{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "Subhanshu Mohan Gupta",
  "home_page_url": "https://subhanshumg.com/blogs",
  "feed_url": "https://subhanshumg.com/feed.json",
  "description": "DevSecOps, platform engineering and cloud security. Long-form essays on the infrastructure that survives production.",
  "language": "en",
  "authors": [
    {
      "name": "Subhanshu Mohan Gupta",
      "url": "https://subhanshumg.com"
    }
  ],
  "items": [
    {
      "id": "https://blogs.subhanshumg.com/your-rate-limiter-was-designed-for-humans",
      "url": "https://blogs.subhanshumg.com/your-rate-limiter-was-designed-for-humans",
      "title": "Your rate limiter was designed for humans",
      "summary": "Agent traffic does not get tired. Four layers of your stack assume it does.",
      "date_published": "2026-08-24T21:26:10.000Z",
      "tags": [
        "Devops",
        "api",
        "Security",
        "System Design",
        "AI",
        "Platform Engineering",
        "Cloud Computing"
      ]
    },
    {
      "id": "https://subhanshumg.com/blogs/prefill-is-compute-decode-is-memory",
      "url": "https://subhanshumg.com/blogs/prefill-is-compute-decode-is-memory",
      "title": "Prefill Is Compute, Decode Is Memory: The Architecture Shift Nobody Budgeted For",
      "summary": "Every LLM request is two workloads with opposite appetites running on one chip. In 2025 the industry quietly stopped sharing the silicon. Here is the architecture, the economics, and the threshold where it pays.",
      "date_published": "2026-06-26T00:00:00.000Z",
      "tags": [
        "LLM Inference",
        "GPU Architecture",
        "Platform Engineering",
        "Systems Design",
        "Performance Optimization"
      ]
    },
    {
      "id": "https://subhanshumg.com/blogs/the-data-plane-is-the-new-perimeter",
      "url": "https://subhanshumg.com/blogs/the-data-plane-is-the-new-perimeter",
      "title": "The Data Plane Is the New Perimeter",
      "summary": "A reference architecture for AI-native data security: making security a property of the platform, not a feature of the app.",
      "date_published": "2026-06-08T00:00:00.000Z",
      "tags": [
        "Security",
        "AI Infrastructure",
        "Platform Engineering"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/teefail-broke-confidential-compute",
      "url": "https://blogs.subhanshumg.com/teefail-broke-confidential-compute",
      "title": "Trust the Silicon. They Said.",
      "summary": "TEE.Fail did not kill confidential compute. It narrowed it. The threat model that excluded physical access stayed safe; the threat model that included it did not. Slatewatch Cyber rebuilt its workload",
      "date_published": "2026-05-24T22:34:35.416Z",
      "tags": [
        "GPU",
        "Environment",
        "#execution",
        "SGX",
        "Devops",
        "sev-snp",
        "gpu tee",
        "google cloud",
        "software development",
        "Security",
        "spire",
        "Machine Learning"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-eu-cra-countdown",
      "url": "https://blogs.subhanshumg.com/the-eu-cra-countdown",
      "title": "The EU CRA countdown",
      "summary": "Every product with digital elements sold in the EU after December 2027 must carry a CE conformity assessment.\nThat is the EU CRA. The scope is broader than GDPR. The documentation trail is non-trivial",
      "date_published": "2026-05-20T08:37:36.830Z",
      "tags": [
        "Regulations",
        "DevSecOps",
        "Devops",
        "conformity",
        "Security",
        "engineering",
        "technology",
        "EU CRA",
        "CEMarking",
        "countdown"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/crypto-inventory-the-platform-workstream-nobody-scoped",
      "url": "https://blogs.subhanshumg.com/crypto-inventory-the-platform-workstream-nobody-scoped",
      "title": "Crypto inventory: the platform workstream nobody scoped",
      "summary": "Ironway Materials ran a crypto audit in 2024 and shipped two years of new TLS code on top of it. The 2026 audit found seventeen new libraries, three of them in the hot path, all of them invisible to t",
      "date_published": "2026-05-15T09:06:52.737Z",
      "tags": [
        "crypto",
        "PQC",
        "Platform Engineering ",
        "Devops",
        "supply chain",
        "idp",
        "falcon",
        "spire",
        "#sigstore",
        "AWS",
        "GCP",
        "Azure",
        "Security"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-agentic-soc-is-here",
      "url": "https://blogs.subhanshumg.com/the-agentic-soc-is-here",
      "title": "The agentic SOC is here",
      "summary": "Three vendor agentic-SOC platforms in Q1 2026. One platform-engineering charter that decides whether they work.\n\nMicrosoft Sentinel AI shipped. Splunk Agentic SOC launched at RSAC. Google SecOps and T",
