<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Arvind Verma]]></title><description><![CDATA[DevOps Engineer⚙️| 4 Years Experience📆| AWS☁️🟠| Azure☁️🔷| GCP☁️🌈| Jenkins🤵| Kubernetes☸️| Terraform🌍| Ansible📦|Docker🐳| Argo CD🚀| Trivy🔍| SonarQube📊]]></description><link>https://arvindverma021.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!HKJC!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d03df4-304c-4617-96ed-7f2d85d7b0a0_1251x1251.jpeg</url><title>Arvind Verma</title><link>https://arvindverma021.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 01 Sep 2026 17:57:18 GMT</lastBuildDate><atom:link href="/__u/arvindverma021.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Arvind Verma]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[arvindverma021@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[arvindverma021@substack.com]]></itunes:email><itunes:name><![CDATA[Arvind Verma]]></itunes:name></itunes:owner><itunes:author><![CDATA[Arvind Verma]]></itunes:author><googleplay:owner><![CDATA[arvindverma021@substack.com]]></googleplay:owner><googleplay:email><![CDATA[arvindverma021@substack.com]]></googleplay:email><googleplay:author><![CDATA[Arvind Verma]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Fake It ’Til You Make It: The Psychology Behind Acting Like Your Future Self 🧠✨]]></title><description><![CDATA[There is a strange idea that keeps appearing in conversations about success, confidence, career growth, and personal transformation: &#8220;Act like you already have what you want.&#8221;]]></description><link>https://arvindverma021.substack.com/p/fake-it-til-you-make-it-the-psychology</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/fake-it-til-you-make-it-the-psychology</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Mon, 31 Aug 2026 09:40:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!L4Ai!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!L4Ai!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!L4Ai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg" width="800" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:198424,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213520592?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!L4Ai!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c2a18ae-e446-4a4f-a05e-17a68271db57_800x1200.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>At first, it sounds almost ridiculous.</p><p>If you want to become a successful engineer, should you simply <em>pretend</em> you are already successful?</p><p>If you want to become a leader, should you start behaving like one before anyone gives you the title?</p><p>If you want to build a better life, should you somehow convince yourself that the future has already arrived?</p><p>The answer is more interesting than simple positive thinking.</p><p>Because there is a meaningful difference between <strong>pretending something is true</strong> and <strong>behaving in a way that makes the desired future more likely to become true.</strong></p><p>That is where the idea of <em>&#8220;fake it &#8217;til you make it&#8221;</em> becomes surprisingly useful.</p><p>Not as magic.</p><p>Not as wishful thinking.</p><p>But as a framework for changing your <strong>behavior, identity, habits, and decisions.</strong> &#127919;</p><div><hr></div><h3>SECTION 1: You Already Do This Without Realizing It &#129504;</h3><p>Think about falling asleep.</p><p>You cannot force yourself to sleep by repeatedly shouting:</p><blockquote><p><em>&#8220;I AM ASLEEP!&#8221;</em></p></blockquote><p>Your brain would probably respond with another beautiful achievement of humanity: <em>more overthinking.</em></p><p>Instead, you behave like someone who is preparing to sleep.</p><p>You close your eyes.</p><p>You become still.</p><p>You slow your breathing.</p><p>You reduce stimulation.</p><p>Eventually, your body follows the behavior.</p><p>The important point is that <strong>the behavior comes before the result.</strong></p><p>You don&#8217;t wait until you&#8217;re asleep to behave like someone sleeping.</p><p>You behave in the way that supports sleep.</p><p>The same principle can appear in personal development.</p><p>Imagine someone who wants to become a senior engineer.</p><p>They could say:</p><blockquote><p><em>&#8220;I&#8217;ll start thinking like a senior engineer after I get promoted.&#8221;</em></p></blockquote><p>But what if the order is reversed?</p><p>Start asking better questions <strong>before</strong> the promotion.</p><p>Instead of:</p><blockquote><p><em>&#8220;What command fixes this?&#8221;</em></p></blockquote><p>Ask:</p><blockquote><p><em>&#8220;Why did this fail, and how do we prevent it from happening again?&#8221;</em></p></blockquote><p>Instead of:</p><blockquote><p><em>&#8220;How do I deploy this application?&#8221;</em></p></blockquote><p>Ask:</p><blockquote><p><em>&#8220;How should this deployment behave during failure, rollback, scaling, and recovery?&#8221;</em></p></blockquote><p>That is a completely different mindset.</p><p>The job title hasn&#8217;t changed.</p><p>But the <strong>way of thinking has.</strong></p><p>And that matters.</p><div><hr></div><h3>Manifestation Isn&#8217;t Simply Wishful Thinking &#127919;</h3><p>The word <em>manifestation</em> is often used to describe visualizing a desired future.</p><p>But visualization alone doesn&#8217;t create a Kubernetes cluster, launch a business, earn a promotion, or magically deposit money into your bank account.</p><p>Humanity has unfortunately not yet discovered the <code>terraform apply</code> command for life.</p><p>The useful interpretation is <strong>intentional alignment</strong>.</p><p>Your:</p><p><strong>Goal &#8594; Thinking &#8594; Decisions &#8594; Actions &#8594; Habits &#8594; Results</strong></p><p>For example:</p><h3>Goal</h3><p>Become a strong DevOps engineer.</p><p>&#11015;&#65039;</p><h3>Thinking</h3><p>Start thinking about reliability, automation, security, scalability and failure.</p><p>&#11015;&#65039;</p><h3>Decisions</h3><p>Choose projects that expose you to real production-style problems.</p><p>&#11015;&#65039;</p><h3>Actions</h3><p>Build systems, troubleshoot failures, automate repetitive work.</p><p>&#11015;&#65039;</p><h3>Habits</h3><p>Keep learning and improving consistently.</p><p>&#11015;&#65039;</p><h3>Results</h3><p>Your skills gradually begin matching the person you wanted to become.</p><p>That&#8217;s not magic.</p><p>That&#8217;s behavioral consistency.</p><div><hr></div><h3>SECTION 2: Act Like the Person You Want to Become &#128640;</h3><p>One of the strongest ideas from the visual is:</p><h3>&#8220;Act as if.&#8221;</h3><p>But this doesn&#8217;t mean pretending.</p><p>It means asking:</p><blockquote><p><em><strong>&#8220;If I were already the person I want to become, how would I behave today?&#8221;</strong></em></p></blockquote><p>That&#8217;s a much better question.</p><div><hr></div><h3>1. Want to Become a Leader? Start Behaving Like One &#128101;</h3><p>A common mistake is thinking leadership begins with a title.</p><p>It doesn&#8217;t.</p><p>You can demonstrate leadership before becoming a manager.</p><p>A leader doesn&#8217;t simply say:</p><blockquote><p><em>&#8220;This isn&#8217;t my responsibility.&#8221;</em></p></blockquote><p>They ask:</p><blockquote><p><em>&#8220;How can we solve this?&#8221;</em></p></blockquote><p>They communicate during incidents.</p><p>They document what they learn.</p><p>They help teammates.</p><p>They take ownership when something breaks.</p><p>They don&#8217;t disappear when production catches fire.</p><p>And production, being production, eventually catches fire. &#128293;</p><p>The title may come later.</p><p>But the behavior can begin today.</p><div><hr></div><h3>2. Want to Become a Better Engineer? Build Like One &#128187;</h3><p>Suppose you&#8217;re learning Kubernetes.</p><p>You can memorize:</p><ul><li><p>Pods</p></li><li></li><li><p>Deployments</p></li><li></li><li><p>Services</p></li><li></li><li><p>Ingress</p></li><li></li><li><p>ConfigMaps</p></li><li></li><li><p>Secrets</p></li><li></li></ul><p>Or you can start thinking like someone responsible for a real system.</p><p>Ask:</p><ul><li><p>What happens if a pod crashes?</p></li><li></li><li><p>What happens if the node disappears?</p></li><li></li><li><p>How will traffic reach the application?</p></li><li></li><li><p>How will I monitor latency?</p></li><li></li><li><p>How will I detect memory leaks?</p></li><li></li><li><p>How will I roll back?</p></li><li></li><li><p>What happens during deployment failure?</p></li><li></li><li><p>How will secrets be protected?</p></li><li></li></ul><p>The second approach changes everything.</p><p>You aren&#8217;t simply <strong>learning Kubernetes</strong>.</p><p>You&#8217;re learning to <strong>operate systems.</strong></p><p>That&#8217;s the difference between collecting knowledge and developing engineering judgment.</p><div><hr></div><h3>3. Want Financial Growth? Change Your Relationship With Money &#128176;</h3><p>This doesn&#8217;t mean pretending to be wealthy.</p><p>Buying expensive things you cannot afford isn&#8217;t manifestation.</p><p>It&#8217;s just expensive cosplay.</p><p>Instead, ask:</p><blockquote><p><em>&#8220;How would someone financially responsible behave?&#8221;</em></p></blockquote><p>Perhaps they would:</p><ul><li><p>Track expenses.</p></li><li></li><li><p>Build savings.</p></li><li></li><li><p>Invest according to their goals.</p></li><li></li><li><p>Avoid unnecessary debt.</p></li><li></li><li><p>Improve their earning ability.</p></li><li></li><li><p>Learn valuable skills.</p></li><li></li><li><p>Think about long-term consequences.</p></li><li></li></ul><p>The goal isn&#8217;t to <em>look wealthy.</em></p><p>The goal is to develop the behaviors that create financial stability.</p><div><hr></div><h3>4. Want Confidence? Stop Waiting to Feel Confident &#10084;&#65039;</h3><p>This is one of the most important lessons.</p><p>Many people think:</p><blockquote><p><em>Confidence &#8594; Action</em></p></blockquote><p>But very often the sequence is:</p><blockquote><p><em><strong>Action &#8594; Experience &#8594; Competence &#8594; Confidence</strong></em></p></blockquote><p>You don&#8217;t always become confident first.</p><p>Sometimes you become confident because you repeatedly did difficult things.</p><p>You give the presentation.</p><p>You attend the interview.</p><p>You build the project.</p><p>You publish the article.</p><p>You make mistakes.</p><p>You recover.</p><p>You try again.</p><p>Eventually your brain starts saying:</p><blockquote><p><em>&#8220;I&#8217;ve handled difficult things before.&#8221;</em></p></blockquote><p>That&#8217;s where genuine confidence comes from.</p><div><hr></div><h3>SECTION 3: Build the Future Through Small Daily Behaviors &#127793;</h3><p>The biggest mistake with this entire concept is trying to transform your entire life overnight.</p><p>Monday:</p><blockquote><p><em>&#8220;I&#8217;m going to completely reinvent myself.&#8221;</em></p></blockquote><p>Tuesday:</p><blockquote><p><em>&#8220;Maybe next month.&#8221;</em></p></blockquote><p>Humans are remarkably talented at negotiating with their own goals.</p><p>A better approach is much smaller.</p><div><hr></div><h3>The Future-Self Exercise &#127919;</h3><p>Take one goal.</p><p>For example:</p><p><strong>&#8220;I want to become a senior DevOps engineer.&#8221;</strong></p><p>Now ask five questions.</p><h3>1. How would that person think?</h3><p>Probably:</p><ul><li><p>Systemically</p></li><li></li><li><p>Calmly</p></li><li></li><li><p>Analytically</p></li><li></li><li><p>With ownership</p></li><li></li><li><p>With attention to reliability</p></li><li></li></ul><h3>2. What would they learn?</h3><p>Perhaps:</p><ul><li><p>Cloud architecture</p></li><li></li><li><p>Kubernetes</p></li><li></li><li><p>Terraform</p></li><li></li><li><p>CI/CD</p></li><li></li><li><p>Security</p></li><li></li><li><p>Observability</p></li><li></li><li><p>Distributed systems</p></li><li></li></ul><h3>3. What would they stop doing?</h3><p>Maybe:</p><ul><li><p>Memorizing without understanding</p></li><li></li><li><p>Blaming others</p></li><li></li><li><p>Avoiding difficult problems</p></li><li></li><li><p>Ignoring documentation</p></li><li></li><li><p>Repeating the same mistakes</p></li><li></li></ul><h3>4. What would they do every day?</h3><p>Even 60 minutes could matter.</p><p>Build.</p><p>Read.</p><p>Troubleshoot.</p><p>Document.</p><p>Experiment.</p><p>Review.</p><h3>5. What would they do when something fails?</h3><p>This is perhaps the most important question.</p><p>They wouldn&#8217;t immediately conclude:</p><blockquote><p><em>&#8220;I&#8217;m not good enough.&#8221;</em></p></blockquote><p>They would ask:</p><blockquote><p><em><strong>&#8220;What can this failure teach me?&#8221;</strong></em></p></blockquote><p>That&#8217;s the mindset shift.</p><div><hr></div><h3>Your Environment Matters Too &#127757;</h3><p>It&#8217;s difficult to become a different version of yourself while constantly reinforcing the old one.</p><p>If you want to become more technically capable, surround yourself with:</p><ul><li><p>Engineers</p></li><li></li><li><p>Technical communities</p></li><li></li><li><p>Open-source projects</p></li><li></li><li><p>Documentation</p></li><li></li><li><p>Real-world projects</p></li><li></li><li><p>Challenging problems</p></li><li></li></ul><p>If you want to become a better communicator, practice communication.</p><p>If you want to become a writer, write.</p><p>If you want to become a leader, take ownership.</p><p>If you want to become healthier, create routines that support your health.</p><p>Your environment constantly gives your behavior feedback.</p><p>So don&#8217;t just ask:</p><blockquote><p><em>&#8220;What do I want?&#8221;</em></p></blockquote><p>Also ask:</p><blockquote><p><em><strong>&#8220;What environment makes that behavior easier?&#8221;</strong></em></p></blockquote><div><hr></div><h3>The &#8220;Act As If&#8221; Framework &#128640;</h3><p>Here&#8217;s a simple framework you can use every morning.</p><h3>Step 1: Define the future version of yourself</h3><p>Write:</p><blockquote><p><em>&#8220;I want to become someone who ______.&#8221;</em></p></blockquote><p>Be specific.</p><p>Not:</p><blockquote><p><em>&#8220;I want to be successful.&#8221;</em></p></blockquote><p>Instead:</p><blockquote><p><em>&#8220;I want to become a technically strong engineer who can design, deploy and troubleshoot production systems.&#8221;</em></p></blockquote><div><hr></div><h3>Step 2: Identify their behaviors</h3><p>Ask:</p><blockquote><p><em>&#8220;What does this person do differently from me?&#8221;</em></p></blockquote><p>Write 3&#8211;5 behaviors.</p><div><hr></div><h3>Step 3: Start with one behavior</h3><p>Don&#8217;t attempt 15 changes simultaneously.</p><p>Pick one.</p><p>For example:</p><p><strong>One hour of hands-on technical work every day.</strong></p><div><hr></div><h3>Step 4: Measure actions, not fantasies &#128202;</h3><p>Don&#8217;t measure:</p><blockquote><p><em>&#8220;Did I feel successful today?&#8221;</em></p></blockquote><p>Measure:</p><blockquote><p><em>&#8220;Did I do the work?&#8221;</em></p></blockquote><p>That&#8217;s much more useful.</p><div><hr></div><h3>Step 5: Repeat long enough for identity to change</h3><p>One day doesn&#8217;t matter much.</p><p>One month starts becoming interesting.</p><p>Several months of consistent behavior can create a very different person.</p><div><hr></div><h3>But Don&#8217;t Confuse Confidence With Delusion &#9888;&#65039;</h3><p>There is an important boundary here.</p><p>&#8220;Act like your future self&#8221; should <strong>not</strong> mean:</p><ul><li><p>Pretending you have skills you don&#8217;t have</p></li><li></li><li><p>Lying on your resume</p></li><li></li><li><p>Claiming experience you never gained</p></li><li></li><li><p>Ignoring weaknesses</p></li><li></li><li><p>Spending money to look successful</p></li><li></li><li><p>Believing effort guarantees a specific outcome</p></li><li></li></ul><p>Reality still exists.</p><p>Unfortunately, reality remains stubbornly employed.</p><p>The healthy version is:</p><blockquote><p><em><strong>Behave according to the person you want to become while honestly acknowledging where you are today.</strong></em></p></blockquote><p>You can say:</p><blockquote><p><em>&#8220;I don&#8217;t know this yet.&#8221;</em></p></blockquote><p>And still behave like an engineer who knows how to learn.</p><p>You can say:</p><blockquote><p><em>&#8220;I&#8217;m not confident yet.&#8221;</em></p></blockquote><p>And still take the presentation.</p><p>You can say:</p><blockquote><p><em>&#8220;I haven&#8217;t worked on production Kubernetes.&#8221;</em></p></blockquote><p>And still build production-style projects to develop the relevant skills.</p><p>That&#8217;s not pretending.</p><p>That&#8217;s <strong>growth.</strong></p><div><hr></div><h3>Final Thought &#128173;</h3><p>Maybe the goal isn&#8217;t to convince yourself that you&#8217;ve already achieved everything.</p><p>Maybe the goal is simpler.</p><p><strong>Start behaving today in ways that your future self will thank you for.</strong></p><p>Want to become healthier?</p><p>Build healthier habits.</p><p>Want to become financially stable?</p><p>Make financially responsible decisions.</p><p>Want to become a better engineer?</p><p>Solve harder problems.</p><p>Want to become a leader?</p><p>Take ownership before someone gives you the title.</p><p>Want to become confident?</p><p>Do difficult things repeatedly.</p><p>The future doesn&#8217;t suddenly appear one morning.</p><p>It is quietly assembled through thousands of ordinary decisions.</p><p>So perhaps <strong>&#8220;fake it &#8217;til you make it&#8221;</strong> needs a better definition:</p><blockquote><p><em><strong>Don&#8217;t fake the result.<br>Practice the identity.<br>Build the habits.<br>Do the work.<br>Let the results catch up.</strong> &#128640;</em></p></blockquote><p>And sometimes, the person you&#8217;re trying to become isn&#8217;t waiting somewhere in the future.</p><p>They&#8217;re being built by what you repeatedly do <strong>today.</strong> &#127793;</p><div><hr></div><h3>&#128273; Key Takeaways</h3><ul><li><p>&#127919; Define the person you want to become.</p></li><li></li><li><p>&#129504; Think about how that person would approach problems.</p></li><li></li><li><p>&#128640; Start practicing those behaviors before receiving the title or reward.</p></li><li></li><li><p>&#128170; Build confidence through action and experience.</p></li><li></li><li><p>&#127793; Focus on consistent habits rather than overnight transformation.</p></li><li></li><li><p>&#128176; Don&#8217;t confuse looking successful with building a successful life.</p></li><li></li><li><p>&#9888;&#65039; Stay grounded in reality while deliberately moving toward your goals.</p></li><li></li><li><p>&#10084;&#65039; Don&#8217;t wait for motivation. Build systems that make progress easier.</p></li><li></li></ul><h3>Hashtags</h3><p>#PersonalGrowth #Mindset #SelfImprovement #SuccessMindset #CareerGrowth #Leadership #Productivity #Confidence #DevOps #SoftwareEngineering #EngineeringMindset #ContinuousImprovement #Manifestation #FutureSelf</p><h3>Follow Me</h3><p>If you enjoyed this article and would like more practical DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🚀 Building an Internal Developer Portal with Backstage: A Hands-On DevOps Walkthrough]]></title><description><![CDATA[Modern engineering organizations rarely suffer from a lack of tools.]]></description><link>https://arvindverma021.substack.com/p/building-an-internal-developer-portal</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/building-an-internal-developer-portal</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Mon, 31 Aug 2026 09:28:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cbbf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!cbbf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!cbbf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2054652,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213518967?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cbbf!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F636b8ee2-d951-408b-8969-6e786541f1c0_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Modern engineering organizations rarely suffer from a lack of tools.</p><p>They suffer from <strong>too many tools</strong>.</p><p>Developers may need to jump between:</p><ul><li><p>GitHub/GitLab</p></li><li><p>Kubernetes</p></li><li><p>Jenkins or GitHub Actions</p></li><li><p>AWS/Azure/GCP</p></li><li><p>Grafana</p></li><li><p>Argo CD</p></li><li><p>Jira</p></li><li><p>SonarQube</p></li><li><p>Documentation</p></li><li><p>Service ownership information</p></li><li><p>Deployment dashboards</p></li></ul><p>And somewhere in the middle of all this, someone asks:</p><blockquote><p>&#8220;Where is the deployment status for this service?&#8221;</p></blockquote><p>Then everyone starts opening browser tabs like they&#8217;re trying to launch a satellite. &#128640;</p><p>This is where an <strong>Internal Developer Portal (IDP)</strong> becomes extremely useful.</p><p>In this article, we&#8217;ll build a practical developer portal using <strong>Backstage</strong>, connect it to a sample service, add documentation, create a software template, and expose Kubernetes information.</p><p>The goal isn&#8217;t just to understand Backstage.</p><p>The goal is to understand how you can build something resembling an internal platform used by engineering teams.</p><div><hr></div><h1>SECTION 1: What Are We Actually Building? &#127959;&#65039;</h1><h2>What is Backstage?</h2><p>Backstage is an open-source developer portal originally created at Spotify.</p><p>Its architecture revolves around a central platform where developers can discover software components, documentation, templates and integrations.</p><p>Backstage provides capabilities such as:</p><ul><li><p>Software Catalog</p></li><li><p>Software Templates</p></li><li><p>TechDocs</p></li><li><p>Plugins</p></li><li><p>Kubernetes integration</p></li><li><p>API documentation</p></li><li><p>Ownership metadata</p></li><li><p>Developer portal homepage</p></li></ul><p>Backstage&#8217;s official architecture describes the Software Catalog as a searchable UI for software entities, while Software Templates can create components from predefined skeletons. (<a href="https://backstage.io/docs/overview/technical-overview/?utm_source=chatgpt.com">Backstage</a>)</p><p>The idea is simple:</p><pre><code><code>                    INTERNAL DEVELOPER PORTAL
                              |
       +----------------------+----------------------+
       |                      |                      |
   Software Catalog        Templates             TechDocs
       |                      |                      |
   Services/APIs         Create Service        Documentation
       |
       +------------------+
       |                  |
   Kubernetes          GitHub
       |                  |
   Deployments        Source Code
       |
   Monitoring</code></code></pre><p>Instead of asking developers to remember where everything lives, the portal becomes the <strong>front door to engineering</strong>.</p><div><hr></div><h2>The Project We&#8217;ll Build</h2><p>We&#8217;ll create:</p><pre><code><code>Backstage Developer Portal
&#9474;
&#9500;&#9472;&#9472; Software Catalog
&#9474;   &#9500;&#9472;&#9472; frontend-service
&#9474;   &#9500;&#9472;&#9472; backend-service
&#9474;   &#9492;&#9472;&#9472; PostgreSQL
&#9474;
&#9500;&#9472;&#9472; Software Templates
&#9474;   &#9492;&#9472;&#9472; Node.js Service Template
&#9474;
&#9500;&#9472;&#9472; TechDocs
&#9474;   &#9492;&#9472;&#9472; Service Documentation
&#9474;
&#9500;&#9472;&#9472; Kubernetes
&#9474;   &#9492;&#9472;&#9472; Deployment / Pods / Services
&#9474;
&#9492;&#9472;&#9472; GitHub
    &#9492;&#9472;&#9472; Repository Links</code></code></pre><p>A simplified architecture:</p><pre><code><code>                    Developers
                         |
                         v
              +--------------------+
              |     BACKSTAGE      |
              | Developer Portal    |
              +---------+----------+
                        |
        +---------------+----------------+
        |               |                |
        v               v                v
   Software          TechDocs       Templates
    Catalog
        |
   +----+---------------------+
   |                          |
   v                          v
GitHub/GitLab             Kubernetes
                              |
                    +---------+---------+
                    |         |         |
                   Pods    Services   Deployments</code></code></pre><p>This is where the project becomes interesting.</p><p>We&#8217;re not just installing a UI.</p><p>We&#8217;re creating a <strong>developer experience layer over infrastructure</strong>.</p><div><hr></div><h1>SECTION 2: Build the Backstage Platform &#128736;&#65039;</h1><h2>Step 1: Install the Prerequisites</h2><p>You&#8217;ll need:</p><pre><code><code>node --version
npm --version
git --version
docker --version
kubectl version --client</code></code></pre><p>Backstage currently recommends using an <strong>Active LTS Node.js release</strong> for creating applications. (<a href="https://backstage.io/docs/frontend-system/building-apps/index/?utm_source=chatgpt.com">Backstage</a>)</p><p>If you&#8217;re using Ubuntu/WSL:</p><pre><code><code>sudo apt update
sudo apt install -y git curl</code></code></pre><p>Install Node.js using your preferred Node version manager.</p><p>Then verify:</p><pre><code><code>node -v
npm -v</code></code></pre><div><hr></div><h2>Step 2: Create the Backstage Application</h2><p>Create the application:</p><pre><code><code>npx @backstage/create-app@latest</code></code></pre><p>The wizard will ask for the application name.</p><p>Use:</p><pre><code><code>internal-developer-portal</code></code></pre><p>Backstage&#8217;s current official scaffolding documentation uses this <code>create-app</code> approach. (<a href="https://backstage.io/docs/frontend-system/building-apps/index/?utm_source=chatgpt.com">Backstage</a>)</p><p>Move into the project:</p><pre><code><code>cd internal-developer-portal</code></code></pre><p>Install dependencies if necessary:</p><pre><code><code>yarn install</code></code></pre><p>Start Backstage:</p><pre><code><code>yarn dev</code></code></pre><p>You should now have:</p><pre><code><code>Frontend: http://localhost:3000
Backend:  http://localhost:7007</code></code></pre><p>The standard development ports are 3000 and 7007. (<a href="https://backstage.io/docs/golden-path/create-app/npx-create-app/?utm_source=chatgpt.com">Backstage</a>)</p><p>Open:</p><p>http://localhost:3000</p><p>And congratulations.</p><p>You have created another web application.</p><p>Humanity survives another npm installation. &#128516;</p><div><hr></div><h1>Step 3: Understand the Project Structure</h1><p>You&#8217;ll see something similar to:</p><pre><code><code>internal-developer-portal/
&#9474;
&#9500;&#9472;&#9472; app-config.yaml
&#9500;&#9472;&#9472; catalog-info.yaml
&#9500;&#9472;&#9472; package.json
&#9474;
&#9500;&#9472;&#9472; packages/
&#9474;   &#9500;&#9472;&#9472; app/
&#9474;   &#9492;&#9472;&#9472; backend/
&#9474;
&#9492;&#9472;&#9472; plugins/</code></code></pre><p>The important files are:</p><h3><code>app-config.yaml</code></h3><p>Main Backstage configuration.</p><h3><code>catalog-info.yaml</code></h3><p>Defines software entities.</p><h3><code>packages/app</code></h3><p>Frontend application.</p><h3><code>packages/backend</code></h3><p>Backend services.</p><p>The official Backstage scaffolding documentation describes this structure and the responsibilities of these files. (<a href="https://backstage.io/docs/golden-path/create-app/npx-create-app/?utm_source=chatgpt.com">Backstage</a>)</p><div><hr></div><h1>Step 4: Register Your First Service</h1><p>Create a service repository.</p><p>For example:</p><pre><code><code>payment-service</code></code></pre><p>Inside it:</p><pre><code><code>payment-service/
&#9500;&#9472;&#9472; src/
&#9500;&#9472;&#9472; package.json
&#9500;&#9472;&#9472; Dockerfile
&#9492;&#9472;&#9472; catalog-info.yaml</code></code></pre><p>Create:</p><pre><code><code>apiVersion: backstage.io/v1alpha1
kind: Component

metadata:
  name: payment-service
  description: Payment processing service
  tags:
    - nodejs
    - backend
    - payments

spec:
  type: service
  lifecycle: production
  owner: platform-team</code></code></pre><p>Now Backstage understands that this repository represents a software component.</p><div><hr></div><h1>Step 5: Add GitHub Metadata</h1><p>You can add repository information:</p><pre><code><code>metadata:
  name: payment-service
  description: Payment processing service

  annotations:
    github.com/project-slug: my-org/payment-service</code></code></pre><p>You can also add useful links:</p><pre><code><code>metadata:
  links:
    - url: https://github.com/my-org/payment-service
      title: Repository
      icon: github

    - url: https://grafana.example.com
      title: Grafana
      icon: dashboard</code></code></pre><p>Now developers can access important resources from one place.</p><div><hr></div><h1>Step 6: Add Kubernetes Information</h1><p>This is where the portal starts becoming particularly useful for DevOps engineers.</p><p>Add:</p><pre><code><code>annotations:
  backstage.io/kubernetes-id: payment-service</code></code></pre><p>The Backstage Kubernetes plugin supports the <code>backstage.io/kubernetes-id</code> annotation for associating Kubernetes resources with catalog entities. (<a href="https://backstage.io/docs/features/kubernetes/configuration/?utm_source=chatgpt.com">Backstage</a>)</p><p>You can also specify a namespace:</p><pre><code><code>annotations:
  backstage.io/kubernetes-id: payment-service
  backstage.io/kubernetes-namespace: production</code></code></pre><p>Now Backstage can associate the catalog entity with Kubernetes resources.</p><div><hr></div><h1>Step 7: Install Kubernetes Integration</h1><p>From the Backstage root:</p><pre><code><code>yarn --cwd packages/app add @backstage/plugin-kubernetes</code></code></pre><p>This is the official installation approach documented for the Kubernetes plugin. (<a href="https://backstage.io/docs/features/kubernetes/installation/?utm_source=chatgpt.com">Backstage</a>)</p><p>You&#8217;ll also need Kubernetes backend configuration and appropriate credentials/access depending on your environment.</p><p>For local development, you could use:</p><pre><code><code>kubectl config get-contexts</code></code></pre><p>Check your current context:</p><pre><code><code>kubectl config current-context</code></code></pre><p>Then verify:</p><pre><code><code>kubectl get nodes</code></code></pre><p>If that works, your local Kubernetes access is alive.</p><p>Which, considering Kubernetes, is already a small victory.</p><div><hr></div><h1>Step 8: Create the Kubernetes Deployment</h1><p>Example:</p><pre><code><code>apiVersion: apps/v1
kind: Deployment

metadata:
  name: payment-service

  labels:
    backstage.io/kubernetes-id: payment-service

spec:
  replicas: 2

  selector:
    matchLabels:
      app: payment-service

  template:
    metadata:
      labels:
        app: payment-service
        backstage.io/kubernetes-id: payment-service

    spec:
      containers:
        - name: payment-service
          image: nginx:latest

          ports:
            - containerPort: 80</code></code></pre><p>Apply:</p><pre><code><code>kubectl apply -f deployment.yaml</code></code></pre><p>Check:</p><pre><code><code>kubectl get deployments</code></code></pre><pre><code><code>kubectl get pods</code></code></pre><pre><code><code>kubectl get svc</code></code></pre><p>Now your infrastructure exists independently of Backstage.</p><p>Backstage becomes the <strong>visibility layer</strong>.</p><p>That&#8217;s an important distinction.</p><div><hr></div><h1>Step 9: Add TechDocs &#128218;</h1><p>Documentation should live alongside the code.</p><p>Create:</p><pre><code><code>payment-service/
&#9474;
&#9500;&#9472;&#9472; catalog-info.yaml
&#9500;&#9472;&#9472; mkdocs.yml
&#9474;
&#9492;&#9472;&#9472; docs/
    &#9492;&#9472;&#9472; index.md</code></code></pre><p>Create <code>mkdocs.yml</code>:</p><pre><code><code>site_name: Payment Service

nav:
  - Home: index.md

plugins:
  - techdocs-core</code></code></pre><p>Then:</p><pre><code><code>docs/index.md</code></code></pre><p>Example:</p><pre><code><code># Payment Service

## Overview

Payment Service handles payment processing.

