived PATs in CI. Most orgs still have PATs in use in 2026. Short-lived OIDC is the one-day win.
Narrative arc
The PAT failu</summary>
    <category term="DevSecOps" />
    <category term="Devops" />
    <category term="identity-management" />
    <category term="OIDC" />
    <category term="GitHub" />
    <category term="CI/CD" />
    <category term="owasp" />
    <category term="Cloud Computing" />
    <category term="Security" />
    <category term="spire" />
    <category term="AWS" />
    <category term="GCP" />
    <category term="Artificial Intelligence" />
    <category term="AI" />
    <category term="full stack" />
    <category term="Azure" />
  </entry>
  <entry>
    <title>The 50ms lie: when edge AI actually matters (and when you&apos;re paying Cloudflare for marketing)</title>
    <link href="https://blogs.subhanshumg.com/the-50ms-lie" />
    <id>https://blogs.subhanshumg.com/the-50ms-lie</id>
    <updated>2026-04-20T17:25:57.196Z</updated>
    <published>2026-04-20T17:25:57.196Z</published>
    <summary>Cloudflare and Fly.io are selling 50ms of latency savings on a 5,000ms inference like it&apos;s a revolution. That&apos;s 1% of the total latency. You&apos;re optimizing the rounding error while paying a 10x penalty</summary>
    <category term="edgecomputing" />
    <category term="AI" />
    <category term="inference" />
    <category term="Cloud" />
    <category term="cloudflare" />
    <category term="workers" />
    <category term="Workers AI" />
    <category term="Devops" />
    <category term="Machine Learning" />
  </entry>
  <entry>
    <title>Stop building agents like prompts. Build them like state machines.</title>
    <link href="https://blogs.subhanshumg.com/stop-building-agents-like-prompts-build-them-like-state-machines" />
    <id>https://blogs.subhanshumg.com/stop-building-agents-like-prompts-build-them-like-state-machines</id>
    <updated>2026-04-19T09:48:30.850Z</updated>
    <published>2026-04-19T09:48:30.850Z</published>
    <summary>Github repo: https://github.com/SubhanshuMG/agents-as-state-machines

The thesis in one paragraph
Stop calling them agents. They are state machines that invoke LLMs at certain transitions. The multi-a</summary>
    <category term="agentic AI" />
    <category term="agents" />
    <category term="state-machines" />
    <category term="temporal" />
    <category term="langgraph" />
    <category term="#llmops" />
    <category term="Devops" />
    <category term="Developer" />
    <category term="SRE" />
    <category term="System Design" />
  </entry>
  <entry>
    <title>How I Built ForgeKit: An Open-Source Engineering Acceleration Platform That Scaffolds Production-Ready Projects in Under 60 Seconds</title>
    <link href="https://blogs.subhanshumg.com/forgekit" />
    <id>https://blogs.subhanshumg.com/forgekit</id>
    <updated>2026-03-24T16:30:51.167Z</updated>
    <published>2026-03-24T16:30:51.167Z</published>
    <summary>https://github.com/SubhanshuMG/ForgeKit


The Problem Nobody Talks About Honestly
It is 9 AM on a Monday. Your team just got greenlit on a new microservice. You spin up a fresh repo and then spend the</summary>
    <category term="Open Source" />
    <category term="cli" />
    <category term="devtools" />
    <category term="TypeScript" />
    <category term="Web Development" />
    <category term="serverless" />
    <category term="AWS" />
    <category term="Devops" />
    <category term="General Programming" />
    <category term="JavaScript" />
    <category term="Python" />
    <category term="vite" />
  </entry>
  <entry>
    <title>Building a Deployment Health Validator</title>
    <link href="https://blogs.subhanshumg.com/building-a-deployment-health-validator" />
    <id>https://blogs.subhanshumg.com/building-a-deployment-health-validator</id>
    <updated>2026-03-10T19:52:12.677Z</updated>
    <published>2026-03-10T19:52:12.677Z</published>
    <summary>A deep-dive into microservice health checking, topological startup ordering and why HTTP 200 does not mean a service is healthy.

