<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Subhanshu Mohan Gupta</title>
    <link>https://subhanshumg.com/blogs</link>
    <description>DevSecOps, platform engineering and cloud security. Long-form essays on the infrastructure that survives production.</description>
    <language>en</language>
    <lastBuildDate>Mon, 24 Aug 2026 21:26:10 GMT</lastBuildDate>
    <atom:link href="https://subhanshumg.com/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Your rate limiter was designed for humans</title>
      <link>https://blogs.subhanshumg.com/your-rate-limiter-was-designed-for-humans</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/your-rate-limiter-was-designed-for-humans</guid>
      <pubDate>Mon, 24 Aug 2026 21:26:10 GMT</pubDate>
      <description>Agent traffic does not get tired. Four layers of your stack assume it does.</description>
      <category>Devops</category>
      <category>api</category>
      <category>Security</category>
      <category>System Design</category>
      <category>AI</category>
      <category>Platform Engineering</category>
      <category>Cloud Computing</category>
    </item>
    <item>
      <title>Prefill Is Compute, Decode Is Memory: The Architecture Shift Nobody Budgeted For</title>
      <link>https://subhanshumg.com/blogs/prefill-is-compute-decode-is-memory</link>
      <guid isPermaLink="true">https://subhanshumg.com/blogs/prefill-is-compute-decode-is-memory</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <description>Every LLM request is two workloads with opposite appetites running on one chip. In 2025 the industry quietly stopped sharing the silicon. Here is the architecture, the economics, and the threshold where it pays.</description>
      <category>LLM Inference</category>
      <category>GPU Architecture</category>
      <category>Platform Engineering</category>
      <category>Systems Design</category>
      <category>Performance Optimization</category>
    </item>
    <item>
      <title>The Data Plane Is the New Perimeter</title>
      <link>https://subhanshumg.com/blogs/the-data-plane-is-the-new-perimeter</link>
      <guid isPermaLink="true">https://subhanshumg.com/blogs/the-data-plane-is-the-new-perimeter</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <description>A reference architecture for AI-native data security: making security a property of the platform, not a feature of the app.</description>
      <category>Security</category>
      <category>AI Infrastructure</category>
      <category>Platform Engineering</category>
    </item>
    <item>
      <title>Trust the Silicon. They Said.</title>
      <link>https://blogs.subhanshumg.com/teefail-broke-confidential-compute</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/teefail-broke-confidential-compute</guid>
      <pubDate>Sun, 24 May 2026 22:34:35 GMT</pubDate>
      <description>TEE.Fail did not kill confidential compute. It narrowed it. The threat model that excluded physical access stayed safe; the threat model that included it did not. Slatewatch Cyber rebuilt its workload</description>
      <category>GPU</category>
      <category>Environment</category>
      <category>#execution</category>
      <category>SGX</category>
      <category>Devops</category>
      <category>sev-snp</category>
      <category>gpu tee</category>
      <category>google cloud</category>
      <category>software development</category>
      <category>Security</category>
      <category>spire</category>
      <category>Machine Learning</category>
    </item>
    <item>
      <title>The EU CRA countdown</title>
      <link>https://blogs.subhanshumg.com/the-eu-cra-countdown</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-eu-cra-countdown</guid>
      <pubDate>Wed, 20 May 2026 08:37:36 GMT</pubDate>
      <description>Every product with digital elements sold in the EU after December 2027 must carry a CE conformity assessment.
That is the EU CRA. The scope is broader than GDPR. The documentation trail is non-trivial</description>
      <category>Regulations</category>
      <category>DevSecOps</category>
      <category>Devops</category>
      <category>conformity</category>
      <category>Security</category>
      <category>engineering</category>
      <category>technology</category>
      <category>EU CRA</category>
      <category>CEMarking</category>
      <category>countdown</category>
    </item>
    <item>
      <title>Crypto inventory: the platform workstream nobody scoped</title>
      <link>https://blogs.subhanshumg.com/crypto-inventory-the-platform-workstream-nobody-scoped</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/crypto-inventory-the-platform-workstream-nobody-scoped</guid>
      <pubDate>Fri, 15 May 2026 09:06:52 GMT</pubDate>
      <description>Ironway Materials ran a crypto audit in 2024 and shipped two years of new TLS code on top of it. The 2026 audit found seventeen new libraries, three of them in the hot path, all of them invisible to t</description>
      <category>crypto</category>
      <category>PQC</category>
      <category>Platform Engineering </category>
      <category>Devops</category>
      <category>supply chain</category>
      <category>idp</category>
      <category>falcon</category>
      <category>spire</category>
      <category>#sigstore</category>
      <category>AWS</category>
      <category>GCP</category>
      <category>Azure</category>
      <category>Security</category>
    </item>
    <item>
      <title>The agentic SOC is here</title>
      <link>https://blogs.subhanshumg.com/the-agentic-soc-is-here</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-agentic-soc-is-here</guid>
      <pubDate>Mon, 11 May 2026 10:38:26 GMT</pubDate>
      <description>Three vendor agentic-SOC platforms in Q1 2026. One platform-engineering charter that decides whether they work.