## Architecture

The service runs on Kubernetes.

## Deployment

Deployment is handled through CI/CD.

## Monitoring

Metrics are available through Prometheus.

## Troubleshooting

Check:

- Pod status
- Application logs
- CPU
- Memory
- Database connectivity</code></code></pre><p>Backstage TechDocs uses a docs-as-code model, keeping Markdown documentation close to the source code. (<a href="https://backstage.io/docs/features/techdocs/creating-and-publishing/?utm_source=chatgpt.com">Backstage</a>)</p><p>Add this annotation:</p><pre><code><code>metadata:
  annotations:
    backstage.io/techdocs-ref: dir:.</code></code></pre><p>Backstage recommends the <code>dir:.</code> reference for most repositories where the documentation lives alongside the catalog entity. (<a href="https://backstage.io/docs/features/techdocs/how-to-guides/?utm_source=chatgpt.com">Backstage</a>)</p><p>You can preview TechDocs locally:</p><pre><code><code>npx @techdocs/cli serve</code></code></pre><p>The official TechDocs documentation provides this command for local previewing. (<a href="https://backstage.io/docs/features/techdocs/creating-and-publishing/?utm_source=chatgpt.com">Backstage</a>)</p><div><hr></div><h1>SECTION 3: Turn It Into a Real Internal Developer Platform &#128640;</h1><p>At this point we have:</p><pre><code><code>Backstage
   |
   +-- Catalog
   |
   +-- Kubernetes
   |
   +-- TechDocs
   |
   +-- GitHub</code></code></pre><p>But there&#8217;s one major capability missing.</p><p><strong>Self-service.</strong></p><p>Imagine a developer wants to create a new service.</p><p>Without an IDP:</p><pre><code><code>Create repository
       &#8595;
Copy Dockerfile
       &#8595;
Create CI/CD
       &#8595;
Create Kubernetes manifests
       &#8595;
Create monitoring
       &#8595;
Create documentation
       &#8595;
Configure ownership
       &#8595;
Configure deployment</code></code></pre><p>That&#8217;s a lot of repetitive work.</p><p>Backstage Software Templates allow organizations to provide reusable scaffolding workflows. (<a href="https://backstage.io/docs/features/software-templates/adding-templates/?utm_source=chatgpt.com">Backstage</a>)</p><div><hr></div><h1>Step 10: Create a Software Template</h1><p>Create:</p><pre><code><code>templates/
&#9492;&#9472;&#9472; node-service/
    &#9500;&#9472;&#9472; template.yaml
    &#9492;&#9472;&#9472; skeleton/
        &#9500;&#9472;&#9472; package.json
        &#9500;&#9472;&#9472; Dockerfile
        &#9492;&#9472;&#9472; catalog-info.yaml</code></code></pre><p>Example <code>template.yaml</code>:</p><pre><code><code>apiVersion: scaffolder.backstage.io/v1beta3
kind: Template

metadata:
  name: node-service-template
  title: Create Node.js Service
  description: Create a production-ready Node.js service

spec:
  owner: platform-team
  type: service

  parameters:

    - title: Service Information
      required:
        - name
        - description

      properties:

        name:
          title: Service Name
          type: string

        description:
          title: Description
          type: string

  steps:

    - id: fetch
      name: Fetch Template
      action: fetch:template

      input:
        url: ./skeleton

        values:
          name: ${{ parameters.name }}
          description: ${{ parameters.description }}

    - id: publish
      name: Publish Repository
      action: publish:github

      input:
        repoUrl: github.com?owner=my-org&amp;repo=${{ parameters.name }}
        description: ${{ parameters.description }}

    - id: register
      name: Register Component
      action: catalog:register

      input:
        repoContentsUrl: ${{ steps.publish.output.repoContentsUrl }}
        catalogInfoPath: /catalog-info.yaml</code></code></pre><p>Backstage templates are YAML-defined workflows containing parameters and actions. (<a href="https://backstage.io/docs/features/software-templates/writing-templates/?utm_source=chatgpt.com">Backstage</a>)</p><div><hr></div><h1>Step 11: Create the Service Skeleton</h1><p>Inside:</p><pre><code><code>skeleton/</code></code></pre><p>Create:</p><pre><code><code>{
  "name": "${{ values.name }}",
  "version": "1.0.0",
  "scripts": {
    "start": "node src/index.js"
  }
}</code></code></pre><p>Create:</p><pre><code><code>src/index.js</code></code></pre><p>Example:</p><pre><code><code>const http = require("http");

const port = process.env.PORT || 8080;

const server = http.createServer((req, res) =&gt; {
  res.writeHead(200, {
    "Content-Type": "application/json"
  });

  res.end(JSON.stringify({
    service: "${{ values.name }}",
    status: "healthy"
  }));
});

server.listen(port, () =&gt; {
  console.log(`Service running on ${port}`);
});</code></code></pre><p>Dockerfile:</p><pre><code><code>FROM node:22-alpine

WORKDIR /app

COPY package*.json ./

RUN npm install --omit=dev

COPY . .

EXPOSE 8080

CMD ["npm", "start"]</code></code></pre><p>Now your template can generate a working service rather than an empty repository with a motivational README.</p><div><hr></div><h1>Step 12: Add the Generated Catalog Metadata</h1><p>Inside the skeleton:</p><pre><code><code>apiVersion: backstage.io/v1alpha1
kind: Component

metadata:
  name: ${{ values.name }}
  description: ${{ values.description }}

spec:
  type: service
  lifecycle: experimental
  owner: platform-team</code></code></pre><p>The generated service can then automatically register itself in Backstage.</p><p>That gives you:</p><pre><code><code>Developer
    |
    v
Backstage
    |
    v
Create Service
    |
    v
Software Template
    |
    +----&gt; Git Repository
    |
    +----&gt; Catalog Registration
    |
    +----&gt; Documentation
    |
    +----&gt; CI/CD
    |
    +----&gt; Kubernetes</code></code></pre><p>That&#8217;s the real value of an Internal Developer Portal.</p><div><hr></div><h1>Step 13: Connect CI/CD</h1><p>A mature implementation would generate CI/CD configuration along with the application.</p><p>For GitHub Actions, the template could generate:</p><pre><code><code>.github/
&#9492;&#9472;&#9472; workflows/
    &#9492;&#9472;&#9472; ci.yaml</code></code></pre><p>Example:</p><pre><code><code>name: CI

on:
  push:
    branches:
      - main

jobs:

  build:
    runs-on: ubuntu-latest

    steps:

      - name: Checkout
        uses: actions/checkout@v4

      - name: Setup Node
        uses: actions/setup-node@v4
        with:
          node-version: 22

      - name: Install
        run: npm ci

      - name: Test
        run: npm test

      - name: Build Docker image
        run: |
          docker build \
            -t payment-service:${{ github.sha }} .</code></code></pre><p>A production implementation can continue with:</p><pre><code><code>Build
 &#8595;
Unit Tests
 &#8595;
SAST
 &#8595;
Dependency Scan
 &#8595;
Container Scan
 &#8595;
Push Image
 &#8595;
Deploy
 &#8595;
Kubernetes
 &#8595;
Observability</code></code></pre><div><hr></div><h1>The Final Developer Experience &#127919;</h1><p>Once everything is connected, the developer experience becomes something like:</p><pre><code><code>                 BACKSTAGE
                     |
        +------------+------------+
        |            |            |
      Catalog      Create       Docs
        |          Service         |
        |            |             |
        v            v             v
    Services      Template      TechDocs
        |
   +----+-------+----------+
   |            |          |
 GitHub      CI/CD    Kubernetes
   |            |          |
   +------------+----------+
                |
          Observability
                |
       Prometheus / Grafana</code></code></pre><p>A developer can open one portal and answer:</p><p><strong>What services do we have?</strong></p><p><strong>Who owns them?</strong></p><p><strong>Where is the source code?</strong></p><p><strong>How do I deploy it?</strong></p><p><strong>What Kubernetes resources are running?</strong></p><p><strong>Where is the documentation?</strong></p><p><strong>How do I create another service?</strong></p><p>That&#8217;s a dramatically better developer experience than asking five different teams for five different URLs.</p><div><hr></div><h1>Production Considerations &#9888;&#65039;</h1><p>A local Backstage installation is not the same thing as a production developer platform.</p><p>Before deploying internally, think about:</p><h3>Authentication</h3><p>Integrate with your enterprise identity provider.</p><p>Examples:</p><pre><code><code>Azure AD / Entra ID
Okta
GitHub
Google
OIDC</code></code></pre><h3>Authorization</h3><p>Developers should not automatically receive administrative access.</p><p>Define:</p><pre><code><code>Developer
Platform Engineer
Service Owner
SRE
Admin</code></code></pre><h3>Secrets</h3><p>Never commit:</p><pre><code><code>AWS_ACCESS_KEY_ID
AWS_SECRET_ACCESS_KEY
GitHub tokens
Database passwords</code></code></pre><p>Use your organization&#8217;s secret management solution.</p><h3>Kubernetes Access</h3><p>Don&#8217;t give Backstage unrestricted cluster-admin access merely because it&#8217;s convenient.</p><p>That&#8217;s how &#8220;internal developer portal&#8221; becomes &#8220;internal incident generator.&#8221;</p><p>Use least privilege.</p><h3>Database</h3><p>For evaluation, the default setup is useful.</p><p>For production, design the persistence layer, backups, migrations and high availability properly.</p><div><hr></div><h1>What This Project Demonstrates on a DevOps Resume &#128188;</h1><p>If implemented properly, this isn&#8217;t merely a &#8220;Backstage project.&#8221;</p><p>It demonstrates knowledge across multiple areas:</p><pre><code><code>Backstage
   +
Developer Experience
   +
Kubernetes
   +
CI/CD
   +
Git
   +
Infrastructure
   +
Documentation
   +
Platform Engineering
   +
Automation</code></code></pre><p>A strong project description could be:</p><blockquote><p><strong>Built an Internal Developer Platform using Backstage to provide centralized service discovery, Kubernetes visibility, TechDocs, Git repository integration and self-service software scaffolding. Automated service creation through reusable templates and integrated CI/CD and Kubernetes workflows.</strong></p></blockquote><p>That&#8217;s considerably stronger than:</p><blockquote><p>&#8220;Created a Backstage dashboard.&#8221;</p></blockquote><p>The second statement describes a screen.</p><p>The first describes a <strong>platform</strong>.</p><div><hr></div><h1>Key Takeaways &#129504;</h1><p>An Internal Developer Portal shouldn&#8217;t simply become another dashboard developers are forced to visit.</p><p>The real objective is to reduce developer friction.</p><p>A good IDP should provide:</p><p>&#9989; Centralized software catalog<br>&#9989; Clear ownership<br>&#9989; Self-service workflows<br>&#9989; Standardized project templates<br>&#9989; Kubernetes visibility<br>&#9989; Documentation close to code<br>&#9989; CI/CD integration<br>&#9989; Consistent engineering standards<br>&#9989; Discoverability of internal services<br>&#9989; A paved road for developers</p><p>Backstage provides the foundation, but the real engineering work is in integrating it with your organization&#8217;s existing ecosystem.</p><p>The most important lesson is this:</p><blockquote><p><strong>A developer portal is not primarily a UI project. It is a platform engineering project.</strong></p></blockquote><p>The UI is simply where developers see the result.</p><p>Behind it are APIs, Kubernetes, Git repositories, CI/CD pipelines, authentication, authorization, templates, documentation, infrastructure and automation.</p><p>And that is where things get interesting. &#128640;</p><div><hr></div><h2>Hashtags</h2><p>#Backstage #InternalDeveloperPlatform #PlatformEngineering #DevOps #Kubernetes #CICD #DeveloperExperience #DevSecOps #CloudEngineering #AWS #GitOps #SRE #SoftwareEngineering #TechDocs</p><h2>Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br>https://www.linkedin.com/in/arvindverma021/</p><p><em>Commands and configuration examples above are intended as a practical learning walkthrough. Backstage plugins and configuration evolve, so check the current official documentation when implementing this in a production environment.</em></p>]]></content:encoded></item><item><title><![CDATA[🚀 Building a Production-Style Kubernetes Cluster with Full Observability: Prometheus, Grafana, Loki, Fluent Bit, Tempo & Alertmanager]]></title><description><![CDATA[Running an application on Kubernetes is relatively easy. Running it reliably in production is a completely different story.]]></description><link>https://arvindverma021.substack.com/p/building-a-production-style-kubernetes</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/building-a-production-style-kubernetes</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Mon, 31 Aug 2026 08:59:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Swr2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Swr2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 424w, /__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 848w, /__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Swr2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png" width="864" height="1821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1821,&quot;width&quot;:864,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1697330,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213517014?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 424w, /__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 848w, /__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Swr2!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda8b5b72-d9dc-4aea-b5d2-60b6de7ead67_864x1821.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>You can deploy your application successfully, see all Pods in <code>Running</code> state, and still have absolutely no idea why users are experiencing latency, why a service is returning 500 errors, why Pods restarted overnight, or which deployment caused the problem.</p><p>That is where <strong>observability</strong> becomes essential.</p><p>In this walkthrough, we will build a production-style Kubernetes observability platform with:</p><ul><li><p>&#9784;&#65039; Kubernetes</p></li><li><p>&#9973; Helm</p></li><li><p>&#128202; Prometheus</p></li><li><p>&#128200; Grafana</p></li><li><p>&#128221; Loki</p></li><li><p>&#128666; Fluent Bit</p></li><li><p>&#128270; Tempo</p></li><li><p>&#128680; Alertmanager</p></li><li><p>&#127760; NGINX Ingress</p></li><li><p>&#128272; cert-manager</p></li><li><p>&#128737;&#65039; SLO-based alerting</p></li><li><p>&#128051; A microservices application</p></li><li><p>&#128225; Metrics + Logs + Traces</p></li></ul><p>The architecture we are building looks like this:</p><pre><code><code>                         USERS
                           |
                           v
                  +----------------+
                  |  NGINX INGRESS |
                  |   + TLS        |
                  +-------+--------+
                          |
                          v
             +--------------------------+
             |    MICROSERVICES APP     |
             |                          |
             | Frontend                 |
             | Product Service          |
             | Order Service            |
             +------------+-------------+
                          |
                 +--------+--------+
                 |                 |
                 v                 v
              Redis           PostgreSQL
                 |
                 |
        +--------+--------+--------+
        |                 |        |
        v                 v        v
    Prometheus          Loki     Tempo
        |                 |        |
        +-----------------+--------+
                          |
                          v
                      Grafana
                          |
                          v
              Dashboards + Alerts
                          |
                          v
                Alertmanager</code></code></pre><p>And the best part?</p><p>We are going to build it <strong>step by step with commands</strong>, rather than waving at an architecture diagram and pretending the infrastructure deployed itself. &#128516;</p><div><hr></div><h1>SECTION 1: &#128640; BUILD THE KUBERNETES FOUNDATION</h1><h2>1. What Are We Building?</h2><p>The objective is to create a Kubernetes environment where we can answer three fundamental questions:</p><h3>Metrics</h3><p><strong>&#8220;Is the system healthy?&#8221;</strong></p><p>Prometheus answers questions such as:</p><pre><code><code>CPU usage?
Memory usage?
Request rate?
Error rate?
Latency?
Pod restarts?</code></code></pre><h3>Logs</h3><p><strong>&#8220;What actually happened?&#8221;</strong></p><p>Loki and Fluent Bit help us investigate:</p><pre><code><code>Application errors
Container logs
Stack traces
Warnings
Request failures</code></code></pre><h3>Traces</h3><p><strong>&#8220;Where did the request spend its time?&#8221;</strong></p><p>Tempo allows us to follow requests across services.</p><p>For example:</p><pre><code><code>User
 |
 v
Frontend
 |
 v
Product Service
 |
 v
Order Service
 |
 v
PostgreSQL</code></code></pre><p>If the request takes 4 seconds, traces can help determine <strong>which service caused the delay</strong>.</p><p>This is the difference between simply monitoring infrastructure and actually understanding an application.</p><div><hr></div><h2>2. Install the Required Tools</h2><p>For a local implementation, we can use:</p><ul><li><p>Docker</p></li><li><p>kubectl</p></li><li><p>Kind</p></li><li><p>Helm</p></li></ul><p>Verify Docker:</p><pre><code><code>docker --version</code></code></pre><p>Verify kubectl:</p><pre><code><code>kubectl version --client</code></code></pre><p>Verify Kind:</p><pre><code><code>kind version</code></code></pre><p>Verify Helm:</p><pre><code><code>helm version</code></code></pre><p>If all four commands work, create the cluster.</p><div><hr></div><h2>3. Create the Kubernetes Cluster</h2><p>Create a project directory:</p><pre><code><code>mkdir kubernetes-observability
cd kubernetes-observability</code></code></pre><p>Create a Kind cluster:</p><pre><code><code>kind create cluster --name observability</code></code></pre><p>Check the cluster:</p><pre><code><code>kubectl cluster-info</code></code></pre><p>Check nodes:</p><pre><code><code>kubectl get nodes</code></code></pre><p>Expected result:</p><pre><code><code>NAME                         STATUS   ROLES
observability-control-plane  Ready    control-plane</code></code></pre><p>Check Kubernetes namespaces:</p><pre><code><code>kubectl get namespaces</code></code></pre><div><hr></div><h2>4. Create Application Namespace</h2><p>Instead of putting everything into the default namespace, create a dedicated namespace.</p><pre><code><code>kubectl create namespace production</code></code></pre><p>Verify:</p><pre><code><code>kubectl get namespace production</code></code></pre><p>Set it as your default namespace:</p><pre><code><code>kubectl config set-context --current --namespace=production</code></code></pre><p>Now:</p><pre><code><code>kubectl get pods</code></code></pre><p>will automatically query the <code>production</code> namespace.</p><div><hr></div><h2>5. Install Helm</h2><p>Add the Prometheus community repository:</p><pre><code><code>helm repo add prometheus-community https://prometheus-community.github.io/helm-charts</code></code></pre><p>Add Grafana:</p><pre><code><code>helm repo add grafana https://grafana.github.io/helm-charts</code></code></pre><p>Add Bitnami:</p><pre><code><code>helm repo add bitnami https://charts.bitnami.com/bitnami</code></code></pre><p>Update repositories:</p><pre><code><code>helm repo update</code></code></pre><p>Verify:</p><pre><code><code>helm repo list</code></code></pre><div><hr></div><h2>6. Deploy a Microservices Application</h2><p>The architecture in the infographic uses a microservices application similar to a Sock Shop.</p><p>Create an application namespace:</p><pre><code><code>kubectl create namespace sock-shop</code></code></pre><p>If you have the application&#8217;s Kubernetes manifests:</p><pre><code><code>kubectl apply -f manifests/ -n sock-shop</code></code></pre><p>Check the Pods:</p><pre><code><code>kubectl get pods -n sock-shop</code></code></pre><p>Check deployments:</p><pre><code><code>kubectl get deployments -n sock-shop</code></code></pre><p>Check services:</p><pre><code><code>kubectl get services -n sock-shop</code></code></pre><p>Check everything:</p><pre><code><code>kubectl get all -n sock-shop</code></code></pre><p>At this stage, we have an application.</p><p>But we still don&#8217;t know much about it.</p><p>And that is exactly the problem observability solves.</p><div><hr></div><h1>SECTION 2: &#128202; ADD METRICS, LOGS, TRACES AND DASHBOARDS</h1><h2>7. Install Prometheus + Grafana + Alertmanager</h2><p>We could install every component individually.</p><p>But Helm gives us a much cleaner approach.</p><p>Install the kube-prometheus-stack:</p><pre><code><code>helm install monitoring \
  prometheus-community/kube-prometheus-stack \
  -n monitoring \
  --create-namespace</code></code></pre><p>Check the deployment:</p><pre><code><code>kubectl get pods -n monitoring</code></code></pre><p>You should see components such as:</p><pre><code><code>prometheus
grafana
alertmanager
node-exporter
kube-state-metrics</code></code></pre><p>Check Helm:</p><pre><code><code>helm list -n monitoring</code></code></pre><div><hr></div><h2>8. Check Prometheus</h2><p>Find the Prometheus service:</p><pre><code><code>kubectl get svc -n monitoring</code></code></pre><p>For local testing, port-forward it:</p><pre><code><code>kubectl port-forward \
  svc/monitoring-kube-prometheus-prometheus \
  9090:9090 \
  -n monitoring</code></code></pre><p>Open:</p><p>http://localhost:9090</p><p>Now Prometheus can query Kubernetes metrics.</p><p>Try a basic PromQL query:</p><pre><code><code>up</code></code></pre><p>You can also inspect CPU:</p><pre><code><code>sum(rate(container_cpu_usage_seconds_total[5m]))</code></code></pre><p>And memory:</p><pre><code><code>sum(container_memory_working_set_bytes)</code></code></pre><div><hr></div><h2>9. Access Grafana</h2><p>Find the Grafana service:</p><pre><code><code>kubectl get svc -n monitoring</code></code></pre><p>Port-forward:</p><pre><code><code>kubectl port-forward \
  svc/monitoring-grafana \
  3000:80 \
  -n monitoring</code></code></pre><p>Open:</p><p>http://localhost:3000</p><p>Retrieve the administrator password:</p><pre><code><code>kubectl get secret \
  monitoring-grafana \
  -n monitoring \
  -o jsonpath="{.data.admin-password}" | base64 --decode</code></code></pre><p>Username:</p><pre><code><code>admin</code></code></pre><p>Now we have a dashboarding platform.</p><div><hr></div><h2>10. Install Loki</h2><p>Create a Loki values file:</p><pre><code><code>cat &gt; loki-values.yaml &lt;&lt;'EOF'
deploymentMode: SingleBinary

singleBinary:
  replicas: 1

loki:
  auth_enabled: false

gateway:
  enabled: false

backend:
  replicas: 0

read:
  replicas: 0

write:
  replicas: 0

chunksCache:
  enabled: false

resultsCache:
  enabled: false

minio:
  enabled: false
EOF</code></code></pre><p>Install Loki:</p><pre><code><code>helm install loki \
  grafana/loki \
  -n monitoring \
  -f loki-values.yaml</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods -n monitoring</code></code></pre><div><hr></div><h2>11. Install Fluent Bit</h2><p>Fluent Bit collects container logs and forwards them to Loki.</p><p>Add the Fluent Helm repository:</p><pre><code><code>helm repo add fluent https://fluent.github.io/helm-charts</code></code></pre><p>Update:</p><pre><code><code>helm repo update</code></code></pre><p>Create:</p><pre><code><code>cat &gt; fluent-bit-values.yaml &lt;&lt;'EOF'
config:
  outputs: |
    [OUTPUT]
        Name loki
        Match *
        Host loki-gateway
        Port 80
        Labels job=fluent-bit
        Auto_Kubernetes_Labels on
EOF</code></code></pre><p>Install:</p><pre><code><code>helm install fluent-bit \
  fluent/fluent-bit \
  -n monitoring \
  -f fluent-bit-values.yaml</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods -n monitoring</code></code></pre><p>You should see Fluent Bit Pods running across the cluster.</p><p>The flow is now:</p><pre><code><code>Application
     |
     v
Container stdout/stderr
     |
     v
Fluent Bit
     |
     v
Loki
     |
     v
Grafana</code></code></pre><p>This is much more useful than SSH-ing into a node and running:</p><pre><code><code>docker logs</code></code></pre><p>at 3 AM while someone from management is asking why production is broken. &#128516;</p><div><hr></div><h2>12. Install Tempo</h2><p>Add the Grafana repository if you haven&#8217;t already:</p><pre><code><code>helm repo add grafana https://grafana.github.io/helm-charts
helm repo update</code></code></pre><p>Create:</p><pre><code><code>cat &gt; tempo-values.yaml &lt;&lt;'EOF'
tempo:
  reportingEnabled: false