The Incident
Picture this: your on-call rotation fires a PagerDuty ale</summary>
    <category term="Devops" />
    <category term="Platform Engineering " />
    <category term="Python" />
    <category term="Microservices" />
    <category term="Security" />
  </entry>
  <entry>
    <title>Platform Engineering at the Edge</title>
    <link href="https://blogs.subhanshumg.com/platform-engineering-at-the-edge" />
    <id>https://blogs.subhanshumg.com/platform-engineering-at-the-edge</id>
    <updated>2026-03-03T10:30:39.873Z</updated>
    <published>2026-03-03T10:30:39.873Z</published>
    <summary>No Internal Developer Platform today supports disconnected edge environments. Backstage, Port, and Cortex all assume always-on cloud connectivity, yet organizations like GE HealthCare (100+ hospital-e</summary>
    <category term="Platform Engineering " />
    <category term="Kubernetes" />
    <category term="Devops" />
    <category term="Security" />
    <category term="edgecomputing" />
    <category term="gitops" />
  </entry>
  <entry>
    <title>Governing the Ungovernable: Building an EU AI Act Article 9 Compliance Framework for Agentic AI That Actually Works in Production</title>
    <link href="https://blogs.subhanshumg.com/governing-the-ungovernable" />
    <id>https://blogs.subhanshumg.com/governing-the-ungovernable</id>
    <updated>2026-02-28T07:04:29.354Z</updated>
    <published>2026-02-28T07:04:29.354Z</published>
    <summary>The EU AI Act&apos;s risk management requirements for high-risk AI systems are now on the clock. August 2, 2026 is the hard deadline for Annex III systems. But nobody has published a practical technical im</summary>
    <category term="euaiact" />
    <category term="agentic AI" />
    <category term="ai compliance certification" />
    <category term="DevSecOps" />
    <category term="llm" />
    <category term="Security" />
    <category term="AI" />
    <category term="Governance" />
    <category term="langgraph" />
    <category term="mlops" />
    <category term="generative ai" />
    <category term="#AIAct2026" />
    <category term="Article9" />
  </entry>
  <entry>
    <title>The 3AM Problem: Why On-Call Burnout Is a System Design Failure, Not a People Problem</title>
    <link href="https://blogs.subhanshumg.com/the-3am-problem-why-on-call-burnout-is-a-system-design-failure-not-a-people-problem" />
    <id>https://blogs.subhanshumg.com/the-3am-problem-why-on-call-burnout-is-a-system-design-failure-not-a-people-problem</id>
    <updated>2026-02-25T10:04:36.956Z</updated>
    <published>2026-02-25T10:04:36.956Z</published>
    <summary>The Human Story Behind the Pager
Meet Priya. Senior backend engineer with 5 years of experience, joined a fintech scale-up to build payment infrastructure. She is good at her job.
Then she went on-cal</summary>
    <category term="Devops" />
    <category term="SRE" />
    <category term="Kubernetes" />
    <category term="#AIOps" />
    <category term="backend" />
  </entry>
  <entry>
    <title>The $4.45M Mistake: How a Missing SBOM Requirement Let the XZ Utils Backdoor Slip Past Millions of Servers</title>
    <link href="https://blogs.subhanshumg.com/xz-utils-backdoor-sbom-supply-chain-security" />
    <id>https://blogs.subhanshumg.com/xz-utils-backdoor-sbom-supply-chain-security</id>
    <updated>2026-02-22T15:05:20.714Z</updated>
    <published>2026-02-22T15:05:20.714Z</published>
    <summary>The XZ Utils backdoor (CVE-2024-3094) nearly became the most devastating supply chain attack in history; a patient, three-year social engineering campaign that embedded a remote code execution backdoo</summary>
    <category term="supply chain" />
    <category term="Security" />
    <category term="DevSecOps" />
    <category term="sbom" />
    <category term="Kubernetes" />
    <category term="Platform Engineering " />
    <category term="Open Source" />
    <category term="cybersecurity" />
    <category term="GitHub" />
    <category term="github-actions" />
    <category term="CVE" />
    <category term="internal developer platforms" />
  </entry>
  <entry>
    <title>The Global Cloud Blackout</title>
    <link href="https://blogs.subhanshumg.com/the-global-cloud-blackout" />
    <id>https://blogs.subhanshumg.com/the-global-cloud-blackout</id>
    <updated>2026-02-17T13:51:01.278Z</updated>
    <published>2026-02-17T13:51:01.278Z</published>
    <summary>If AWS disappeared tomorrow, would your company survive?

Not degraded. Not slow. Gone.
Most &quot;highly available&quot; systems would collapse within hours. This isn&apos;t fear-mongering. It&apos;s an architectural re</summary>
    <category term="Cloud" />
    <category term="architecture" />
    <category term="Disaster recovery" />
    <category term="SRE" />
    <category term="Devops" />
    <category term="Terraform" />
    <category term="Chaos Engineering" />
    <category term="high availability" />
    <category term="System Design" />
    <category term="multi-cloud" />
    <category term="Kubernetes" />
  </entry>
  <entry>
    <title>How Attackers Bypass Your “Compliant” CI/CD Pipeline (And How to Redesign It)</title>
    <link href="https://blogs.subhanshumg.com/how-attackers-bypass-your-compliant-cicd-pipeline-and-how-to-redesign-it" />
    <id>https://blogs.subhanshumg.com/how-attackers-bypass-your-compliant-cicd-pipeline-and-how-to-redesign-it</id>
    <updated>2026-02-08T23:43:21.588Z</updated>
    <published>2026-02-08T23:43:21.588Z</published>
    <summary>Modern CI/CD pipelines are often treated as untouchable “trusted builds” – locked down by code review and best practices but that trust is a myth. A pipeline is a prime attack surface, containing ever</summary>
    <category term="Devops" />
    <category term="cybersecurity" />
    <category term="Cloud" />
    <category term="Security" />
    <category term="Platform Engineering " />
    <category term="supply chain" />
    <category term="cicd" />
    <category term="Kubernetes" />
    <category term="technology" />
    <category term="github-actions" />
  </entry>
  <entry>
    <title>The $0 Compliance Stack</title>
    <link href="https://blogs.subhanshumg.com/the-zero-dollar-compliance-stack" />
    <id>https://blogs.subhanshumg.com/the-zero-dollar-compliance-stack</id>
    <updated>2026-01-26T20:38:25.885Z</updated>
    <published>2026-01-26T20:38:25.885Z</published>
    <summary>The Lie We’re All Sold

“You need expensive GRC tools to pass enterprise audits.”