Microsoft Sentinel AI shipped. Splunk Agentic SOC launched at RSAC. Google SecOps and T</description>
      <category>agentic-soc</category>
      <category>agentic AI</category>
      <category>AI</category>
      <category>SecOps</category>
      <category>Security</category>
      <category>Platform Engineering </category>
      <category>Devops</category>
      <category>DevSecOps</category>
      <category>SOC</category>
      <category>OpenTelemetry</category>
      <category>Open Source</category>
      <category>AWS</category>
      <category>Cloud</category>
    </item>
    <item>
      <title>The distributed monolith tax</title>
      <link>https://blogs.subhanshumg.com/the-distributed-monolith-tax</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-distributed-monolith-tax</guid>
      <pubDate>Wed, 06 May 2026 03:17:08 GMT</pubDate>
      <description>We collapsed 47 microservices to 8. Deploy time went up, latency went down, and on-call went silent. Here&apos;s what the microservices evangelists didn&apos;t tell you about Dunbar&apos;s number for services.




M</description>
      <category>DevSecOps</category>
      <category>System Design</category>
      <category>monolithic architecture</category>
      <category>Microservices</category>
      <category>architecture</category>
      <category>Devops</category>
      <category>Kubernetes</category>
      <category>AWS</category>
      <category>production</category>
      <category>ci-cd</category>
      <category>software development</category>
      <category>engineering</category>
      <category>leadership</category>
    </item>
    <item>
      <title>Short-lived OIDC for CI: kill every long-lived GitHub Actions token</title>
      <link>https://blogs.subhanshumg.com/short-lived-oidc</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/short-lived-oidc</guid>
      <pubDate>Sun, 03 May 2026 05:31:09 GMT</pubDate>
      <description>GitHub OIDC to AWS/GCP/Azure federated credentials killed the need for long-lived PATs in CI. Most orgs still have PATs in use in 2026. Short-lived OIDC is the one-day win.
Narrative arc
The PAT failu</description>
      <category>DevSecOps</category>
      <category>Devops</category>
      <category>identity-management</category>
      <category>OIDC</category>
      <category>GitHub</category>
      <category>CI/CD</category>
      <category>owasp</category>
      <category>Cloud Computing</category>
      <category>Security</category>
      <category>spire</category>
      <category>AWS</category>
      <category>GCP</category>
      <category>Artificial Intelligence</category>
      <category>AI</category>
      <category>full stack</category>
      <category>Azure</category>
    </item>
    <item>
      <title>The 50ms lie: when edge AI actually matters (and when you&apos;re paying Cloudflare for marketing)</title>
      <link>https://blogs.subhanshumg.com/the-50ms-lie</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-50ms-lie</guid>
      <pubDate>Mon, 20 Apr 2026 17:25:57 GMT</pubDate>
      <description>Cloudflare and Fly.io are selling 50ms of latency savings on a 5,000ms inference like it&apos;s a revolution. That&apos;s 1% of the total latency. You&apos;re optimizing the rounding error while paying a 10x penalty</description>
      <category>edgecomputing</category>
      <category>AI</category>
      <category>inference</category>
      <category>Cloud</category>
      <category>cloudflare</category>
      <category>workers</category>
      <category>Workers AI</category>
      <category>Devops</category>
      <category>Machine Learning</category>
    </item>
    <item>
      <title>Stop building agents like prompts. Build them like state machines.</title>
      <link>https://blogs.subhanshumg.com/stop-building-agents-like-prompts-build-them-like-state-machines</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/stop-building-agents-like-prompts-build-them-like-state-machines</guid>
      <pubDate>Sun, 19 Apr 2026 09:48:30 GMT</pubDate>
      <description>Github repo: https://github.com/SubhanshuMG/agents-as-state-machines

The thesis in one paragraph
Stop calling them agents. They are state machines that invoke LLMs at certain transitions. The multi-a</description>
      <category>agentic AI</category>
      <category>agents</category>
      <category>state-machines</category>
      <category>temporal</category>
      <category>langgraph</category>
      <category>#llmops</category>
      <category>Devops</category>
      <category>Developer</category>
      <category>SRE</category>
      <category>System Design</category>
    </item>
    <item>
      <title>How I Built ForgeKit: An Open-Source Engineering Acceleration Platform That Scaffolds Production-Ready Projects in Under 60 Seconds</title>
      <link>https://blogs.subhanshumg.com/forgekit</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/forgekit</guid>
      <pubDate>Tue, 24 Mar 2026 16:30:51 GMT</pubDate>
      <description>https://github.com/SubhanshuMG/ForgeKit


The Problem Nobody Talks About Honestly
It is 9 AM on a Monday. Your team just got greenlit on a new microservice. You spin up a fresh repo and then spend the</description>
      <category>Open Source</category>
      <category>cli</category>
      <category>devtools</category>
      <category>TypeScript</category>
      <category>Web Development</category>
      <category>serverless</category>
      <category>AWS</category>
      <category>Devops</category>
      <category>General Programming</category>
      <category>JavaScript</category>
      <category>Python</category>
      <category>vite</category>
    </item>
    <item>
      <title>Building a Deployment Health Validator</title>
      <link>https://blogs.subhanshumg.com/building-a-deployment-health-validator</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/building-a-deployment-health-validator</guid>
      <pubDate>Tue, 10 Mar 2026 19:52:12 GMT</pubDate>
      <description>A deep-dive into microservice health checking, topological startup ordering and why HTTP 200 does not mean a service is healthy.