persistence:
  enabled: false

service:
  type: ClusterIP
EOF</code></code></pre><p>Install:</p><pre><code><code>helm install tempo \
  grafana/tempo \
  -n monitoring \
  -f tempo-values.yaml</code></code></pre><p>Verify:</p><pre><code><code>kubectl get pods -n monitoring</code></code></pre><p>Tempo gives us distributed tracing.</p><p>The observability model is now:</p><pre><code><code>                OBSERVABILITY
                     |
        +------------+------------+
        |            |            |
      Metrics       Logs        Traces
        |            |            |
   Prometheus       Loki         Tempo
        |            |            |
        +------------+------------+
                     |
                   Grafana</code></code></pre><p>This is the famous <strong>three pillars of observability</strong>.</p><div><hr></div><h2>13. Configure Grafana Data Sources</h2><p>In Grafana, add:</p><h3>Prometheus</h3><p>http://monitoring-kube-prometheus-prometheus:9090</p><h3>Loki</h3><p>Depending on the deployment:</p><p>http://loki-gateway</p><h3>Tempo</h3><p>http://tempo:3100</p><p>The exact service names can be verified with:</p><pre><code><code>kubectl get svc -n monitoring</code></code></pre><p>This is important.</p><p>Don&#8217;t blindly copy service names from someone&#8217;s blog from three Kubernetes releases ago. Kubernetes has enough ways to humble engineers already.</p><div><hr></div><h2>14. Create Kubernetes Dashboards</h2><p>Grafana can import Kubernetes dashboards.</p><p>You can also build your own panels using PromQL.</p><p>Useful panels include:</p><h3>CPU</h3><pre><code><code>sum by (pod) (
  rate(container_cpu_usage_seconds_total[5m])
)</code></code></pre><h3>Memory</h3><pre><code><code>sum by (pod) (
  container_memory_working_set_bytes
)</code></code></pre><h3>Pod restarts</h3><pre><code><code>sum by (namespace, pod) (
  increase(kube_pod_container_status_restarts_total[15m])
)</code></code></pre><h3>Request rate</h3><p>For applications exposing Prometheus metrics:</p><pre><code><code>sum(rate(http_requests_total[5m]))</code></code></pre><h3>Error rate</h3><pre><code><code>sum(rate(http_requests_total{status=~"5.."}[5m]))
/
sum(rate(http_requests_total[5m]))</code></code></pre><p>Now we&#8217;re getting somewhere.</p><div><hr></div><h1>SECTION 3: &#128680; INGRESS, TLS, SLO ALERTING AND PRODUCTION OPERATIONS</h1><h2>15. Install NGINX Ingress Controller</h2><p>Add the repository:</p><pre><code><code>helm repo add ingress-nginx \
  https://kubernetes.github.io/ingress-nginx</code></code></pre><p>Update:</p><pre><code><code>helm repo update</code></code></pre><p>Install:</p><pre><code><code>helm install ingress-nginx \
  ingress-nginx/ingress-nginx \
  -n ingress-nginx \
  --create-namespace</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods -n ingress-nginx</code></code></pre><p>Check services:</p><pre><code><code>kubectl get svc -n ingress-nginx</code></code></pre><div><hr></div><h2>16. Create an Ingress</h2><p>Create:</p><pre><code><code>cat &gt; application-ingress.yaml &lt;&lt;'EOF'
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: application-ingress
  namespace: sock-shop
spec:
  ingressClassName: nginx
  rules:
  - host: shop.local
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: front-end
            port:
              number: 80
EOF</code></code></pre><p>Apply:</p><pre><code><code>kubectl apply -f application-ingress.yaml</code></code></pre><p>Verify:</p><pre><code><code>kubectl get ingress -n sock-shop</code></code></pre><div><hr></div><h2>17. Configure Local DNS</h2><p>For local Kind testing, you can map:</p><pre><code><code>127.0.0.1 shop.local</code></code></pre><p>to your hosts file.</p><p>Linux:</p><pre><code><code>sudo nano /etc/hosts</code></code></pre><p>Windows:</p><pre><code><code>C:\Windows\System32\drivers\etc\hosts</code></code></pre><p>Add:</p><pre><code><code>127.0.0.1 shop.local</code></code></pre><p>Your application can now be accessed through:</p><p>http://shop.local</p><div><hr></div><h2>18. Install cert-manager</h2><p>Add the repository:</p><pre><code><code>helm repo add jetstack \
  https://charts.jetstack.io</code></code></pre><p>Update:</p><pre><code><code>helm repo update</code></code></pre><p>Install:</p><pre><code><code>helm install cert-manager \
  jetstack/cert-manager \
  --namespace cert-manager \
  --create-namespace \
  --set crds.enabled=true</code></code></pre><p>Verify:</p><pre><code><code>kubectl get pods -n cert-manager</code></code></pre><p>You should see:</p><pre><code><code>cert-manager
cert-manager-cainjector
cert-manager-webhook</code></code></pre><p>For production, certificates should normally be managed through a proper issuer such as Let&#8217;s Encrypt or an organization&#8217;s internal PKI.</p><div><hr></div><h1>&#128680; 19. Create an SLO-Based Alert</h1><p>This is where the project becomes much more interesting.</p><p>Instead of simply saying:</p><blockquote><p>&#8220;CPU is high.&#8221;</p></blockquote><p>we want to ask:</p><blockquote><p>&#8220;Are users experiencing a bad service?&#8221;</p></blockquote><p>For example:</p><pre><code><code>Error Rate &gt; 1%
for 2 minutes</code></code></pre><p>Create an alert rule:</p><pre><code><code>cat &gt; slo-alert.yaml &lt;&lt;'EOF'
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
  name: application-slo-alert
  namespace: monitoring
  labels:
    release: monitoring
spec:
  groups:
  - name: slo-alerts
    rules:
    - alert: HighErrorRate
      expr: |
        (
          sum(rate(http_requests_total{status=~"5.."}[5m]))
          /
          sum(rate(http_requests_total[5m]))
        ) &gt; 0.01
      for: 2m
      labels:
        severity: critical
      annotations:
        summary: "Application error rate exceeds SLO"
        description: "HTTP 5xx error rate has exceeded 1% for more than 2 minutes."
EOF</code></code></pre><p>Apply:</p><pre><code><code>kubectl apply -f slo-alert.yaml</code></code></pre><p>Verify:</p><pre><code><code>kubectl get prometheusrule -n monitoring</code></code></pre><p>Check Prometheus rules:</p><pre><code><code>kubectl get prometheusrules -n monitoring</code></code></pre><p>Now Alertmanager can process the alert.</p><div><hr></div><h1>20. Test the Alert</h1><p>This is an important production habit.</p><p>Don&#8217;t build an alert and assume it works.</p><p><strong>Break something intentionally in a controlled environment.</strong></p><p>For example:</p><pre><code><code>kubectl scale deployment front-end \
  -n sock-shop \
  --replicas=0</code></code></pre><p>Watch:</p><pre><code><code>kubectl get pods -n sock-shop -w</code></code></pre><p>Restore:</p><pre><code><code>kubectl scale deployment front-end \
  -n sock-shop \
  --replicas=2</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods -n sock-shop</code></code></pre><p>You can also simulate CPU pressure, application errors, failed Pods, or network problems in a test environment.</p><p>The goal is to verify:</p><pre><code><code>Failure
   &#8595;
Metric changes
   &#8595;
Prometheus detects
   &#8595;
Alert fires
   &#8595;
Alertmanager receives
   &#8595;
Notification sent
   &#8595;
Engineer investigates</code></code></pre><p>That&#8217;s an actual operational workflow.</p><div><hr></div><h1>&#128270; 21. Useful Kubernetes Troubleshooting Commands</h1><p>These commands are worth knowing before production decides to teach you them at 2 AM.</p><h3>List Pods</h3><pre><code><code>kubectl get pods -A</code></code></pre><h3>Watch Pods</h3><pre><code><code>kubectl get pods -w</code></code></pre><h3>Describe Pod</h3><pre><code><code>kubectl describe pod &lt;pod-name&gt; -n &lt;namespace&gt;</code></code></pre><h3>Logs</h3><pre><code><code>kubectl logs &lt;pod-name&gt; -n &lt;namespace&gt;</code></code></pre><h3>Follow logs</h3><pre><code><code>kubectl logs -f &lt;pod-name&gt; -n &lt;namespace&gt;</code></code></pre><h3>Previous container logs</h3><pre><code><code>kubectl logs &lt;pod-name&gt; \
  -n &lt;namespace&gt; \
  --previous</code></code></pre><h3>Deployment status</h3><pre><code><code>kubectl rollout status deployment/&lt;deployment-name&gt; \
  -n &lt;namespace&gt;</code></code></pre><h3>Deployment history</h3><pre><code><code>kubectl rollout history deployment/&lt;deployment-name&gt; \
  -n &lt;namespace&gt;</code></code></pre><h3>Rollback</h3><pre><code><code>kubectl rollout undo deployment/&lt;deployment-name&gt; \
  -n &lt;namespace&gt;</code></code></pre><h3>Services</h3><pre><code><code>kubectl get svc -A</code></code></pre><h3>Endpoints</h3><pre><code><code>kubectl get endpoints -A</code></code></pre><h3>Events</h3><pre><code><code>kubectl get events \
  -A \
  --sort-by=.lastTimestamp</code></code></pre><h3>Resource consumption</h3><pre><code><code>kubectl top nodes</code></code></pre><pre><code><code>kubectl top pods -A</code></code></pre><p>These commands form a surprisingly large portion of the difference between:</p><blockquote><p>&#8220;The application is down.&#8221;</p></blockquote><p>and:</p><blockquote><p>&#8220;The frontend deployment is healthy, but the order service is returning 5xx responses after the latest rollout, and traces show database latency increased immediately afterward.&#8221;</p></blockquote><p>The second engineer gets invited to more meetings. Unfortunately.</p><div><hr></div><h1>&#129514; 22. Production Debugging Workflow</h1><p>Suppose users report:</p><blockquote><p>&#8220;The application is slow.&#8221;</p></blockquote><p>Don&#8217;t immediately restart everything.</p><p>Use a systematic workflow.</p><h3>Step 1: Check Pods</h3><pre><code><code>kubectl get pods -A</code></code></pre><p>Look for:</p><pre><code><code>CrashLoopBackOff
ImagePullBackOff
Pending
OOMKilled</code></code></pre><h3>Step 2: Check Events</h3><pre><code><code>kubectl get events -A \
  --sort-by=.lastTimestamp</code></code></pre><h3>Step 3: Check Metrics</h3><p>In Prometheus/Grafana investigate:</p><pre><code><code>CPU
Memory
Request rate
Error rate
Latency
Pod restarts
Node saturation</code></code></pre><h3>Step 4: Check Logs</h3><pre><code><code>kubectl logs &lt;pod&gt; -n &lt;namespace&gt;</code></code></pre><p>Or query Loki through Grafana.</p><h3>Step 5: Check Traces</h3><p>Look for:</p><pre><code><code>Frontend
   &#8595;
Product
   &#8595;
Order
   &#8595;
Database</code></code></pre><p>Find where latency increases.</p><h3>Step 6: Check Recent Deployments</h3><pre><code><code>kubectl rollout history deployment/&lt;deployment&gt; \
  -n &lt;namespace&gt;</code></code></pre><h3>Step 7: Roll Back if Necessary</h3><pre><code><code>kubectl rollout undo deployment/&lt;deployment&gt; \
  -n &lt;namespace&gt;</code></code></pre><p>This gives you a repeatable incident-response process.</p><div><hr></div><h1>&#128193; 23. Suggested Project Structure</h1><p>Keep the repository organized:</p><pre><code><code>kubernetes-observability/
&#9474;
&#9500;&#9472;&#9472; application/
&#9474;   &#9500;&#9472;&#9472; namespace.yaml
&#9474;   &#9500;&#9472;&#9472; deployment.yaml
&#9474;   &#9500;&#9472;&#9472; service.yaml
&#9474;   &#9492;&#9472;&#9472; ingress.yaml
&#9474;
&#9500;&#9472;&#9472; monitoring/
&#9474;   &#9500;&#9472;&#9472; prometheus/
&#9474;   &#9500;&#9472;&#9472; grafana/
&#9474;   &#9500;&#9472;&#9472; alerts/
&#9474;   &#9500;&#9472;&#9472; loki/
&#9474;   &#9500;&#9472;&#9472; fluent-bit/
&#9474;   &#9492;&#9472;&#9472; tempo/
&#9474;
&#9500;&#9472;&#9472; ingress/
&#9474;   &#9492;&#9472;&#9472; nginx/
&#9474;
&#9500;&#9472;&#9472; security/
&#9474;   &#9492;&#9472;&#9472; cert-manager/
&#9474;
&#9500;&#9472;&#9472; dashboards/
&#9474;   &#9500;&#9472;&#9472; application.json
&#9474;   &#9500;&#9472;&#9472; kubernetes.json
&#9474;   &#9492;&#9472;&#9472; alerts.json
&#9474;
&#9500;&#9472;&#9472; scripts/
&#9474;   &#9500;&#9472;&#9472; install.sh
&#9474;   &#9500;&#9472;&#9472; uninstall.sh
&#9474;   &#9492;&#9472;&#9472; test-alert.sh
&#9474;
&#9492;&#9472;&#9472; README.md</code></code></pre><p>This makes the project much easier to maintain and explain during interviews.</p><div><hr></div><h1>&#127919; 24. What This Project Demonstrates</h1><p>This isn&#8217;t just another:</p><pre><code><code>kubectl apply -f deployment.yaml</code></code></pre><p>project.</p><p>It demonstrates an end-to-end production mindset.</p><h3>&#9784;&#65039; Kubernetes</h3><p>Cluster management, Deployments, Services, namespaces and workloads.</p><h3>&#9973; Helm</h3><p>Packaging and repeatable installation of infrastructure components.</p><h3>&#128202; Prometheus</h3><p>Metrics collection and PromQL-based analysis.</p><h3>&#128200; Grafana</h3><p>Operational dashboards and visualization.</p><h3>&#128221; Loki</h3><p>Centralized log aggregation.</p><h3>&#128666; Fluent Bit</h3><p>Container log collection and forwarding.</p><h3>&#128270; Tempo</h3><p>Distributed tracing.</p><h3>&#128680; Alertmanager</h3><p>Alert routing and notification management.</p><h3>&#127760; NGINX</h3><p>Application ingress and traffic management.</p><h3>&#128272; cert-manager</h3><p>Automated TLS certificate management.</p><h3>&#127919; SLOs</h3><p>Alerting based on user-impacting reliability rather than arbitrary infrastructure thresholds.</p><div><hr></div><h1>&#129504; The Most Important Lesson</h1><p>Observability isn&#8217;t:</p><pre><code><code>Install Prometheus
+
Install Grafana
=
Observability</code></code></pre><p>That&#8217;s just installing tools.</p><p>Real observability is:</p><pre><code><code>Metrics
   +
Logs
   +
Traces
   +
Alerts
   +
Dashboards
   +
SLOs
   +
Incident Response
   =
Operational Understanding</code></code></pre><p>Imagine your application suddenly starts returning errors.</p><p>Without observability:</p><pre><code><code>Something is broken.
&#128528;</code></code></pre><p>With metrics:</p><pre><code><code>Error rate increased to 8%.</code></code></pre><p>With logs:</p><pre><code><code>Database connection timeout.</code></code></pre><p>With traces:</p><pre><code><code>Order Service &#8594; PostgreSQL
Latency: 3.8 seconds</code></code></pre><p>With dashboards:</p><pre><code><code>Problem started immediately after deployment v1.8.</code></code></pre><p>Now you have a much better chance of finding the root cause instead of restarting Pods and hoping the Kubernetes gods accept your sacrifice. &#128579;</p><div><hr></div><h1>&#128640; Final Takeaways</h1><p>A production Kubernetes platform should not stop at:</p><pre><code><code>Application &#8594; Kubernetes</code></code></pre><p>A stronger architecture looks like:</p><pre><code><code>                    USERS
                      |
                      v
                NGINX INGRESS
                      |
                      v
             MICROSERVICES APP
                      |
          +-----------+-----------+
          |           |           |
       Metrics       Logs       Traces
          |           |           |
     Prometheus      Loki        Tempo
          |           |           |
          +-----------+-----------+
                      |
                   Grafana
                      |
                 Alertmanager
                      |
                Engineering Team</code></code></pre><p>The goal isn&#8217;t to collect as much data as possible.</p><p>The goal is to answer three questions quickly:</p><p><strong>What is broken?</strong></p><p><strong>Why is it broken?</strong></p><p><strong>What should I do next?</strong></p><p>That is what turns Kubernetes monitoring into genuine observability.</p><p>And when you&#8217;re building your next DevOps project, don&#8217;t just demonstrate that you can deploy an application.</p><p>Demonstrate that you can <strong>operate it when things go wrong.</strong> &#128640;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#Kubernetes #DevOps #Observability #Prometheus #Grafana #Loki #FluentBit #Tempo #Alertmanager #SRE #CloudNative #Helm #Docker #Monitoring #DevSecOps #KubernetesMonitoring #Microservices #CI_CD #PlatformEngineering</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/?utm_source=chatgpt.com">linkedin.com/in/arvindverma021</a></p>]]></content:encoded></item><item><title><![CDATA[AWS vs Azure vs GCP: Which Cloud Is Actually Better? ☁️]]></title><description><![CDATA[If you work in DevOps, Cloud Engineering, or Infrastructure, you have probably heard the same question dozens of times: &#8220;AWS vs Azure vs GCP. Which one is the best?&#8221;]]></description><link>https://arvindverma021.substack.com/p/aws-vs-azure-vs-gcp-which-cloud-is</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/aws-vs-azure-vs-gcp-which-cloud-is</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Mon, 31 Aug 2026 08:44:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lMIT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lMIT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lMIT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1771343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213515651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lMIT!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5689e369-0c4a-427d-a0a2-c874ca7efb7e_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>It sounds like a simple question.</p><p>It isn&#8217;t.</p><p>Asking which cloud is &#8220;best&#8221; is a little like asking whether a Swiss Army knife, a power drill, or a laptop is the best tool. The answer depends entirely on what you are trying to build.</p><p>AWS may be the right choice for one organization. Azure may make more sense for another. GCP can be an excellent fit for teams heavily focused on data, analytics, AI, or Kubernetes.</p><p>And here is the part that many engineers discover only after working on real production systems:</p><blockquote><p><strong>The cloud provider matters. But architecture matters even more.</strong></p></blockquote><p>A poorly designed system on AWS can fail.</p><p>A well-designed system on Azure can survive.</p><p>A well-designed system on GCP can scale beautifully.</p><p>So instead of asking:</p><p><strong>&#8220;Which cloud is the best?&#8221;</strong></p><p>A better engineering question is:</p><blockquote><p><strong>&#8220;Which cloud fits our workload, team, architecture, budget, and business requirements best?&#8221;</strong></p></blockquote><p>Let&#8217;s break it down. &#128640;</p><div><hr></div><h1>SECTION 1: AWS vs Azure vs GCP, What Actually Separates Them? &#9729;&#65039;</h1><p>The three major cloud platforms offer overlapping capabilities.</p><p>You can run virtual machines.</p><p>You can build Kubernetes clusters.</p><p>You can create databases.</p><p>You can deploy containers.</p><p>You can build serverless applications.</p><p>You can implement CI/CD.</p><p>You can create highly available architectures.</p><p>So why does the choice matter?</p><p>Because the surrounding ecosystem, integrations, pricing models, operational experience, and organizational requirements can be very different.</p><h2>&#128992; AWS: The Broad Cloud Ecosystem</h2><p>Amazon Web Services is often a strong choice when an organization needs a very broad collection of cloud services.</p><p>A typical AWS environment might contain:</p><ul><li><p>EC2 for compute</p></li><li><p>S3 for object storage</p></li><li><p>VPC for networking</p></li><li><p>RDS for relational databases</p></li><li><p>EKS for Kubernetes</p></li><li><p>Lambda for serverless workloads</p></li><li><p>CloudFront for content delivery</p></li><li><p>IAM for identity and access management</p></li><li><p>CloudWatch for monitoring</p></li></ul><p>For DevOps engineers, AWS can feel like a giant toolbox.</p><p>There is almost always another service available for the problem you are trying to solve.</p><p>That is powerful.</p><p>It can also become slightly ridiculous.</p><p>You start with:</p><blockquote><p>&#8220;I just need to host an application.&#8221;</p></blockquote><p>Three weeks later, you&#8217;re discussing VPC endpoints, Transit Gateway, IAM policies, NAT Gateway costs, Route 53, CloudFront, EKS, autoscaling and why the monthly bill suddenly resembles a small mortgage. &#128184;</p><h3>Where AWS tends to fit well</h3><p>AWS can be particularly attractive for:</p><ul><li><p>Large-scale production workloads</p></li><li><p>Startups that want broad cloud flexibility</p></li><li><p>Global applications</p></li><li><p>DevOps-heavy organizations</p></li><li><p>Multi-region architectures</p></li><li><p>Organizations already invested heavily in AWS</p></li></ul><p>The ecosystem is one of its biggest strengths.</p><div><hr></div><h1>&#128309; Azure: Strong Enterprise Integration</h1><p>Microsoft Azure becomes especially interesting when an organization already lives inside the Microsoft ecosystem.</p><p>Think about an enterprise using:</p><ul><li><p>Windows Server</p></li><li><p>Active Directory</p></li><li><p>Microsoft 365</p></li><li><p>Entra ID</p></li><li><p>SQL Server</p></li><li><p>.NET</p></li><li><p>Microsoft security and compliance tooling</p></li></ul><p>Moving toward Azure can provide strong integration across these environments.</p><p>Azure also offers:</p><ul><li><p>Virtual Machines</p></li><li><p>AKS</p></li><li><p>Azure DevOps</p></li><li><p>Azure Functions</p></li><li><p>Azure Storage</p></li><li><p>Azure SQL</p></li><li><p>Virtual Network</p></li><li><p>Entra ID</p></li><li><p>Azure Monitor</p></li></ul><p>For a large enterprise, cloud migration isn&#8217;t simply about:</p><blockquote><p>&#8220;Which provider has the cheapest VM?&#8221;</p></blockquote><p>It is about:</p><blockquote><p>&#8220;How easily can our existing identity, applications, networking, security, governance and operational processes integrate with the cloud?&#8221;</p></blockquote><p>That changes the decision considerably.</p><h3>Where Azure tends to fit well</h3><p>Azure can be particularly attractive for:</p><ul><li><p>Microsoft-heavy organizations</p></li><li><p>Large enterprises</p></li><li><p>Hybrid cloud environments</p></li><li><p>Organizations with existing Microsoft licensing</p></li><li><p>Enterprise identity integration</p></li><li><p>Corporate IT environments</p></li></ul><p>The existing ecosystem can sometimes be more important than raw cloud service pricing.</p><div><hr></div><h1>&#128994; GCP: Data, AI and Kubernetes Strength</h1><p>Google Cloud has a particularly strong reputation around:</p><ul><li><p>Data engineering</p></li><li><p>Analytics</p></li><li><p>AI/ML</p></li><li><p>Kubernetes</p></li><li><p>Cloud-native workloads</p></li></ul><p>Some important services include:</p><ul><li><p>GKE</p></li><li><p>BigQuery</p></li><li><p>Cloud Storage</p></li><li><p>Compute Engine</p></li><li><p>Cloud Run</p></li><li><p>Vertex AI</p></li><li><p>Cloud SQL</p></li><li><p>VPC</p></li></ul><p>GCP&#8217;s Kubernetes story is particularly interesting because Kubernetes originated at Google.</p><p>For organizations building heavily around containers, Kubernetes, analytics, and machine learning, GCP can be an extremely compelling option.</p><p>Imagine a company processing enormous amounts of customer data.</p><p>The important question isn&#8217;t necessarily:</p><blockquote><p>&#8220;Which cloud has the cheapest server?&#8221;</p></blockquote><p>It might be:</p><blockquote><p>&#8220;Which platform lets our data engineers process this information efficiently while integrating analytics and ML into the application?&#8221;</p></blockquote><p>That&#8217;s a completely different decision.</p><div><hr></div><h1>SECTION 2: Stop Comparing Clouds Like Shopping Products &#129504;</h1><p>One of the biggest mistakes engineers make is comparing clouds using isolated service prices.</p><p>For example:</p><p><strong>EC2 vs Azure VM vs Compute Engine</strong></p><p>That comparison is useful.</p><p>But it isn&#8217;t enough.</p><p>A production platform consists of much more than compute.</p><p>You have:</p><pre><code><code>Users
   &#8595;
DNS
   &#8595;
CDN / Load Balancer
   &#8595;
Application
   &#8595;
Database
   &#8595;
Storage
   &#8595;
Monitoring
   &#8595;
Security
   &#8595;
Backup / Disaster Recovery</code></code></pre><p>Every layer contributes to cost, reliability and operational complexity.</p><h2>&#128176; Which Cloud Is Cheapest?</h2><p>There is no universal answer.</p><p>The infographic highlights an important reality:</p><p><strong>AWS has a huge ecosystem, but poorly optimized resources can become expensive quickly.</strong></p><p>For example, an organization might accidentally create:</p><ul><li><p>oversized EC2 instances</p></li><li><p>unused EBS volumes</p></li><li><p>unnecessary NAT Gateway traffic</p></li><li><p>idle load balancers</p></li><li><p>excessive data transfer</p></li><li><p>forgotten development environments</p></li></ul><p>The cloud isn&#8217;t necessarily expensive.</p><p><strong>Unused infrastructure is expensive.</strong></p><p>Azure can be highly cost-effective in organizations already using Microsoft technologies and licensing.</p><p>GCP can be attractive for certain compute-heavy, Kubernetes, analytics and AI workloads.</p><p>But pricing depends heavily on workload architecture.</p><p>That&#8217;s why a simple:</p><blockquote><p>&#8220;AWS is cheaper.&#8221;</p></blockquote><p>or</p><blockquote><p>&#8220;GCP is cheaper.&#8221;</p></blockquote><p>is usually an incomplete statement.</p><div><hr></div><h2>&#128737;&#65039; Reliability Isn&#8217;t Just About the Cloud Provider</h2><p>This is one of the most important lessons for cloud engineers.</p><p>All three major providers offer mechanisms for building highly available systems.</p><p>But cloud infrastructure doesn&#8217;t automatically become reliable because you selected a famous provider.</p><p>Consider this architecture:</p><pre><code><code>Internet
   |
Load Balancer
   |
Application
   |
Single Database</code></code></pre><p>Your application might run across multiple instances.</p><p>But your database is still a single point of failure.</p><p>Now compare:</p><pre><code><code>                 Internet
                    |
              Load Balancer
                    |
          ---------------------
          |                   |
       AZ-A                AZ-B
          |                   |
      App Server          App Server
          |                   |
          -------- Database --------
                 Multi-AZ</code></code></pre><p>Suddenly the architecture has a much stronger availability model.</p><p>The lesson is simple:</p><blockquote><p><strong>Cloud availability doesn&#8217;t replace architecture design.</strong></p></blockquote><p>A badly designed architecture can fail on any cloud.</p><div><hr></div><h2>&#128272; Security Works the Same Way</h2><p>AWS, Azure and GCP all provide extensive security capabilities.</p><p>But security still depends on engineering decisions.</p><p>For example:</p><pre><code><code>Identity
   &#8595;
IAM / RBAC
   &#8595;
Network Controls
   &#8595;
Application Security
   &#8595;
Secrets Management
   &#8595;
Logging
   &#8595;
Monitoring
   &#8595;
Incident Response</code></code></pre><p>Having IAM doesn&#8217;t automatically mean your IAM design is secure.</p><p>Having a firewall doesn&#8217;t automatically mean your network is secure.</p><p>Having encryption doesn&#8217;t automatically mean your data protection strategy is complete.</p><p>Security is a system.</p><p>Not a checkbox.</p><div><hr></div><h2>&#9784;&#65039; Kubernetes Makes the Comparison Interesting</h2><p>For DevOps engineers, Kubernetes is one of the most useful areas to compare.</p><p>You might choose:</p><p><strong>AWS &#8594; EKS</strong></p><p><strong>Azure &#8594; AKS</strong></p><p><strong>GCP &#8594; GKE</strong></p><p>The basic concept is similar:</p><pre><code><code>Developer
    &#8595;
Git
    &#8595;
CI/CD
    &#8595;
Container Image
    &#8595;
Kubernetes
    &#8595;
Service
    &#8595;
Users</code></code></pre><p>But the surrounding integrations differ.</p><p>Your decision might depend on:</p><ul><li><p>IAM integration</p></li><li><p>Networking</p></li><li><p>Load balancing</p></li><li><p>Container registry</p></li><li><p>Monitoring</p></li><li><p>Security</p></li><li><p>Identity</p></li><li><p>Existing cloud infrastructure</p></li><li><p>Team expertise</p></li></ul><p>For example:</p><pre><code><code>AWS
EKS + ECR + IAM + ALB + CloudWatch