Reality:

Auditors don’t care about tools

They care about controls, traceability and evidence


Compliance ≠ Softwar</summary>
    <category term="Devops" />
    <category term="audit" />
    <category term="compliance " />
    <category term="ISO 27001" />
    <category term="PCI DSS" />
    <category term="Cloud" />
    <category term="Security" />
    <category term="System Design" />
  </entry>
  <entry>
    <title>Secrets are a Supply Chain</title>
    <link href="https://blogs.subhanshumg.com/secrets-are-a-supply-chain" />
    <id>https://blogs.subhanshumg.com/secrets-are-a-supply-chain</id>
    <updated>2026-01-23T14:32:43.990Z</updated>
    <published>2026-01-23T14:32:43.990Z</published>
    <summary>Everyone rotates secrets.
Very few design secret lifecycle risk and that gap is where breaches live.

Most organizations believe secret rotation equals security. It doesn’t.
Rotation is a maintenance </summary>
    <category term="cybersecurity" />
    <category term="Devops" />
    <category term="Security" />
    <category term="secrets" />
    <category term="Supply Chain Management" />
    <category term="architecture" />
    <category term="leadership" />
  </entry>
  <entry>
    <title>Designing an ISO-27001-Native CI/CD Pipeline on AWS</title>
    <link href="https://blogs.subhanshumg.com/iso-27001" />
    <id>https://blogs.subhanshumg.com/iso-27001</id>
    <updated>2026-01-21T08:20:08.740Z</updated>
    <published>2026-01-21T08:20:08.740Z</published>
    <summary>“We passed an ISO-27001 surveillance audit with zero Jira tickets, zero screenshots, and zero manual evidence.”

That line usually gets silence. Then disbelief. Then the real question:

“Okay… how?”

</summary>
    <category term="Devops" />
    <category term="audit" />
    <category term="ISO 27001" />
    <category term="compliance " />
    <category term="automation" />
    <category term="AWS" />
    <category term="ci-cd" />
    <category term="Security" />
  </entry>
  <entry>
    <title>Beyond the Kernel</title>
    <link href="https://blogs.subhanshumg.com/beyond-the-kernel" />
    <id>https://blogs.subhanshumg.com/beyond-the-kernel</id>
    <updated>2025-11-09T17:00:42.993Z</updated>
    <published>2025-11-09T17:00:42.993Z</published>
    <summary>Security no longer lives outside the system. It lives within the kernel.
In a world of microservices, containers, and ephemeral workloads, traditional observability tools see only what applications ex</summary>
    <category term="eBPF" />
    <category term="DevSecOps" />
    <category term="cloud native" />
    <category term="Kubernetes" />
    <category term="Security" />
    <category term="falco" />
    <category term="cilium" />
    <category term="AWS" />
    <category term="Linux" />
    <category term="Kernel" />
    <category term="monitoring" />
    <category term="observability" />
    <category term="zerotrust" />
  </entry>
  <entry>
    <title>DevSecOps for the Mind</title>
    <link href="https://blogs.subhanshumg.com/devsecops-for-the-mind" />
    <id>https://blogs.subhanshumg.com/devsecops-for-the-mind</id>
    <updated>2025-08-31T19:26:40.150Z</updated>
    <published>2025-08-31T19:26:40.150Z</published>
    <summary>Introduction
Developers build systems. DevSecOps engineers build secure, automated pipelines.But what happens when you apply the same principles to your own life and knowledge?
Over the last year, I’v</summary>
    <category term="DevSecOps" />
    <category term="cognitive" />
    <category term="Futureofwork" />
    <category term="KnowledgeManagement" />
    <category term="secondbrain" />
    <category term="pkm" />
    <category term="Artificial Intelligence" />
    <category term="collective thinking" />
    <category term="zerotrust" />
    <category term="Security" />
  </entry>
  <entry>
    <title>Deploying a Bitcoin Regtest Network with Docker and CI/CD Tools</title>
    <link href="https://blogs.subhanshumg.com/deploying-a-bitcoin-regtest-network-with-docker-and-cicd-tools" />
    <id>https://blogs.subhanshumg.com/deploying-a-bitcoin-regtest-network-with-docker-and-cicd-tools</id>
    <updated>2025-08-23T08:17:11.286Z</updated>
    <published>2025-08-23T08:17:11.286Z</published>
    <summary>Hands-on + R&amp;D guide.
We’ll stand up a private Bitcoin regtest network with two nodes, peer them, mine spendable coins and send/confirm transactions; wrapped in a clean repo with CI and an optional de</summary>
    <category term="Bitcoin" />
    <category term="Devops" />
    <category term="Docker" />
    <category term="Blockchain" />
    <category term="engineering" />
    <category term="SRE" />
    <category term="cicd" />
    <category term="observability" />
    <category term="Open Source" />
  </entry>
  <entry>
    <title>The Ultimate GitLab Import/Export Toolkit for Engineers</title>
    <link href="https://blogs.subhanshumg.com/gitlab-import-export-toolkit" />
    <id>https://blogs.subhanshumg.com/gitlab-import-export-toolkit</id>
    <updated>2025-07-30T21:30:09.997Z</updated>
    <published>2025-07-30T21:30:09.997Z</published>
    <summary>“I’m a DevOps engineer - if I’m doing it manually twice, I’m writing a script.”


