Skip to main content

Practical DevOps, Cloud, AI & Linux engineering guides

Featured Article

GitLab's New Rate Limits: What to Fix Before Oct 19

GitLab is capping unauthenticated API calls at 60 an hour starting October 19, and the preview windows land before most teams will have noticed.

KU
Kiril UrbonasAI Engineer
|Oct 4, 2026
GitLab's New Rate Limits: What to Fix Before Oct 19

Most read

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05

Topics

Latest Articles

View All →
Run only the CI jobs a change actually affects using if conditionals, trigger path filters, and per-job path detection in a monorepo.
••2 months ago

Conditional Jobs and Path Filters in GitHub Actions

Run only the CI jobs a change actually affects using if conditionals, trigger path filters, and per-job path detection in a monorepo.

KU
Kiril Urbonas·3 min read·44
Read article
A practical guide to scoping GitHub Actions secrets correctly, avoiding leaks in logs, blocking fork-PR theft, and preferring OIDC over stored keys.
••2 months ago

Using Secrets in GitHub Actions Safely

A practical guide to scoping GitHub Actions secrets correctly, avoiding leaks in logs, blocking fork-PR theft, and preferring OIDC over stored keys.

KU
Kiril Urbonas·2 min read·32
Read article
A practical guide to building, tagging, caching, and pushing Docker images from GitHub Actions using buildx, GHCR, and multi-arch builds.
••2 months ago

Build and Push Docker Images in GitHub Actions

A practical guide to building, tagging, caching, and pushing Docker images from GitHub Actions using buildx, GHCR, and multi-arch builds.

KU
Kiril Urbonas·2 min read·43
Read article
Stop re-downloading the same packages on every CI run by caching dependencies with keys that actually hit.
••2 months ago

Cache Dependencies in GitHub Actions

Stop re-downloading the same packages on every CI run by caching dependencies with keys that actually hit.

KU
Kiril Urbonas·2 min read·43
Read article
A practical guide to matrix builds in GitHub Actions that tests across versions and platforms without burning your monthly minutes.
••2 months ago

GitHub Actions Matrix Builds That Don't Waste Minutes

A practical guide to matrix builds in GitHub Actions that tests across versions and platforms without burning your monthly minutes.

KU
Kiril Urbonas·3 min read·30
Read article
A likelihood-ordered checklist for tracing "Permission denied" on Linux through mode bits, ownership, ACLs, SELinux, and mount options.
••2 months ago

Linux "Permission Denied" — Diagnose It Fast

A likelihood-ordered checklist for tracing "Permission denied" on Linux through mode bits, ownership, ACLs, SELinux, and mount options.

KU
Kiril Urbonas·2 min read·51
Read article
Most breaches come from the same short list of application bugs. This is the map: the vulnerabilities that actually get exploited and how to shut each one down.
••2 months ago

Application Security Best Practices — The Complete Guide

Most breaches come from the same short list of application bugs. This is the map: the vulnerabilities that actually get exploited and how to shut each one down.

KU
Kiril Urbonas·2 min read·12
Read article
When a Linux box misbehaves, the same dozen problems come up again and again. This is the map: what each symptom means and the fast path to the fix.
••2 months ago

Linux Troubleshooting — The Complete Guide

When a Linux box misbehaves, the same dozen problems come up again and again. This is the map: what each symptom means and the fast path to the fix.

KU
Kiril Urbonas·2 min read·20
Read article
A practical look at how SCA scanning finds vulnerable dependencies, cuts CVE noise, and where SAST, DAST, and IAST fit into CI/CD.
••2 months ago

Dependency Scanning and SCA — A Practical Guide

A practical look at how SCA scanning finds vulnerable dependencies, cuts CVE noise, and where SAST, DAST, and IAST fit into CI/CD.

KU
Kiril Urbonas·2 min read·32
Read article
A field-tested workflow for diagnosing why a systemd unit refuses to start, from status output to exit codes to the usual root causes.
••2 months ago

Debugging a systemd Service That Won't Start

A field-tested workflow for diagnosing why a systemd unit refuses to start, from status output to exit codes to the usual root causes.

KU
Kiril Urbonas·3 min read·135
Read article
A lightweight, whiteboard-friendly way to find design-level security flaws that scanners miss, using STRIDE, data-flow diagrams, and four plain questions.
••2 months ago

Threat Modeling for Engineers — A Practical Guide

A lightweight, whiteboard-friendly way to find design-level security flaws that scanners miss, using STRIDE, data-flow diagrams, and four plain questions.

KU
Kiril Urbonas·2 min read·16
Read article
A practical walkthrough of the HTTP response headers that harden a web app, with a real rollout plan for Content-Security-Policy.
••2 months ago

The HTTP Security Headers Guide (with CSP)

A practical walkthrough of the HTTP response headers that harden a web app, with a real rollout plan for Content-Security-Policy.

KU
Kiril Urbonas·2 min read·15
Read article
Page 12 of 47 · 559 posts