Azure
AKS + ACR + Entra ID + Application Gateway + Azure Monitor

GCP
GKE + Artifact Registry + IAM + Cloud Load Balancing + Cloud Monitoring</code></code></pre><p>None of these is automatically &#8220;the winner.&#8221;</p><p>The better question is:</p><blockquote><p><strong>Which ecosystem makes our architecture easier to operate?</strong></p></blockquote><div><hr></div><h1>SECTION 3: How I Would Actually Choose a Cloud in Production &#128640;</h1><p>If I were designing a new platform, I wouldn&#8217;t start with:</p><p><strong>&#8220;AWS vs Azure vs GCP?&#8221;</strong></p><p>I&#8217;d start with requirements.</p><h2>1. Understand the Workload</h2><p>Ask:</p><ul><li><p>Is it compute-heavy?</p></li><li><p>Data-heavy?</p></li><li><p>AI-heavy?</p></li><li><p>Kubernetes-heavy?</p></li><li><p>Windows-heavy?</p></li><li><p>Latency-sensitive?</p></li><li><p>Global?</p></li><li><p>Regulatory?</p></li><li><p>Hybrid?</p></li></ul><p>For example:</p><h3>AI / Analytics Platform</h3><p>GCP may deserve serious consideration.</p><h3>Microsoft Enterprise</h3><p>Azure may be a natural fit.</p><h3>Broad Cloud-Native Platform</h3><p>AWS may be a strong candidate.</p><p>But these are starting points, not universal rules.</p><div><hr></div><h2>2. Evaluate Existing Infrastructure</h2><p>This is often ignored.</p><p>Imagine a company already has:</p><pre><code><code>Active Directory
Microsoft 365
Windows Servers
SQL Server
.NET Applications
Microsoft Licensing</code></code></pre><p>Moving everything to AWS simply because someone read that AWS is &#8220;the best cloud&#8221; could create unnecessary migration and integration work.</p><p>Architecture decisions should consider the environment that already exists.</p><div><hr></div><h2>3. Evaluate Your Engineering Team &#128104;&#8205;&#128187;</h2><p>This matters more than people admit.</p><p>Suppose:</p><pre><code><code>Team A
AWS experience: 5 years
Azure experience: 6 months
GCP experience: 2 months</code></code></pre><p>And the organization chooses GCP because:</p><blockquote><p>&#8220;GCP is technically better.&#8221;</p></blockquote><p>Now the team has to learn:</p><ul><li><p>networking</p></li><li><p>IAM</p></li><li><p>Kubernetes integrations</p></li><li><p>monitoring</p></li><li><p>deployment</p></li><li><p>security</p></li><li><p>cost management</p></li></ul><p>Learning is good.</p><p>But production isn&#8217;t a classroom.</p><p>Operational maturity matters.</p><div><hr></div><h2>4. Compare Total Cost, Not Just Compute</h2><p>Calculate:</p><pre><code><code>Compute
+
Storage
+
Database
+
Network
+
Load Balancing
+
Monitoring
+
Security
+
Backup
+
Data Transfer
+
Engineering Effort
=
Total Cost</code></code></pre><p>That last part is frequently forgotten.</p><p>If a platform saves &#8377;10 lakh in infrastructure costs but requires significantly more engineering effort to operate, the actual business benefit may be smaller than expected.</p><p>Cloud economics is about <strong>total cost of ownership</strong>, not just hourly VM pricing.</p><div><hr></div><h2>5. Design for Failure</h2><p>Before selecting a platform, ask:</p><blockquote><p>&#8220;What happens when something fails?&#8221;</p></blockquote><p>Test scenarios such as:</p><ul><li><p>Availability Zone failure</p></li><li><p>Database failure</p></li><li><p>Node failure</p></li><li><p>Network failure</p></li><li><p>Region failure</p></li><li><p>Credential compromise</p></li><li><p>Deployment failure</p></li><li><p>Storage failure</p></li></ul><p>A mature architecture doesn&#8217;t assume failure won&#8217;t happen.</p><p>It assumes failure <strong>will</strong> happen.</p><p>Then it designs around it.</p><div><hr></div><h2>6. Think About Vendor Lock-In</h2><p>Every cloud has proprietary services.</p><p>For example:</p><pre><code><code>Application
   &#8595;
Cloud-specific database
   &#8595;
Cloud-specific messaging
   &#8595;
Cloud-specific analytics
   &#8595;
Cloud-specific AI service</code></code></pre><p>The more tightly integrated your application becomes with provider-specific services, the harder migration may become.</p><p>That isn&#8217;t necessarily bad.</p><p>Vendor lock-in can be a reasonable tradeoff if the service provides substantial business value.</p><p>The mistake is not choosing proprietary services.</p><p>The mistake is choosing them <strong>without understanding the long-term tradeoff</strong>.</p><div><hr></div><h1>The Real Cloud Engineering Mindset &#129504;</h1><p>The most valuable cloud engineers aren&#8217;t necessarily the people who memorize hundreds of services.</p><p>They understand <strong>tradeoffs</strong>.</p><p>They can look at a requirement and reason:</p><pre><code><code>Requirement
     &#8595;
Architecture
     &#8595;
Cloud Services
     &#8595;
Security
     &#8595;
Reliability
     &#8595;
Cost
     &#8595;
Operations</code></code></pre><p>That&#8217;s much more valuable than saying:</p><blockquote><p>&#8220;AWS is better.&#8221;</p></blockquote><p>or:</p><blockquote><p>&#8220;Azure is better.&#8221;</p></blockquote><p>or:</p><blockquote><p>&#8220;GCP is better.&#8221;</p></blockquote><p>Because production engineering rarely gives you perfect answers.</p><p>It gives you tradeoffs.</p><div><hr></div><h1>AWS vs Azure vs GCP: My Practical Cheat Sheet &#128202;</h1><p>RequirementStrong CandidateBroad cloud ecosystemAWSLarge enterprise environmentAzureMicrosoft ecosystemAzureAI/ML workloadsGCPData analyticsGCPKubernetes-heavy workloadsGCP / AWS / AzureGlobal cloud-native applicationsAWSHybrid Microsoft environmentsAzureDevOps-heavy AWS ecosystemAWSExisting Google data ecosystemGCPExisting enterprise Microsoft ecosystemAzure</p><p>These aren&#8217;t hard rules.</p><p>They are decision starting points.</p><div><hr></div><h1>The Biggest Lesson &#128640;</h1><p>The infographic&#8217;s central message is actually more important than the comparison itself:</p><blockquote><p><strong>The best cloud is the one that fits your workload.</strong></p></blockquote><p>A company shouldn&#8217;t select AWS because everyone else uses AWS.</p><p>It shouldn&#8217;t select Azure because Microsoft is popular.</p><p>It shouldn&#8217;t select GCP because Kubernetes came from Google.</p><p>Instead, evaluate:</p><p><strong>Cost + Reliability + Scalability + Security + Team Expertise + Existing Ecosystem + Business Requirements</strong></p><p>Then make the decision.</p><p>Because in real engineering:</p><blockquote><p><strong>Cloud selection is not a religion. It is an architecture decision.</strong> &#9729;&#65039;</p></blockquote><p>And architecture decisions should be driven by requirements, constraints and measurable tradeoffs.</p><div><hr></div><h1>Final Thought &#127919;</h1><p>There is no universal &#8220;best cloud.&#8221;</p><p>There is only the <strong>best cloud for a particular workload and organization</strong>.</p><p>AWS brings enormous ecosystem depth.</p><p>Azure brings powerful enterprise and Microsoft integration.</p><p>GCP brings strong capabilities around data, AI and cloud-native technologies.</p><p>But none of them can rescue an architecture that ignores:</p><ul><li><p>security</p></li><li><p>observability</p></li><li><p>cost</p></li><li><p>availability</p></li><li><p>disaster recovery</p></li><li><p>capacity planning</p></li><li><p>operational complexity</p></li></ul><p>The cloud provider gives you the building blocks.</p><p><strong>Your architecture determines what you build with them.</strong></p><p>And that is where good cloud engineering begins. &#9729;&#65039;&#128640;</p><div><hr></div><h2>Key Takeaways</h2><p>&#9989; Don&#8217;t choose a cloud based only on popularity.</p><p>&#9989; Evaluate the entire ecosystem, not one service.</p><p>&#9989; Compare total cost of ownership.</p><p>&#9989; Consider existing infrastructure and team expertise.</p><p>&#9989; Design for failure.</p><p>&#9989; Treat security as a system.</p><p>&#9989; Kubernetes doesn&#8217;t eliminate the need for good architecture.</p><p>&#9989; Understand vendor lock-in before embracing proprietary services.</p><p>&#9989; Measure reliability through architecture, not provider branding.</p><p>&#9989; <strong>Choose the cloud that fits the workload, not the cloud that wins an internet argument.</strong> &#128516;</p><div><hr></div><h3>Hashtags</h3><p>#AWS #Azure #GCP #CloudComputing #CloudEngineering #DevOps #Kubernetes #EKS #AKS #GKE #Terraform #CloudArchitecture #DevSecOps #SRE #InfrastructureAsCode #CloudSecurity #DevOpsEngineering #SoftwareEngineering</p><h3>Follow Me</h3><p>If you enjoyed this article and would like more practical DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[6 Hybrid Cloud Patterns Every Cloud Engineer Should Understand ☁️🏢]]></title><description><![CDATA[Hybrid cloud sounds simple until you actually have to operate one.]]></description><link>https://arvindverma021.substack.com/p/6-hybrid-cloud-patterns-every-cloud</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/6-hybrid-cloud-patterns-every-cloud</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Mon, 31 Aug 2026 07:42:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LIKP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!LIKP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!LIKP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1600412,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213510902?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!LIKP!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff2b49f8-e314-4dea-b47b-10e841ac0852_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On a whiteboard, it looks like:</p><p><strong>On-Premises &#8594; Cloud</strong></p><p>In production, it becomes:</p><p><strong>On-Premises + AWS/Azure/GCP + Identity + Networking + Data + Security + Legacy Systems + Compliance + Edge</strong></p><p>And suddenly that neat little arrow has become an architecture diagram that needs its own architecture diagram. &#128516;</p><p>The reality is that organizations rarely move everything to the cloud overnight.</p><p>They have databases that cannot move yet.<br>Applications that still depend on physical infrastructure.<br>Regulatory requirements.<br>Existing investments in data centers.<br>Factories and edge locations.<br>Identity systems that have existed longer than some engineers on the team.</p><p>That is where <strong>hybrid cloud architecture patterns</strong> become useful.</p><p>This article explores six important patterns:</p><ol><li><p>&#9729;&#65039; Cloud Bursting</p></li><li><p>&#127959;&#65039; Tiered / Split-Tier Architecture</p></li><li><p>&#128260; Disaster Recovery to Cloud</p></li><li><p>&#128190; Hybrid Data &amp; Storage Replication</p></li><li><p>&#128272; Hybrid Identity &amp; Access</p></li><li><p>&#127981; Edge-to-Cloud / Distributed Hybrid</p></li></ol><p>The goal isn&#8217;t simply to memorize these patterns.</p><p>The goal is to understand <strong>when they make sense, what problems they solve, and what can go wrong in production.</strong></p><div><hr></div><h1>SECTION 1: The First Three Hybrid Cloud Patterns</h1><h2>1&#65039;&#8419; Cloud Bursting</h2><p>Imagine you run an application inside your company&#8217;s data center.</p><p>Normally, your on-premises infrastructure handles the workload comfortably.</p><p>But once in a while, traffic suddenly increases.</p><p>Maybe it&#8217;s:</p><ul><li><p>&#128722; A seasonal sale</p></li><li><p>&#127891; College admission season</p></li><li><p>&#127951; A major sporting event</p></li><li><p>&#128202; Month-end processing</p></li><li><p>&#127903;&#65039; Ticket sales</p></li><li><p>&#129302; A batch or AI workload</p></li></ul><p>Buying enough physical servers to handle the maximum possible traffic would be expensive.</p><p>So instead:</p><p><strong>Normal traffic &#8594; On-premises</strong></p><p><strong>Traffic exceeds threshold &#8594; Cloud capacity</strong></p><p>That&#8217;s <strong>cloud bursting</strong>.</p><h3>Simple architecture</h3><pre><code><code>             Traffic
                |
                v
        +---------------+
        | Load Balancer |
        +---------------+
           /         \
          /           \
         v             v
   On-Prem Cluster   Cloud
   Base Capacity     Auto Scaling</code></code></pre><p>The cloud becomes an extension of your existing infrastructure.</p><h3>When does it work well?</h3><p>The source diagram highlights scenarios such as:</p><ul><li><p>Predictable baseline with sharp peaks</p></li><li><p>Seasonal or batch spikes</p></li><li><p>Existing hardware that still has useful life</p></li></ul><p>But there is an important condition:</p><h3>Your application should be suitable for bursting.</h3><p>Stateless applications are much easier to move between environments.</p><p>For example:</p><pre><code><code>Web/API Layer
     |
     +---- On-Prem
     |
     +---- Cloud</code></code></pre><p>If the application depends heavily on local state, bursting becomes significantly harder.</p><h3>&#9888;&#65039; What can go wrong?</h3><p>The architecture can look fantastic until the application needs data sitting inside the data center.</p><p>Then you discover:</p><pre><code><code>Cloud Application
       |
       | Internet/VPN
       v
On-Prem Database</code></code></pre><p>Now latency matters.</p><p>Bandwidth matters.</p><p>Data transfer costs matter.</p><p>Connectivity failures matter.</p><p>And suddenly your &#8220;simple cloud bursting solution&#8221; has become a distributed-systems problem.</p><p>Because apparently infrastructure enjoys consequences.</p><div><hr></div><h1>2&#65039;&#8419; Tiered / Split-Tier Architecture</h1><p>This is one of the most practical hybrid patterns.</p><p>Instead of moving the entire application to the cloud, you split the architecture.</p><p>For example:</p><pre><code><code>             Users
               |
               v
        Cloud Web / App
               |
          Private Link
               |
               v
       On-Prem Database</code></code></pre><p>The cloud handles the <strong>front end or application tier</strong>, while the on-premises environment continues to host the <strong>system of record</strong>.</p><h3>Why would an organization do this?</h3><p>Perhaps the database:</p><ul><li><p>Has regulatory requirements</p></li><li><p>Contains sensitive information</p></li><li><p>Is difficult to migrate</p></li><li><p>Has legacy dependencies</p></li><li><p>Requires specialized infrastructure</p></li></ul><p>Meanwhile, the application tier can benefit from cloud scalability.</p><h3>Example</h3><p>A financial organization might have:</p><pre><code><code>Cloud
 &#9500;&#9472;&#9472; Web Application
 &#9500;&#9472;&#9472; API
 &#9492;&#9472;&#9472; Application Services

          |
          | Private Connectivity
          v

On-Premises
 &#9492;&#9472;&#9472; Core Database</code></code></pre><p>This allows modernization without forcing a risky database migration.</p><h3>&#9888;&#65039; Watch out for the network</h3><p>The source diagram correctly emphasizes that every request crossing the link introduces risk.</p><p>If:</p><pre><code><code>Cloud App &#8594; Private Link &#8594; On-Prem DB</code></code></pre><p>fails, the application may fail too.</p><p>Latency can also become a major issue.</p><p>An application making 20 database calls per request may behave perfectly inside a data center but become painfully slow across environments.</p><p>So before implementing this pattern, measure:</p><ul><li><p>Latency</p></li><li><p>Throughput</p></li><li><p>Connection limits</p></li><li><p>Failure behavior</p></li><li><p>Retry behavior</p></li><li><p>Data consistency</p></li></ul><p>Don&#8217;t discover these characteristics at 2 AM during an incident.</p><div><hr></div><h1>3&#65039;&#8419; Disaster Recovery to Cloud</h1><p>Here&#8217;s another practical pattern.</p><p>You maintain your primary workload on-premises.</p><p>But instead of building a second physical data center, you use the cloud as the disaster-recovery environment.</p><pre><code><code>             Primary
          On-Premises
               |
          Replication
               |
               v
          Cloud DR
       Pilot Light /
        Warm Standby</code></code></pre><p>The source architecture highlights <strong>RTO</strong> and <strong>RPO</strong>.</p><h3>RTO</h3><p><strong>Recovery Time Objective</strong></p><p>How quickly do you need the system back?</p><p>Example:</p><blockquote><p>RTO = 1 hour</p></blockquote><p>You have roughly an hour to restore service.</p><h3>RPO</h3><p><strong>Recovery Point Objective</strong></p><p>How much data can you afford to lose?</p><p>Example:</p><blockquote><p>RPO = 15 minutes</p></blockquote><p>Your recovery process should aim to lose no more than roughly 15 minutes of data.</p><p>These two numbers influence your architecture.</p><div><hr></div><h3>Pilot Light</h3><p>Keep the minimum infrastructure available in the cloud.</p><p>When disaster happens:</p><pre><code><code>Primary Failure
      &#8595;
Activate Cloud
      &#8595;
Scale Infrastructure
      &#8595;
Restore/Attach Data
      &#8595;
Redirect Traffic</code></code></pre><h3>Warm Standby</h3><p>Keep a smaller but operational environment running continuously.</p><p>Failover becomes faster, but it costs more.</p><p>That&#8217;s the classic tradeoff:</p><p><strong>Lower cost &#8596; Faster recovery</strong></p><p>You don&#8217;t get to escape physics or budgets. &#128176;</p><div><hr></div><h1>SECTION 2: Data, Identity and Access</h1><h2>4&#65039;&#8419; Hybrid Data &amp; Storage Replication</h2><p>Data is often the hardest part of cloud migration.</p><p>Moving an application can sometimes be relatively straightforward.</p><p>Moving <strong>terabytes or petabytes of business-critical data</strong> is another story.</p><p>A hybrid storage architecture might look like:</p><pre><code><code>On-Prem File / NAS
        |
        v
 Storage Gateway
        |
        v
 Cloud Object Storage</code></code></pre><p>This allows organizations to gradually move data while continuing to operate existing systems.</p><h3>Common use cases</h3><p>According to the architecture shown in the source:</p><ul><li><p>Bottomless backup and archive targets</p></li><li><p>Cloud analytics against on-premises data</p></li><li><p>Gradual data migration</p></li></ul><p>For example:</p><pre><code><code>Production Data
      |
      +---- On-Prem Storage
      |
      +---- Cloud Backup
      |
      +---- Archive
      |
      +---- Analytics</code></code></pre><p>The cloud can provide practically elastic storage without requiring an immediate migration of everything.</p><h3>But there&#8217;s a catch.</h3><p>Data movement isn&#8217;t free.</p><p>You need to consider:</p><ul><li><p>&#128225; Network bandwidth</p></li><li><p>&#128176; Egress costs</p></li><li><p>&#128272; Encryption</p></li><li><p>&#129513; Data consistency</p></li><li><p>&#9201;&#65039; Initial synchronization time</p></li><li><p>&#128260; Ongoing replication</p></li></ul><p>The first transfer might take days or weeks depending on the dataset and network capacity.</p><p>And if someone tells you, &#8220;We&#8217;ll just replicate everything to the cloud,&#8221; ask them <strong>how much data, how often, and at what bandwidth</strong>.</p><p>Those three questions have ruined many optimistic architecture meetings.</p><div><hr></div><h1>5&#65039;&#8419; Hybrid Identity &amp; Access</h1><p>Now we reach something that affects almost everything:</p><p><strong>Identity.</strong></p><p>Organizations frequently have an existing on-premises directory while also using cloud identity providers.</p><p>The goal is to give users a consistent identity across environments.</p><p>A simplified architecture:</p><pre><code><code>        On-Prem Directory
               |
          Sync/Federation
               |
               v
       Cloud Identity
          Provider
          /      \
         /        \
 On-Prem Apps    SaaS Apps</code></code></pre><p>This enables:</p><ul><li><p>&#128272; Single Sign-On</p></li><li><p>&#128100; Centralized identity</p></li><li><p>&#128273; Consistent access control</p></li><li><p>&#128737;&#65039; Centralized lifecycle management</p></li></ul><p>A user shouldn&#8217;t ideally need five completely different identities just because the company has five different environments.</p><h3>The interesting part is security.</h3><p>Hybrid identity introduces another attack surface.</p><p>For example:</p><pre><code><code>Compromised Identity
        |
        v
On-Prem Directory
        |
        v
Cloud Identity
        |
        v
Cloud Resources</code></code></pre><p>A compromised privileged account could potentially cross multiple environments.</p><p>That&#8217;s why hybrid identity architectures need:</p><ul><li><p>Least privilege</p></li><li><p>MFA</p></li><li><p>Privileged access controls</p></li><li><p>Conditional access</p></li><li><p>Strong authentication</p></li><li><p>Regular access reviews</p></li><li><p>Monitoring</p></li></ul><p>Identity becomes the bridge between environments.</p><p>And bridges need security too. &#128272;</p><div><hr></div><h1>6&#65039;&#8419; Edge-to-Cloud / Distributed Hybrid</h1><p>This pattern becomes increasingly important as organizations deploy applications outside traditional data centers.</p><p>Think about:</p><ul><li><p>&#127981; Manufacturing plants</p></li><li><p>&#127978; Retail stores</p></li><li><p>&#128663; Vehicles</p></li><li><p>&#128225; Remote locations</p></li><li><p>&#127973; Hospitals</p></li><li><p>&#127806; Agriculture</p></li><li><p>&#128752;&#65039; Industrial environments</p></li></ul><p>The architecture might look like:</p><pre><code><code>        Factory / Edge
        Local Compute
             |
             | Intermittent Link
             |
             v
       Cloud Control Plane
        + Analytics</code></code></pre><p>The key idea is:</p><p><strong>Compute locally when necessary.</strong></p><p><strong>Use the cloud for centralized control, analytics and management.</strong></p><h3>Why not send everything to the cloud?</h3><p>Because sometimes you can&#8217;t.</p><p>The network may be:</p><ul><li><p>Slow</p></li><li><p>Expensive</p></li><li><p>Unreliable</p></li><li><p>Intermittent</p></li></ul><p>And some decisions simply cannot wait for a round trip to the cloud.</p><p>Imagine a manufacturing machine that needs to react in milliseconds.</p><p>You don&#8217;t want:</p><pre><code><code>Sensor
  &#8595;
Internet
  &#8595;
Cloud
  &#8595;
Decision
  &#8595;
Internet
  &#8595;
Machine</code></code></pre><p>Instead:</p><pre><code><code>Sensor
  &#8595;
Edge Compute
  &#8595;
Immediate Decision