A few weeks ago, I was handed a deceptively simple‑sounding task: spin up an entire playground environment, pipelines,</summary>
    <category term="Devops" />
    <category term="GitLab" />
    <category term="automation" />
    <category term="Scripting" />
    <category term="Python" />
    <category term="ci-cd" />
    <category term="migration" />
    <category term="Cloud" />
    <category term="Branching Strategies" />
    <category term="engineering" />
    <category term="vcs" />
    <category term="Open Source" />
  </entry>
  <entry>
    <title>Integrating RASP with CI/CD for Automated Vulnerability Response</title>
    <link href="https://blogs.subhanshumg.com/rasp-integration" />
    <id>https://blogs.subhanshumg.com/rasp-integration</id>
    <updated>2025-06-24T06:53:34.156Z</updated>
    <published>2025-06-24T06:53:34.156Z</published>
    <summary>Introduction
Runtime Application Self-Protection (RASP) embeds security within running applications and can report attacks in real-time. By integrating RASP into CI/CD pipelines, production threat int</summary>
    <category term="SelfHealingSecurity" />
    <category term="Devops" />
    <category term="cicd" />
    <category term="rasp" />
    <category term="Application Security" />
    <category term="runtime-security" />
    <category term="automation" />
    <category term="Security" />
    <category term="infosec" />
    <category term="ThreatDetection" />
  </entry>
  <entry>
    <title>Mastering Traefik as a Dynamic Reverse Proxy for Containerized Environments</title>
    <link href="https://blogs.subhanshumg.com/mastering-traefik-as-a-dynamic-reverse-proxy-for-containerized-environments" />
    <id>https://blogs.subhanshumg.com/mastering-traefik-as-a-dynamic-reverse-proxy-for-containerized-environments</id>
    <updated>2025-05-18T22:28:48.818Z</updated>
    <published>2025-05-18T22:28:48.818Z</published>
    <summary>Introduction
In modern microservices and containerized ecosystems, Traefik serves as a powerful reverse proxy, offering dynamic service discovery, advanced routing capabilities and automated SSL/TLS m</summary>
    <category term="Docker" />
    <category term="Traefik" />
    <category term="routing" />
    <category term="Security" />
    <category term="TLS" />
    <category term="scalability" />
    <category term="Cloud Computing" />
    <category term="proxy" />
    <category term="#IaC" />
    <category term="containerization" />
  </entry>
  <entry>
    <title>Building Agentic RAG Systems: DevSecOps Blueprint for Autonomous &amp; Secure AI</title>
    <link href="https://blogs.subhanshumg.com/building-agentic-rag-systems-devsecops-blueprint-for-autonomous-and-secure-ai" />
    <id>https://blogs.subhanshumg.com/building-agentic-rag-systems-devsecops-blueprint-for-autonomous-and-secure-ai</id>
    <updated>2025-04-22T23:39:23.505Z</updated>
    <published>2025-04-22T23:39:23.505Z</published>
    <summary>Introduction: Why Agentic RAG is the Next Frontier
Retrieval-Augmented Generation (RAG) revolutionized LLMs by grounding them in external data. But static, one-shot retrieval struggles with dynamic, m</summary>
    <category term="RAG " />
    <category term="agentic AI" />
    <category term="AI" />
    <category term="Security" />
    <category term="observability" />
    <category term="policy as code" />
    <category term="compliance " />
    <category term="Kubernetes" />
    <category term="DevSecOps" />
    <category term="cloud native" />
    <category term="mlops" />
  </entry>
  <entry>
    <title>End-to-End Cloud-Native Deployment</title>
    <link href="https://blogs.subhanshumg.com/end-to-end-cloud-native-deployment" />
    <id>https://blogs.subhanshumg.com/end-to-end-cloud-native-deployment</id>
    <updated>2025-04-15T21:22:03.456Z</updated>
    <published>2025-04-15T21:22:03.456Z</published>
    <summary>Introduction
This technical walkthrough demonstrates how to deploy a secure, scalable microservice on AWS using infrastructure-as-code (Terraform), containerization (Docker), and serverless computing </summary>
    <category term="AWS" />
    <category term="Terraform" />
    <category term="Docker" />
    <category term="ECS" />
    <category term="aws-fargate" />
    <category term="Devops" />