      "date_published": "2026-05-11T10:38:26.907Z",
      "tags": [
        "agentic-soc",
        "agentic AI",
        "AI",
        "SecOps",
        "Security",
        "Platform Engineering ",
        "Devops",
        "DevSecOps",
        "SOC",
        "OpenTelemetry",
        "Open Source",
        "AWS",
        "Cloud"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-distributed-monolith-tax",
      "url": "https://blogs.subhanshumg.com/the-distributed-monolith-tax",
      "title": "The distributed monolith tax",
      "summary": "We collapsed 47 microservices to 8. Deploy time went up, latency went down, and on-call went silent. Here's what the microservices evangelists didn't tell you about Dunbar's number for services.\n\n\n\n\nM",
      "date_published": "2026-05-06T03:17:08.047Z",
      "tags": [
        "DevSecOps",
        "System Design",
        "monolithic architecture",
        "Microservices",
        "architecture",
        "Devops",
        "Kubernetes",
        "AWS",
        "production",
        "ci-cd",
        "software development",
        "engineering",
        "leadership"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/short-lived-oidc",
      "url": "https://blogs.subhanshumg.com/short-lived-oidc",
      "title": "Short-lived OIDC for CI: kill every long-lived GitHub Actions token",
      "summary": "GitHub OIDC to AWS/GCP/Azure federated credentials killed the need for long-lived PATs in CI. Most orgs still have PATs in use in 2026. Short-lived OIDC is the one-day win.\nNarrative arc\nThe PAT failu",
      "date_published": "2026-05-03T05:31:09.663Z",
      "tags": [
        "DevSecOps",
        "Devops",
        "identity-management",
        "OIDC",
        "GitHub",
        "CI/CD",
        "owasp",
        "Cloud Computing",
        "Security",
        "spire",
        "AWS",
        "GCP",
        "Artificial Intelligence",
        "AI",
        "full stack",
        "Azure"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-50ms-lie",
      "url": "https://blogs.subhanshumg.com/the-50ms-lie",
      "title": "The 50ms lie: when edge AI actually matters (and when you're paying Cloudflare for marketing)",
      "summary": "Cloudflare and Fly.io are selling 50ms of latency savings on a 5,000ms inference like it's a revolution. That's 1% of the total latency. You're optimizing the rounding error while paying a 10x penalty",
      "date_published": "2026-04-20T17:25:57.196Z",
      "tags": [
        "edgecomputing",
        "AI",
        "inference",
        "Cloud",
        "cloudflare",
        "workers",
        "Workers AI",
        "Devops",
        "Machine Learning"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/stop-building-agents-like-prompts-build-them-like-state-machines",
      "url": "https://blogs.subhanshumg.com/stop-building-agents-like-prompts-build-them-like-state-machines",
      "title": "Stop building agents like prompts. Build them like state machines.",
      "summary": "Github repo: https://github.com/SubhanshuMG/agents-as-state-machines\n\nThe thesis in one paragraph\nStop calling them agents. They are state machines that invoke LLMs at certain transitions. The multi-a",
      "date_published": "2026-04-19T09:48:30.850Z",
      "tags": [
        "agentic AI",
        "agents",
        "state-machines",
        "temporal",
        "langgraph",
        "#llmops",
        "Devops",
        "Developer",
        "SRE",
        "System Design"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/forgekit",
      "url": "https://blogs.subhanshumg.com/forgekit",
      "title": "How I Built ForgeKit: An Open-Source Engineering Acceleration Platform That Scaffolds Production-Ready Projects in Under 60 Seconds",
      "summary": "https://github.com/SubhanshuMG/ForgeKit\n\n\nThe Problem Nobody Talks About Honestly\nIt is 9 AM on a Monday. Your team just got greenlit on a new microservice. You spin up a fresh repo and then spend the",
      "date_published": "2026-03-24T16:30:51.167Z",
      "tags": [
        "Open Source",
        "cli",
        "devtools",
        "TypeScript",
        "Web Development",
        "serverless",
        "AWS",
        "Devops",
        "General Programming",
        "JavaScript",
        "Python",
        "vite"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/building-a-deployment-health-validator",
      "url": "https://blogs.subhanshumg.com/building-a-deployment-health-validator",
      "title": "Building a Deployment Health Validator",
      "summary": "A deep-dive into microservice health checking, topological startup ordering and why HTTP 200 does not mean a service is healthy.\n\nThe Incident\nPicture this: your on-call rotation fires a PagerDuty ale",
      "date_published": "2026-03-10T19:52:12.677Z",
      "tags": [
        "Devops",
        "Platform Engineering ",
        "Python",
        "Microservices",