       +
       
Cloud
  &#8595;
Analytics
  &#8595;
Central Management</code></code></pre><p>This provides a better balance between latency and centralized intelligence.</p><div><hr></div><h1>SECTION 3: Putting the Patterns Together</h1><p>The interesting part is that real organizations don&#8217;t necessarily choose <strong>one</strong> hybrid-cloud pattern.</p><p>They often use several.</p><p>Imagine an enterprise architecture:</p><pre><code><code>                     CLOUD
        &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
        &#9474; Web / APIs                   &#9474;
        &#9474; Analytics                    &#9474;
        &#9474; DR Environment              &#9474;
        &#9474; Object Storage              &#9474;
        &#9474; Identity Provider           &#9474;
        &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                       &#9474;
                Private Connectivity
                       &#9474;
        &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
        &#9474;                             &#9474;
   ON-PREMISES                    EDGE
   &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;          &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
   &#9474; Applications  &#9474;          &#9474; Factory      &#9474;
   &#9474; Databases     &#9474;          &#9474; Local Apps   &#9474;
   &#9474; Identity      &#9474;          &#9474; Sensors      &#9474;
   &#9474; Storage       &#9474;          &#9474; Processing   &#9474;
   &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;          &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;</code></code></pre><p>Now combine the patterns:</p><h3>Pattern 1</h3><p>Cloud bursting handles <strong>capacity spikes</strong>.</p><h3>Pattern 2</h3><p>Split-tier architecture handles <strong>gradual modernization</strong>.</p><h3>Pattern 3</h3><p>Cloud DR handles <strong>business continuity</strong>.</p><h3>Pattern 4</h3><p>Storage replication handles <strong>data mobility and backup</strong>.</p><h3>Pattern 5</h3><p>Hybrid identity provides <strong>consistent access</strong>.</p><h3>Pattern 6</h3><p>Edge-to-cloud handles <strong>distributed workloads</strong>.</p><p>This is where hybrid cloud becomes less about &#8220;where the server runs&#8221; and more about <strong>how the entire system operates across boundaries</strong>.</p><div><hr></div><h1>What Should a Cloud Engineer Think About? &#129504;</h1><p>Before implementing any hybrid architecture, I would break the problem into several questions.</p><h2>1. Where does the data live?</h2><p>Data location often determines the architecture.</p><p>Ask:</p><blockquote><p>Can the application tolerate data being somewhere else?</p></blockquote><p>If not, don&#8217;t blindly move the application tier.</p><div><hr></div><h2>2. What happens when connectivity fails?</h2><p>Every hybrid architecture has a network boundary.</p><p>Assume that boundary will eventually fail.</p><p>Design for:</p><pre><code><code>Connected
   &#8595;
Degraded
   &#8595;
Disconnected
   &#8595;
Recovered</code></code></pre><p>The application should have an intentional failure strategy.</p><div><hr></div><h2>3. What is the RTO and RPO?</h2><p>Don&#8217;t say:</p><blockquote><p>&#8220;We need high availability.&#8221;</p></blockquote><p>That&#8217;s not an architecture requirement.</p><p>Instead:</p><blockquote><p>&#8220;We need an RTO of 30 minutes and an RPO of 5 minutes.&#8221;</p></blockquote><p>Now engineering teams can design something measurable.</p><div><hr></div><h2>4. Who owns the identity?</h2><p>Hybrid environments can become complicated quickly.</p><p>You need to clearly understand:</p><pre><code><code>User
 &#8595;
Identity Provider
 &#8595;
Authentication
 &#8595;
Authorization
 &#8595;
Resource</code></code></pre><p>Don&#8217;t let identity become an accidental collection of exceptions.</p><div><hr></div><h2>5. How much does data movement cost?</h2><p>Cloud bills aren&#8217;t only about compute.</p><p>Network traffic can become a significant component.</p><p>Calculate:</p><pre><code><code>Data Volume
&#215;
Transfer Frequency
&#215;
Transfer Cost</code></code></pre><p>before committing to an architecture.</p><div><hr></div><h1>Common Mistakes &#128680;</h1><h3>&#10060; Treating hybrid cloud as temporary infrastructure</h3><p>Some organizations assume:</p><blockquote><p>&#8220;We&#8217;ll use hybrid cloud for six months.&#8221;</p></blockquote><p>Five years later, the architecture is still there.</p><p>Design it properly.</p><div><hr></div><h3>&#10060; Ignoring latency</h3><p>An application may work perfectly in a local environment and become slow when database calls cross a network boundary.</p><p>Measure before designing.</p><div><hr></div><h3>&#10060; Building DR without testing it</h3><p>A DR environment that has never been tested is basically an expensive hope.</p><p>Run:</p><ul><li><p>Failover tests</p></li><li><p>Restore tests</p></li><li><p>Recovery drills</p></li><li><p>Application validation</p></li><li><p>DNS/traffic switching tests</p></li></ul><div><hr></div><h3>&#10060; Moving workloads without understanding dependencies</h3><p>An application isn&#8217;t just a VM.</p><p>It might depend on:</p><pre><code><code>Application
 &#8595;
Database
 &#8595;
DNS
 &#8595;
Identity
 &#8595;
Storage
 &#8595;
Message Queue
 &#8595;
External API</code></code></pre><p>Moving one component can affect all the others.</p><div><hr></div><h1>The Bigger Lesson &#127919;</h1><p>Hybrid cloud isn&#8217;t simply:</p><blockquote><p><strong>On-premises + Cloud</strong></p></blockquote><p>It&#8217;s a strategy for deciding <strong>where each workload should live based on business and technical requirements.</strong></p><p>Sometimes the answer is cloud.</p><p>Sometimes it&#8217;s on-premises.</p><p>Sometimes it&#8217;s both.</p><p>Sometimes the right answer is edge computing.</p><p>The strongest cloud engineers don&#8217;t ask:</p><blockquote><p>&#8220;How do we move everything to the cloud?&#8221;</p></blockquote><p>They ask:</p><blockquote><p><strong>&#8220;What architecture gives us the best balance of availability, performance, security, cost and operational simplicity?&#8221;</strong></p></blockquote><p>That is a much better question.</p><p>And it leads to much better systems.</p><div><hr></div><h1>Final Takeaways &#128640;</h1><p>Here is the breakdown of the six hybrid cloud patterns formatted as a clean, structured list:</p><ul><li><p>&#9729;&#65039; <strong>Cloud Bursting:</strong> Handle temporary workload spikes by overflowing from on-premises to the cloud.</p></li><li><p>&#127959;&#65039; <strong>Split-Tier:</strong> Modernize monolithic applications gradually by hosting different application layers across environments.</p></li><li><p>&#128260; <strong>Cloud DR (Disaster Recovery):</strong> Improve disaster recovery and business continuity with cost-effective failover targets.</p></li><li><p>&#128190; <strong>Data Replication:</strong> Move, protect, and analyze data across hybrid environments for backup and insights.</p></li><li><p>&#128272; <strong>Hybrid Identity:</strong> Provide unified authentication, single sign-on (SSO), and centralized access control across systems.</p></li><li><p>&#127981; <strong>Edge-to-Cloud:</strong> Process workloads close to users or physical devices while syncing aggregate data back to the cloud.</p></li></ul><p>Hybrid cloud isn&#8217;t automatically better than public cloud or private infrastructure.</p><p>It&#8217;s simply another architectural tool.</p><p>The real engineering skill is knowing <strong>when to use it and when not to.</strong></p><p>Because architecture isn&#8217;t about collecting technologies.</p><p>It&#8217;s about making trade-offs deliberately.</p><p>And in production, those trade-offs are where the real engineering begins. &#9729;&#65039;&#9881;&#65039;&#128272;</p><div><hr></div><h2>Hashtags</h2><p>#HybridCloud #CloudComputing #AWS #Azure #GCP #CloudArchitecture #DevOps #DevSecOps #CloudEngineering #Kubernetes #InfrastructureAsCode #SRE #CloudSecurity #DistributedSystems #EdgeComputing #CloudMigration</p><h2>Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br>https://www.linkedin.com/in/arvindverma021/</p>]]></content:encoded></item><item><title><![CDATA[The Real Advantage Isn’t More Time. It’s Knowing How to Use It. ⏰]]></title><description><![CDATA[We all get the same 24 hours.]]></description><link>https://arvindverma021.substack.com/p/the-real-advantage-isnt-more-time</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/the-real-advantage-isnt-more-time</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Mon, 31 Aug 2026 07:32:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!321P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!321P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!321P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1916019,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213510150?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!321P!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac89314-3381-4f17-a5e1-68ca50290672_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>We all get the same 24 hours.</p><p>A CEO gets 24 hours.<br>A student gets 24 hours.<br>A software engineer gets 24 hours.<br>Someone building a company gets 24 hours.<br>And someone scrolling through Instagram for three hours also gets 24 hours. &#128241;</p><p>The clock doesn&#8217;t negotiate.</p><p>Yet somehow, some people consistently learn faster, build more, grow their careers, and still find time for family, health, and themselves.</p><p>So what is the difference?</p><p>It isn&#8217;t always intelligence.<br>It isn&#8217;t always money.<br>And it certainly isn&#8217;t having more time.</p><p><strong>The real advantage is knowing where your time deserves to go.</strong></p><p>That sounds simple.</p><p>But humans have somehow managed to turn a 24-hour day into a complicated project involving meetings about meetings, endless notifications, unnecessary scrolling, and the occasional existential crisis at 2 AM. &#128516;</p><p>The problem isn&#8217;t always a lack of time.</p><p>Very often, it is a lack of <strong>direction, prioritization, and intentionality.</strong></p><div><hr></div><h1>SECTION 1: TIME IS EQUAL, BUT ITS VALUE IS NOT &#9203;</h1><p>Think about two people who both have eight hours available outside work.</p><p>Person A spends those hours reacting.</p><p>Messages.<br>Notifications.<br>Random videos.<br>Unplanned meetings.<br>Constant context switching.<br>Checking what everyone else is doing.</p><p>At the end of the day, they are exhausted.</p><p>But when they ask themselves:</p><blockquote><p>&#8220;What did I actually accomplish?&#8221;</p></blockquote><p>The answer isn&#8217;t particularly impressive.</p><p>Now consider Person B.</p><p>They spend two hours learning something valuable.</p><p>One hour exercising.</p><p>Two hours working on an important project.</p><p>One hour with family.</p><p>And the remaining time resting.</p><p>Same 24 hours.</p><p>Completely different outcome.</p><p>That&#8217;s because <strong>time itself isn&#8217;t the advantage. The allocation of time is.</strong></p><h3>The Time Allocation Equation</h3><p>A useful way to think about your day is:</p><p><strong>Time &#215; Focus &#215; Direction = Progress</strong></p><p>If you have plenty of time but no focus, progress is slow.</p><p>If you have focus but no direction, you can become extremely efficient at doing the wrong thing.</p><p>And if you have direction but constantly waste your available time, nothing moves.</p><p>You need all three.</p><h3>Stop Asking, &#8220;Do I Have Time?&#8221;</h3><p>A better question is:</p><blockquote><p><strong>&#8220;Is this worth my time?&#8221;</strong></p></blockquote><p>That&#8217;s a completely different question.</p><p>You probably don&#8217;t need another hour.</p><p>You might need to remove something that is consuming three unnecessary hours.</p><p>For example:</p><p>Instead of spending two hours watching random DevOps tutorials, spend one focused hour learning Kubernetes networking and then actually deploy something.</p><p>Instead of endlessly updating your resume, spend an hour building a project you can discuss during interviews.</p><p>Instead of consuming motivational content for an hour, spend 30 minutes doing the difficult thing you&#8217;ve been postponing.</p><p><strong>Consumption feels productive. Creation usually is.</strong></p><p>And that distinction matters.</p><div><hr></div><h1>SECTION 2: YOUR CALENDAR REVEALS YOUR REAL PRIORITIES &#127919;</h1><p>People often say:</p><blockquote><p>&#8220;My career is important to me.&#8221;</p></blockquote><p>Then you look at their week.</p><p>Three hours of social media.<br>Two hours of random entertainment.<br>Five hours of unnecessary browsing.</p><p>But zero hours spent developing the skill they claim is important.</p><p>Your calendar doesn&#8217;t care about your intentions.</p><p>It reveals your behavior.</p><h3>The 80/20 Problem</h3><p>Not every activity produces equal results.</p><p>A small number of activities usually create most of your progress.</p><p>For a technology professional, those activities might be:</p><ul><li><p>Building real projects</p></li><li><p>Learning difficult concepts</p></li><li><p>Solving production problems</p></li><li><p>Improving communication</p></li><li><p>Networking with the right people</p></li><li><p>Preparing for interviews</p></li><li><p>Writing technical content</p></li><li><p>Contributing to open source</p></li><li><p>Staying current with important technologies</p></li></ul><p>Meanwhile, some activities consume enormous amounts of time without moving your career forward.</p><p>The challenge is identifying the difference.</p><h3>Ask Yourself Three Questions</h3><p>At the beginning of each week, ask:</p><p><strong>1. What can create the biggest impact?</strong></p><p>Maybe it&#8217;s preparing for an upcoming interview.</p><p>Maybe it&#8217;s finishing a project.</p><p>Maybe it&#8217;s learning AWS networking properly.</p><p>Maybe it&#8217;s improving your communication.</p><p><strong>2. What can only I do?</strong></p><p>This is important.</p><p>Some tasks can be delegated, automated, simplified, or eliminated.</p><p>Your time should increasingly go toward things that require your judgment and creativity.</p><p><strong>3. What am I doing simply because I&#8217;ve always done it?</strong></p><p>This one hurts.</p><p>Humans love routines, even inefficient ones.</p><p>A process can survive for years simply because nobody asks:</p><blockquote><p>&#8220;Why are we still doing this?&#8221;</p></blockquote><p>The same thing happens in careers.</p><p>People keep doing tasks that don&#8217;t contribute to growth because they became comfortable with them.</p><p>Comfort is useful.</p><p>But too much comfort quietly becomes stagnation.</p><div><hr></div><h1>SECTION 3: THE REAL ADVANTAGE IS COMPOUNDING YOUR TIME &#128640;</h1><p>The biggest misunderstanding about time management is thinking it is about squeezing more tasks into every day.</p><p>It isn&#8217;t.</p><p><strong>Good time management isn&#8217;t about doing more.</strong></p><p>It&#8217;s about doing more of what matters.</p><p>Imagine spending one hour every day learning a valuable technical skill.</p><p>One hour doesn&#8217;t look impressive.</p><p>After one day: barely noticeable.</p><p>After one week: some progress.</p><p>After one month: significant improvement.</p><p>After one year:</p><p><strong>365 hours of focused learning.</strong></p><p>Now imagine spending that same hour every day building projects.</p><p>Or writing.</p><p>Or networking.</p><p>Or exercising.</p><p>Or improving communication.</p><p>Small actions become surprisingly powerful when repeated for long enough.</p><p>That&#8217;s the magic of compounding. &#128200;</p><h3>Small Progress Is Still Progress</h3><p>You don&#8217;t need to completely transform your life tomorrow.</p><p>You need to make tomorrow slightly better than today.</p><p>Read 10 pages.</p><p>Write 500 words.</p><p>Solve one difficult problem.</p><p>Learn one Kubernetes concept.</p><p>Build one feature.</p><p>Send one thoughtful networking message.</p><p>Exercise for 30 minutes.</p><p>Do it again tomorrow.</p><p>And again.</p><p>And again.</p><p>Eventually, the person you become is dramatically different from the person who started.</p><div><hr></div><h2>The Difference Between Busy and Productive</h2><p>This distinction can change your entire career.</p><p><strong>Busy people ask:</strong></p><blockquote><p>&#8220;How much did I do?&#8221;</p></blockquote><p><strong>Productive people ask:</strong></p><blockquote><p>&#8220;What changed because I did it?&#8221;</p></blockquote><p>That&#8217;s a much better question.</p><p>You can spend ten hours working and accomplish very little.</p><p>You can spend three focused hours and create something meaningful.</p><p>Being busy is easy to measure.</p><p>Impact is harder.</p><p>And unfortunately, humans have a strange tendency to celebrate the appearance of busyness.</p><p>Someone says:</p><blockquote><p>&#8220;I&#8217;ve been working 12 hours every day.&#8221;</p></blockquote><p>The better question is:</p><blockquote><p>&#8220;What did those 12 hours produce?&#8221;</p></blockquote><p>Hours are not outcomes.</p><h3>Learn to Protect Deep Work</h3><p>Modern work has an attention problem.</p><p>Notifications constantly interrupt us.</p><p>Emails arrive.</p><p>Slack messages appear.</p><p>WhatsApp buzzes.</p><p>Someone sends a meeting invitation titled:</p><p><strong>&#8220;Quick Sync.&#8221;</strong></p><p>And somehow the meeting lasts 47 minutes. &#128528;</p><p>Deep work requires protection.</p><p>Try creating blocks of uninterrupted time where:</p><ul><li><p>Notifications are disabled</p></li><li><p>Phone is away</p></li><li><p>One task is selected</p></li><li><p>No unnecessary meetings are accepted</p></li><li><p>The goal is clearly defined</p></li></ul><p>Even 60 minutes of genuine focus can outperform several hours of fragmented attention.</p><div><hr></div><h1>A PRACTICAL FRAMEWORK FOR USING YOUR TIME BETTER &#129504;</h1><p>Here&#8217;s a simple framework you can apply immediately.</p><h3>Step 1: Identify Your One Big Goal</h3><p>Don&#8217;t start with ten goals.</p><p>Choose one major outcome.</p><p>For example:</p><blockquote><p>&#8220;Become interview-ready for a senior DevOps role.&#8221;</p></blockquote><p>Then everything becomes easier to prioritize.</p><h3>Step 2: Break It Into Weekly Outcomes</h3><p>Instead of:</p><blockquote><p>&#8220;Learn Kubernetes.&#8221;</p></blockquote><p>Define:</p><blockquote><p>&#8220;Deploy an application on EKS, configure ingress, implement autoscaling, and troubleshoot common failures.&#8221;</p></blockquote><p>Specific outcomes create measurable progress.</p><h3>Step 3: Reserve Focused Time</h3><p>Put important work on your calendar.</p><p>Not:</p><blockquote><p>&#8220;I&#8217;ll do it sometime tomorrow.&#8221;</p></blockquote><p>That&#8217;s how tomorrow becomes next month.</p><p>Instead:</p><p><strong>7:00 AM &#8211; 8:00 AM &#8594; Kubernetes learning</strong></p><p><strong>8:00 PM &#8211; 9:00 PM &#8594; Project implementation</strong></p><p>Your calendar should contain your priorities, not just other people&#8217;s requests.</p><h3>Step 4: Remove Low-Value Activities</h3><p>Ask:</p><p><strong>Can I eliminate it?</strong><br><strong>Can I automate it?</strong><br><strong>Can I delegate it?</strong><br><strong>Can I simplify it?</strong></p><p>This is where technology professionals have an advantage.</p><p>Automation isn&#8217;t only for infrastructure.</p><p>It can also protect your time.</p><p>Scripts can automate repetitive tasks.</p><p>Templates can reduce repeated work.</p><p>AI can accelerate research, documentation, and brainstorming.</p><p>CI/CD can remove manual deployment work.</p><p>The objective isn&#8217;t to become busy faster.</p><p>It&#8217;s to <strong>free your time for higher-value thinking.</strong></p><div><hr></div><h1>One More Important Lesson: REST IS PRODUCTIVE &#128564;</h1><p>There is another trap.</p><p>People sometimes believe every minute must be productive.</p><p>That&#8217;s nonsense.</p><p>Your brain isn&#8217;t a Kubernetes cluster that you can scale horizontally whenever traffic increases. &#128516;</p><p>You need recovery.</p><p>Sleep matters.</p><p>Exercise matters.</p><p>Family matters.</p><p>Quiet time matters.</p><p>Doing absolutely nothing occasionally matters.</p><p>A system running at 100% CPU continuously isn&#8217;t considered healthy.</p><p>Neither is a human.</p><p><strong>Rest isn&#8217;t the opposite of productivity.</strong></p><p>It is part of sustainable productivity.</p><div><hr></div><h1>The Final Lesson &#127919;</h1><p>You don&#8217;t need more time.</p><p>You need better decisions about the time you already have.</p><p>You don&#8217;t need to become busy.</p><p>You need to become intentional.</p><p>You don&#8217;t need to learn everything.</p><p>You need to learn what matters.</p><p>You don&#8217;t need to chase every opportunity.</p><p>You need to recognize the right ones.</p><p>And you don&#8217;t need to transform your entire life overnight.</p><p>You need to consistently invest small amounts of time into things that compound.</p><p>Because five years from now, you will have spent those five years somehow.</p><p>The question is:</p><p><strong>What will those five years have produced?</strong></p><p>A better career?</p><p>Stronger skills?</p><p>Better health?</p><p>Meaningful relationships?</p><p>Financial stability?</p><p>A project you are proud of?</p><p>Or simply more hours spent reacting to whatever happened to appear on your screen?</p><p>The clock doesn&#8217;t care.</p><p>It keeps moving.</p><p>So don&#8217;t obsess over having more time.</p><p><strong>Learn to use the time you already have.</strong> &#9200;</p><p>Because the real advantage isn&#8217;t having 25 hours in a day.</p><p><strong>It&#8217;s knowing what deserves your 24.</strong></p><div><hr></div><h2>Key Takeaways &#128640;</h2><ul><li><p>&#9200; Everyone gets the same 24 hours, but not everyone allocates them equally.</p></li><li><p>&#127919; Prioritize activities that create meaningful long-term results.</p></li><li><p>&#129504; Deep focus is often more valuable than long working hours.</p></li><li><p>&#9881;&#65039; Automate repetitive work wherever possible.</p></li><li><p>&#128200; Small consistent actions compound over time.</p></li><li><p>&#128721; Eliminate activities that consume time without creating value.</p></li><li><p>&#128564; Rest is necessary for sustainable performance.</p></li><li><p>&#128640; Don&#8217;t aim to do everything. Aim to do what matters.</p></li></ul><p><strong>Your time is one of the few resources you spend every day without knowing how much you have left.</strong></p><p>Use it accordingly.</p><div><hr></div><h2>Hashtags</h2><p>#TimeManagement #Productivity #CareerGrowth #PersonalGrowth #DevOps #SoftwareEngineering #Technology #Learning #Leadership #GrowthMindset #CareerDevelopment #ContinuousLearning #Success #Mindset #WorkLifeBalance</p><h2>Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br>https://www.linkedin.com/in/arvindverma021/</p>]]></content:encoded></item><item><title><![CDATA[🚀 AWS DevOps Mastery | Full Video Lectures + Self-Paced Learning]]></title><description><![CDATA[You know the names of 10+ tools, but you&#8217;re still wondering how they actually fit together.]]></description><link>https://arvindverma021.substack.com/p/aws-devops-mastery-full-video-lectures</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/aws-devops-mastery-full-video-lectures</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sun, 30 Aug 2026 21:09:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zfFb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!zfFb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 424w, /__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 848w, /__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 1272w, /__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!zfFb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png" width="1055" height="1491" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1491,&quot;width&quot;:1055,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1803710,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213456772?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 424w, /__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 848w, /__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 1272w, /__u/substackcdn.com/image/fetch/$s_!zfFb!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F733e1826-9b3b-4f1c-bbb3-25e9b630b296_1055x1491.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>&#128279; <strong>Purchase &amp; Start Learning:</strong><br><a href="https://topmate.io/arvindverma021/2275139">https://topmate.io/arvindverma021/2275139</a></p><p>Learning DevOps is easy to make complicated.</p><p>One tutorial for Git.<br>Another for Jenkins.<br>Then Docker.<br>Then Kubernetes.<br>Then Terraform.<br>Then AWS.</p><p>A few months later, you know the names of 10+ tools, but you&#8217;re still wondering how they actually fit together.</p><p><strong>That&#8217;s the problem this course is designed to solve.</strong></p><h2>&#127909; Learn DevOps Through Full Video Lectures</h2><p><strong>AWS DevOps Mastery</strong> is a structured, self-paced learning experience built around <strong>step-by-step video lectures, practical demonstrations, hands-on learning and interview preparation</strong>.</p><p>The learning journey follows:</p><p><strong>Concept &#8594; Demonstration &#8594; Hands-on &#8594; Automation &#8594; Real-World Implementation</strong></p><p>Instead of simply memorizing commands, the focus is on understanding <strong>what you&#8217;re doing, why you&#8217;re doing it, how it works and when to use it</strong>.</p><div><hr></div><h1>&#128293; THE COMPLETE DEVOPS JOURNEY</h1><p>The course connects the major components of a modern DevOps workflow:</p><p><strong>Git &#8594; Jenkins &#8594; Docker &#8594; Kubernetes &#8594; Terraform &#8594; Ansible &#8594; AWS &#8594; Python Automation &#8594; Production</strong></p><p>This means you&#8217;re not learning each technology as an isolated subject.</p><p>You&#8217;ll understand how they contribute to the larger software delivery and infrastructure workflow.</p><div><hr></div><h1>&#128256; Git</h1><p>Start with the foundation of modern software collaboration.</p><p>Learn:</p><ul><li><p>Branching strategies</p></li><li><p>Git Flow</p></li><li><p>Trunk-based development</p></li><li><p>Merge conflicts</p></li><li><p>Pull-request workflows</p></li><li><p>Releases</p></li></ul><p>Git becomes the starting point for the complete delivery process.</p><div><hr></div><h1>&#9881;&#65039; Jenkins</h1><p>Move from source code to automated CI/CD.</p><p>The course covers:</p><ul><li><p>Declarative pipelines</p></li><li><p>Multibranch pipelines</p></li><li><p>Shared libraries</p></li><li><p>CI/CD automation</p></li><li><p>Docker and Kubernetes-based workflows</p></li></ul><p>The goal is to understand how automated delivery pipelines are designed and used.</p><div><hr></div><h1>&#128051; Docker</h1><p>Learn how applications are packaged and prepared for deployment.</p><p>You&#8217;ll explore:</p><ul><li><p>Production-oriented images</p></li><li><p>Multi-stage builds</p></li><li><p>Docker Compose</p></li><li><p>Container registries</p></li><li><p>Container workflows</p></li></ul><div><hr></div><h1>&#9784;&#65039; Kubernetes</h1><p>Understand the platform used to deploy and manage containerized applications.</p><p>Topics include:</p><ul><li><p>Deployments</p></li><li><p>Services</p></li><li><p>Ingress</p></li><li><p>Helm</p></li><li><p>Horizontal Pod Autoscaling</p></li><li><p>Practical troubleshooting</p></li></ul><p>The emphasis is on understanding Kubernetes as part of the complete application delivery workflow.</p><div><hr></div><h1>&#127959;&#65039; Terraform</h1><p>Learn how infrastructure can be managed as code.</p><p>You&#8217;ll work with concepts including:</p><ul><li><p>Reusable modules</p></li><li><p>Remote state</p></li><li><p>State locking</p></li><li><p>Plan and apply workflows</p></li><li><p>Infrastructure drift</p></li></ul><p>This connects infrastructure management with the rest of your DevOps workflow.</p><div><hr></div><h1>&#128295; Ansible + &#128039; Linux</h1><p>Build the foundation needed for configuration management and troubleshooting.</p><p>You&#8217;ll cover:</p><p><strong>Ansible:</strong> Playbooks, roles, idempotency, dynamic inventories and Ansible Vault.</p><p><strong>Linux:</strong> Shell scripting, systemd, logs and troubleshooting CPU, memory and disk issues.</p><div><hr></div><h1>&#9729;&#65039; AWS</h1><p>The course brings the workflow into the cloud with core AWS services including:</p><p><strong>EC2 &#8226; VPC &#8226; IAM &#8226; S3 &#8226; RDS &#8226; Auto Scaling &#8226; CloudFormation</strong></p><p>This helps connect DevOps practices with real cloud infrastructure.</p><div><hr></div><h1>&#128013; Python Automation</h1><p>Automation is a major part of practical DevOps engineering.</p><p>The course also includes <strong>Python automation and scripts</strong> to help you understand how repetitive DevOps tasks can be automated and operational work can be reduced.</p><p>The mindset changes from:</p><p><strong>&#8220;I&#8217;ll do this manually every time.&#8221;</strong></p><p>to:</p><p><strong>&#8220;Can I automate this?&#8221;</strong></p><p>That is an important shift in DevOps thinking.</p><div><hr></div><h1>&#128188; INTERVIEW PREPARATION</h1><p>The course isn&#8217;t only about learning tools.</p><p>It also includes <strong>DevOps interview questions and practical scenarios</strong> covering areas such as:</p><p>&#9989; AWS<br>&#9989; CI/CD<br>&#9989; Jenkins<br>&#9989; Docker<br>&#9989; Kubernetes<br>&#9989; Terraform<br>&#9989; Ansible<br>&#9989; Linux<br>&#9989; Python automation<br>&#9989; Troubleshooting<br>&#9989; Production scenarios</p><p>The goal is to help you explain your technical decisions rather than simply recite definitions.</p><div><hr></div><h1>&#127919; WHO IS THIS COURSE FOR?</h1><h3>&#128104;&#8205;&#127891; Beginners</h3><p>Build a structured foundation instead of jumping randomly between tutorials.</p><h3>&#128640; Aspiring DevOps Engineers</h3><p>Connect Git, CI/CD, containers, Kubernetes, infrastructure and cloud.</p><h3>&#128188; Working Engineers</h3><p>Strengthen practical knowledge, automation skills and troubleshooting ability.</p><h3>&#127919; Interview Preparation</h3><p>Build the confidence to explain <strong>what, why, how and when</strong> during technical discussions.</p><div><hr></div><h1>&#128218; WHAT YOU GET</h1><p>&#127909; <strong>Full Step-by-Step Video Lectures</strong></p><p>&#129514; <strong>Hands-On Practical Learning</strong></p><p>&#128013; <strong>Python Automation &amp; Scripts</strong></p><p>&#128188; <strong>Interview Questions &amp; Answers</strong></p><p>&#9729;&#65039; <strong>AWS-Focused DevOps Training</strong></p><p>&#128295; <strong>Real-World Workflows</strong></p><p>&#128736;&#65039; <strong>Troubleshooting Practice</strong></p><p>&#128218; <strong>Self-Paced Learning</strong></p><div><hr></div><h1>&#128640; FROM LEARNING TO ENGINEERING</h1><p>The real objective isn&#8217;t to finish another DevOps course.</p><p>It&#8217;s to move from:</p><p><strong>&#8220;I know Git, Docker, Kubernetes and Terraform.&#8221;</strong></p><p>to:</p><p><strong>&#8220;I understand how these technologies work together to deliver and operate applications.&#8221;</strong></p><p>That&#8217;s the difference between memorizing tools and developing <strong>practical DevOps engineering understanding</strong>.</p><p>You learn the concepts.</p><p>You see them implemented.</p><p>You practice them.</p><p>You automate repetitive work.</p><p>You prepare for interview scenarios.</p><p>And you can revisit the lectures at your own pace.</p><h2>&#128279; START YOUR DEVOPS JOURNEY</h2><p><strong>AWS DevOps Mastery | Full Video Lectures + Self-Paced Learning</strong></p><p>&#128073; <strong>Purchase &amp; Access:</strong><br><a href="https://topmate.io/arvindverma021/2275139">https://topmate.io/arvindverma021/2275139</a></p><p><strong>Learn the tools. Connect the workflow. Automate the repetitive work. Think like a DevOps engineer. &#128640;</strong></p><p>#DevOps #AWS #AWSDevOps #DevOpsEngineer #Kubernetes #Docker #Jenkins #Terraform #Ansible #Python #PythonAutomation #CICD #CloudComputing #DevOpsCareer #DevOpsInterview #CloudEngineer #Linux #InfrastructureAsCode #DevOpsLearning</p>]]></content:encoded></item><item><title><![CDATA[12 Architecture Concepts Every Developer Should Know]]></title><description><![CDATA[Software development is no longer just about writing code that works.]]></description><link>https://arvindverma021.substack.com/p/12-architecture-concepts-every-developer</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/12-architecture-concepts-every-developer</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sun, 30 Aug 2026 06:49:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!C88p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!C88p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!C88p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1862196,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213368400?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!C88p!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5875751e-517e-4075-a6ed-13c34863cb50_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Modern applications run across <strong>cloud platforms, containers, databases, APIs, networks, queues, caches, and distributed services</strong>. One small architectural decision can affect performance, reliability, security, and cost.</p><p>And this is where many developers hit a wall.</p><p>You can be excellent at writing functions and still struggle to understand why an application becomes slow when traffic increases.</p><p>You can know Kubernetes commands and still not understand why a service keeps returning <code>503</code>.</p><p>You can deploy an application successfully and still have no idea how it should behave when an entire availability zone goes down.</p><p>That is why understanding <strong>software architecture fundamentals</strong> matters.</p><p>You don&#8217;t need to become an architect overnight. But you should understand the building blocks that modern systems are constructed from.</p><p>Here are <strong>12 architecture concepts every developer should know.</strong></p><div><hr></div><h3>1. Client-Server Architecture &#128187;</h3><p>The simplest place to start.</p><p>In a client-server architecture, the client sends a request and the server processes it.</p><p>For example:</p><pre><code>User
  &#8595;
Browser / Mobile App
  &#8595;
API Server
  &#8595;
Database</code></pre><p>The client might be a browser or mobile application.</p><p>The server handles business logic, authentication, data processing, and communication with other services.</p><h3>Why it matters</h3><p>Almost every modern application still relies on this fundamental relationship, even when the architecture becomes much more complicated.</p><p>Understanding it helps you reason about:</p><ul><li><p>Request flow</p></li><li></li><li><p>APIs</p></li><li></li><li><p>Authentication</p></li><li></li><li><p>Backend services</p></li><li></li><li><p>Databases</p></li><li></li><li><p>Network communication</p></li><li></li></ul><div><hr></div><h3>2. Load Balancing &#9878;&#65039;</h3><p>Imagine 10,000 users sending requests to one server.</p><p>That server is going to have a rather unpleasant afternoon.</p><p>A load balancer distributes incoming traffic across multiple servers.</p><pre><code>Users
               &#8595;
        Load Balancer
        &#8601;     &#8595;     &#8600;
     Server  Server  Server
       A       B       C</code></pre><p>Instead of:</p><pre><code>Users &#8594; One Server &#8594; &#128165;</code></pre><p>you get:</p><pre><code>Users &#8594; Load Balancer &#8594; Multiple Servers</code></pre><h3>Benefits</h3><ul><li><p>High availability</p></li><li></li><li><p>Better performance</p></li><li></li><li><p>Horizontal scaling</p></li><li></li><li><p>Fault tolerance</p></li><li></li></ul><p>In AWS environments, services such as Application Load Balancer and Network Load Balancer are commonly used for this purpose.</p><div><hr></div><h3>3. Caching &#9889;</h3><p>Why repeatedly calculate or retrieve something when you already have the answer?</p><p>Caching stores frequently accessed data closer to the application or user.</p><p>For example:</p><pre><code>User
 &#8595;
Application
 &#8595;
Cache &#8594; Data available?
 &#8595;
Yes &#8594; Return immediately
 &#8595;
No
 &#8595;