    <category term="serverless" />
    <category term="Security" />
    <category term="zerotrust" />
    <category term="scalability" />
    <category term="technology" />
    <category term="community" />
    <category term="innovation" />
  </entry>
  <entry>
    <title>Caching Conundrum: Is There Truly Just One Path to API Efficiency?</title>
    <link href="https://blogs.subhanshumg.com/caching-conundrum" />
    <id>https://blogs.subhanshumg.com/caching-conundrum</id>
    <updated>2025-04-14T16:21:15.463Z</updated>
    <published>2025-04-14T16:21:15.463Z</published>
    <summary>Caching involves storing duplicates of frequently accessed data at various points along the request-response path.
When a consumer seeks a resource like a YouTube video, the request traverses one or m</summary>
    <category term="api" />
    <category term="caching" />
    <category term="optimization" />
    <category term="Redis" />
    <category term="Devops" />
    <category term="performance" />
    <category term="System Design" />
    <category term="innovation" />
    <category term="scalability" />
    <category term="software development" />
  </entry>
  <entry>
    <title>Micro-Segmentation Strategies in DevSecOps</title>
    <link href="https://blogs.subhanshumg.com/micro-segmentation-strategies-in-devsecops" />
    <id>https://blogs.subhanshumg.com/micro-segmentation-strategies-in-devsecops</id>
    <updated>2025-03-23T14:42:10.126Z</updated>
    <published>2025-03-23T14:42:10.126Z</published>
    <summary>Introduction
Traditional perimeter security is no longer sufficient in today’s dynamic and threat-laden IT environments. Micro-segmentation: The process of dividing your network into granular zones en</summary>
    <category term="microsegmentation" />
    <category term="Kubernetes" />
    <category term="DevSecOps" />
    <category term="zerotrust" />
    <category term="cloudsecurity" />
    <category term="Security" />
    <category term="#infosec" />
    <category term="ci-cd" />
    <category term="architecture" />
  </entry>
  <entry>
    <title>Designing Scalable, Secure Systems w/ DevSecOps</title>
    <link href="https://blogs.subhanshumg.com/designing-scalable-secure-systems-w-devsecops" />
    <id>https://blogs.subhanshumg.com/designing-scalable-secure-systems-w-devsecops</id>
    <updated>2025-03-02T21:22:03.282Z</updated>
    <published>2025-03-02T21:22:03.282Z</published>
    <summary>In the fast-evolving landscape of modern application development, building scalable, high-performance systems demands more than just robust code it calls for a thoughtful blend of system design, opera</summary>
    <category term="DevSecOps" />
    <category term="System Design" />
    <category term="scalability" />
    <category term="Security" />
    <category term="Microservices" />
    <category term="concurrency" />
    <category term="multithreading" />
    <category term="cicd" />
    <category term="APIs" />
    <category term="performance" />
    <category term="infrastructure" />
    <category term="Cloud" />
    <category term="architecture" />
    <category term="AWS" />
    <category term="Kubernetes" />
  </entry>
  <entry>
    <title>Unikernel Containers</title>
    <link href="https://blogs.subhanshumg.com/unikernel-containers" />
    <id>https://blogs.subhanshumg.com/unikernel-containers</id>
    <updated>2025-01-28T11:39:40.716Z</updated>
    <published>2025-01-28T11:39:40.716Z</published>
    <summary>Introduction
In a rapidly evolving technological landscape, where agility and security are paramount, unikernel containers are emerging as a revolutionary force in DevSecOps. These ultra-lightweight c</summary>
    <category term="DevSecOps" />
    <category term="unikernel" />
    <category term="cicd" />
    <category term="containers" />
    <category term="innovation" />
    <category term="Security" />
    <category term="revolution" />
    <category term="technology" />
    <category term="operating system" />
    <category term="virtualization" />
    <category term="Linux" />
  </entry>
  <entry>
    <title>The Power of Rootless Docker Containers</title>
    <link href="https://blogs.subhanshumg.com/the-power-of-rootless-docker-containers" />
    <id>https://blogs.subhanshumg.com/the-power-of-rootless-docker-containers</id>