        "Security"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/platform-engineering-at-the-edge",
      "url": "https://blogs.subhanshumg.com/platform-engineering-at-the-edge",
      "title": "Platform Engineering at the Edge",
      "summary": "No Internal Developer Platform today supports disconnected edge environments. Backstage, Port, and Cortex all assume always-on cloud connectivity, yet organizations like GE HealthCare (100+ hospital-e",
      "date_published": "2026-03-03T10:30:39.873Z",
      "tags": [
        "Platform Engineering ",
        "Kubernetes",
        "Devops",
        "Security",
        "edgecomputing",
        "gitops"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/governing-the-ungovernable",
      "url": "https://blogs.subhanshumg.com/governing-the-ungovernable",
      "title": "Governing the Ungovernable: Building an EU AI Act Article 9 Compliance Framework for Agentic AI That Actually Works in Production",
      "summary": "The EU AI Act's risk management requirements for high-risk AI systems are now on the clock. August 2, 2026 is the hard deadline for Annex III systems. But nobody has published a practical technical im",
      "date_published": "2026-02-28T07:04:29.354Z",
      "tags": [
        "euaiact",
        "agentic AI",
        "ai compliance certification",
        "DevSecOps",
        "llm",
        "Security",
        "AI",
        "Governance",
        "langgraph",
        "mlops",
        "generative ai",
        "#AIAct2026",
        "Article9"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-3am-problem-why-on-call-burnout-is-a-system-design-failure-not-a-people-problem",
      "url": "https://blogs.subhanshumg.com/the-3am-problem-why-on-call-burnout-is-a-system-design-failure-not-a-people-problem",
      "title": "The 3AM Problem: Why On-Call Burnout Is a System Design Failure, Not a People Problem",
      "summary": "The Human Story Behind the Pager\nMeet Priya. Senior backend engineer with 5 years of experience, joined a fintech scale-up to build payment infrastructure. She is good at her job.\nThen she went on-cal",
      "date_published": "2026-02-25T10:04:36.956Z",
      "tags": [
        "Devops",
        "SRE",
        "Kubernetes",
        "#AIOps",
        "backend"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/xz-utils-backdoor-sbom-supply-chain-security",
      "url": "https://blogs.subhanshumg.com/xz-utils-backdoor-sbom-supply-chain-security",
      "title": "The $4.45M Mistake: How a Missing SBOM Requirement Let the XZ Utils Backdoor Slip Past Millions of Servers",
      "summary": "The XZ Utils backdoor (CVE-2024-3094) nearly became the most devastating supply chain attack in history; a patient, three-year social engineering campaign that embedded a remote code execution backdoo",
      "date_published": "2026-02-22T15:05:20.714Z",
      "tags": [
        "supply chain",
        "Security",
        "DevSecOps",
        "sbom",
        "Kubernetes",
        "Platform Engineering ",
        "Open Source",
        "cybersecurity",
        "GitHub",
        "github-actions",
        "CVE",
        "internal developer platforms"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-global-cloud-blackout",
      "url": "https://blogs.subhanshumg.com/the-global-cloud-blackout",
      "title": "The Global Cloud Blackout",
      "summary": "If AWS disappeared tomorrow, would your company survive?\n\nNot degraded. Not slow. Gone.\nMost \"highly available\" systems would collapse within hours. This isn't fear-mongering. It's an architectural re",
      "date_published": "2026-02-17T13:51:01.278Z",
      "tags": [
        "Cloud",
        "architecture",
        "Disaster recovery",
        "SRE",
        "Devops",
        "Terraform",
        "Chaos Engineering",
        "high availability",
        "System Design",
        "multi-cloud",
        "Kubernetes"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/how-attackers-bypass-your-compliant-cicd-pipeline-and-how-to-redesign-it",
      "url": "https://blogs.subhanshumg.com/how-attackers-bypass-your-compliant-cicd-pipeline-and-how-to-redesign-it",
      "title": "How Attackers Bypass Your “Compliant” CI/CD Pipeline (And How to Redesign It)",
      "summary": "Modern CI/CD pipelines are often treated as untouchable “trusted builds” – locked down by code review and best practices but that trust is a myth. A pipeline is a prime attack surface, containing ever",
      "date_published": "2026-02-08T23:43:21.588Z",
      "tags": [
        "Devops",
        "cybersecurity",
        "Cloud",
        "Security",
        "Platform Engineering ",
        "supply chain",
        "cicd",
        "Kubernetes",
        "technology",
        "github-actions"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-zero-dollar-compliance-stack",
      "url": "https://blogs.subhanshumg.com/the-zero-dollar-compliance-stack",
      "title": "The $0 Compliance Stack",