Database</code></pre><p>Common technologies include:</p><ul><li><p>Redis</p></li><li></li><li><p>Memcached</p></li><li></li><li><p>CDN caching</p></li><li></li><li><p>Browser caching</p></li><li></li></ul><h3>The important question</h3><p>Caching improves performance, but introduces a difficult problem:</p><p><strong>When should cached data expire or be invalidated?</strong></p><p>That is where the famous engineering headache appears:</p><blockquote><p><em>Cache invalidation.</em></p></blockquote><p>Two words capable of ruining an otherwise peaceful afternoon.</p><div><hr></div><h3>4. Database Replication &#128452;&#65039;</h3><p>A production database should not necessarily depend on one machine.</p><p>Replication creates copies of database data across multiple instances.</p><p>For example:</p><pre><code>Application
                  &#8595;
             Primary DB
              &#8601;      &#8600;
         Replica A   Replica B</code></pre><p>Replicas can help with:</p><ul><li><p>Read scaling</p></li><li></li><li><p>High availability</p></li><li></li><li><p>Disaster recovery</p></li><li></li><li><p>Reducing load on the primary database</p></li><li></li></ul><p>A common architecture is:</p><pre><code>Writes &#8594; Primary
Reads  &#8594; Replicas</code></pre><p>But replication introduces questions around:</p><ul><li><p>Consistency</p></li><li></li><li><p>Replication lag</p></li><li></li><li><p>Failover</p></li><li></li><li><p>Data synchronization</p></li><li></li></ul><p>Understanding these trade-offs is far more valuable than simply knowing how to create a database.</p><div><hr></div><h3>5. Microservices Architecture &#129513;</h3><p>Instead of building one enormous application, functionality can be divided into smaller services.</p><p>For example:</p><pre><code>API Gateway
                    &#8595;
        &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
        &#8595;           &#8595;           &#8595;
     User        Payment       Order
    Service      Service       Service
        &#8595;           &#8595;           &#8595;
      DB          DB           DB</code></pre><p>Each service can potentially be:</p><ul><li><p>Developed independently</p></li><li></li><li><p>Deployed independently</p></li><li></li><li><p>Scaled independently</p></li><li></li></ul><h3>But here&#8217;s the catch</h3><p>Microservices don&#8217;t magically make systems better.</p><p>They introduce:</p><ul><li><p>Network communication</p></li><li></li><li><p>Distributed failures</p></li><li></li><li><p>Service discovery</p></li><li></li><li><p>Observability challenges</p></li><li></li><li><p>Data consistency problems</p></li><li></li><li><p>More deployments</p></li><li></li></ul><p>You haven&#8217;t eliminated complexity.</p><p>You&#8217;ve distributed it across 27 repositories.</p><div><hr></div><h3>6. API Gateway &#128682;</h3><p>An API Gateway acts as an entry point between clients and backend services.</p><pre><code>Client
  &#8595;
API Gateway
  &#8595;
 &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
 &#8595;       &#8595;        &#8595;
User   Orders   Payments</code></pre><p>It can handle things such as:</p><ul><li><p>Authentication</p></li><li></li><li><p>Routing</p></li><li></li><li><p>Rate limiting</p></li><li></li><li><p>Request transformation</p></li><li></li><li><p>Logging</p></li><li></li><li><p>Traffic control</p></li><li></li></ul><p>Instead of exposing every backend service directly to the internet, the gateway provides a controlled entry point.</p><div><hr></div><h3>7. Message Queues &#128236;</h3><p>Not everything needs to happen synchronously.</p><p>Suppose a user uploads a document.</p><p>Instead of making the user wait while five backend operations complete:</p><pre><code>User &#8594; API &#8594; Process everything &#8594; Response</code></pre><p>you can use asynchronous processing:</p><pre><code>User
 &#8595;
API
 &#8595;
Message Queue
 &#8595;
Worker
 &#8595;
Processing</code></pre><p>Popular technologies include:</p><ul><li><p>Amazon SQS</p></li><li></li><li><p>Apache Kafka</p></li><li></li><li><p>RabbitMQ</p></li><li></li><li><p>Amazon SNS</p></li><li></li></ul><p>Queues help with:</p><ul><li><p>Traffic spikes</p></li><li></li><li><p>Asynchronous processing</p></li><li></li><li><p>Decoupling services</p></li><li></li><li><p>Retry mechanisms</p></li><li></li><li><p>Workload buffering</p></li><li></li></ul><p>This becomes particularly important when one service can temporarily process work faster or slower than another.</p><div><hr></div><h3>8. Horizontal vs Vertical Scaling &#128200;</h3><p>This is one of those concepts that sounds complicated until you draw it.</p><h3>Vertical scaling</h3><p>Make the existing machine bigger.</p><pre><code>2 CPU
 &#8595;
8 CPU
 &#8595;
16 CPU</code></pre><h3>Horizontal scaling</h3><p>Add more machines.</p><pre><code>Server
  &#8595;
Server + Server
  &#8595;
Server + Server + Server</code></pre><p>Cloud-native systems generally favor horizontal scaling where practical because it can provide better resilience and elasticity.</p><p>Kubernetes makes this particularly useful through mechanisms such as:</p><ul><li><p>Horizontal Pod Autoscaler</p></li><li></li><li><p>Cluster Autoscaler</p></li><li></li><li><p>Multiple replicas</p></li><li></li></ul><p>But scaling isn&#8217;t simply:</p><blockquote><p><em>&#8220;Add more pods.&#8221;</em></p></blockquote><p>You also need to consider databases, network capacity, queues, dependencies, and bottlenecks.</p><div><hr></div><h3>9. Stateless vs Stateful Applications &#128260;</h3><p>A <strong>stateless application</strong> doesn&#8217;t rely on local instance memory to maintain user state.</p><p>For example:</p><pre><code>Request 1 &#8594; Server A
Request 2 &#8594; Server B
Request 3 &#8594; Server C</code></pre><p>Any server can handle the request.</p><p>Stateful systems depend on persistent state.</p><p>Examples include:</p><ul><li><p>Databases</p></li><li></li><li><p>Persistent storage</p></li><li></li><li><p>Stateful applications</p></li><li></li></ul><p>A common cloud architecture tries to keep application servers stateless while storing persistent data in external systems.</p><pre><code>Users
 &#8595;
Load Balancer
 &#8595;
Stateless App Servers
 &#8595;
Database / Object Storage</code></pre><p>This makes scaling and replacement much easier.</p><div><hr></div><h3>10. CDN Architecture &#127757;</h3><p>A Content Delivery Network places cached content closer to users geographically.</p><p>Without a CDN:</p><pre><code>User in India
      &#8595;
US Server
      &#8595;
Content</code></pre><p>With a CDN:</p><pre><code>User in India
      &#8595;
Nearest CDN Edge
      &#8595;
Cached Content</code></pre><p>This can significantly reduce latency for static or cacheable content.</p><p>AWS CloudFront is a common example.</p><p>CDNs are particularly useful for:</p><ul><li><p>Images</p></li><li></li><li><p>JavaScript</p></li><li></li><li><p>CSS</p></li><li></li><li><p>Videos</p></li><li></li><li><p>Static websites</p></li><li></li><li><p>Cacheable API responses</p></li><li></li></ul><div><hr></div><h3>11. High Availability &amp; Disaster Recovery &#128737;&#65039;</h3><p>What happens when your server disappears?</p><p>What happens when an availability zone fails?</p><p>What happens when someone deletes the wrong database?</p><p>Production architecture needs answers before those questions become incidents.</p><p>A highly available architecture might look like:</p><pre><code>Users
                  &#8595;
             Load Balancer
              &#8601;        &#8600;
          AZ-1          AZ-2
           &#8595;              &#8595;
        App A           App B
           &#8600;              &#8601;
             Database</code></pre><p>Disaster recovery goes further.</p><p>You need to think about:</p><ul><li><p>Backups</p></li><li></li><li><p>Replication</p></li><li></li><li><p>Recovery Point Objective</p></li><li></li><li><p>Recovery Time Objective</p></li><li></li><li><p>Multi-AZ</p></li><li></li><li><p>Multi-region strategies</p></li><li></li></ul><p>The goal isn&#8217;t merely:</p><blockquote><p><em>&#8220;We have backups.&#8221;</em></p></blockquote><p>The important question is:</p><blockquote><p><em><strong>&#8220;Can we actually restore the system when production is unavailable?&#8221;</strong></em></p></blockquote><p>A backup nobody has tested is basically a very expensive optimism file.</p><div><hr></div><h3>12. Observability &#128270;</h3><p>A production system should tell you what is happening.</p><p>Observability typically combines:</p><h3>Metrics</h3><p>What is happening?</p><pre><code>CPU
Memory
Latency
Request rate
Error rate</code></pre><h3>Logs</h3><p>What happened?</p><pre><code>Application errors
Authentication failures
Deployment events
Database errors</code></pre><h3>Traces</h3><p>Where did the request spend its time?</p><pre><code>API
 &#8595;
Service A
 &#8595;
Service B
 &#8595;
Database</code></pre><p>Together, these help engineers answer the question that matters during an incident:</p><p><strong>&#8220;Why is the system behaving this way?&#8221;</strong></p><p>Tools commonly used include:</p><ul><li><p>Prometheus</p></li><li></li><li><p>Grafana</p></li><li></li><li><p>OpenTelemetry</p></li><li></li><li><p>Elasticsearch</p></li><li></li><li><p>Loki</p></li><li></li><li><p>CloudWatch</p></li><li></li></ul><div><hr></div><h3>The Bigger Picture &#129504;</h3><p>These concepts shouldn&#8217;t be learned as isolated definitions.</p><p>The real value comes from understanding how they work together.</p><p>For example, a modern AWS application might look something like this:</p><pre><code>Users
                       &#8595;
                    Route 53
                       &#8595;
                    CloudFront
                       &#8595;
                 Load Balancer
                       &#8595;
              Kubernetes / EKS
              &#8601;      &#8595;       &#8600;
           Service Service Service
              &#8595;       &#8595;        &#8595;
             Cache   Queue    APIs
                &#8600;      &#8595;      &#8601;
                  Databases
                       &#8595;
                  Monitoring</code></pre><p>Now you&#8217;re no longer thinking about individual technologies.</p><p>You&#8217;re thinking about <strong>system behavior</strong>.</p><p>That&#8217;s the real shift.</p><div><hr></div><h3>Architecture Is About Trade-offs &#9878;&#65039;</h3><p>There is rarely one perfect architecture.</p><p>Every decision introduces trade-offs.</p><p>For example:</p><h3>Microservices</h3><p>More independent deployments.</p><p>But also more distributed-system complexity.</p><h3>Caching</h3><p>Faster responses.</p><p>But potentially stale data.</p><h3>Replication</h3><p>Better availability and read scalability.</p><p>But consistency becomes more complicated.</p><h3>Multi-region</h3><p>Better disaster resilience.</p><p>But higher operational and infrastructure costs.</p><h3>Kubernetes</h3><p>Powerful orchestration.</p><p>But significantly more operational complexity than simply running one container.</p><p>Good engineers don&#8217;t just ask:</p><blockquote><p><em>&#8220;Can we use this technology?&#8221;</em></p></blockquote><p>They ask:</p><blockquote><p><em><strong>&#8220;What problem are we solving, and what complexity are we accepting in return?&#8221;</strong></em></p></blockquote><div><hr></div><h3>What Developers Should Focus On &#128640;</h3><p>You don&#8217;t need to memorize hundreds of architecture diagrams.</p><p>Start with these fundamentals:</p><p><strong>1. Understand request flow</strong></p><pre><code>User &#8594; DNS &#8594; CDN &#8594; Load Balancer &#8594; Application &#8594; Database</code></pre><p><strong>2. Understand failure</strong></p><p>Ask:</p><blockquote><p><em>What happens if this component fails?</em></p></blockquote><p><strong>3. Understand scaling</strong></p><p>Ask:</p><blockquote><p><em>What happens when traffic becomes 10x larger?</em></p></blockquote><p><strong>4. Understand security</strong></p><p>Ask:</p><blockquote><p><em>Who can access this component?</em></p></blockquote><p><strong>5. Understand observability</strong></p><p>Ask:</p><blockquote><p><em>How will I know something is broken?</em></p></blockquote><p><strong>6. Understand cost</strong></p><p>Ask:</p><blockquote><p><em>What will this architecture cost at scale?</em></p></blockquote><p>That mindset will take you much further than memorizing technology definitions.</p><div><hr></div><h3>Final Takeaway &#127919;</h3><p>Modern engineering isn&#8217;t about knowing the most tools.</p><p>It&#8217;s about understanding <strong>how systems behave</strong>.</p><p>You can learn AWS.</p><p>You can learn Kubernetes.</p><p>You can learn Terraform.</p><p>You can learn Docker.</p><p>But if you don&#8217;t understand networking, scaling, availability, databases, caching, observability, and distributed systems, you&#8217;re still learning individual tools rather than architecture.</p><p>The strongest engineers gradually move from:</p><p><strong>&#8220;How do I deploy this?&#8221;</strong></p><p>to:</p><p><strong>&#8220;How should this system be designed?&#8221;</strong></p><p>And eventually:</p><p><strong>&#8220;What happens when everything goes wrong?&#8221;</strong></p><p>That&#8217;s where architecture thinking begins.</p><blockquote><p><em><strong>Tools change. Architecture principles stay.</strong></em></p></blockquote><div><hr></div><h3>&#128279; Connect With Me</h3><p>I regularly share practical content around <strong>DevOps, AWS, Kubernetes, Terraform, CI/CD, DevSecOps, cloud architecture, production troubleshooting, and interview preparation.</strong></p><p><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p><p>If you&#8217;re building your DevOps or cloud engineering career, follow along for practical architecture breakdowns and real-world engineering scenarios.</p><h3>&#128640; Keep Learning. Keep Building. Keep Thinking in Systems.</h3><p>#SoftwareArchitecture #DevOps #AWS #CloudComputing #Kubernetes #Terraform #Docker #CloudArchitecture #SystemDesign #DevSecOps #SRE #Microservices #SoftwareEngineering #InfrastructureAsCode #CICD</p>]]></content:encoded></item><item><title><![CDATA[🌱 The Things Life Teaches You When You Stop Trying to Control Everything]]></title><description><![CDATA[There are some lessons you learn from books.]]></description><link>https://arvindverma021.substack.com/p/the-things-life-teaches-you-when</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/the-things-life-teaches-you-when</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 10:17:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Tn70!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Tn70!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Tn70!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2262945,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213259460?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Tn70!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0b389e-f9b1-4c4b-be59-56f08b44eff3_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>There are some lessons you learn from books. &#128218;</p><p>Some you learn from failure. &#128148;</p><p>And some arrive through a simple picture that makes you stop scrolling for a few seconds and think:</p><p><strong>&#8220;Maybe I needed to see this.&#8221;</strong></p><p>The PDF you shared contains <strong>seven simple but powerful visual lessons</strong> about life, growth, leadership, consistency, comparison, support, and accepting that things don&#8217;t always go according to plan.</p><p>And when you put all seven together, they tell one bigger story:</p><blockquote><p><strong>You don&#8217;t need to have everything figured out. You need to keep moving in the right direction.</strong> &#128694;&#8205;&#9794;&#65039;&#10145;&#65039;</p></blockquote><div><hr></div><h1>&#128214; SECTION 1: Small Progress Doesn&#8217;t Look Impressive Until You Look Back</h1><h2>&#128170; The Power of Consistency</h2><p>The first image shows a transformation over:</p><p><strong>1 Month &#8594; 1 Year &#8594; 3 Years</strong></p><p>The difference is obvious.</p><p>But the most important part is what you <strong>don&#8217;t</strong> see.</p><p>There wasn&#8217;t one magical day when everything changed. &#10024;</p><p>There wasn&#8217;t one perfect workout.</p><p>There wasn&#8217;t one perfect decision.</p><p>There wasn&#8217;t one moment when suddenly everything became better.</p><p>The transformation came from doing something repeatedly for a long period of time.</p><p><strong>That&#8217;s consistency.</strong> &#128257;</p><p>And honestly, consistency is one of the hardest things for human beings to respect.</p><p>We want results immediately.</p><p>We study for two weeks and expect mastery.</p><p>We start exercising and expect a different body next month.</p><p>We learn Kubernetes for a few weeks and expect to troubleshoot production clusters like a senior engineer.</p><p>We apply for jobs for ten days and expect multiple offers.</p><p>We publish five articles and expect thousands of readers.</p><p>Then we look at the results and think:</p><blockquote><p><strong>&#8220;Maybe this isn&#8217;t working.&#8221;</strong> &#129335;&#8205;&#9794;&#65039;</p></blockquote><p>Sometimes the problem isn&#8217;t that it isn&#8217;t working.</p><p>The problem is that <strong>we stopped too early.</strong></p><div><hr></div><h2>&#128187; Think About Learning DevOps</h2><p>Imagine someone starts learning AWS.</p><h3>Day 1</h3><blockquote><p>&#8220;I don&#8217;t understand VPCs.&#8221; &#128565;&#8205;&#128171;</p></blockquote><h3>Day 10</h3><blockquote><p>&#8220;I still don&#8217;t understand networking.&#8221;</p></blockquote><h3>Day 30</h3><blockquote><p>&#8220;Maybe DevOps isn&#8217;t for me.&#8221;</p></blockquote><p>Now imagine another person who spends <strong>one focused hour every day for a year.</strong> &#9203;</p><p>They build projects.</p><p>They break infrastructure.</p><p>They troubleshoot Terraform.</p><p>They deploy Kubernetes applications.</p><p>They make mistakes.</p><p>They read documentation.</p><p>They repeat the process.</p><p>After one year, their knowledge may look completely different.</p><p>Not necessarily because they were smarter.</p><p>But because they <strong>stayed in the game.</strong> &#127919;</p><div><hr></div><h2>&#128293; Consistency Beats Intensity</h2><p>You don&#8217;t need to become extraordinary tomorrow.</p><p>You need to become <strong>slightly better today.</strong></p><p>Then do it again tomorrow.</p><p>And again.</p><p>And again.</p><p>That boring repetition is where most meaningful growth happens.</p><p>The target illustration on <strong>page 3</strong> makes the same point visually. The arrows start scattered, then gradually become more accurate over time.</p><p>&#127919; <strong>Today:</strong> You may miss.</p><p>&#127919; <strong>Next month:</strong> You understand more.</p><p>&#127919; <strong>Next year:</strong> Your accuracy improves dramatically.</p><p>Every mistake gives you information.</p><p>Every failed attempt teaches you something.</p><p>Every experience improves your next attempt.</p><p>Eventually, your arrows start getting closer to the target.</p><h3>&#128680; The Real Enemy Isn&#8217;t Failure</h3><p>It&#8217;s <strong>inconsistency.</strong></p><p>Failure is normal.</p><p>Missing the target is normal.</p><p>Getting rejected is normal.</p><p>Having a bad day is normal.</p><p>Changing direction is normal.</p><p>What becomes dangerous is repeatedly quitting whenever progress becomes invisible.</p><p>The world celebrates results. &#127942;</p><p>But results are usually the final layer of <strong>thousands of boring actions nobody saw.</strong></p><div><hr></div><h1>&#128101; SECTION 2: Stop Pulling People and Stop Carrying the Past</h1><h2>&#128084; Boss vs Leader</h2><p>The second image presents a simple contrast:</p><p><strong>BOSS vs. LEADER</strong></p><p>In the first illustration, the boss sits on top of a platform while employees pull him forward.</p><p>In the second, the leader gets down and moves alongside the team.</p><p>That difference represents something much bigger than management style.</p><p>It represents the difference between:</p><p><strong>Authority &#128084; vs. Influence &#129309;</strong></p><p>A boss gives instructions.</p><p>A leader creates movement.</p><p>A boss says:</p><blockquote><p>&#8220;Get this done.&#8221;</p></blockquote><p>A leader says:</p><blockquote><p>&#8220;Let&#8217;s figure out how we&#8217;re going to get this done.&#8221;</p></blockquote><p>A boss focuses on <strong>who made the mistake.</strong></p><p>A leader focuses on <strong>why the system allowed the mistake to happen.</strong></p><p>Those two questions create completely different cultures.</p><p>One creates fear. &#128552;</p><p>The other creates learning. &#128218;</p><div><hr></div><h2>&#128736;&#65039; Leadership in a Production Environment</h2><p>Imagine a production deployment fails at 2 AM. &#127769;</p><p>The boss asks:</p><blockquote><p><strong>&#8220;Who deployed this?&#8221;</strong></p></blockquote><p>The leader asks:</p><blockquote><p><strong>&#8220;What happened, and how do we prevent it from happening again?&#8221;</strong></p></blockquote><p>That&#8217;s a massive difference.</p><p>One searches for someone to blame.</p><p>The other searches for a way to improve the system.</p><p>In engineering teams, this distinction matters enormously.</p><h3>A strong leader doesn&#8217;t need to be the smartest person in the room.</h3><p>Sometimes the strongest leader is the person who says:</p><blockquote><p><strong>&#8220;I don&#8217;t know. Let&#8217;s investigate.&#8221;</strong> &#128270;</p></blockquote><p>That requires confidence.</p><p>Because insecure leaders try to have answers for everything.</p><p>Good leaders understand that their responsibility isn&#8217;t to know everything.</p><p>Their responsibility is to <strong>help the team solve problems.</strong></p><div><hr></div><h1>&#127890; Stop Carrying Yesterday Everywhere You Go</h1><p>The fourth image shows a person carrying a massive bag labeled:</p><p><strong>PAST</strong></p><p>The message asks whether it would be easier if he simply left it behind.</p><p>It&#8217;s a simple image.</p><p>But it&#8217;s painfully relatable.</p><p>We carry old failures into new situations.</p><p>A failed interview becomes:</p><blockquote><p>&#8220;I&#8217;m probably not good enough.&#8221;</p></blockquote><p>One rejection becomes:</p><blockquote><p>&#8220;Companies don&#8217;t want me.&#8221;</p></blockquote><p>A failed project becomes:</p><blockquote><p>&#8220;I&#8217;m not capable.&#8221;</p></blockquote><p>One bad decision becomes:</p><blockquote><p>&#8220;I always make bad decisions.&#8221;</p></blockquote><p>And suddenly something that happened months or years ago is making decisions for us today.</p><p>That&#8217;s a strange way to live.</p><h3>&#129504; Your Past Should Be a Teacher, Not a Permanent Roommate.</h3><p>Learn from it.</p><p>Analyze it.</p><p>Understand it.</p><p>Then keep moving.</p><p>If you made a mistake, understand what caused it.</p><p>If you failed, understand what you can improve.</p><p>If a career decision didn&#8217;t work, change your approach.</p><p>But don&#8217;t continuously punish your present self for something your past self didn&#8217;t know.</p><p>You were making decisions with the information you had <strong>at that time.</strong></p><p>Today, you know more.</p><p>That&#8217;s called <strong>growth.</strong> &#127793;</p><div><hr></div><h1>&#127937; SECTION 3: You Don&#8217;t Have to Win Every Race</h1><h2>&#129409; Stop Trying to Prove You&#8217;re the Best</h2><p>One of the most striking images in the PDF says:</p><blockquote><p><strong>Sometimes trying to prove that you are the best is an insult.</strong></p></blockquote><p>The illustration shows two dogs outside numbered doors while a lion sits calmly between them.</p><p>The message is about <strong>comparison.</strong></p><p>And comparison has become almost unavoidable.</p><p>You open LinkedIn.</p><p>Someone got promoted. &#128200;</p><p>Someone moved to a major company.</p><p>Someone announced a &#8377;40 LPA package. &#128176;</p><p>Someone launched a startup. &#128640;</p><p>Someone became a manager at 28.</p><p>Someone bought a house.</p><p>Someone is traveling through Europe. &#9992;&#65039;</p><p>Someone apparently achieved enlightenment before breakfast.</p><p>And suddenly you start questioning your own life.</p><p>Human beings somehow turned LinkedIn into a scoreboard. &#128517;</p><p>But here&#8217;s the problem:</p><blockquote><p><strong>You don&#8217;t know the rules of someone else&#8217;s game.</strong></p></blockquote><p>You don&#8217;t know their starting point.</p><p>You don&#8217;t know their struggles.</p><p>You don&#8217;t know their responsibilities.</p><p>You don&#8217;t know what they sacrificed.</p><p>And you don&#8217;t know whether what they achieved is even what you actually want.</p><div><hr></div><h2>&#127919; Your Competition Is Yesterday&#8217;s Version of You</h2><p>If you understand AWS better this month than last month:</p><p><strong>That&#8217;s progress.</strong> &#128218;</p><p>If you can troubleshoot a Kubernetes issue today that confused you six months ago:</p><p><strong>That&#8217;s progress.</strong> &#9784;&#65039;</p><p>If you&#8217;re financially more responsible than you were last year:</p><p><strong>That&#8217;s progress.</strong> &#128176;</p><p>If you&#8217;re becoming more disciplined:</p><p><strong>That&#8217;s progress.</strong> &#129504;</p><p>Not every victory needs an audience.</p><p>Some of the most important improvements in life happen quietly.</p><div><hr></div><h1>&#129309; Sometimes You Need Support</h1><p>Another image in the PDF contrasts:</p><p><strong>&#8220;The support&#8221;</strong><br>with<br><strong>&#8220;The congratulations.&#8221;</strong></p><p>The first shows someone walking alone.</p><p>The second shows a crowd following behind after the person has already achieved something.</p><p>That&#8217;s painfully familiar.</p><p>When you&#8217;re struggling, there may be very few people around.</p><p>When you&#8217;re building something from scratch, the audience is usually small.</p><p>When you&#8217;re learning, failing, applying, experimenting, or starting again, nobody is particularly interested in your progress.</p><p>Then one day, things work.</p><p>Suddenly:</p><blockquote><p>&#8220;Congratulations!&#8221; &#127881;</p><p>&#8220;I always knew you could do it!&#8221;</p><p>&#8220;So proud of you!&#8221;</p></blockquote><p>Human behavior occasionally has the efficiency of a marketing department. &#128516;</p><p>But the lesson isn&#8217;t to become bitter.</p><p>The lesson is to <strong>recognize genuine support.</strong></p><p>Pay attention to the people who encourage you when there is nothing to celebrate yet.</p><p>The person who checks on you when you&#8217;re struggling.</p><p>The friend who helps you prepare before the interview.</p><p>The colleague who explains something without making you feel stupid.</p><p>The mentor who gives you honest feedback instead of empty motivation.</p><p>Those people matter.</p><p>Because:</p><blockquote><p><strong>Celebration is easy. Support is expensive.</strong> &#10084;&#65039;</p></blockquote><div><hr></div><h1>&#128591; And Then There Is God&#8217;s Plan</h1><p>The final image might be the most relatable of all.</p><p>On one side:</p><h3><strong>My Plans</strong></h3><p>A small number of roses. &#127801;</p><p>On the other:</p><h3><strong>God&#8217;s Plan</strong></h3><p>An entire wall filled with roses. &#127801;&#127801;&#127801;&#127801;&#127801;</p><p>The image captures something many of us struggle to accept:</p><p><strong>Our plans may not always be the best version of our future.</strong></p><p>We create timelines.</p><p>At 22:</p><blockquote><p>&#8220;I&#8217;ll achieve this.&#8221;</p></blockquote><p>At 25:</p><blockquote><p>&#8220;I&#8217;ll be settled.&#8221;</p></blockquote><p>At 30:</p><blockquote><p>&#8220;Everything should be figured out.&#8221;</p></blockquote><p>Then life happens.</p><p>A job doesn&#8217;t work out.</p><p>A relationship changes.</p><p>A business fails.</p><p>An opportunity disappears.</p><p>A career takes a completely different direction.</p><p>And suddenly the timeline we created for ourselves looks completely irrelevant.</p><p>But sometimes the detour isn&#8217;t the end of the journey.</p><p><strong>It&#8217;s part of the journey.</strong> &#128739;&#65039;</p><div><hr></div><h2>&#128682; Not Every Closed Door Is Rejection</h2><p>Sometimes it&#8217;s redirection.</p><p>You may desperately want one opportunity because you believe it will solve everything.</p><p>Then it doesn&#8217;t happen.</p><p>Months later, another opportunity appears.</p><p>And you realize:</p><p><strong>If the first thing had worked, you might never have reached the second.</strong></p><p>Life has a strange habit of making sense <strong>backward.</strong></p><p>That&#8217;s why patience matters.</p><p>You can have goals.</p><p>You should have goals.</p><p>You should work hard.</p><p>You should build skills.</p><p>You should take responsibility.</p><p>But you also need enough humility to accept:</p><blockquote><p><strong>&#8220;I may not know what comes next.&#8221;</strong> &#128591;</p></blockquote><p>And that&#8217;s okay.</p><div><hr></div><h1>&#127793; What These Seven Images Are Really Trying to Tell Us</h1><p>When you put all seven lessons together, they form one surprisingly coherent philosophy.</p><h3>&#128170; Be consistent.</h3><p>You don&#8217;t need spectacular progress every day.</p><h3>&#129309; Lead instead of controlling.</h3><p>Help people move forward rather than simply demanding that they do.</p><h3>&#127919; Keep aiming.</h3><p>Your accuracy improves through repetition.</p><h3>&#127890; Leave the past behind.</h3><p>Carry lessons, not unnecessary weight.</p><h3>&#10084;&#65039; Accept support.</h3><p>Remember who stood beside you before the results arrived.</p><h3>&#129409; Stop obsessing over comparison.</h3><p>Someone else&#8217;s success doesn&#8217;t reduce yours.</p><h3>&#128591; Trust the journey.</h3><p>Your plan is important, but it isn&#8217;t the only possible path.</p><div><hr></div><h1>&#9881;&#65039; A Practical Way to Apply This in Real Life</h1><p>You don&#8217;t need to completely redesign your life tomorrow.</p><p>Start with five simple rules.</p><h3>1&#65039;&#8419; Improve Something Every Day</h3><p>Even <strong>30 minutes of focused learning</strong> can compound over time. &#128218;</p><h3>2&#65039;&#8419; Measure Yourself Against Yourself</h3><p>Ask:</p><blockquote><p><strong>&#8220;Am I better than I was six months ago?&#8221;</strong></p></blockquote><p>Not:</p><blockquote><p>&#8220;Am I ahead of everyone else?&#8221;</p></blockquote><h3>3&#65039;&#8419; Learn From Your Mistakes</h3><p>Failure without reflection is just expensive repetition. &#128184;</p><h3>4&#65039;&#8419; Help People When You Can</h3><p>Leadership starts long before you receive a leadership title. &#129309;</p><h3>5&#65039;&#8419; Make Plans, But Stay Flexible</h3><p>Have a destination. &#128506;&#65039;</p><p>Don&#8217;t become emotionally attached to one specific route.</p><div><hr></div><h1>&#10084;&#65039; Final Thoughts</h1><p>The most interesting thing about these images is that none of them promises an easy life.</p><p>They don&#8217;t say:</p><p><strong>&#8220;Everything will work out tomorrow.&#8221;</strong></p><p>They say something more realistic.</p><p>You will fail.</p><p>You will be misunderstood.</p><p>You will sometimes walk alone.</p><p>You will miss targets.</p><p>You will compare yourself with others.</p><p>You will make plans that don&#8217;t work.</p><p>And there will be days when your progress is almost impossible to see.</p><p>But <strong>keep going.</strong> &#128694;&#8205;&#9794;&#65039;</p><p>Because the person who keeps showing up for three years will eventually look very different from the person who keeps restarting every three weeks.</p><p>The person who learns to lead instead of command will build stronger teams.</p><p>The person who stops carrying the past will have more energy for the future.</p><p>The person who stops comparing will finally notice their own progress.</p><p>And the person who learns to accept uncertainty will discover that not every unexpected turn is a disaster.</p><p>Sometimes it&#8217;s simply <strong>another road.</strong> &#128739;&#65039;</p><p>So perhaps the real lesson isn&#8217;t:</p><blockquote><p><strong>&#8220;Work harder.&#8221;</strong></p></blockquote><p>Maybe it&#8217;s:</p><blockquote><p>&#127793; <strong>Keep moving. Keep learning. Keep improving. Let go of what no longer serves you. Help others along the way. And trust that the picture may look very different when you finally reach the end.</strong></p></blockquote><p>Because sometimes...</p><p><strong>the best chapter of your life isn&#8217;t the one you planned.</strong></p><p><strong>It&#8217;s the one you never saw coming.</strong> &#10024;</p><div><hr></div><h1>&#128221; Key Takeaways</h1><p>&#128170; <strong>Consistency beats short bursts of motivation.</strong></p><p>&#128084; <strong>Leadership is about moving with people, not sitting above them.</strong></p><p>&#127919; <strong>Small improvements compound over time.</strong></p><p>&#127890; <strong>Your past should educate you, not imprison you.</strong></p><p>&#129309; <strong>Real support matters more than late congratulations.</strong></p><p>&#129409; <strong>Comparison can distract you from your own journey.</strong></p><p>&#128591; <strong>Make plans, but leave room for life to surprise you.</strong></p><p>&#127793; <strong>Progress often becomes visible only when you look backward.</strong></p><div><hr></div><h2>&#128278;Hashtags</h2><p>#PersonalGrowth #Consistency #Leadership #SelfImprovement #CareerGrowth #DevOps #SoftwareEngineering #Learning #Mindset #Success #LifeLessons #GrowthMindset #ProfessionalGrowth #Motivation #DevOpsEngineer</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong></p><p>https://www.linkedin.com/in/arvindverma021/<br></p>]]></content:encoded></item><item><title><![CDATA[🔐 Static Analysis Can Find Cloud Security Problems. But Can It Understand the Whole Infrastructure?]]></title><description><![CDATA[Cloud infrastructure has changed dramatically. A few years ago, security teams could often review individual servers, firewall rules, and manually configured permissions.]]></description><link>https://arvindverma021.substack.com/p/static-analysis-can-find-cloud-security</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/static-analysis-can-find-cloud-security</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 09:05:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LIRF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!LIRF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!LIRF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0716c46b-837d-467f-89f9-551a92202430_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1846753,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213255849?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!LIRF!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0716c46b-837d-467f-89f9-551a92202430_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Today, an AWS environment can contain hundreds or thousands of resources created through Terraform, spread across multiple accounts, connected through IAM roles, SCPs, VPCs, CI/CD pipelines, and managed services.</p><p>And here is where things get interesting.</p><p>A security scanner might correctly tell you:</p><blockquote><p>&#8220;This S3 bucket is publicly accessible.&#8221;</p></blockquote><p>Useful.</p><p>But a much harder question is:</p><blockquote><p><strong>&#8220;Can an attacker actually reach sensitive data through the complete infrastructure?&#8221;</strong></p></blockquote><p>That distinction is becoming increasingly important.</p><p>Tools such as Checkov and tfsec can analyze Infrastructure as Code and catch many dangerous configurations before they reach production. That&#8217;s a huge improvement over discovering security problems after deployment, which is basically the cloud equivalent of locking the door after the burglar has already left.</p><p>But modern cloud security requires more than checking individual resources.</p><p>It requires understanding <strong>relationships, permissions, identities, dependencies, and attack paths.</strong></p><p>And that&#8217;s where static analysis starts getting interesting. &#128269;</p><div><hr></div><h1>&#128196; SECTION 1: Static Analysis Is Extremely Useful</h1><p>Infrastructure as Code changed the way we build cloud environments.</p><p>Instead of manually creating an AWS VPC through the console, we can define it in Terraform:</p><pre><code><code>resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}</code></code></pre><p>The infrastructure becomes:</p><ul><li><p>Version controlled</p></li><li><p>Reviewable</p></li><li><p>Repeatable</p></li><li><p>Testable</p></li><li><p>Automatable</p></li></ul><p>And because infrastructure is represented as code, we can analyze it before deployment.</p><p>That&#8217;s where <strong>IaC security scanning</strong> comes in.</p><p>Tools such as:</p><ul><li><p>Checkov</p></li><li><p>tfsec</p></li><li><p>Terrascan</p></li><li><p>KICS</p></li><li><p>Semgrep</p></li><li><p>OPA/Conftest</p></li></ul><p>can inspect Terraform and identify known security problems.</p><p>For example:</p><pre><code><code>resource "aws_s3_bucket" "data" {
  bucket = "company-sensitive-data"