    <updated>2025-01-20T19:40:23.737Z</updated>
    <published>2025-01-20T19:40:23.737Z</published>
    <summary>In the rapidly evolving world of DevSecOps, ensuring secure deployments is more critical than ever. Enter Docker rootless containers, a groundbreaking solution designed to enhance container security b</summary>
    <category term="RootlessDocker" />
    <category term="DevSecOps" />
    <category term="Docker" />
    <category term="containersecurity" />
    <category term="#cybersecurity" />
    <category term="cloudsecurity" />
    <category term="compliance " />
    <category term="cicd" />
    <category term="Linux" />
    <category term="advanced" />
  </entry>
  <entry>
    <title>Container Networking Security with Traefik</title>
    <link href="https://blogs.subhanshumg.com/container-networking-security-with-traefik" />
    <id>https://blogs.subhanshumg.com/container-networking-security-with-traefik</id>
    <updated>2025-01-16T13:49:55.144Z</updated>
    <published>2025-01-16T13:49:55.144Z</published>
    <summary>Introduction
Container networking security is a cornerstone of modern microservices architecture. Tools like Traefik and Docker Compose simplify orchestration and networking, but implementing advanced</summary>
    <category term="Microservices" />
    <category term="cloud security" />
    <category term="Traefik" />
    <category term="Devops" />
    <category term="Portainer" />
    <category term="elk-stack" />
    <category term="Grafana" />
    <category term="#prometheus" />
    <category term="#multitenancy" />
    <category term="mTLS" />
    <category term="Docker compose" />
    <category term="containerization" />
    <category term="containers" />
  </entry>
  <entry>
    <title>Serverless 2.0: Hybrid Decentralized Frameworks for Stateless Compute</title>
    <link href="https://blogs.subhanshumg.com/serverless-20-hybrid-decentralized-frameworks-for-stateless-compute" />
    <id>https://blogs.subhanshumg.com/serverless-20-hybrid-decentralized-frameworks-for-stateless-compute</id>
    <updated>2025-01-02T10:40:14.040Z</updated>
    <published>2025-01-02T10:40:14.040Z</published>
    <summary>Introduction
In the age of cloud computing, serverless architectures have become synonymous with scalability, cost-efficiency, and operational simplicity. However, these advantages often come with a c</summary>
    <category term="serverless" />
    <category term="decentralization" />
    <category term="Devops" />
    <category term="Hybrid Cloud" />
    <category term="Blockchain" />
    <category term="StateLESS" />
    <category term="ipfs" />
    <category term="filecoin" />
    <category term="Smart Contracts" />
    <category term="innovation" />
    <category term="Resilience" />
    <category term="Cloud" />
    <category term="computing" />
    <category term="akash network " />
  </entry>
  <entry>
    <title>The Future of DevSecOps</title>
    <link href="https://blogs.subhanshumg.com/the-future-of-devsecops" />
    <id>https://blogs.subhanshumg.com/the-future-of-devsecops</id>
    <updated>2024-12-21T15:50:37.644Z</updated>
    <published>2024-12-21T15:50:37.644Z</published>
    <summary>In today’s hyper-connected world, building software often involves diverse, distributed teams collaborating across multiple organizations. Traditional DevSecOps pipelines rely on centralized tools and</summary>
    <category term="DevSecOps" />
    <category term="decentralization" />
    <category term="cicd" />
    <category term="AI" />
    <category term="Smart Contracts" />
    <category term="immutable" />
    <category term="infrastructure" />
    <category term="Security" />
    <category term="Trustless" />
    <category term="automation" />
    <category term="#cybersecurity" />
  </entry>
  <entry>
    <title>Streamlining Node Operator Docker Images with Automated Rolling Updates</title>
    <link href="https://blogs.subhanshumg.com/architecture-design-for-automated-rolling-updates-of-node-operator-docker-images" />
    <id>https://blogs.subhanshumg.com/architecture-design-for-automated-rolling-updates-of-node-operator-docker-images</id>
    <updated>2024-12-10T06:13:41.248Z</updated>
    <published>2024-12-10T06:13:41.248Z</published>
    <summary>Components