      "summary": "The Lie We’re All Sold\n\n“You need expensive GRC tools to pass enterprise audits.”\n\nReality:\n\nAuditors don’t care about tools\n\nThey care about controls, traceability and evidence\n\n\nCompliance ≠ Softwar",
      "date_published": "2026-01-26T20:38:25.885Z",
      "tags": [
        "Devops",
        "audit",
        "compliance ",
        "ISO 27001",
        "PCI DSS",
        "Cloud",
        "Security",
        "System Design"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/secrets-are-a-supply-chain",
      "url": "https://blogs.subhanshumg.com/secrets-are-a-supply-chain",
      "title": "Secrets are a Supply Chain",
      "summary": "Everyone rotates secrets.\nVery few design secret lifecycle risk and that gap is where breaches live.\n\nMost organizations believe secret rotation equals security. It doesn’t.\nRotation is a maintenance ",
      "date_published": "2026-01-23T14:32:43.990Z",
      "tags": [
        "cybersecurity",
        "Devops",
        "Security",
        "secrets",
        "Supply Chain Management",
        "architecture",
        "leadership"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/iso-27001",
      "url": "https://blogs.subhanshumg.com/iso-27001",
      "title": "Designing an ISO-27001-Native CI/CD Pipeline on AWS",
      "summary": "“We passed an ISO-27001 surveillance audit with zero Jira tickets, zero screenshots, and zero manual evidence.”\n\nThat line usually gets silence. Then disbelief. Then the real question:\n\n“Okay… how?”\n\n",
      "date_published": "2026-01-21T08:20:08.740Z",
      "tags": [
        "Devops",
        "audit",
        "ISO 27001",
        "compliance ",
        "automation",
        "AWS",
        "ci-cd",
        "Security"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/beyond-the-kernel",
      "url": "https://blogs.subhanshumg.com/beyond-the-kernel",
      "title": "Beyond the Kernel",
      "summary": "Security no longer lives outside the system. It lives within the kernel.\nIn a world of microservices, containers, and ephemeral workloads, traditional observability tools see only what applications ex",
      "date_published": "2025-11-09T17:00:42.993Z",
      "tags": [
        "eBPF",
        "DevSecOps",
        "cloud native",
        "Kubernetes",
        "Security",
        "falco",
        "cilium",
        "AWS",
        "Linux",
        "Kernel",
        "monitoring",
        "observability",
        "zerotrust"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/devsecops-for-the-mind",
      "url": "https://blogs.subhanshumg.com/devsecops-for-the-mind",
      "title": "DevSecOps for the Mind",
      "summary": "Introduction\nDevelopers build systems. DevSecOps engineers build secure, automated pipelines.But what happens when you apply the same principles to your own life and knowledge?\nOver the last year, I’v",
      "date_published": "2025-08-31T19:26:40.150Z",
      "tags": [
        "DevSecOps",
        "cognitive",
        "Futureofwork",
        "KnowledgeManagement",
        "secondbrain",
        "pkm",
        "Artificial Intelligence",
        "collective thinking",
        "zerotrust",
        "Security"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/deploying-a-bitcoin-regtest-network-with-docker-and-cicd-tools",
      "url": "https://blogs.subhanshumg.com/deploying-a-bitcoin-regtest-network-with-docker-and-cicd-tools",
      "title": "Deploying a Bitcoin Regtest Network with Docker and CI/CD Tools",
      "summary": "Hands-on + R&D guide.\nWe’ll stand up a private Bitcoin regtest network with two nodes, peer them, mine spendable coins and send/confirm transactions; wrapped in a clean repo with CI and an optional de",
      "date_published": "2025-08-23T08:17:11.286Z",
      "tags": [
        "Bitcoin",
        "Devops",
        "Docker",
        "Blockchain",
        "engineering",
        "SRE",
        "cicd",
        "observability",
        "Open Source"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/gitlab-import-export-toolkit",
      "url": "https://blogs.subhanshumg.com/gitlab-import-export-toolkit",
      "title": "The Ultimate GitLab Import/Export Toolkit for Engineers",
      "summary": "“I’m a DevOps engineer - if I’m doing it manually twice, I’m writing a script.”\n\n\nA few weeks ago, I was handed a deceptively simple‑sounding task: spin up an entire playground environment, pipelines,",
      "date_published": "2025-07-30T21:30:09.997Z",
      "tags": [
        "Devops",
        "GitLab",
        "automation",
        "Scripting",
        "Python",
        "ci-cd",
        "migration",
        "Cloud",
        "Branching Strategies",
        "engineering",
        "vcs",
        "Open Source"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/rasp-integration",
      "url": "https://blogs.subhanshumg.com/rasp-integration",
      "title": "Integrating RASP with CI/CD for Automated Vulnerability Response",