The Incident
Picture this: your on-call rotation fires a PagerDuty ale</description>
      <category>Devops</category>
      <category>Platform Engineering </category>
      <category>Python</category>
      <category>Microservices</category>
      <category>Security</category>
    </item>
    <item>
      <title>Platform Engineering at the Edge</title>
      <link>https://blogs.subhanshumg.com/platform-engineering-at-the-edge</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/platform-engineering-at-the-edge</guid>
      <pubDate>Tue, 03 Mar 2026 10:30:39 GMT</pubDate>
      <description>No Internal Developer Platform today supports disconnected edge environments. Backstage, Port, and Cortex all assume always-on cloud connectivity, yet organizations like GE HealthCare (100+ hospital-e</description>
      <category>Platform Engineering </category>
      <category>Kubernetes</category>
      <category>Devops</category>
      <category>Security</category>
      <category>edgecomputing</category>
      <category>gitops</category>
    </item>
    <item>
      <title>Governing the Ungovernable: Building an EU AI Act Article 9 Compliance Framework for Agentic AI That Actually Works in Production</title>
      <link>https://blogs.subhanshumg.com/governing-the-ungovernable</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/governing-the-ungovernable</guid>
      <pubDate>Sat, 28 Feb 2026 07:04:29 GMT</pubDate>
      <description>The EU AI Act&apos;s risk management requirements for high-risk AI systems are now on the clock. August 2, 2026 is the hard deadline for Annex III systems. But nobody has published a practical technical im</description>
      <category>euaiact</category>
      <category>agentic AI</category>
      <category>ai compliance certification</category>
      <category>DevSecOps</category>
      <category>llm</category>
      <category>Security</category>
      <category>AI</category>
      <category>Governance</category>
      <category>langgraph</category>
      <category>mlops</category>
      <category>generative ai</category>
      <category>#AIAct2026</category>
      <category>Article9</category>
    </item>
    <item>
      <title>The 3AM Problem: Why On-Call Burnout Is a System Design Failure, Not a People Problem</title>
      <link>https://blogs.subhanshumg.com/the-3am-problem-why-on-call-burnout-is-a-system-design-failure-not-a-people-problem</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-3am-problem-why-on-call-burnout-is-a-system-design-failure-not-a-people-problem</guid>
      <pubDate>Wed, 25 Feb 2026 10:04:36 GMT</pubDate>
      <description>The Human Story Behind the Pager
Meet Priya. Senior backend engineer with 5 years of experience, joined a fintech scale-up to build payment infrastructure. She is good at her job.
Then she went on-cal</description>
      <category>Devops</category>
      <category>SRE</category>
      <category>Kubernetes</category>
      <category>#AIOps</category>
      <category>backend</category>
    </item>
    <item>
      <title>The $4.45M Mistake: How a Missing SBOM Requirement Let the XZ Utils Backdoor Slip Past Millions of Servers</title>
      <link>https://blogs.subhanshumg.com/xz-utils-backdoor-sbom-supply-chain-security</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/xz-utils-backdoor-sbom-supply-chain-security</guid>
      <pubDate>Sun, 22 Feb 2026 15:05:20 GMT</pubDate>
      <description>The XZ Utils backdoor (CVE-2024-3094) nearly became the most devastating supply chain attack in history; a patient, three-year social engineering campaign that embedded a remote code execution backdoo</description>
      <category>supply chain</category>
      <category>Security</category>
      <category>DevSecOps</category>
      <category>sbom</category>
      <category>Kubernetes</category>
      <category>Platform Engineering </category>
      <category>Open Source</category>
      <category>cybersecurity</category>
      <category>GitHub</category>
      <category>github-actions</category>
      <category>CVE</category>
      <category>internal developer platforms</category>
    </item>
    <item>
      <title>The Global Cloud Blackout</title>
      <link>https://blogs.subhanshumg.com/the-global-cloud-blackout</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-global-cloud-blackout</guid>
      <pubDate>Tue, 17 Feb 2026 13:51:01 GMT</pubDate>
      <description>If AWS disappeared tomorrow, would your company survive?

Not degraded. Not slow. Gone.
Most &quot;highly available&quot; systems would collapse within hours. This isn&apos;t fear-mongering. It&apos;s an architectural re</description>
      <category>Cloud</category>
      <category>architecture</category>
      <category>Disaster recovery</category>
      <category>SRE</category>
      <category>Devops</category>
      <category>Terraform</category>
      <category>Chaos Engineering</category>
      <category>high availability</category>
      <category>System Design</category>
      <category>multi-cloud</category>
      <category>Kubernetes</category>
    </item>
    <item>
      <title>How Attackers Bypass Your “Compliant” CI/CD Pipeline (And How to Redesign It)</title>
      <link>https://blogs.subhanshumg.com/how-attackers-bypass-your-compliant-cicd-pipeline-and-how-to-redesign-it</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/how-attackers-bypass-your-compliant-cicd-pipeline-and-how-to-redesign-it</guid>
      <pubDate>Sun, 08 Feb 2026 23:43:21 GMT</pubDate>
      <description>Modern CI/CD pipelines are often treated as untouchable “trusted builds” – locked down by code review and best practices but that trust is a myth. A pipeline is a prime attack surface, containing ever</description>
      <category>Devops</category>
      <category>cybersecurity</category>
      <category>Cloud</category>
      <category>Security</category>
      <category>Platform Engineering </category>
      <category>supply chain</category>
      <category>cicd</category>
      <category>Kubernetes</category>
      <category>technology</category>
      <category>github-actions</category>
    </item>
    <item>
      <title>The $0 Compliance Stack</title>
      <link>https://blogs.subhanshumg.com/the-zero-dollar-compliance-stack</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-zero-dollar-compliance-stack</guid>
      <pubDate>Mon, 26 Jan 2026 20:38:25 GMT</pubDate>
      <description>The Lie We’re All Sold

“You need expensive GRC tools to pass enterprise audits.”