Docker Registry Monitoring:

Uses a webhook or polling mechanism to detect new releases of the bitscrunch:latest image.

Integrates with a CI/CD pipeline to automate the update process.

A</summary>
    <category term="Docker" />
    <category term="automation" />
    <category term="DevSecOps" />
    <category term="kafka" />
    <category term="architecture" />
    <category term="node" />
    <category term="Grafana Monitoring" />
    <category term="Kubernetes" />
  </entry>
  <entry>
    <title>Ensuring Inter-Agent Data Integrity in Multi-Node DevSecOps</title>
    <link href="https://blogs.subhanshumg.com/ensuring-inter-agent-data-integrity-in-multi-node-devsecops" />
    <id>https://blogs.subhanshumg.com/ensuring-inter-agent-data-integrity-in-multi-node-devsecops</id>
    <updated>2024-11-30T08:30:03.233Z</updated>
    <published>2024-11-30T08:30:03.233Z</published>
    <summary>Introduction
In modern DevSecOps environments, where distributed systems and multi-node architectures are prevalent, ensuring data integrity during inter-agent communication is crucial. Compromised da</summary>
    <category term="MultiNodeArchitecture" />
    <category term="SecuringData" />
    <category term="MITMPrevention" />
    <category term="Cryptography" />
    <category term="DevSecOps" />
    <category term="#cybersecurity" />
    <category term="Hashing" />
    <category term="TLS" />
    <category term="Resilience" />
    <category term="#dataintegrity" />
  </entry>
  <entry>
    <title>Federated Learning for Distributed MLOps Security</title>
    <link href="https://blogs.subhanshumg.com/federated-learning-for-distributed-mlops-security" />
    <id>https://blogs.subhanshumg.com/federated-learning-for-distributed-mlops-security</id>
    <updated>2024-11-17T00:52:04.027Z</updated>
    <published>2024-11-17T00:52:04.027Z</published>
    <summary>Introduction
As Machine Learning Operations (MLOps) scale across industries, safeguarding sensitive data while enabling distributed training becomes a significant challenge. Enter Federated Learning (</summary>
    <category term="pysyft" />
    <category term="smpc" />
    <category term="federated learning" />
    <category term="mlops" />
    <category term="distributed system" />
    <category term="Kubernetes" />
    <category term="#prometheus" />
    <category term="elk" />
    <category term="DevSecOps" />
    <category term="Datadog" />
    <category term="flower" />
    <category term="HPA" />
    <category term="Deep Learning" />
  </entry>
  <entry>
    <title>Accelerating Deployment Velocity: Reducing Build Times and Image Sizes in Kubernetes</title>
    <link href="https://blogs.subhanshumg.com/accelerating-deployment-velocity-reducing-build-times-and-image-sizes-in-kubernetes" />
    <id>https://blogs.subhanshumg.com/accelerating-deployment-velocity-reducing-build-times-and-image-sizes-in-kubernetes</id>
    <updated>2024-10-29T04:22:09.879Z</updated>
    <published>2024-10-29T04:22:09.879Z</published>
    <summary>Introduction
Welcome to the final part of my Kubernetes CI/CD optimization series!So far, we’ve covered the essentials of Kubernetes deployment, container image optimization, and strategies for speedi</summary>
    <category term="Kaniko" />
    <category term="Kubernetes" />
    <category term="optimization" />
    <category term="DevSecOps" />
    <category term="Devops" />
    <category term="Microservices" />
    <category term="Docker" />
    <category term="containerization" />
    <category term="Continuous Integration" />
    <category term="continuous deployment" />
    <category term="cloud native" />
    <category term="automation" />
    <category term="#IaC" />
    <category term="SRE" />
  </entry>
  <entry>
    <title>Securing Kubernetes Operations with Runtime Security Best Practices</title>
    <link href="https://blogs.subhanshumg.com/securing-kubernetes-operations-with-runtime-security-best-practices" />
    <id>https://blogs.subhanshumg.com/securing-kubernetes-operations-with-runtime-security-best-practices</id>
    <updated>2024-10-22T03:46:21.583Z</updated>
    <published>2024-10-22T03:46:21.583Z</published>
    <summary>Welcome to the 9th installment of my Kubernetes series wherw we’ll dive into advanced runtime security techniques for Kubernetes environments to detect anomalies, enforce strict container security pol</summary>
    <category term="Kubernetes" />
    <category term="#cybersecurity" />
    <category term="containerization" />
    <category term="Orchestration" />
    <category term="cloudsecurity" />
    <category term="falco" />
    <category term="sysdig" />
    <category term="aquasec" />
    <category term="cloudops" />
    <category term="DevSecOps" />
    <category term="runtime" />
    <category term="Security" />
  </entry>
  <entry>
    <title>Picking the Right Load Balancer for Your Kubernetes Environment</title>
    <link href="https://blogs.subhanshumg.com/picking-the-right-load-balancer-for-your-kubernetes-environment" />
    <id>https://blogs.subhanshumg.com/picking-the-right-load-balancer-for-your-kubernetes-environment</id>
    <updated>2024-10-17T16:50:08.461Z</updated>
    <published>2024-10-17T16:50:08.461Z</published>
    <summary>Introduction
As Kubernetes adoption skyrockets, managing traffic within and to your clusters becomes a critical aspect of ensuring availability, performance, and scalability. One of the most important</summary>
    <category term="Load Balancing" />
    <category term="nginx" />
    <category term="Devops" />
    <category term="SecOps" />
    <category term="ingress" />
    <category term="Traefik" />
    <category term="Microservices" />
    <category term="cloudnative" />
    <category term="AWS" />
    <category term="Kubernetes" />
    <category term="EKS" />
  </entry>
  <entry>
    <title>Designing an Effective Fallback Plan for Kubernetes Failures</title>
    <link href="https://blogs.subhanshumg.com/designing-an-effective-fallback-plan-for-kubernetes-failures" />
    <id>https://blogs.subhanshumg.com/designing-an-effective-fallback-plan-for-kubernetes-failures</id>
    <updated>2024-10-10T19:42:38.492Z</updated>
