Skip to main content

Practical DevOps, Cloud, AI & Linux engineering guides

Featured Article

GitLab's New Rate Limits: What to Fix Before Oct 19

GitLab is capping unauthenticated API calls at 60 an hour starting October 19, and the preview windows land before most teams will have noticed.

KU
Kiril UrbonasAI Engineer
|Oct 4, 2026
GitLab's New Rate Limits: What to Fix Before Oct 19

Most read

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05

Topics

Latest Articles

View All →
A single NAT Gateway quietly billed us $2,900 in one month, mostly for data processing on traffic that never needed to leave the VPC. Here's how we found it and cut it.
••3 months ago

NAT Gateway Costs: The Silent Line Item and How to Cut It

A single NAT Gateway quietly billed us $2,900 in one month, mostly for data processing on traffic that never needed to leave the VPC. Here's how we found it and cut it.

KU
Kiril Urbonas·1 min read·17
Read article
Most agents that "need memory" actually need a smaller context window and a database. Here's how we cut a support agent's token bill by 60 percent by deleting memory.
••3 months ago

Agent Memory: Short-Term, Long-Term, and When You Need Neither

Most agents that "need memory" actually need a smaller context window and a database. Here's how we cut a support agent's token bill by 60 percent by deleting memory.

KU
Kiril Urbonas·2 min read·23
Read article
The Backstage demo always wows leadership. Then six months later the catalog has 400 stale entries and nobody trusts it. Here's what got ours to actually stick.
••3 months ago

Backstage Software Catalog: Getting Adoption Past the Demo

The Backstage demo always wows leadership. Then six months later the catalog has 400 stale entries and nobody trusts it. Here's what got ours to actually stick.

KU
Kiril Urbonas·2 min read·17
Read article
A user got our support bot to recite its system prompt and then draft a refund it wasn't authorized to give. Two layers of guardrails, one on input, one on output, closed both holes.
••3 months ago

Guardrails for Production LLMs: Input and Output Filtering That Holds

A user got our support bot to recite its system prompt and then draft a refund it wasn't authorized to give. Two layers of guardrails, one on input, one on output, closed both holes.

KU
Kiril Urbonas·2 min read·26
Read article
Our S3 bill tripled in a month with no growth in stored data. The storage line was flat. The cost was in requests and a misconfigured lifecycle rule quietly shredding money.
••3 months ago

S3 Cost Traps: Storage Classes, Requests, and the Surprise Bill

Our S3 bill tripled in a month with no growth in stored data. The storage line was flat. The cost was in requests and a misconfigured lifecycle rule quietly shredding money.

KU
Kiril Urbonas·2 min read·13
Read article
Everyone says Compose is for dev only. We ran it in production for two years on a single node and it was the right call, until the day it very much wasn't.
••3 months ago

Docker Compose in Production: When It Fits and When It Doesn't

Everyone says Compose is for dev only. We ran it in production for two years on a single node and it was the right call, until the day it very much wasn't.

KU
Kiril Urbonas·2 min read·20
Read article
We had 140 engineers with 300 static public keys scattered across authorized_keys files nobody could audit. Moving to SSH certificates with short TTLs made access reviewable again.
••3 months ago

SSH Hardening in 2026: Keys, Certificates, and Bastion Patterns

We had 140 engineers with 300 static public keys scattered across authorized_keys files nobody could audit. Moving to SSH certificates with short TTLs made access reviewable again.

KU
Kiril Urbonas·2 min read·19
Read article
We rotated a leaked AWS access key that a workflow had committed to logs. Switching GitHub Actions to OIDC federation meant no static AWS keys exist to leak in the first place.
••3 months ago

OIDC Federation for GitHub Actions to AWS: Killing Long-Lived Keys

We rotated a leaked AWS access key that a workflow had committed to logs. Switching GitHub Actions to OIDC federation meant no static AWS keys exist to leak in the first place.

KU
Kiril Urbonas·2 min read·19
Read article
We inherited 200-odd AWS resources built by hand over four years, with no state file anywhere. Here's how import blocks and a generation workflow got them under Terraform without a rebuild.
••3 months ago

Terraform Import at Scale: Bringing Legacy Infra Under Code

We inherited 200-odd AWS resources built by hand over four years, with no state file anywhere. Here's how import blocks and a generation workflow got them under Terraform without a rebuild.

KU
Kiril Urbonas·2 min read·22
Read article
Our RAG answers kept citing the wrong paragraph even when the right one was retrieved. A cross-encoder reranker fixed relevance but added 180ms. Here's when that trade pays off.
••3 months ago

Reranking in RAG: When a Cross-Encoder Earns Its Latency

Our RAG answers kept citing the wrong paragraph even when the right one was retrieved. A cross-encoder reranker fixed relevance but added 180ms. Here's when that trade pays off.

KU
Kiril Urbonas·2 min read·23
Read article
Adding a read replica cut primary load 60%, then support tickets rolled in about users not seeing their own edits. Replication lag turned into a correctness bug we had to route around.
••3 months ago

Postgres Read Replicas: Routing Reads Without Stale-Data Bugs

Adding a read replica cut primary load 60%, then support tickets rolled in about users not seeing their own edits. Replication lag turned into a correctness bug we had to route around.

KU
Kiril Urbonas·2 min read·28
Read article
A single ALTER TABLE took a lock and stalled every write for 40 seconds during peak traffic. Expand-contract is how we stopped shipping outages.
••3 months ago

Zero-Downtime Postgres Migrations: Expand-Contract in Practice

A single ALTER TABLE took a lock and stalled every write for 40 seconds during peak traffic. Expand-contract is how we stopped shipping outages.

KU
Kiril Urbonas·2 min read·23
Read article
Page 25 of 47 · 559 posts