      "summary": "Introduction\nRuntime Application Self-Protection (RASP) embeds security within running applications and can report attacks in real-time. By integrating RASP into CI/CD pipelines, production threat int",
      "date_published": "2025-06-24T06:53:34.156Z",
      "tags": [
        "SelfHealingSecurity",
        "Devops",
        "cicd",
        "rasp",
        "Application Security",
        "runtime-security",
        "automation",
        "Security",
        "infosec",
        "ThreatDetection"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/mastering-traefik-as-a-dynamic-reverse-proxy-for-containerized-environments",
      "url": "https://blogs.subhanshumg.com/mastering-traefik-as-a-dynamic-reverse-proxy-for-containerized-environments",
      "title": "Mastering Traefik as a Dynamic Reverse Proxy for Containerized Environments",
      "summary": "Introduction\nIn modern microservices and containerized ecosystems, Traefik serves as a powerful reverse proxy, offering dynamic service discovery, advanced routing capabilities and automated SSL/TLS m",
      "date_published": "2025-05-18T22:28:48.818Z",
      "tags": [
        "Docker",
        "Traefik",
        "routing",
        "Security",
        "TLS",
        "scalability",
        "Cloud Computing",
        "proxy",
        "#IaC",
        "containerization"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/building-agentic-rag-systems-devsecops-blueprint-for-autonomous-and-secure-ai",
      "url": "https://blogs.subhanshumg.com/building-agentic-rag-systems-devsecops-blueprint-for-autonomous-and-secure-ai",
      "title": "Building Agentic RAG Systems: DevSecOps Blueprint for Autonomous & Secure AI",
      "summary": "Introduction: Why Agentic RAG is the Next Frontier\nRetrieval-Augmented Generation (RAG) revolutionized LLMs by grounding them in external data. But static, one-shot retrieval struggles with dynamic, m",
      "date_published": "2025-04-22T23:39:23.505Z",
      "tags": [
        "RAG ",
        "agentic AI",
        "AI",
        "Security",
        "observability",
        "policy as code",
        "compliance ",
        "Kubernetes",
        "DevSecOps",
        "cloud native",
        "mlops"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/end-to-end-cloud-native-deployment",
      "url": "https://blogs.subhanshumg.com/end-to-end-cloud-native-deployment",
      "title": "End-to-End Cloud-Native Deployment",
      "summary": "Introduction\nThis technical walkthrough demonstrates how to deploy a secure, scalable microservice on AWS using infrastructure-as-code (Terraform), containerization (Docker), and serverless computing ",
      "date_published": "2025-04-15T21:22:03.456Z",
      "tags": [
        "AWS",
        "Terraform",
        "Docker",
        "ECS",
        "aws-fargate",
        "Devops",
        "serverless",
        "Security",
        "zerotrust",
        "scalability",
        "technology",
        "community",
        "innovation"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/caching-conundrum",
      "url": "https://blogs.subhanshumg.com/caching-conundrum",
      "title": "Caching Conundrum: Is There Truly Just One Path to API Efficiency?",
      "summary": "Caching involves storing duplicates of frequently accessed data at various points along the request-response path.\nWhen a consumer seeks a resource like a YouTube video, the request traverses one or m",
      "date_published": "2025-04-14T16:21:15.463Z",
      "tags": [
        "api",
        "caching",
        "optimization",
        "Redis",
        "Devops",
        "performance",
        "System Design",
        "innovation",
        "scalability",
        "software development"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/micro-segmentation-strategies-in-devsecops",
      "url": "https://blogs.subhanshumg.com/micro-segmentation-strategies-in-devsecops",
      "title": "Micro-Segmentation Strategies in DevSecOps",
      "summary": "Introduction\nTraditional perimeter security is no longer sufficient in today’s dynamic and threat-laden IT environments. Micro-segmentation: The process of dividing your network into granular zones en",
      "date_published": "2025-03-23T14:42:10.126Z",
      "tags": [
        "microsegmentation",
        "Kubernetes",
        "DevSecOps",
        "zerotrust",
        "cloudsecurity",
        "Security",
        "#infosec",
        "ci-cd",
        "architecture"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/designing-scalable-secure-systems-w-devsecops",
      "url": "https://blogs.subhanshumg.com/designing-scalable-secure-systems-w-devsecops",
      "title": "Designing Scalable, Secure Systems w/ DevSecOps",
      "summary": "In the fast-evolving landscape of modern application development, building scalable, high-performance systems demands more than just robust code it calls for a thoughtful blend of system design, opera",