Reality:

Auditors don’t care about tools

They care about controls, traceability and evidence


Compliance ≠ Softwar</description>
      <category>Devops</category>
      <category>audit</category>
      <category>compliance </category>
      <category>ISO 27001</category>
      <category>PCI DSS</category>
      <category>Cloud</category>
      <category>Security</category>
      <category>System Design</category>
    </item>
    <item>
      <title>Secrets are a Supply Chain</title>
      <link>https://blogs.subhanshumg.com/secrets-are-a-supply-chain</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/secrets-are-a-supply-chain</guid>
      <pubDate>Fri, 23 Jan 2026 14:32:43 GMT</pubDate>
      <description>Everyone rotates secrets.
Very few design secret lifecycle risk and that gap is where breaches live.

Most organizations believe secret rotation equals security. It doesn’t.
Rotation is a maintenance </description>
      <category>cybersecurity</category>
      <category>Devops</category>
      <category>Security</category>
      <category>secrets</category>
      <category>Supply Chain Management</category>
      <category>architecture</category>
      <category>leadership</category>
    </item>
    <item>
      <title>Designing an ISO-27001-Native CI/CD Pipeline on AWS</title>
      <link>https://blogs.subhanshumg.com/iso-27001</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/iso-27001</guid>
      <pubDate>Wed, 21 Jan 2026 08:20:08 GMT</pubDate>
      <description>“We passed an ISO-27001 surveillance audit with zero Jira tickets, zero screenshots, and zero manual evidence.”

That line usually gets silence. Then disbelief. Then the real question:

“Okay… how?”

</description>
      <category>Devops</category>
      <category>audit</category>
      <category>ISO 27001</category>
      <category>compliance </category>
      <category>automation</category>
      <category>AWS</category>
      <category>ci-cd</category>
      <category>Security</category>
    </item>
    <item>
      <title>Beyond the Kernel</title>
      <link>https://blogs.subhanshumg.com/beyond-the-kernel</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/beyond-the-kernel</guid>
      <pubDate>Sun, 09 Nov 2025 17:00:42 GMT</pubDate>
      <description>Security no longer lives outside the system. It lives within the kernel.
In a world of microservices, containers, and ephemeral workloads, traditional observability tools see only what applications ex</description>
      <category>eBPF</category>
      <category>DevSecOps</category>
      <category>cloud native</category>
      <category>Kubernetes</category>
      <category>Security</category>
      <category>falco</category>
      <category>cilium</category>
      <category>AWS</category>
      <category>Linux</category>
      <category>Kernel</category>
      <category>monitoring</category>
      <category>observability</category>
      <category>zerotrust</category>
    </item>
    <item>
      <title>DevSecOps for the Mind</title>
      <link>https://blogs.subhanshumg.com/devsecops-for-the-mind</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/devsecops-for-the-mind</guid>
      <pubDate>Sun, 31 Aug 2025 19:26:40 GMT</pubDate>
      <description>Introduction
Developers build systems. DevSecOps engineers build secure, automated pipelines.But what happens when you apply the same principles to your own life and knowledge?
Over the last year, I’v</description>
      <category>DevSecOps</category>
      <category>cognitive</category>
      <category>Futureofwork</category>
      <category>KnowledgeManagement</category>
      <category>secondbrain</category>
      <category>pkm</category>
      <category>Artificial Intelligence</category>
      <category>collective thinking</category>
      <category>zerotrust</category>
      <category>Security</category>
    </item>
    <item>
      <title>Deploying a Bitcoin Regtest Network with Docker and CI/CD Tools</title>
      <link>https://blogs.subhanshumg.com/deploying-a-bitcoin-regtest-network-with-docker-and-cicd-tools</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/deploying-a-bitcoin-regtest-network-with-docker-and-cicd-tools</guid>
      <pubDate>Sat, 23 Aug 2025 08:17:11 GMT</pubDate>
      <description>Hands-on + R&amp;D guide.
We’ll stand up a private Bitcoin regtest network with two nodes, peer them, mine spendable coins and send/confirm transactions; wrapped in a clean repo with CI and an optional de</description>
      <category>Bitcoin</category>
      <category>Devops</category>
      <category>Docker</category>
      <category>Blockchain</category>
      <category>engineering</category>
      <category>SRE</category>
      <category>cicd</category>
      <category>observability</category>
      <category>Open Source</category>
    </item>
    <item>
      <title>The Ultimate GitLab Import/Export Toolkit for Engineers</title>
      <link>https://blogs.subhanshumg.com/gitlab-import-export-toolkit</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/gitlab-import-export-toolkit</guid>
      <pubDate>Wed, 30 Jul 2025 21:30:09 GMT</pubDate>
      <description>“I’m a DevOps engineer - if I’m doing it manually twice, I’m writing a script.”