    <published>2024-10-10T19:42:38.492Z</published>
    <summary>Welcome to Part VII of my Kubernetes series, where we’ll explore the essential strategies for building a robust disaster recovery and fallback plan for your Kubernetes workloads. In this article we&apos;ll</summary>
    <category term="Disaster recovery" />
    <category term="Kubernetes" />
    <category term="Devops" />
    <category term="AWS" />
    <category term="dns" />
    <category term="failover" />
    <category term="velero" />
    <category term="Backup" />
    <category term="scalability" />
    <category term="multicloud" />
    <category term="replication" />
    <category term="route53" />
    <category term="kubefed" />
    <category term="Helm" />
  </entry>
  <entry>
    <title>Leveraging Caching, CDN, and Rate Limiting to Enhance Kubernetes Performance</title>
    <link href="https://blogs.subhanshumg.com/leveraging-caching-cdn-and-rate-limiting-to-enhance-kubernetes-performance" />
    <id>https://blogs.subhanshumg.com/leveraging-caching-cdn-and-rate-limiting-to-enhance-kubernetes-performance</id>
    <updated>2024-10-06T19:29:21.548Z</updated>
    <published>2024-10-06T19:29:21.548Z</published>
    <summary>Welcome to Part VI of my Kubernetes series! In this post, we’re diving deep into three powerful techniques: caching, Content Delivery Networks (CDNs), and rate limiting that can significantly boost th</summary>
    <category term="Kubernetes" />
    <category term="cloudflare" />
    <category term="ratelimit" />
    <category term="CDN" />
    <category term="caching" />
    <category term="performance" />
    <category term="Microservices" />
    <category term="Redis" />
    <category term="Devops" />
    <category term="cloudnative" />
    <category term="scalability" />
    <category term="SRE" />
    <category term="System Architecture" />
  </entry>
  <entry>
    <title>Understanding Composite SLA Calculations in Kubernetes Systems</title>
    <link href="https://blogs.subhanshumg.com/understanding-composite-sla-calculations-in-kubernetes-systems" />
    <id>https://blogs.subhanshumg.com/understanding-composite-sla-calculations-in-kubernetes-systems</id>
    <updated>2024-10-04T18:35:14.087Z</updated>
    <published>2024-10-04T18:35:14.087Z</published>
    <summary>Welcome to Part V of my Kubernetes series! In this installment, we’re going to explore the complex yet crucial process of calculating the Composite Service Level Agreement (SLA) for distributed applic</summary>
    <category term="sla" />
    <category term="sli" />
    <category term="Devops" />
    <category term="Kubernetes" />
    <category term="caching" />
    <category term="CDN" />
    <category term="distributed system" />
    <category term="Performance Optimization" />
    <category term="Microservices" />
    <category term="SRE" />
    <category term="ratelimit" />
    <category term="containerization" />
  </entry>
  <entry>
    <title>Ensuring PCI-DSS, POPI, GDPR, and HIPAA Compliance in Kubernetes Systems</title>
    <link href="https://blogs.subhanshumg.com/ensuring-pci-dss-popi-gdpr-and-hipaa-compliance-in-kubernetes-systems" />
    <id>https://blogs.subhanshumg.com/ensuring-pci-dss-popi-gdpr-and-hipaa-compliance-in-kubernetes-systems</id>
    <updated>2024-10-02T15:52:18.813Z</updated>
    <published>2024-10-02T15:52:18.813Z</published>
    <summary>Introduction
Welcome to Part IV of my Kubernetes series, where we delve into building compliant systems on Kubernetes to meet stringent regulatory standards such as PCI-DSS, POPI, GDPR, and HIPAA. As </summary>
    <category term="pcidss" />
    <category term="HIPAA" />
    <category term="rbac" />
    <category term="#istio" />
    <category term="Kubernetes" />
    <category term="compliance " />
    <category term="#gdpr" />
    <category term="openpolicyagent" />
    <category term="DevSecOps" />
    <category term="cloud native" />
    <category term="#cybersecurity" />
    <category term="#DataProtection" />
  </entry>
  <entry>
    <title>Optimizing Costs for Cloud Architectures with Kubernetes Workloads</title>
    <link href="https://blogs.subhanshumg.com/optimizing-costs-for-cloud-architectures-with-kubernetes-workloads" />
    <id>https://blogs.subhanshumg.com/optimizing-costs-for-cloud-architectures-with-kubernetes-workloads</id>
    <updated>2024-09-30T17:05:40.875Z</updated>
    <published>2024-09-30T17:05:40.875Z</published>
    <summary>In this III part of my Kubernetes series, we will dive deep into Cost Estimation for Cloud Architectures, focusing on practical strategies for managing the cost of running Kubernetes workloads in clou</summary>
    <category term="Devops" />
    <category term="Kubernetes" />
    <category term="#prometheus" />
    <category term="Grafana" />
    <category term="Cloud Computing" />
    <category term="savings" />
    <category term="finops" />
    <category term="HPA" />
    <category term="Microservices" />
    <category term="Kubecost" />
    <category term="AWS" />
    <category term="Azure" />
    <category term="GCP" />
    <category term="autoscaling" />
    <category term="technology" />
  </entry>
  <entry>
    <title>Tweaking Kubernetes Deployments for Enhanced Backward Compatibility</title>
    <link href="https://blogs.subhanshumg.com/tweaking-kubernetes-deployments-for-enhanced-backward-compatibility" />
    <id>https://blogs.subhanshumg.com/tweaking-kubernetes-deployments-for-enhanced-backward-compatibility</id>
    <updated>2024-09-29T15:46:28.195Z</updated>
    <published>2024-09-29T15:46:28.195Z</published>
    <summary>Welcome to Part II of my Kubernetes series, where we explore how to Master Kubernetes Deployments for Seamless Backward Compatibility. Managing Kubernetes upgrades can be tricky, especially when you n</summary>
    <category term="Canary deployment" />
    <category term="Devops" />
    <category term="cloudnative" />
    <category term="containerization" />
    <category term="Microservices" />
    <category term="Blue/Green deployment" />
    <category term="APIs" />
    <category term="backward compatibility" />
    <category term="Kubernetes" />
    <category term="Security" />
  </entry>
</feed>