      "date_published": "2025-03-02T21:22:03.282Z",
      "tags": [
        "DevSecOps",
        "System Design",
        "scalability",
        "Security",
        "Microservices",
        "concurrency",
        "multithreading",
        "cicd",
        "APIs",
        "performance",
        "infrastructure",
        "Cloud",
        "architecture",
        "AWS",
        "Kubernetes"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/unikernel-containers",
      "url": "https://blogs.subhanshumg.com/unikernel-containers",
      "title": "Unikernel Containers",
      "summary": "Introduction\nIn a rapidly evolving technological landscape, where agility and security are paramount, unikernel containers are emerging as a revolutionary force in DevSecOps. These ultra-lightweight c",
      "date_published": "2025-01-28T11:39:40.716Z",
      "tags": [
        "DevSecOps",
        "unikernel",
        "cicd",
        "containers",
        "innovation",
        "Security",
        "revolution",
        "technology",
        "operating system",
        "virtualization",
        "Linux"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-power-of-rootless-docker-containers",
      "url": "https://blogs.subhanshumg.com/the-power-of-rootless-docker-containers",
      "title": "The Power of Rootless Docker Containers",
      "summary": "In the rapidly evolving world of DevSecOps, ensuring secure deployments is more critical than ever. Enter Docker rootless containers, a groundbreaking solution designed to enhance container security b",
      "date_published": "2025-01-20T19:40:23.737Z",
      "tags": [
        "RootlessDocker",
        "DevSecOps",
        "Docker",
        "containersecurity",
        "#cybersecurity",
        "cloudsecurity",
        "compliance ",
        "cicd",
        "Linux",
        "advanced"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/container-networking-security-with-traefik",
      "url": "https://blogs.subhanshumg.com/container-networking-security-with-traefik",
      "title": "Container Networking Security with Traefik",
      "summary": "Introduction\nContainer networking security is a cornerstone of modern microservices architecture. Tools like Traefik and Docker Compose simplify orchestration and networking, but implementing advanced",
      "date_published": "2025-01-16T13:49:55.144Z",
      "tags": [
        "Microservices",
        "cloud security",
        "Traefik",
        "Devops",
        "Portainer",
        "elk-stack",
        "Grafana",
        "#prometheus",
        "#multitenancy",
        "mTLS",
        "Docker compose",
        "containerization",
        "containers"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/serverless-20-hybrid-decentralized-frameworks-for-stateless-compute",
      "url": "https://blogs.subhanshumg.com/serverless-20-hybrid-decentralized-frameworks-for-stateless-compute",
      "title": "Serverless 2.0: Hybrid Decentralized Frameworks for Stateless Compute",
      "summary": "Introduction\nIn the age of cloud computing, serverless architectures have become synonymous with scalability, cost-efficiency, and operational simplicity. However, these advantages often come with a c",
      "date_published": "2025-01-02T10:40:14.040Z",
      "tags": [
        "serverless",
        "decentralization",
        "Devops",
        "Hybrid Cloud",
        "Blockchain",
        "StateLESS",
        "ipfs",
        "filecoin",
        "Smart Contracts",
        "innovation",
        "Resilience",
        "Cloud",
        "computing",
        "akash network "
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/the-future-of-devsecops",
      "url": "https://blogs.subhanshumg.com/the-future-of-devsecops",
      "title": "The Future of DevSecOps",
      "summary": "In today’s hyper-connected world, building software often involves diverse, distributed teams collaborating across multiple organizations. Traditional DevSecOps pipelines rely on centralized tools and",
      "date_published": "2024-12-21T15:50:37.644Z",
      "tags": [
        "DevSecOps",
        "decentralization",
        "cicd",
        "AI",
        "Smart Contracts",
        "immutable",
        "infrastructure",
        "Security",
        "Trustless",
        "automation",
        "#cybersecurity"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/architecture-design-for-automated-rolling-updates-of-node-operator-docker-images",
      "url": "https://blogs.subhanshumg.com/architecture-design-for-automated-rolling-updates-of-node-operator-docker-images",
      "title": "Streamlining Node Operator Docker Images with Automated Rolling Updates",
      "summary": "Components\n\nDocker Registry Monitoring:\n\nUses a webhook or polling mechanism to detect new releases of the bitscrunch:latest image.\n\nIntegrates with a CI/CD pipeline to automate the update process.\n\nA",