A few weeks ago, I was handed a deceptively simple‑sounding task: spin up an entire playground environment, pipelines,</description>
      <category>Devops</category>
      <category>GitLab</category>
      <category>automation</category>
      <category>Scripting</category>
      <category>Python</category>
      <category>ci-cd</category>
      <category>migration</category>
      <category>Cloud</category>
      <category>Branching Strategies</category>
      <category>engineering</category>
      <category>vcs</category>
      <category>Open Source</category>
    </item>
    <item>
      <title>Integrating RASP with CI/CD for Automated Vulnerability Response</title>
      <link>https://blogs.subhanshumg.com/rasp-integration</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/rasp-integration</guid>
      <pubDate>Tue, 24 Jun 2025 06:53:34 GMT</pubDate>
      <description>Introduction
Runtime Application Self-Protection (RASP) embeds security within running applications and can report attacks in real-time. By integrating RASP into CI/CD pipelines, production threat int</description>
      <category>SelfHealingSecurity</category>
      <category>Devops</category>
      <category>cicd</category>
      <category>rasp</category>
      <category>Application Security</category>
      <category>runtime-security</category>
      <category>automation</category>
      <category>Security</category>
      <category>infosec</category>
      <category>ThreatDetection</category>
    </item>
    <item>
      <title>Mastering Traefik as a Dynamic Reverse Proxy for Containerized Environments</title>
      <link>https://blogs.subhanshumg.com/mastering-traefik-as-a-dynamic-reverse-proxy-for-containerized-environments</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/mastering-traefik-as-a-dynamic-reverse-proxy-for-containerized-environments</guid>
      <pubDate>Sun, 18 May 2025 22:28:48 GMT</pubDate>
      <description>Introduction
In modern microservices and containerized ecosystems, Traefik serves as a powerful reverse proxy, offering dynamic service discovery, advanced routing capabilities and automated SSL/TLS m</description>
      <category>Docker</category>
      <category>Traefik</category>
      <category>routing</category>
      <category>Security</category>
      <category>TLS</category>
      <category>scalability</category>
      <category>Cloud Computing</category>
      <category>proxy</category>
      <category>#IaC</category>
      <category>containerization</category>
    </item>
    <item>
      <title>Building Agentic RAG Systems: DevSecOps Blueprint for Autonomous &amp; Secure AI</title>
      <link>https://blogs.subhanshumg.com/building-agentic-rag-systems-devsecops-blueprint-for-autonomous-and-secure-ai</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/building-agentic-rag-systems-devsecops-blueprint-for-autonomous-and-secure-ai</guid>
      <pubDate>Tue, 22 Apr 2025 23:39:23 GMT</pubDate>
      <description>Introduction: Why Agentic RAG is the Next Frontier
Retrieval-Augmented Generation (RAG) revolutionized LLMs by grounding them in external data. But static, one-shot retrieval struggles with dynamic, m</description>
      <category>RAG </category>
      <category>agentic AI</category>
      <category>AI</category>
      <category>Security</category>
      <category>observability</category>
      <category>policy as code</category>
      <category>compliance </category>
      <category>Kubernetes</category>
      <category>DevSecOps</category>
      <category>cloud native</category>
      <category>mlops</category>
    </item>
    <item>
      <title>End-to-End Cloud-Native Deployment</title>
      <link>https://blogs.subhanshumg.com/end-to-end-cloud-native-deployment</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/end-to-end-cloud-native-deployment</guid>
      <pubDate>Tue, 15 Apr 2025 21:22:03 GMT</pubDate>
      <description>Introduction
This technical walkthrough demonstrates how to deploy a secure, scalable microservice on AWS using infrastructure-as-code (Terraform), containerization (Docker), and serverless computing </description>
      <category>AWS</category>
      <category>Terraform</category>
      <category>Docker</category>
      <category>ECS</category>
      <category>aws-fargate</category>
      <category>Devops</category>
      <category>serverless</category>
      <category>Security</category>
      <category>zerotrust</category>
      <category>scalability</category>
      <category>technology</category>
      <category>community</category>
      <category>innovation</category>
    </item>
    <item>
      <title>Caching Conundrum: Is There Truly Just One Path to API Efficiency?</title>
      <link>https://blogs.subhanshumg.com/caching-conundrum</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/caching-conundrum</guid>
      <pubDate>Mon, 14 Apr 2025 16:21:15 GMT</pubDate>
      <description>Caching involves storing duplicates of frequently accessed data at various points along the request-response path.
When a consumer seeks a resource like a YouTube video, the request traverses one or m</description>
      <category>api</category>
      <category>caching</category>
      <category>optimization</category>
      <category>Redis</category>
      <category>Devops</category>
      <category>performance</category>
      <category>System Design</category>
      <category>innovation</category>
      <category>scalability</category>
      <category>software development</category>
    </item>
    <item>
      <title>Micro-Segmentation Strategies in DevSecOps</title>
      <link>https://blogs.subhanshumg.com/micro-segmentation-strategies-in-devsecops</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/micro-segmentation-strategies-in-devsecops</guid>
      <pubDate>Sun, 23 Mar 2025 14:42:10 GMT</pubDate>
      <description>Introduction
Traditional perimeter security is no longer sufficient in today’s dynamic and threat-laden IT environments. Micro-segmentation: The process of dividing your network into granular zones en</description>
      <category>microsegmentation</category>
      <category>Kubernetes</category>
      <category>DevSecOps</category>
      <category>zerotrust</category>
      <category>cloudsecurity</category>
      <category>Security</category>
      <category>#infosec</category>
      <category>ci-cd</category>
      <category>architecture</category>
    </item>
    <item>
      <title>Designing Scalable, Secure Systems w/ DevSecOps</title>
      <link>https://blogs.subhanshumg.com/designing-scalable-secure-systems-w-devsecops</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/designing-scalable-secure-systems-w-devsecops</guid>
      <pubDate>Sun, 02 Mar 2025 21:22:03 GMT</pubDate>
      <description>In the fast-evolving landscape of modern application development, building scalable, high-performance systems demands more than just robust code it calls for a thoughtful blend of system design, opera</description>
      <category>DevSecOps</category>
      <category>System Design</category>
      <category>scalability</category>
      <category>Security</category>
      <category>Microservices</category>
      <category>concurrency</category>
      <category>multithreading</category>
      <category>cicd</category>
      <category>APIs</category>
      <category>performance</category>
      <category>infrastructure</category>
      <category>Cloud</category>
      <category>architecture</category>
      <category>AWS</category>
      <category>Kubernetes</category>
    </item>
    <item>
      <title>Unikernel Containers</title>
      <link>https://blogs.subhanshumg.com/unikernel-containers</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/unikernel-containers</guid>
      <pubDate>Tue, 28 Jan 2025 11:39:40 GMT</pubDate>
      <description>Introduction
In a rapidly evolving technological landscape, where agility and security are paramount, unikernel containers are emerging as a revolutionary force in DevSecOps. These ultra-lightweight c</description>
      <category>DevSecOps</category>
      <category>unikernel</category>
      <category>cicd</category>
      <category>containers</category>
      <category>innovation</category>
      <category>Security</category>
      <category>revolution</category>
      <category>technology</category>
      <category>operating system</category>
      <category>virtualization</category>
      <category>Linux</category>
    </item>
    <item>
      <title>The Power of Rootless Docker Containers</title>
      <link>https://blogs.subhanshumg.com/the-power-of-rootless-docker-containers</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-power-of-rootless-docker-containers</guid>
      <pubDate>Mon, 20 Jan 2025 19:40:23 GMT</pubDate>
      <description>In the rapidly evolving world of DevSecOps, ensuring secure deployments is more critical than ever. Enter Docker rootless containers, a groundbreaking solution designed to enhance container security b</description>
      <category>RootlessDocker</category>
      <category>DevSecOps</category>
      <category>Docker</category>
      <category>containersecurity</category>
      <category>#cybersecurity</category>
      <category>cloudsecurity</category>
      <category>compliance </category>
      <category>cicd</category>
      <category>Linux</category>
      <category>advanced</category>
    </item>
    <item>
      <title>Container Networking Security with Traefik</title>
      <link>https://blogs.subhanshumg.com/container-networking-security-with-traefik</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/container-networking-security-with-traefik</guid>
      <pubDate>Thu, 16 Jan 2025 13:49:55 GMT</pubDate>
      <description>Introduction
Container networking security is a cornerstone of modern microservices architecture. Tools like Traefik and Docker Compose simplify orchestration and networking, but implementing advanced</description>
      <category>Microservices</category>
      <category>cloud security</category>
      <category>Traefik</category>
      <category>Devops</category>
      <category>Portainer</category>
      <category>elk-stack</category>
      <category>Grafana</category>
      <category>#prometheus</category>
      <category>#multitenancy</category>
      <category>mTLS</category>
      <category>Docker compose</category>
      <category>containerization</category>
      <category>containers</category>
    </item>
    <item>
      <title>Serverless 2.0: Hybrid Decentralized Frameworks for Stateless Compute</title>
      <link>https://blogs.subhanshumg.com/serverless-20-hybrid-decentralized-frameworks-for-stateless-compute</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/serverless-20-hybrid-decentralized-frameworks-for-stateless-compute</guid>
      <pubDate>Thu, 02 Jan 2025 10:40:14 GMT</pubDate>
      <description>Introduction
In the age of cloud computing, serverless architectures have become synonymous with scalability, cost-efficiency, and operational simplicity. However, these advantages often come with a c</description>
      <category>serverless</category>
      <category>decentralization</category>
      <category>Devops</category>
      <category>Hybrid Cloud</category>
      <category>Blockchain</category>
      <category>StateLESS</category>
      <category>ipfs</category>
      <category>filecoin</category>
      <category>Smart Contracts</category>
      <category>innovation</category>
      <category>Resilience</category>
      <category>Cloud</category>
      <category>computing</category>
      <category>akash network </category>
    </item>
    <item>
      <title>The Future of DevSecOps</title>
      <link>https://blogs.subhanshumg.com/the-future-of-devsecops</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/the-future-of-devsecops</guid>
      <pubDate>Sat, 21 Dec 2024 15:50:37 GMT</pubDate>
      <description>In today’s hyper-connected world, building software often involves diverse, distributed teams collaborating across multiple organizations. Traditional DevSecOps pipelines rely on centralized tools and</description>
      <category>DevSecOps</category>
      <category>decentralization</category>
      <category>cicd</category>
      <category>AI</category>
      <category>Smart Contracts</category>
      <category>immutable</category>
      <category>infrastructure</category>
      <category>Security</category>
      <category>Trustless</category>
      <category>automation</category>
      <category>#cybersecurity</category>
    </item>
    <item>
      <title>Streamlining Node Operator Docker Images with Automated Rolling Updates</title>
      <link>https://blogs.subhanshumg.com/architecture-design-for-automated-rolling-updates-of-node-operator-docker-images</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/architecture-design-for-automated-rolling-updates-of-node-operator-docker-images</guid>
      <pubDate>Tue, 10 Dec 2024 06:13:41 GMT</pubDate>
      <description>Components