      "date_published": "2024-12-10T06:13:41.248Z",
      "tags": [
        "Docker",
        "automation",
        "DevSecOps",
        "kafka",
        "architecture",
        "node",
        "Grafana Monitoring",
        "Kubernetes"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/ensuring-inter-agent-data-integrity-in-multi-node-devsecops",
      "url": "https://blogs.subhanshumg.com/ensuring-inter-agent-data-integrity-in-multi-node-devsecops",
      "title": "Ensuring Inter-Agent Data Integrity in Multi-Node DevSecOps",
      "summary": "Introduction\nIn modern DevSecOps environments, where distributed systems and multi-node architectures are prevalent, ensuring data integrity during inter-agent communication is crucial. Compromised da",
      "date_published": "2024-11-30T08:30:03.233Z",
      "tags": [
        "MultiNodeArchitecture",
        "SecuringData",
        "MITMPrevention",
        "Cryptography",
        "DevSecOps",
        "#cybersecurity",
        "Hashing",
        "TLS",
        "Resilience",
        "#dataintegrity"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/federated-learning-for-distributed-mlops-security",
      "url": "https://blogs.subhanshumg.com/federated-learning-for-distributed-mlops-security",
      "title": "Federated Learning for Distributed MLOps Security",
      "summary": "Introduction\nAs Machine Learning Operations (MLOps) scale across industries, safeguarding sensitive data while enabling distributed training becomes a significant challenge. Enter Federated Learning (",
      "date_published": "2024-11-17T00:52:04.027Z",
      "tags": [
        "pysyft",
        "smpc",
        "federated learning",
        "mlops",
        "distributed system",
        "Kubernetes",
        "#prometheus",
        "elk",
        "DevSecOps",
        "Datadog",
        "flower",
        "HPA",
        "Deep Learning"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/accelerating-deployment-velocity-reducing-build-times-and-image-sizes-in-kubernetes",
      "url": "https://blogs.subhanshumg.com/accelerating-deployment-velocity-reducing-build-times-and-image-sizes-in-kubernetes",
      "title": "Accelerating Deployment Velocity: Reducing Build Times and Image Sizes in Kubernetes",
      "summary": "Introduction\nWelcome to the final part of my Kubernetes CI/CD optimization series!So far, we’ve covered the essentials of Kubernetes deployment, container image optimization, and strategies for speedi",
      "date_published": "2024-10-29T04:22:09.879Z",
      "tags": [
        "Kaniko",
        "Kubernetes",
        "optimization",
        "DevSecOps",
        "Devops",
        "Microservices",
        "Docker",
        "containerization",
        "Continuous Integration",
        "continuous deployment",
        "cloud native",
        "automation",
        "#IaC",
        "SRE"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/securing-kubernetes-operations-with-runtime-security-best-practices",
      "url": "https://blogs.subhanshumg.com/securing-kubernetes-operations-with-runtime-security-best-practices",
      "title": "Securing Kubernetes Operations with Runtime Security Best Practices",
      "summary": "Welcome to the 9th installment of my Kubernetes series wherw we’ll dive into advanced runtime security techniques for Kubernetes environments to detect anomalies, enforce strict container security pol",
      "date_published": "2024-10-22T03:46:21.583Z",
      "tags": [
        "Kubernetes",
        "#cybersecurity",
        "containerization",
        "Orchestration",
        "cloudsecurity",
        "falco",
        "sysdig",
        "aquasec",
        "cloudops",
        "DevSecOps",
        "runtime",
        "Security"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/picking-the-right-load-balancer-for-your-kubernetes-environment",
      "url": "https://blogs.subhanshumg.com/picking-the-right-load-balancer-for-your-kubernetes-environment",
      "title": "Picking the Right Load Balancer for Your Kubernetes Environment",
      "summary": "Introduction\nAs Kubernetes adoption skyrockets, managing traffic within and to your clusters becomes a critical aspect of ensuring availability, performance, and scalability. One of the most important",
      "date_published": "2024-10-17T16:50:08.461Z",
      "tags": [
        "Load Balancing",
        "nginx",
        "Devops",
        "SecOps",
        "ingress",
        "Traefik",
        "Microservices",
        "cloudnative",
        "AWS",
        "Kubernetes",
        "EKS"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/designing-an-effective-fallback-plan-for-kubernetes-failures",
      "url": "https://blogs.subhanshumg.com/designing-an-effective-fallback-plan-for-kubernetes-failures",
      "title": "Designing an Effective Fallback Plan for Kubernetes Failures",