Docker Registry Monitoring:

Uses a webhook or polling mechanism to detect new releases of the bitscrunch:latest image.

Integrates with a CI/CD pipeline to automate the update process.

A</description>
      <category>Docker</category>
      <category>automation</category>
      <category>DevSecOps</category>
      <category>kafka</category>
      <category>architecture</category>
      <category>node</category>
      <category>Grafana Monitoring</category>
      <category>Kubernetes</category>
    </item>
    <item>
      <title>Ensuring Inter-Agent Data Integrity in Multi-Node DevSecOps</title>
      <link>https://blogs.subhanshumg.com/ensuring-inter-agent-data-integrity-in-multi-node-devsecops</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/ensuring-inter-agent-data-integrity-in-multi-node-devsecops</guid>
      <pubDate>Sat, 30 Nov 2024 08:30:03 GMT</pubDate>
      <description>Introduction
In modern DevSecOps environments, where distributed systems and multi-node architectures are prevalent, ensuring data integrity during inter-agent communication is crucial. Compromised da</description>
      <category>MultiNodeArchitecture</category>
      <category>SecuringData</category>
      <category>MITMPrevention</category>
      <category>Cryptography</category>
      <category>DevSecOps</category>
      <category>#cybersecurity</category>
      <category>Hashing</category>
      <category>TLS</category>
      <category>Resilience</category>
      <category>#dataintegrity</category>
    </item>
    <item>
      <title>Federated Learning for Distributed MLOps Security</title>
      <link>https://blogs.subhanshumg.com/federated-learning-for-distributed-mlops-security</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/federated-learning-for-distributed-mlops-security</guid>
      <pubDate>Sun, 17 Nov 2024 00:52:04 GMT</pubDate>
      <description>Introduction
As Machine Learning Operations (MLOps) scale across industries, safeguarding sensitive data while enabling distributed training becomes a significant challenge. Enter Federated Learning (</description>
      <category>pysyft</category>
      <category>smpc</category>
      <category>federated learning</category>
      <category>mlops</category>
      <category>distributed system</category>
      <category>Kubernetes</category>
      <category>#prometheus</category>
      <category>elk</category>
      <category>DevSecOps</category>
      <category>Datadog</category>
      <category>flower</category>
      <category>HPA</category>
      <category>Deep Learning</category>
    </item>
    <item>
      <title>Accelerating Deployment Velocity: Reducing Build Times and Image Sizes in Kubernetes</title>
      <link>https://blogs.subhanshumg.com/accelerating-deployment-velocity-reducing-build-times-and-image-sizes-in-kubernetes</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/accelerating-deployment-velocity-reducing-build-times-and-image-sizes-in-kubernetes</guid>
      <pubDate>Tue, 29 Oct 2024 04:22:09 GMT</pubDate>
      <description>Introduction
Welcome to the final part of my Kubernetes CI/CD optimization series!So far, we’ve covered the essentials of Kubernetes deployment, container image optimization, and strategies for speedi</description>
      <category>Kaniko</category>
      <category>Kubernetes</category>
      <category>optimization</category>
      <category>DevSecOps</category>
      <category>Devops</category>
      <category>Microservices</category>
      <category>Docker</category>
      <category>containerization</category>
      <category>Continuous Integration</category>
      <category>continuous deployment</category>
      <category>cloud native</category>
      <category>automation</category>
      <category>#IaC</category>
      <category>SRE</category>
    </item>
    <item>
      <title>Securing Kubernetes Operations with Runtime Security Best Practices</title>
      <link>https://blogs.subhanshumg.com/securing-kubernetes-operations-with-runtime-security-best-practices</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/securing-kubernetes-operations-with-runtime-security-best-practices</guid>
      <pubDate>Tue, 22 Oct 2024 03:46:21 GMT</pubDate>
      <description>Welcome to the 9th installment of my Kubernetes series wherw we’ll dive into advanced runtime security techniques for Kubernetes environments to detect anomalies, enforce strict container security pol</description>
      <category>Kubernetes</category>
      <category>#cybersecurity</category>
      <category>containerization</category>
      <category>Orchestration</category>
      <category>cloudsecurity</category>
      <category>falco</category>
      <category>sysdig</category>
      <category>aquasec</category>
      <category>cloudops</category>
      <category>DevSecOps</category>
      <category>runtime</category>
      <category>Security</category>
    </item>
    <item>
      <title>Picking the Right Load Balancer for Your Kubernetes Environment</title>
      <link>https://blogs.subhanshumg.com/picking-the-right-load-balancer-for-your-kubernetes-environment</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/picking-the-right-load-balancer-for-your-kubernetes-environment</guid>
      <pubDate>Thu, 17 Oct 2024 16:50:08 GMT</pubDate>
      <description>Introduction
As Kubernetes adoption skyrockets, managing traffic within and to your clusters becomes a critical aspect of ensuring availability, performance, and scalability. One of the most important</description>
      <category>Load Balancing</category>
      <category>nginx</category>
      <category>Devops</category>
      <category>SecOps</category>
      <category>ingress</category>
      <category>Traefik</category>
      <category>Microservices</category>
      <category>cloudnative</category>
      <category>AWS</category>
      <category>Kubernetes</category>
      <category>EKS</category>
    </item>
    <item>
      <title>Designing an Effective Fallback Plan for Kubernetes Failures</title>
      <link>https://blogs.subhanshumg.com/designing-an-effective-fallback-plan-for-kubernetes-failures</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/designing-an-effective-fallback-plan-for-kubernetes-failures</guid>
      <pubDate>Thu, 10 Oct 2024 19:42:38 GMT</pubDate>
      <description>Welcome to Part VII of my Kubernetes series, where we’ll explore the essential strategies for building a robust disaster recovery and fallback plan for your Kubernetes workloads. In this article we&apos;ll</description>
      <category>Disaster recovery</category>
      <category>Kubernetes</category>
      <category>Devops</category>
      <category>AWS</category>
      <category>dns</category>
      <category>failover</category>
      <category>velero</category>
      <category>Backup</category>
      <category>scalability</category>
      <category>multicloud</category>
      <category>replication</category>
      <category>route53</category>
      <category>kubefed</category>
      <category>Helm</category>
    </item>
    <item>
      <title>Leveraging Caching, CDN, and Rate Limiting to Enhance Kubernetes Performance</title>
      <link>https://blogs.subhanshumg.com/leveraging-caching-cdn-and-rate-limiting-to-enhance-kubernetes-performance</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/leveraging-caching-cdn-and-rate-limiting-to-enhance-kubernetes-performance</guid>
      <pubDate>Sun, 06 Oct 2024 19:29:21 GMT</pubDate>
      <description>Welcome to Part VI of my Kubernetes series! In this post, we’re diving deep into three powerful techniques: caching, Content Delivery Networks (CDNs), and rate limiting that can significantly boost th</description>
      <category>Kubernetes</category>
      <category>cloudflare</category>
      <category>ratelimit</category>
      <category>CDN</category>
      <category>caching</category>
      <category>performance</category>
      <category>Microservices</category>
      <category>Redis</category>
      <category>Devops</category>
      <category>cloudnative</category>
      <category>scalability</category>
      <category>SRE</category>
      <category>System Architecture</category>
    </item>
    <item>
      <title>Understanding Composite SLA Calculations in Kubernetes Systems</title>
      <link>https://blogs.subhanshumg.com/understanding-composite-sla-calculations-in-kubernetes-systems</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/understanding-composite-sla-calculations-in-kubernetes-systems</guid>
      <pubDate>Fri, 04 Oct 2024 18:35:14 GMT</pubDate>
      <description>Welcome to Part V of my Kubernetes series! In this installment, we’re going to explore the complex yet crucial process of calculating the Composite Service Level Agreement (SLA) for distributed applic</description>
      <category>sla</category>
      <category>sli</category>
      <category>Devops</category>
      <category>Kubernetes</category>
      <category>caching</category>
      <category>CDN</category>
      <category>distributed system</category>
      <category>Performance Optimization</category>
      <category>Microservices</category>
      <category>SRE</category>
      <category>ratelimit</category>
      <category>containerization</category>
    </item>
    <item>
      <title>Ensuring PCI-DSS, POPI, GDPR, and HIPAA Compliance in Kubernetes Systems</title>
      <link>https://blogs.subhanshumg.com/ensuring-pci-dss-popi-gdpr-and-hipaa-compliance-in-kubernetes-systems</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/ensuring-pci-dss-popi-gdpr-and-hipaa-compliance-in-kubernetes-systems</guid>
      <pubDate>Wed, 02 Oct 2024 15:52:18 GMT</pubDate>
      <description>Introduction
Welcome to Part IV of my Kubernetes series, where we delve into building compliant systems on Kubernetes to meet stringent regulatory standards such as PCI-DSS, POPI, GDPR, and HIPAA. As </description>
      <category>pcidss</category>
      <category>HIPAA</category>
      <category>rbac</category>
      <category>#istio</category>
      <category>Kubernetes</category>
      <category>compliance </category>
      <category>#gdpr</category>
      <category>openpolicyagent</category>
      <category>DevSecOps</category>
      <category>cloud native</category>
      <category>#cybersecurity</category>
      <category>#DataProtection</category>
    </item>
    <item>
      <title>Optimizing Costs for Cloud Architectures with Kubernetes Workloads</title>
      <link>https://blogs.subhanshumg.com/optimizing-costs-for-cloud-architectures-with-kubernetes-workloads</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/optimizing-costs-for-cloud-architectures-with-kubernetes-workloads</guid>
      <pubDate>Mon, 30 Sep 2024 17:05:40 GMT</pubDate>
      <description>In this III part of my Kubernetes series, we will dive deep into Cost Estimation for Cloud Architectures, focusing on practical strategies for managing the cost of running Kubernetes workloads in clou</description>
      <category>Devops</category>
      <category>Kubernetes</category>
      <category>#prometheus</category>
      <category>Grafana</category>
      <category>Cloud Computing</category>
      <category>savings</category>
      <category>finops</category>
      <category>HPA</category>
      <category>Microservices</category>
      <category>Kubecost</category>
      <category>AWS</category>
      <category>Azure</category>
      <category>GCP</category>
      <category>autoscaling</category>
      <category>technology</category>
    </item>
    <item>
      <title>Tweaking Kubernetes Deployments for Enhanced Backward Compatibility</title>
      <link>https://blogs.subhanshumg.com/tweaking-kubernetes-deployments-for-enhanced-backward-compatibility</link>
      <guid isPermaLink="true">https://blogs.subhanshumg.com/tweaking-kubernetes-deployments-for-enhanced-backward-compatibility</guid>
      <pubDate>Sun, 29 Sep 2024 15:46:28 GMT</pubDate>
      <description>Welcome to Part II of my Kubernetes series, where we explore how to Master Kubernetes Deployments for Seamless Backward Compatibility. Managing Kubernetes upgrades can be tricky, especially when you n</description>
      <category>Canary deployment</category>
      <category>Devops</category>
      <category>cloudnative</category>
      <category>containerization</category>
      <category>Microservices</category>
      <category>Blue/Green deployment</category>
      <category>APIs</category>
      <category>backward compatibility</category>
      <category>Kubernetes</category>
      <category>Security</category>
    </item>
  </channel>
</rss>