      "summary": "Welcome to Part VII of my Kubernetes series, where we’ll explore the essential strategies for building a robust disaster recovery and fallback plan for your Kubernetes workloads. In this article we'll",
      "date_published": "2024-10-10T19:42:38.492Z",
      "tags": [
        "Disaster recovery",
        "Kubernetes",
        "Devops",
        "AWS",
        "dns",
        "failover",
        "velero",
        "Backup",
        "scalability",
        "multicloud",
        "replication",
        "route53",
        "kubefed",
        "Helm"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/leveraging-caching-cdn-and-rate-limiting-to-enhance-kubernetes-performance",
      "url": "https://blogs.subhanshumg.com/leveraging-caching-cdn-and-rate-limiting-to-enhance-kubernetes-performance",
      "title": "Leveraging Caching, CDN, and Rate Limiting to Enhance Kubernetes Performance",
      "summary": "Welcome to Part VI of my Kubernetes series! In this post, we’re diving deep into three powerful techniques: caching, Content Delivery Networks (CDNs), and rate limiting that can significantly boost th",
      "date_published": "2024-10-06T19:29:21.548Z",
      "tags": [
        "Kubernetes",
        "cloudflare",
        "ratelimit",
        "CDN",
        "caching",
        "performance",
        "Microservices",
        "Redis",
        "Devops",
        "cloudnative",
        "scalability",
        "SRE",
        "System Architecture"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/understanding-composite-sla-calculations-in-kubernetes-systems",
      "url": "https://blogs.subhanshumg.com/understanding-composite-sla-calculations-in-kubernetes-systems",
      "title": "Understanding Composite SLA Calculations in Kubernetes Systems",
      "summary": "Welcome to Part V of my Kubernetes series! In this installment, we’re going to explore the complex yet crucial process of calculating the Composite Service Level Agreement (SLA) for distributed applic",
      "date_published": "2024-10-04T18:35:14.087Z",
      "tags": [
        "sla",
        "sli",
        "Devops",
        "Kubernetes",
        "caching",
        "CDN",
        "distributed system",
        "Performance Optimization",
        "Microservices",
        "SRE",
        "ratelimit",
        "containerization"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/ensuring-pci-dss-popi-gdpr-and-hipaa-compliance-in-kubernetes-systems",
      "url": "https://blogs.subhanshumg.com/ensuring-pci-dss-popi-gdpr-and-hipaa-compliance-in-kubernetes-systems",
      "title": "Ensuring PCI-DSS, POPI, GDPR, and HIPAA Compliance in Kubernetes Systems",
      "summary": "Introduction\nWelcome to Part IV of my Kubernetes series, where we delve into building compliant systems on Kubernetes to meet stringent regulatory standards such as PCI-DSS, POPI, GDPR, and HIPAA. As ",
      "date_published": "2024-10-02T15:52:18.813Z",
      "tags": [
        "pcidss",
        "HIPAA",
        "rbac",
        "#istio",
        "Kubernetes",
        "compliance ",
        "#gdpr",
        "openpolicyagent",
        "DevSecOps",
        "cloud native",
        "#cybersecurity",
        "#DataProtection"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/optimizing-costs-for-cloud-architectures-with-kubernetes-workloads",
      "url": "https://blogs.subhanshumg.com/optimizing-costs-for-cloud-architectures-with-kubernetes-workloads",
      "title": "Optimizing Costs for Cloud Architectures with Kubernetes Workloads",
      "summary": "In this III part of my Kubernetes series, we will dive deep into Cost Estimation for Cloud Architectures, focusing on practical strategies for managing the cost of running Kubernetes workloads in clou",
      "date_published": "2024-09-30T17:05:40.875Z",
      "tags": [
        "Devops",
        "Kubernetes",
        "#prometheus",
        "Grafana",
        "Cloud Computing",
        "savings",
        "finops",
        "HPA",
        "Microservices",
        "Kubecost",
        "AWS",
        "Azure",
        "GCP",
        "autoscaling",
        "technology"
      ]
    },
    {
      "id": "https://blogs.subhanshumg.com/tweaking-kubernetes-deployments-for-enhanced-backward-compatibility",
      "url": "https://blogs.subhanshumg.com/tweaking-kubernetes-deployments-for-enhanced-backward-compatibility",
      "title": "Tweaking Kubernetes Deployments for Enhanced Backward Compatibility",
      "summary": "Welcome to Part II of my Kubernetes series, where we explore how to Master Kubernetes Deployments for Seamless Backward Compatibility. Managing Kubernetes upgrades can be tricky, especially when you n",
      "date_published": "2024-09-29T15:46:28.195Z",
      "tags": [
        "Canary deployment",
        "Devops",
        "cloudnative",
        "containerization",
        "Microservices",
        "Blue/Green deployment",
        "APIs",
        "backward compatibility",
        "Kubernetes",
        "Security"
      ]
    }
  ]
}