  acl = "public-read"
}</code></code></pre><p>A scanner can flag this because exposing sensitive storage publicly is obviously not a particularly inspired security decision.</p><p>Another example:</p><pre><code><code>resource "aws_iam_policy" "admin" {
  policy = jsonencode({
    Version = "2012-10-17"

    Statement = [{
      Effect   = "Allow"
      Action="/__u/arvindverma021.substack.com/*"
      Resource = "*"
    }]
  })
}</code></code></pre><p>A static scanner can identify the excessive permissions.</p><p>Similarly, it can detect things like:</p><p>&#128308; Public security groups<br>&#128308; Unencrypted storage<br>&#128308; Public databases<br>&#128308; Missing logging<br>&#128308; Overly permissive IAM policies<br>&#128308; Missing encryption<br>&#128308; Weak Kubernetes security contexts<br>&#128308; Hardcoded secrets</p><p>This is incredibly valuable.</p><p>Imagine catching a dangerous configuration during a pull request:</p><pre><code><code>Developer
   &#8595;
Git Push
   &#8595;
Pull Request
   &#8595;
IaC Security Scan
   &#8595;
&#10060; Security Finding
   &#8595;
Fix
   &#8595;
Deploy</code></code></pre><p>The security issue never reaches AWS.</p><p>That&#8217;s the fundamental idea behind <strong>Shift Left Security</strong>.</p><p>Instead of:</p><blockquote><p>Deploy &#8594; Discover &#8594; Panic &#8594; Fix</p></blockquote><p>we want:</p><blockquote><p>Write &#8594; Scan &#8594; Fix &#8594; Deploy</p></blockquote><p>Much cheaper.</p><p>Much safer.</p><p>And considerably less likely to involve someone getting paged at 2:17 AM. &#128516;</p><p>But there is a problem.</p><p>Static analysis generally sees <strong>configuration</strong>.</p><p>Cloud security often depends on <strong>relationships</strong>.</p><div><hr></div><h1>&#129513; SECTION 2: The Infrastructure Is a Graph, Not a Collection of Files</h1><p>Consider a simple AWS environment.</p><p>You might have:</p><pre><code><code>AWS Organization
      &#9474;
      &#9500;&#9472;&#9472; Security Account
      &#9474;
      &#9500;&#9472;&#9472; Production Account
      &#9474;       &#9474;
      &#9474;       &#9500;&#9472;&#9472; VPC
      &#9474;       &#9500;&#9472;&#9472; EKS
      &#9474;       &#9500;&#9472;&#9472; IAM Roles
      &#9474;       &#9492;&#9472;&#9472; S3
      &#9474;
      &#9492;&#9472;&#9472; Development Account</code></code></pre><p>Inside production, there might be:</p><pre><code><code>User
 &#8595;
IAM Identity
 &#8595;
IAM Role A
 &#8595;
AssumeRole
 &#8595;
IAM Role B
 &#8595;
S3 Access
 &#8595;
Sensitive Bucket</code></code></pre><p>Now imagine each individual Terraform configuration looks reasonable.</p><p>Role A has a limited permission.</p><p>Role B has a limited permission.</p><p>The S3 bucket has appropriate controls.</p><p>The security group is correctly configured.</p><p>The SCP looks restrictive.</p><p>Individually, everything may appear acceptable.</p><p>But when you connect the pieces, you might discover:</p><pre><code><code>Identity A
    &#9474;
    &#9660;
Role A
    &#9474;
    &#9474; sts:AssumeRole
    &#9660;
Role B
    &#9474;
    &#9660;
S3:GetObject
    &#9474;
    &#9660;
Sensitive Bucket</code></code></pre><p>Suddenly, the security question changes.</p><p>We aren&#8217;t simply asking:</p><blockquote><p>&#8220;Is this IAM policy too permissive?&#8221;</p></blockquote><p>We&#8217;re asking:</p><blockquote><p><strong>&#8220;Can Identity A ultimately access Resource D?&#8221;</strong></p></blockquote><p>That&#8217;s a graph problem.</p><p>And this is one of the biggest challenges for modern cloud security.</p><h3>Static analysis sees rules.</h3><h3>Cloud security often requires understanding paths.</h3><p>Consider another example.</p><p>You have:</p><pre><code><code>Internet
   &#8595;
Application Load Balancer
   &#8595;
EKS Ingress
   &#8595;
Service
   &#8595;
Pod
   &#8595;
IAM Role
   &#8595;
S3</code></code></pre><p>A vulnerability may not exist in any single component.</p><p>The risk could emerge from the <strong>combination</strong> of those components.</p><p>This creates several difficult questions.</p><h3>&#128313; Who can access what?</h3><p>IAM is rarely simple in large organizations.</p><p>Permissions can come from:</p><ul><li><p>Identity policies</p></li><li><p>Resource policies</p></li><li><p>IAM roles</p></li><li><p>Role chaining</p></li><li><p>Permissions boundaries</p></li><li><p>SCPs</p></li><li><p>Session policies</p></li><li><p>KMS policies</p></li><li><p>Kubernetes RBAC</p></li><li><p>IRSA or workload identity</p></li></ul><p>Understanding the effective permission requires evaluating these relationships together.</p><h3>&#128313; What happens across accounts?</h3><p>Imagine:</p><pre><code><code>Account A
Developer
   &#8595;
Role A
   &#8595;
AssumeRole
   &#8595;
Account B
   &#8595;
Role B
   &#8595;
Production Resource</code></code></pre><p>A scanner analyzing only Account A may not understand the complete path.</p><h3>&#128313; What about Terraform modules?</h3><p>Large Terraform repositories rarely contain everything in one file.</p><p>You might have:</p><pre><code><code>terraform/
&#9500;&#9472;&#9472; modules/
&#9474;   &#9500;&#9472;&#9472; vpc/
&#9474;   &#9500;&#9472;&#9472; eks/
&#9474;   &#9500;&#9472;&#9472; iam/
&#9474;   &#9500;&#9472;&#9472; s3/
&#9474;   &#9492;&#9472;&#9472; rds/
&#9474;
&#9500;&#9472;&#9472; environments/
&#9474;   &#9500;&#9472;&#9472; dev/
&#9474;   &#9500;&#9472;&#9472; staging/
&#9474;   &#9492;&#9472;&#9472; production/
&#9474;
&#9492;&#9472;&#9472; policies/</code></code></pre><p>The security implication may emerge only after modules are combined.</p><h3>&#128313; What about runtime state?</h3><p>This is another major challenge.</p><p>Terraform describes intended infrastructure.</p><p>AWS contains actual infrastructure.</p><p>And reality occasionally has a sense of humor.</p><p>Someone might manually modify a resource.</p><p>A CI/CD pipeline might generate resources dynamically.</p><p>A Kubernetes controller might create additional infrastructure.</p><p>A security group might be changed outside Terraform.</p><p>Now the question becomes:</p><blockquote><p>Is the infrastructure secure according to the code, or secure according to what actually exists?</p></blockquote><p>Those are not always the same thing.</p><div><hr></div><h1>&#129504; SECTION 3: The Future Is Context-Aware Cloud Security</h1><p>I don&#8217;t think static analysis is going away.</p><p>Quite the opposite.</p><p>It&#8217;s going to become one layer of a much larger security system.</p><p>The evolution could look something like this:</p><pre><code><code>                 &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
                 &#9474;   Terraform     &#9474;
                 &#9474;      IaC        &#9474;
                 &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                          &#9474;
                          &#9660;
                 &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
                 &#9474; Static Analysis &#9474;
                 &#9474; Checkov / KICS  &#9474;
                 &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                          &#9474;
                          &#9660;
                 &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
                 &#9474; Infrastructure  &#9474;
                 &#9474;     Graph       &#9474;
                 &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                          &#9474;
             &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
             &#9660;            &#9660;            &#9660;
           IAM          Network       Data
          Policies       Paths         Access
             &#9474;            &#9474;            &#9474;
             &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                          &#9660;
                 &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
                 &#9474; Attack Path     &#9474;
                 &#9474;    Analysis     &#9474;
                 &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                          &#9474;
                          &#9660;
                 &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
                 &#9474; Risk Priorit.   &#9474;
                 &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;</code></code></pre><p>Instead of generating hundreds of findings, the system could potentially prioritize the paths that actually matter.</p><p>For example:</p><h3>Traditional scanner</h3><pre><code><code>HIGH
IAM Policy overly permissive

MEDIUM
Security group allows 0.0.0.0/0

MEDIUM
S3 configuration issue

HIGH
Missing encryption</code></code></pre><p>Useful, but noisy.</p><p>A context-aware system could potentially say:</p><pre><code><code>&#128680; CRITICAL ATTACK PATH

Internet
   &#8595;
Public ALB
   &#8595;
EKS Workload
   &#8595;
IAM Role
   &#8595;
Cross-account AssumeRole
   &#8595;
Production Account
   &#8595;
Sensitive S3 Bucket

Potential impact:
Unauthorized access to sensitive data</code></code></pre><p>That&#8217;s a fundamentally different security conversation.</p><p>It moves from:</p><p><strong>&#8220;Which rule was violated?&#8221;</strong></p><p>to:</p><p><strong>&#8220;What can actually happen?&#8221;</strong></p><p>And that distinction matters enormously.</p><div><hr></div><h2>&#128300; Where Research Gets Interesting</h2><p>There are several fascinating areas worth exploring.</p><h3>1&#65039;&#8419; Infrastructure Graph Modeling</h3><p>Can Terraform resources be represented as a graph?</p><p>For example:</p><pre><code><code>VPC
 &#9474;
 &#9500;&#9472;&#9472; Subnet
 &#9474;      &#9474;
 &#9474;      &#9492;&#9472;&#9472; EC2
 &#9474;             &#9474;
 &#9474;             &#9492;&#9472;&#9472; IAM Role
 &#9474;
 &#9492;&#9472;&#9472; Security Group</code></code></pre><p>Then security relationships could be modeled alongside infrastructure dependencies.</p><div><hr></div><h3>2&#65039;&#8419; IAM Graph Analysis</h3><p>Instead of analyzing policies independently:</p><pre><code><code>Identity
   &#8595;
Policy
   &#8595;
Role
   &#8595;
AssumeRole
   &#8595;
Resource</code></code></pre><p>The entire authorization chain could be evaluated.</p><p>This is particularly important in multi-account AWS environments.</p><div><hr></div><h3>3&#65039;&#8419; Combining Static + Runtime Analysis</h3><p>Static analysis tells us:</p><blockquote><p>&#8220;This is what the infrastructure code intends to create.&#8221;</p></blockquote><p>Runtime analysis tells us:</p><blockquote><p>&#8220;This is what actually exists.&#8221;</p></blockquote><p>Combining both provides much stronger context.</p><pre><code><code>Terraform
   +
AWS APIs
   +
CloudTrail
   +
IAM
   +
Network Data
   +
Kubernetes
        &#8595;
Infrastructure Security Graph
        &#8595;
Risk Analysis</code></code></pre><p>Now security becomes much closer to understanding the actual environment.</p><div><hr></div><h3>4&#65039;&#8419; Attack-Path Detection</h3><p>This could be one of the most valuable improvements.</p><p>Instead of finding isolated misconfigurations, security systems could identify chains such as:</p><pre><code><code>Public Endpoint
      &#8595;
Vulnerable Workload
      &#8595;
IAM Credential
      &#8595;
AssumeRole
      &#8595;
Production Account
      &#8595;
Sensitive Database</code></code></pre><p>The individual findings might look moderate.</p><p>The complete path could be critical.</p><div><hr></div><h2>&#9888;&#65039; But There Is an Important Catch</h2><p>More intelligence doesn&#8217;t automatically mean better security.</p><p>A system that attempts to understand everything can also produce:</p><ul><li><p>False positives</p></li><li><p>False negatives</p></li><li><p>Incorrect assumptions</p></li><li><p>Massive graphs</p></li><li><p>Difficult-to-explain findings</p></li><li><p>High computational costs</p></li></ul><p>Security engineers need explanations.</p><p>If a tool says:</p><blockquote><p>&#8220;CRITICAL RISK&#8221;</p></blockquote><p>the next question will always be:</p><blockquote><p><strong>&#8220;Why?&#8221;</strong></p></blockquote><p>The best security systems won&#8217;t simply identify risk.</p><p>They will explain the chain.</p><p>Something like:</p><pre><code><code>WHY?

Identity A
  can assume Role B

Role B
  can access Resource C

Resource C
  contains sensitive data

Therefore:

Identity A &#8594; Resource C</code></code></pre><p>That makes the finding actionable.</p><div><hr></div><h1>&#128736;&#65039; What DevOps Engineers Can Do Today</h1><p>We don&#8217;t need to wait for some magical AI-powered security platform from the future.</p><p>There are practical things teams can implement today.</p><h3>&#9989; Scan Terraform before merge</h3><p>For example:</p><pre><code><code>checkov -d .</code></code></pre><h3>&#9989; Integrate security into CI/CD</h3><pre><code><code>Git Push
   &#8595;
Terraform Validate
   &#8595;
Terraform Plan
   &#8595;
IaC Security Scan
   &#8595;
Policy Check
   &#8595;
Approval
   &#8595;
Terraform Apply</code></code></pre><h3>&#9989; Enforce policies</h3><p>Tools such as OPA/Conftest can help enforce organizational rules.</p><p>For example:</p><pre><code><code>Production S3
    &#8595;
Encryption required
    &#8595;
Public access prohibited</code></code></pre><h3>&#9989; Combine IaC scanning with cloud posture monitoring</h3><p>Don&#8217;t rely exclusively on Terraform scanning.</p><p>Check the deployed environment too.</p><h3>&#9989; Review IAM paths</h3><p>Don&#8217;t only ask:</p><blockquote><p>&#8220;Does this role have AdministratorAccess?&#8221;</p></blockquote><p>Ask:</p><blockquote><p>&#8220;What can this role eventually reach?&#8221;</p></blockquote><h3>&#9989; Reduce security noise</h3><p>Not every scanner finding deserves the same priority.</p><p>Prioritize:</p><p><strong>Exploitability &#215; Exposure &#215; Impact</strong></p><p>A theoretical misconfiguration inside an isolated development account isn&#8217;t necessarily equivalent to an externally reachable path into a production database.</p><p>Context matters.</p><div><hr></div><h1>&#127919; The Bigger Picture</h1><p>Infrastructure as Code gave us something incredibly powerful.</p><p>It made infrastructure <strong>visible</strong>.</p><p>Security scanners made that infrastructure <strong>testable</strong>.</p><p>But the next challenge is making security systems understand infrastructure <strong>contextually</strong>.</p><p>Because modern cloud environments aren&#8217;t just Terraform files.</p><p>They&#8217;re interconnected systems.</p><pre><code><code>People
  &#8595;
Identities
  &#8595;
Policies
  &#8595;
Accounts
  &#8595;
Networks
  &#8595;
Workloads
  &#8595;
Services
  &#8595;
Data</code></code></pre><p>The security risk can emerge from the connections between them.</p><p>That&#8217;s why I believe the future of IaC security isn&#8217;t simply:</p><blockquote><p><strong>More security rules.</strong></p></blockquote><p>It&#8217;s:</p><blockquote><p><strong>More context.</strong></p></blockquote><p>The goal shouldn&#8217;t be to produce a bigger security report.</p><p>It should be to answer a much more useful question:</p><blockquote><p><strong>&#8220;What is the most realistic dangerous path through my infrastructure, and what should I fix first?&#8221;</strong></p></blockquote><p>That&#8217;s where static analysis could evolve from a configuration checker into something much more powerful.</p><p>&#128272; <strong>Static analysis is the starting point.</strong></p><p>&#129513; <strong>Infrastructure context is the next step.</strong></p><p>&#128376;&#65039; <strong>Graph-based reasoning could connect the pieces.</strong></p><p>&#127919; <strong>Attack-path analysis could tell us what actually matters.</strong></p><p>And ultimately, cloud security should become less about counting vulnerabilities and more about understanding <strong>real-world risk</strong>.</p><p>Because finding 500 security findings isn&#8217;t necessarily impressive.</p><p>Knowing <strong>which one can actually bring down your organization</strong> is.</p><div><hr></div><h2>&#128640; Key Takeaways</h2><ol><li><p><strong>IaC security scanning is extremely valuable</strong>, especially before deployment.</p></li><li><p>Tools like <strong>Checkov and tfsec</strong> can catch many known configuration problems.</p></li><li><p>Modern AWS environments are highly interconnected.</p></li><li><p>IAM permissions, cross-account access, network paths, and resource policies can create risks that aren&#8217;t obvious in isolated files.</p></li><li><p>Static analysis generally evaluates configurations, while cloud security often requires understanding relationships.</p></li><li><p><strong>Infrastructure graphs</strong> could provide deeper security context.</p></li><li><p>Combining static analysis with runtime data can provide a more realistic picture.</p></li><li><p>The future may shift from <strong>rule detection &#8594; attack-path understanding</strong>.</p></li><li><p>Security tools need to explain <em>why</em> a finding is dangerous.</p></li><li><p>The ultimate goal isn&#8217;t more alerts. It&#8217;s <strong>better decisions</strong>. &#128272;</p></li></ol><div><hr></div><h2>&#128173; Final Thought</h2><p>Cloud security is becoming less like checking a list of boxes and more like understanding a living system.</p><p>Terraform tells us what we intend to build.</p><p>AWS tells us what actually exists.</p><p>IAM tells us who can do what.</p><p>Networking tells us what can communicate.</p><p>Kubernetes tells us how workloads interact.</p><p>And security needs to connect all of those dots.</p><p><strong>The next generation of cloud security won&#8217;t just ask, &#8220;Is this configuration vulnerable?&#8221;</strong></p><p>It will ask:</p><blockquote><p><strong>&#8220;Given everything connected to this resource, what could actually happen?&#8221;</strong></p></blockquote><p>That is a much harder problem.</p><p>And probably a much more interesting one. &#129504;&#9729;&#65039;&#128272;</p><div><hr></div><h3>&#128278;Hashtags</h3><p>#CloudSecurity #InfrastructureAsCode #Terraform #AWS #DevSecOps #CloudSecurity #CyberSecurity #IaCSecurity #Checkov #tfsec #Kubernetes #IAM #CloudEngineering #DevOps #PlatformEngineering #SRE #InfrastructureSecurity #ShiftLeftSecurity #SecurityEngineering #CloudArchitecture</p><h3>&#129309; Follow Me</h3><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong> </p><p>https://www.linkedin.com/in/arvindverma021/</p>]]></content:encoded></item><item><title><![CDATA[🎓 A ₹5 Lakh B.Tech Should Not End With a ₹15K Salary]]></title><description><![CDATA[The uncomfortable conversation India&#8217;s engineering education system needs to have about employability, skills, placements, and what happens after graduation.]]></description><link>https://arvindverma021.substack.com/p/a-5-lakh-btech-should-not-end-with</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/a-5-lakh-btech-should-not-end-with</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 08:54:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R9pv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!R9pv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!R9pv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2078238,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213254744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!R9pv!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3550661d-f463-4e06-a084-56a2eb357f9b_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Every year, thousands of students walk into engineering colleges with the same dream.</p><p><strong>&#8220;I&#8217;ll complete B.Tech CSE, get a good IT job, and build a stable career.&#8221;</strong></p><p>Four years later, reality can look very different.</p><p>A student may have spent several lakhs on tuition and living expenses, survived endless assignments and examinations, completed a final-year project, and collected a degree.</p><p>Then comes the placement season.</p><p>And the offer is:</p><p><strong>&#8377;15,000 per month.</strong></p><p>Sometimes &#8377;20,000.</p><p>Sometimes &#8377;25,000.</p><p>And sometimes, incredibly, an unpaid internship marketed as an &#8220;opportunity to gain experience.&#8221;</p><p>Now, to be fair, <strong>not every college is bad, not every placement is poor, and not every fresher should expect a massive salary immediately after graduation.</strong></p><p>But there is a serious question worth asking:</p><blockquote><p><strong>If students spend four years preparing to become software engineers, why are so many graduating without the practical skills companies actually need?</strong></p></blockquote><p>That is where the conversation becomes uncomfortable.</p><p>And perhaps, necessary. &#128680;</p><div><hr></div><h1>SECTION 1: &#127891; The Gap Between a Degree and a Career</h1><p>The problem isn&#8217;t that engineering education has no value.</p><p>The problem is that <strong>a degree and employability are no longer the same thing.</strong></p><p>A student can spend four years learning programming concepts, operating systems, databases, computer networks, software engineering and other subjects.</p><p>But during an interview, the company might ask:</p><blockquote><p>&#8220;Can you deploy your application?&#8221;</p><p>&#8220;Have you used Git?&#8221;</p><p>&#8220;Can you work with Linux?&#8221;</p><p>&#8220;How would you build a CI/CD pipeline?&#8221;</p><p>&#8220;Can you deploy this application using Docker?&#8221;</p><p>&#8220;What happens if your production server goes down?&#8221;</p></blockquote><p>Suddenly, knowing the definition of a database isn&#8217;t enough.</p><p>Knowing what Kubernetes is isn&#8217;t enough.</p><p>Memorizing 50 Java programs isn&#8217;t enough.</p><p>The industry increasingly wants people who can <strong>build, troubleshoot and explain real systems.</strong></p><p>And that&#8217;s where many students discover a painful gap.</p><h3>College teaches:</h3><p>&#128218; Theory<br>&#128221; Examinations<br>&#129518; Assignments<br>&#127891; Academic projects<br>&#128187; Programming fundamentals</p><h3>Industry often expects:</h3><p>&#9729;&#65039; Cloud<br>&#128051; Containers<br>&#128295; Automation<br>&#128260; CI/CD<br>&#128039; Linux<br>&#127760; Networking<br>&#128272; Security<br>&#128202; Monitoring<br>&#129302; AI-assisted development<br>&#129504; Problem-solving<br>&#129309; Communication</p><p>The difference is enormous.</p><p>Imagine teaching someone how an engine works for four years but never allowing them to open the hood of a real car.</p><p>Then, on graduation day, handing them a toolbox and saying:</p><p><strong>&#8220;Congratulations. You&#8217;re now an automobile engineer.&#8221;</strong></p><p>That is roughly what happens when education becomes too disconnected from implementation.</p><div><hr></div><h1>SECTION 2: &#128187; What Should Engineering Colleges Actually Teach?</h1><p>The answer isn&#8217;t to remove theoretical education.</p><p>Students absolutely need fundamentals.</p><p>Operating systems matter.</p><p>Computer networks matter.</p><p>Data structures matter.</p><p>Databases matter.</p><p>Programming fundamentals matter.</p><p>But students also need to <strong>use those fundamentals in realistic environments.</strong></p><p>A modern CSE curriculum should make students comfortable with things such as:</p><h3>&#128039; Linux</h3><p>Students should actually work with Linux.</p><p>Not just memorize:</p><blockquote><p>&#8220;Linux is an open-source operating system.&#8221;</p></blockquote><p>They should know how to:</p><ul><li><p>investigate CPU and memory usage</p></li><li><p>inspect processes</p></li><li><p>manage permissions</p></li><li><p>analyze logs</p></li><li><p>troubleshoot networking</p></li><li><p>write shell scripts</p></li><li><p>automate repetitive tasks</p></li></ul><h3>&#128025; Git &amp; GitHub</h3><p>Students should work with Git throughout their projects.</p><p>They should understand:</p><pre><code><code>git clone
git checkout
git add
git commit
git push
git pull
git merge
git rebase</code></code></pre><p>But more importantly, they should understand <strong>why</strong> these commands are being used.</p><h3>&#9729;&#65039; Cloud</h3><p>Give students an actual cloud environment.</p><p>Let them deploy something.</p><p>For example:</p><p><strong>User &#8594; Load Balancer &#8594; Application &#8594; Database</strong></p><p>Then let something break.</p><p>Now they have to troubleshoot it.</p><p>That&#8217;s learning.</p><h3>&#128051; Docker</h3><p>Instead of simply explaining containers, give students an application and ask:</p><blockquote><p>&#8220;Containerize it.&#8221;</p></blockquote><p>They should learn:</p><pre><code><code>docker build
docker run
docker ps
docker logs
docker exec
docker push</code></code></pre><p>Then understand images, containers, registries, networking and volumes.</p><h3>&#9784;&#65039; Kubernetes</h3><p>This is where theory becomes particularly interesting.</p><p>A student shouldn&#8217;t merely memorize:</p><blockquote><p>&#8220;A Pod is the smallest deployable unit in Kubernetes.&#8221;</p></blockquote><p>They should deploy one.</p><p>Then expose it through a Service.</p><p>Then configure Ingress.</p><p>Then scale it.</p><p>Then break the configuration.</p><p>Then troubleshoot why users are receiving:</p><p><strong>503 Service Unavailable.</strong></p><p>That&#8217;s when Kubernetes becomes memorable.</p><h3>&#128260; CI/CD</h3><p>Students should build an actual pipeline:</p><pre><code><code>Developer
   &#8595;
Git
   &#8595;
Build
   &#8595;
Test
   &#8595;
Security Scan
   &#8595;
Docker Image
   &#8595;
Registry
   &#8595;
Deployment
   &#8595;
Monitoring</code></code></pre><p>Suddenly, &#8220;DevOps&#8221; stops being a buzzword and becomes something they understand.</p><div><hr></div><h2>&#128640; The biggest opportunity: project-based education</h2><p>One of the biggest changes colleges could make is simple:</p><p><strong>Stop making the final-year project a documentation exercise.</strong></p><p>Instead, students could build something resembling a real engineering project.</p><p>For example:</p><h3>Project: Production-Ready Web Application</h3><p>Students could be required to:</p><ol><li><p>Build an application</p></li><li><p>Store code in GitHub</p></li><li><p>Create a Docker image</p></li><li><p>Push it to a container registry</p></li><li><p>Provision infrastructure using Terraform</p></li><li><p>Deploy using Kubernetes</p></li><li><p>Configure monitoring</p></li><li><p>Implement logging</p></li><li><p>Add security scanning</p></li><li><p>Build CI/CD</p></li><li><p>Document architecture</p></li><li><p>Handle a simulated production incident</p></li></ol><p>Now imagine a fresher walking into an interview and saying:</p><blockquote><p>&#8220;I built the infrastructure using Terraform, containerized the application with Docker, deployed it on Kubernetes, created a CI/CD pipeline, and configured monitoring.&#8221;</p></blockquote><p>That&#8217;s a completely different conversation.</p><div><hr></div><h1>SECTION 3: &#127919; Students Also Need to Change Their Approach</h1><p>There is another uncomfortable truth.</p><p><strong>Colleges aren&#8217;t the only ones responsible.</strong></p><p>Students have more access to learning resources than any previous generation.</p><p>YouTube.</p><p>GitHub.</p><p>Cloud free tiers.</p><p>Documentation.</p><p>Open-source projects.</p><p>AI assistants.</p><p>Online courses.</p><p>Communities.</p><p>Technical blogs.</p><p>The barrier to learning has fallen dramatically.</p><p>The bigger challenge is <strong>consistency.</strong></p><p>A student doesn&#8217;t need to learn 50 technologies.</p><p>They need to become really good at solving problems.</p><p>For example, a student interested in DevOps could start with:</p><pre><code><code>Linux
  &#8595;
Git
  &#8595;
Networking
  &#8595;
AWS
  &#8595;
Docker
  &#8595;
Kubernetes
  &#8595;
Terraform
  &#8595;
CI/CD
  &#8595;
Monitoring
  &#8595;
Security</code></code></pre><p>Then build projects around them.</p><p>Don&#8217;t just watch a Kubernetes tutorial.</p><p><strong>Deploy something.</strong></p><p>Don&#8217;t just watch Terraform videos.</p><p><strong>Provision something.</strong></p><p>Don&#8217;t just read about AWS.</p><p><strong>Build an architecture.</strong></p><p>Don&#8217;t just memorize interview questions.</p><p><strong>Break your own infrastructure and fix it.</strong></p><p>Because that&#8217;s what engineering eventually becomes.</p><div><hr></div><h1>&#128161; The degree still matters. But it cannot be the entire strategy.</h1><p>A B.Tech degree can open the door.</p><p>But practical skills help you walk through it.</p><p>And increasingly, employers want evidence that you can actually do the work.</p><p>That evidence can come from:</p><p>&#9989; GitHub projects<br>&#9989; Open-source contributions<br>&#9989; Internships<br>&#9989; Freelance work<br>&#9989; Personal cloud projects<br>&#9989; Technical blogs<br>&#9989; Certifications<br>&#9989; Hackathons<br>&#9989; Real deployment experience<br>&#9989; Strong problem-solving ability</p><p>The goal shouldn&#8217;t be:</p><p><strong>&#8220;How do I get a certificate?&#8221;</strong></p><p>It should be:</p><p><strong>&#8220;What can I build that proves I understand this?&#8221;</strong></p><p>That small change in mindset can completely alter a student&#8217;s career trajectory.</p><div><hr></div><h1>&#128176; And What About &#8377;15K&#8211;&#8377;25K Salaries?</h1><p>This deserves nuance.</p><p>A fresher starting at &#8377;15K or &#8377;25K isn&#8217;t automatically being exploited.</p><p>Everyone starts somewhere.</p><p>Different cities, companies, economic conditions, skills and roles lead to different salaries.</p><p>The problem is when a person spends four years studying engineering and graduates with <strong>no practical skills, no meaningful project experience and no clear understanding of the job they&#8217;re applying for.</strong></p><p>Then the student is stuck in a vicious cycle:</p><p><strong>No experience &#8594; Low salary &#8594; Limited learning opportunities &#8594; More difficulty getting better jobs &#8594; Frustration</strong></p><p>Breaking that cycle requires both sides to change.</p><h3>Colleges need to provide:</h3><p>&#127891; Better industry alignment<br>&#128736;&#65039; Practical labs<br>&#9729;&#65039; Cloud exposure<br>&#128187; Real projects<br>&#128104;&#8205;&#128187; Industry mentorship<br>&#128260; Modern curricula<br>&#128640; Stronger internship ecosystems</p><h3>Students need to build:</h3><p>&#129504; Fundamentals<br>&#128295; Practical skills<br>&#9729;&#65039; Cloud knowledge<br>&#128187; Real projects<br>&#128194; GitHub portfolio<br>&#128483;&#65039; Communication<br>&#128200; Continuous learning</p><p>And companies also have a role.</p><p>If a job genuinely requires production-level skills, the industry should be clear about what it expects from freshers and should provide reasonable pathways to develop those skills.</p><div><hr></div><h1>&#127793; The Bigger Question</h1><p>Maybe the real question isn&#8217;t:</p><blockquote><p><strong>&#8220;Why aren&#8217;t graduates getting high salaries?&#8221;</strong></p></blockquote><p>Maybe it&#8217;s:</p><blockquote><p><strong>&#8220;Are we actually preparing graduates for the jobs they&#8217;re applying for?&#8221;</strong></p></blockquote><p>Because the world of software engineering has changed dramatically.</p><p>A developer today might interact with:</p><p>&#9729;&#65039; Cloud infrastructure<br>&#128051; Containers<br>&#9784;&#65039; Kubernetes<br>&#128260; CI/CD<br>&#129302; AI tools<br>&#128272; Security systems<br>&#128202; Observability platforms<br>&#127760; Distributed systems</p><p>A DevOps engineer might be expected to understand:</p><p><strong>Linux + Networking + Cloud + Terraform + Kubernetes + CI/CD + Security + Monitoring.</strong></p><p>The technology stack keeps evolving.</p><p>Education cannot remain frozen while the industry moves forward.</p><div><hr></div><h1>&#10084;&#65039; The Students Deserve Better</h1><p>Behind every engineering student is usually a family making a significant investment.</p><p>Money.</p><p>Time.</p><p>Expectations.</p><p>Four years of education.</p><p>And often a tremendous amount of pressure.</p><p>Most students aren&#8217;t asking for a guaranteed six-figure salary.</p><p>They&#8217;re asking for something much simpler:</p><p><strong>A fair opportunity.</strong></p><p>An opportunity to prove what they can do.</p><p>An opportunity to learn.</p><p>An opportunity to earn.</p><p>An opportunity to build a career.</p><p>And if someone spends four years studying engineering but leaves college without knowing how the technology is actually used in the real world, we should not simply tell that student:</p><p><strong>&#8220;You didn&#8217;t work hard enough.&#8221;</strong></p><p>Sometimes the system itself needs to ask whether it prepared them properly.</p><div><hr></div><h1>&#128640; Final Thought</h1><p>A degree should not be the finish line.</p><p>It should be the <strong>starting point.</strong></p><p>The future belongs to students who combine:</p><p><strong>&#127891; Education + &#128187; Practical Skills + &#129504; Problem Solving + &#128640; Continuous Learning</strong></p><p>And perhaps the most important lesson is this:</p><blockquote><p><strong>Don&#8217;t wait for college to make you job-ready. Start building before graduation.</strong></p></blockquote><p>Build projects.</p><p>Break things.</p><p>Fix them.</p><p>Deploy applications.</p><p>Learn Linux.</p><p>Use Git.</p><p>Experiment with cloud.</p><p>Automate something.</p><p>Contribute to open source.</p><p>Write about what you learn.</p><p>And slowly turn yourself from someone who <strong>studied technology</strong> into someone who can <strong>actually use it.</strong></p><p>Because in the end, companies don&#8217;t just hire degrees.</p><p>They hire people who can solve problems.</p><p>And that&#8217;s something no syllabus can completely teach. &#128640;</p><div><hr></div><h2>&#128273; Key Takeaways</h2><ul><li><p>&#127891; A degree is valuable, but it isn&#8217;t enough by itself.</p></li><li><p>&#128187; Practical implementation should be part of engineering education.</p></li><li><p>&#9729;&#65039; Cloud, Linux, Git, Docker, Kubernetes, CI/CD and AI tools should be taught through projects.</p></li><li><p>&#128640; Students should build portfolios before graduation.</p></li><li><p>&#127979; Colleges need stronger industry alignment.</p></li><li><p>&#129309; Companies should be clearer about expectations for freshers.</p></li><li><p>&#129504; Students need to take ownership of continuous learning.</p></li><li><p>&#128176; Salary discussions should consider skills, role and market conditions rather than treating one number as universal.</p></li><li><p>&#127793; The ultimate goal should be <strong>career readiness, not simply degree completion.</strong></p></li></ul><p><strong>The technology industry is moving fast.</strong></p><p>Education needs to move with it.</p><p>Because students shouldn&#8217;t graduate after four years asking:</p><blockquote><p><strong>&#8220;What job can I get with this degree?&#8221;</strong></p></blockquote><p>They should graduate saying:</p><blockquote><p><strong>&#8220;Here is what I can build.&#8221;</strong> &#128640;</p></blockquote><div><hr></div><h3>Hashtags</h3><p>#BTech #ComputerScience #EngineeringEducation #SoftwareEngineering #DevOps #CloudComputing #AWS #Kubernetes #Docker #Terraform #CICD #AI #CareerGrowth #TechCareers #Freshers #Students #ITJobs #India #Education #FutureOfWork</p><h3>Follow Me</h3><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🚀 20 DevOps Interview Questions That Reveal How You Think in Production]]></title><description><![CDATA[Real-world questions. Practical answers. Production mindset.]]></description><link>https://arvindverma021.substack.com/p/20-devops-interview-questions-that</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/20-devops-interview-questions-that</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 08:38:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mXVH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!mXVH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!mXVH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2065055,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213253780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!mXVH!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7756889f-d355-4733-86f1-02652b7d38ea_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><blockquote><p>&#8220;What is Kubernetes?&#8221;<br>&#8220;What is Docker?&#8221;<br>&#8220;What is Terraform?&#8221;<br>&#8220;What is CI/CD?&#8221;</p></blockquote><p>You could memorize definitions, repeat them confidently, and somehow survive the interview.</p><p>Those days are slowly disappearing.</p><p>For DevOps, SRE, Cloud and Platform Engineering roles, interviewers increasingly want to understand <strong>how you think when something actually breaks</strong>.</p><p>Because knowing that Kubernetes has Services is one thing.</p><p>Knowing <strong>why a perfectly healthy Pod is returning 503</strong> is another.</p><p>Knowing Terraform is another.</p><p>Knowing <strong>how to recover when </strong><code>terraform apply</code><strong> fails halfway through production infrastructure</strong> is what gets interesting.</p><p>And, unfortunately for everyone who enjoys peaceful interviews, that is where the real questions begin. &#128516;</p><p>I put together these <strong>20 scenario-based DevOps questions</strong> around Kubernetes, CI/CD, AWS, Terraform, security, observability and production incidents.</p><p>Let&#8217;s go through them the way you should approach them in an interview.</p><div><hr></div><h1>SECTION 1: Kubernetes, Containers &amp; CI/CD &#128051;&#9784;&#65039;</h1><h2>1. A Pod is running but returning 503. How would you debug it?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would first check the Pod logs and readiness probe. Then I would verify the Service selector and endpoints. After that, I would check the Ingress or Load Balancer configuration and confirm whether traffic is reaching the correct backend.&#8221;</p></blockquote><p>That&#8217;s enough for the first answer.</p><p>If the interviewer goes deeper, explain your flow:</p><pre><code><code>User
 &#8595;
Load Balancer / Ingress
 &#8595;
Service
 &#8595;
Endpoints
 &#8595;
Pod
 &#8595;
Application</code></code></pre><p>You don&#8217;t randomly restart Pods because production isn&#8217;t a vending machine.</p><p>Check each layer systematically.</p><p><strong>Production usage:</strong><br>This is commonly used when applications are healthy from Kubernetes&#8217; perspective but unavailable to users.</p><div><hr></div><h2>2. How does Kubernetes scheduling work?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;The scheduler evaluates available nodes and selects a suitable node based on resource requirements, taints, tolerations, affinity, topology and other scheduling constraints.&#8221;</p></blockquote><p>For example, if a Pod requests:</p><pre><code><code>resources:
  requests:
    cpu: "500m"
    memory: "512Mi"</code></code></pre><p>Kubernetes won&#8217;t simply throw it onto the first node it finds.</p><p>It evaluates whether the node can satisfy the request and whether other scheduling rules allow placement.</p><p><strong>Production usage:</strong><br>Important when workloads aren&#8217;t getting scheduled because of insufficient resources, taints, affinity rules or topology constraints.</p><div><hr></div><h2>3. How would you achieve zero-downtime deployment for a stateful application?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would use rolling updates carefully, maintain backward-compatible database changes, use replicas where appropriate, and make sure readiness probes prevent traffic from reaching an unready instance.&#8221;</p></blockquote><p>For databases, application deployment and schema migration need special attention.</p><p>A dangerous approach is:</p><pre><code><code>Deploy new application
&#8595;
Immediately change database schema
&#8595;
Old Pods break</code></code></pre><p>A safer approach is usually:</p><pre><code><code>Backward-compatible schema
&#8595;
Deploy new application
&#8595;
Migrate gradually
&#8595;
Remove old compatibility later</code></code></pre><div><hr></div><h2>4. How do CNI plugins work?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;CNI plugins provide networking for Pods. They create the required network interfaces, assign IP addresses and configure connectivity between workloads.&#8221;</p></blockquote><p>Common Kubernetes networking solutions include:</p><ul><li><p>Calico</p></li><li><p>Cilium</p></li><li><p>Flannel</p></li><li><p>AWS VPC CNI</p></li></ul><p>In EKS, the AWS VPC CNI integrates Pod networking with the AWS VPC networking model.</p><p><strong>Production usage:</strong><br>This becomes particularly important when troubleshooting Pod-to-Pod communication, IP exhaustion and network policies.</p><div><hr></div><h2>5. Pods randomly restart but there are no useful application logs. What do you check?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would check <code>kubectl describe pod</code>, container exit codes, events, resource limits, OOMKilled status and node health.&#8221;</p></blockquote><p>Useful commands:</p><pre><code><code>kubectl get pods
kubectl describe pod &lt;pod-name&gt;
kubectl logs &lt;pod-name&gt; --previous
kubectl get events --sort-by=.lastTimestamp</code></code></pre><p>If you see:</p><pre><code><code>OOMKilled</code></code></pre><p>I&#8217;d investigate memory limits and actual application consumption.</p><p>If there are no useful container logs, I&#8217;d also investigate the <strong>node and Kubernetes events</strong>.</p><div><hr></div><h2>6. Your pipeline builds 50 Docker images in 20 minutes. How would you reduce it to under 5 minutes?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would parallelize independent builds, use Docker layer caching, avoid rebuilding unchanged components and consider BuildKit or similar optimized build mechanisms.&#8221;</p></blockquote><p>For example:</p><pre><code><code>Application A &#9472;&#9488;
Application B &#9472;&#9532;&#9472;&#9472;&gt; Parallel Build
Application C &#9472;&#9508;
Application D &#9472;&#9496;</code></code></pre><p>Instead of:</p><pre><code><code>A &#8594; B &#8594; C &#8594; D</code></code></pre><p>you want:</p><pre><code><code>A &#9472;&#9488;
B &#9472;&#9508;
C &#9472;&#9532;&#9472;&#9472;&gt; Test &#8594; Package &#8594; Deploy
D &#9472;&#9496;</code></code></pre><div><hr></div><h2>7. How do you design a secure CI/CD pipeline?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would secure secrets, scan dependencies and container images, use least-privilege access, protect production environments and make deployments auditable.&#8221;</p></blockquote><p>A mature pipeline might look like:</p><pre><code><code>Git Push
   &#8595;
Build
   &#8595;
Unit Tests
   &#8595;
SAST / Dependency Scan
   &#8595;
Container Scan
   &#8595;
Artifact
   &#8595;
Approval / Policy
   &#8595;
Deployment
   &#8595;
Monitoring</code></code></pre><p>Security shouldn&#8217;t be something you remember five minutes before production deployment.</p><div><hr></div><h2>8. Pipeline works in staging but fails in production. What do you check?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would compare environment variables, secrets, IAM permissions, network connectivity, resource configuration and external dependencies between staging and production.&#8221;</p></blockquote><p>The important point is <strong>comparison</strong>.</p><p>Don&#8217;t immediately rewrite the pipeline.</p><p>Find what&#8217;s different.</p><div><hr></div><h1>SECTION 2: AWS, Terraform &amp; Infrastructure &#9729;&#65039;</h1><h2>9. How would you design a highly available multi-region architecture?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would deploy workloads across multiple regions, use global traffic routing, replicate required data and define a disaster recovery strategy based on RTO and RPO.&#8221;</p></blockquote><p>A simplified architecture:</p><pre><code><code>                 Global DNS
                    &#9474;
          &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
          &#8595;                   &#8595;
      Region A             Region B
          &#9474;                   &#9474;
      Application          Application
          &#9474;                   &#9474;
       Database           Replica</code></code></pre><p>But there is always a tradeoff.</p><p>Multi-region improves resilience, but increases:</p><ul><li><p>Cost</p></li><li><p>Operational complexity</p></li><li><p>Data replication complexity</p></li><li><p>Monitoring requirements</p></li></ul><p>High availability isn&#8217;t free. AWS has unfortunately noticed this too. &#128184;</p><div><hr></div><h2>10. Your AWS bill suddenly increases 3x. What do you do?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would use AWS Cost Explorer and billing data to identify which service and resource caused the increase, then check recent deployments, scaling events, data transfer and unexpected resource creation.&#8221;</p></blockquote><p>Typical investigation:</p><pre><code><code>AWS Bill
   &#8595;
Service-level breakdown
   &#8595;
Region
   &#8595;
Resource
   &#8595;
Recent change
   &#8595;
Root cause</code></code></pre><p>Possible causes include:</p><ul><li><p>Auto Scaling</p></li><li><p>Data transfer</p></li><li><p>NAT Gateway usage</p></li><li><p>Large EC2 instances</p></li><li><p>Forgotten resources</p></li><li><p>Log storage</p></li><li><p>EBS volumes</p></li><li><p>Unexpected workloads</p></li></ul><div><hr></div><h2>11. How do you handle Terraform drift?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would run <code>terraform plan</code> to detect differences between the state and actual infrastructure, identify whether the change was intentional, and then either update the Terraform code or revert the manual change.&#8221;</p></blockquote><p>Useful command:</p><pre><code><code>terraform plan</code></code></pre><p>The important principle is:</p><blockquote><p><strong>Terraform code should remain the source of truth.</strong></p></blockquote><div><hr></div><h2>12. Terraform apply fails halfway. What do you do?</h2><p>This is one of the questions where candidates often panic.</p><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;First I would inspect the error and Terraform state. I would identify which resources were successfully created and which failed. Then I would fix the root cause and run plan again before applying.&#8221;</p></blockquote><p>Useful commands:</p><pre><code><code>terraform state list
terraform plan
terraform validate
terraform apply</code></code></pre><p>Don&#8217;t blindly destroy everything.</p><p>If 80 resources were created successfully and one failed, destroying the entire environment is usually not the smartest recovery strategy.</p><div><hr></div><h2>13. How do you securely manage secrets?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I avoid storing secrets directly in Git or Terraform code. I would use services such as AWS Secrets Manager, Parameter Store or Vault and provide access through IAM or workload identity.&#8221;</p></blockquote><p>For Kubernetes, you might integrate with a centralized secrets solution rather than treating a Git repository as a password vault.</p><p>Never do this:</p><pre><code><code>password: MyProductionPassword123</code></code></pre><p>inside Git.</p><p>Git remembers things.</p><p>Forever.</p><div><hr></div><h1>SECTION 3: Security, Observability &amp; Production Thinking &#128272;&#128202;</h1><h2>14. Your system passes security scans but still gets compromised. Why?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;Security scanning only covers certain classes of vulnerabilities. I would also consider IAM, network controls, runtime security, secrets, monitoring, patching and application-level security.&#8221;</p></blockquote><p>This is the <strong>defense-in-depth</strong> approach.</p><p>Think:</p><pre><code><code>Identity
   +
Network
   +
Application
   +
Container
   +
Infrastructure
   +
Runtime Monitoring</code></code></pre><p>One scanner cannot magically secure an entire organization.</p><div><hr></div><h2>15. How would you design observability?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would use metrics for system health, logs for detailed events and traces to follow requests across services.&#8221;</p></blockquote><p>Simple example:</p><h3>Metrics</h3><pre><code><code>CPU: 85%
Latency: 400ms
Error Rate: 5%</code></code></pre><h3>Logs</h3><pre><code><code>Payment API failed
Database connection timeout</code></code></pre><h3>Traces</h3><pre><code><code>API
 &#8595;
Auth Service
 &#8595;
Order Service
 &#8595;
Payment Service
 &#8595;
Database</code></code></pre><p>Together, they help answer:</p><p><strong>What happened? Why did it happen? Where did it happen?</strong></p><div><hr></div><h2>16. How do you create alerts without causing alert fatigue?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would alert based on user impact and service objectives rather than every infrastructure metric.&#8221;</p></blockquote><p>For example, instead of alerting every time CPU reaches 80%, consider:</p><pre><code><code>High CPU
+
High latency
+
User-facing impact</code></code></pre><p>This produces a more meaningful alert.</p><p>The goal isn&#8217;t:</p><blockquote><p>&#8220;Send engineers 700 notifications.&#8221;</p></blockquote><p>The goal is:</p><blockquote><p>&#8220;Wake someone up when they actually need to do something.&#8221;</p></blockquote><div><hr></div><h2>17. Latency spikes every 60 seconds. How would you debug it?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;Because it&#8217;s periodic, I would look for scheduled or recurring activities such as garbage collection, cron jobs, backups, batch processing, connection pool behavior or database maintenance.&#8221;</p></blockquote><p>The periodicity itself is a clue.</p><p>If something happens every 60 seconds, ask:</p><p><strong>What also happens every 60 seconds?</strong></p><p>Check:</p><pre><code><code>Application
   &#8595;
Cron / Scheduled jobs
   &#8595;
Database
   &#8595;
Infrastructure
   &#8595;
External dependencies</code></code></pre><div><hr></div><h2>18. Production is completely down. What are your first five steps?</h2><p>This tests your incident-management mindset more than your Kubernetes knowledge.</p><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;First I confirm the impact. Then I identify the affected services, check monitoring, look for recent changes, and mitigate the issue. At the same time, I communicate with the relevant stakeholders.&#8221;</p></blockquote><p>A practical sequence:</p><pre><code><code>1. Detect
2. Assess impact
3. Stabilize
4. Communicate
5. Investigate</code></code></pre><p>During an outage, don&#8217;t immediately start changing random things.</p><p>Production troubleshooting is not the time for creative improvisation.</p><div><hr></div><h2>19. How would you design graceful degradation?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would design fallback behavior so non-critical functionality can fail without taking down the entire application.&#8221;</p></blockquote><p>Examples:</p><pre><code><code>Recommendation Service DOWN
        &#8595;
Show default recommendations</code></code></pre><p>Instead of:</p><pre><code><code>Recommendation Service DOWN
        &#8595;
Entire website DOWN</code></code></pre><p>Techniques include:</p><ul><li><p>Circuit breakers</p></li><li><p>Caching</p></li><li><p>Timeouts</p></li><li><p>Retries with backoff</p></li><li><p>Fallback responses</p></li><li><p>Feature flags</p></li></ul><div><hr></div><h2>20. How would you perform a zero-downtime Kubernetes upgrade?</h2><p><strong>Interview-style answer:</strong></p><blockquote><p>&#8220;I would upgrade in a controlled manner, maintain multiple healthy nodes, drain nodes safely, respect PodDisruptionBudgets and verify application readiness during the upgrade.&#8221;</p></blockquote><p>A simplified approach:</p><pre><code><code>Check compatibility
       &#8595;
Backup / recovery plan
       &#8595;
Upgrade control plane
       &#8595;
Upgrade node groups
       &#8595;
Drain nodes safely
       &#8595;
Validate workloads
       &#8595;
Monitor</code></code></pre><p>Never treat a production cluster upgrade like:</p><pre><code><code>kubectl upgrade --hope</code></code></pre><p>Sadly, that command does not exist. &#128516;</p><div><hr></div><h1>What Interviewers Are Actually Looking For &#127919;</h1><p>The interesting part of these questions is that <strong>the tools aren&#8217;t really the main test</strong>.</p><p>The interviewer is evaluating your engineering thinking.</p><p>When they ask:</p><blockquote><p>&#8220;Pods are running but users get 503.&#8221;</p></blockquote><p>They&#8217;re not only asking about Kubernetes.</p><p>They&#8217;re asking:</p><p><strong>Can you isolate a problem layer by layer?</strong></p><p>When they ask:</p><blockquote><p>&#8220;Terraform failed halfway.&#8221;</p></blockquote><p>They&#8217;re testing:</p><p><strong>Can you recover infrastructure safely?</strong></p><p>When they ask:</p><blockquote><p>&#8220;AWS costs increased 3x.&#8221;</p></blockquote><p>They&#8217;re testing:</p><p><strong>Can you investigate instead of guessing?</strong></p><p>When they ask:</p><blockquote><p>&#8220;Production is down.&#8221;</p></blockquote><p>They&#8217;re testing:</p><p><strong>Can you stay systematic under pressure?</strong></p><p>And when they ask:</p><blockquote><p>&#8220;What would you improve in this architecture?&#8221;</p></blockquote><p>They&#8217;re testing whether you understand <strong>trade-offs</strong>, not whether you can list 25 AWS services from memory.</p><div><hr></div><h1>The DevOps Interview Mindset &#129504;</h1><p>A strong DevOps answer usually follows this pattern:</p><pre><code><code>Understand the problem
        &#8595;
Check the evidence
        &#8595;
Identify the failure layer
        &#8595;
Take the safest action
        &#8595;
Validate the fix
        &#8595;
Monitor the system
        &#8595;
Prevent recurrence</code></code></pre><p>For example, don&#8217;t simply say:</p><blockquote><p>&#8220;I will restart the Pod.&#8221;</p></blockquote><p>Say:</p><blockquote><p>&#8220;I would first check logs, events, readiness, service endpoints and recent changes. Once I identify the cause, I would apply the least disruptive fix and monitor the workload.&#8221;</p></blockquote><p>That small difference makes your answer sound much more like someone who has actually worked around production systems.</p><div><hr></div><h1>Final Takeaway &#128640;</h1><p>You don&#8217;t need to memorize 500 definitions to become better at DevOps interviews.</p><p>You need to learn how systems behave when things <strong>don&#8217;t go according to plan</strong>.</p><p>Because production doesn&#8217;t care that you memorized the definition of Kubernetes.</p><p>It cares that when the application starts returning 503 at 2:17 AM, you can figure out <strong>why</strong>.</p><p>It doesn&#8217;t care that you know Terraform syntax.</p><p>It cares that when infrastructure creation fails halfway through, you can recover it without making the situation worse.</p><p>And it definitely doesn&#8217;t care that you can explain what monitoring is.</p><p>It cares whether your alerts help the team find the problem before customers start calling.</p><h3>The mindset to remember:</h3><p><strong>Think in systems.</strong><br><strong>Troubleshoot with evidence.</strong><br><strong>Automate repetitive work.</strong><br><strong>Measure everything important.</strong><br><strong>Understand trade-offs.</strong><br><strong>Stay calm under pressure.</strong></p><p>Tools can be learned.</p><p>Production judgment takes practice.</p><p>That&#8217;s what separates someone who <strong>knows DevOps tools</strong> from someone who can <strong>do DevOps in production</strong>. &#128640;</p><div><hr></div><h2>&#128204; Save This for Your Next Interview</h2><p>If you&#8217;re preparing for <strong>DevOps, SRE, Cloud, Platform Engineering or Kubernetes roles</strong>, don&#8217;t just practice:</p><blockquote><p>&#8220;What is Kubernetes?&#8221;</p></blockquote><p>Practice:</p><blockquote><p>&#8220;What would you do if Kubernetes is behaving strangely at 2 AM?&#8221;</p></blockquote><p>Because that is where the interview usually gets interesting.</p><p>And, naturally, where your coffee becomes part of the architecture. &#9749;&#128516;</p><h3>Hashtags</h3><p>#DevOps #DevOpsInterview #SRE #CloudEngineering #Kubernetes #AWS #Terraform #Docker #CICD #Linux #DevSecOps #CloudComputing #PlatformEngineering #InfrastructureAsCode #Observability #ProductionEngineering #SiteReliabilityEngineering #CareerGrowth #TechInterview #DevOpsEngineer</p><h3>Follow Me</h3><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering</strong> content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🚀 Infrastructure as Code: Build a Production-Ready AWS Environment from Scratch with Terraform]]></title><description><![CDATA[VPC + Public & Private Subnets + EC2 + ALB + RDS PostgreSQL + S3 + Remote State + DynamoDB Locking]]></description><link>https://arvindverma021.substack.com/p/infrastructure-as-code-build-a-production</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/infrastructure-as-code-build-a-production</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 08:25:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EkxU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!EkxU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!EkxU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1861061,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213253099?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!EkxU!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F441e0389-5e43-43cb-b4f9-e1fd8a439906_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>There is a big difference between knowing Terraform commands and actually being able to design an AWS environment with Terraform.</p><p>You can memorize:</p><pre><code><code>terraform init
terraform plan
terraform apply</code></code></pre><p>But in a real DevOps interview or production environment, the questions quickly become:</p><blockquote><p>How will you design the VPC?<br>Where will your application servers live?<br>How will you protect the database?<br>How will multiple engineers manage Terraform state?<br>What happens if two engineers run <code>terraform apply</code> at the same time?</p></blockquote><p>That is where Infrastructure as Code becomes much more interesting. And, naturally, humans decided that manually creating 30 AWS resources through the console wasn&#8217;t painful enough, so we automated it. &#128516;</p><p>In this project, we will build an AWS environment <strong>from scratch using Terraform</strong>, following production-oriented practices such as:</p><ul><li><p>Modular Terraform architecture</p></li><li><p>Multi-AZ networking</p></li><li><p>Public and private subnets</p></li><li><p>Application Load Balancer</p></li><li><p>EC2 application servers</p></li><li><p>RDS PostgreSQL</p></li><li><p>S3 for application storage</p></li><li><p>Remote Terraform state</p></li><li><p>State locking</p></li><li><p>IAM and security groups</p></li><li><p>Environment separation</p></li><li><p>Reproducible infrastructure</p></li></ul><div><hr></div><h1>&#128196; SECTION 1: Understanding the Architecture Before Writing Terraform</h1><p>Before writing Terraform code, understand what we are actually building.</p><p>A production environment should not look like:</p><pre><code><code>Internet
   |
EC2
   |
Database</code></code></pre><p>That architecture works beautifully until the first security review arrives. Then everyone suddenly discovers that putting everything in one subnet was perhaps not the pinnacle of cloud engineering. &#128516;</p><p>Instead, we&#8217;ll create a layered architecture.</p><h2>&#127959;&#65039; Target AWS Architecture</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hF95!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hF95!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg" width="1224" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1224,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!hF95!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14782d91-8fa5-41bc-8e21-65c37ef6992c_1224x816.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!uiDp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!uiDp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg" width="1358" height="905" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:905,&quot;width&quot;:1358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!uiDp!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ac6d3ce-c331-497f-9dd2-a7f91ec396a9_1358x905.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!oQuJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!oQuJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg" width="950" height="749" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:749,&quot;width&quot;:950,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!oQuJ!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c7d8554-2f7b-41a6-b0e5-dd61fab476b8_950x749.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!GYfU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!GYfU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg" width="800" height="616" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:616,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!GYfU!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7f58a25-7051-49ab-8d9b-6d4773ebbb00_800x616.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!tpqp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!tpqp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg" width="1254" height="857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:857,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!tpqp!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18b0358d-0fce-4b65-b016-8c5d52c7ded5_1254x857.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The architecture looks roughly like this:</p><pre><code><code>                         Internet
                            |
                            v
                    +---------------+
                    |      ALB      |
                    | Public Subnet |
                    +-------+-------+
                            |
                +-----------+-----------+
                |                       |
                v                       v
        +---------------+       +---------------+
        |  EC2 Server A |       |  EC2 Server B |
        | Private Sub A|       | Private Sub B|
        +-------+-------+       +-------+-------+
                |                       |
                +-----------+-----------+
                            |
                            v
                  +-------------------+
                  |   RDS PostgreSQL  |
                  |   Private DB Sub  |
                  +-------------------+</code></code></pre><p>The VPC could use:</p><pre><code><code>VPC: 10.0.0.0/16</code></code></pre><p>And across two Availability Zones:</p><pre><code><code>AZ-A                         AZ-B

Public Subnet A              Public Subnet B
10.0.1.0/24                  10.0.2.0/24

Private App A                Private App B
10.0.3.0/24                  10.0.4.0/24

Private DB A                 Private DB B
10.0.5.0/24                  10.0.6.0/24</code></code></pre><h3>Why separate these layers?</h3><p>Because different resources have different exposure requirements.</p><p><strong>Public subnet:</strong></p><ul><li><p>Application Load Balancer</p></li><li><p>NAT Gateway</p></li><li><p>Bastion host, if required</p></li></ul><p><strong>Private application subnet:</strong></p><ul><li><p>EC2 application servers</p></li><li><p>Internal services</p></li><li><p>Containers or workloads</p></li></ul><p><strong>Private database subnet:</strong></p><ul><li><p>RDS</p></li><li><p>Database-related resources</p></li></ul><p>The database should not be directly reachable from the Internet.</p><div><hr></div><h2>&#127760; Public vs Private Subnets</h2><p>A subnet is considered public when its route table has a route to an Internet Gateway.</p><p>For example:</p><pre><code><code>0.0.0.0/0 &#8594; Internet Gateway</code></code></pre><p>A private application subnet typically routes outbound Internet traffic through a NAT Gateway:</p><pre><code><code>Private Subnet
      |
      v
NAT Gateway
      |
      v
Internet Gateway
      |
   Internet</code></code></pre><p>This allows private instances to download updates or reach external services without giving them a public IP.</p><div><hr></div><h2>&#128272; Security Groups</h2><p>Security should follow the principle:</p><blockquote><p>Allow only what is required.</p></blockquote><p>For example:</p><pre><code><code>Internet
   |
   | HTTPS 443
   v
ALB
   |
   | HTTP 80 / application port
   v
EC2
   |
   | PostgreSQL 5432
   v
RDS</code></code></pre><p>The RDS security group should allow PostgreSQL traffic <strong>only from the application security group</strong>, rather than:</p><pre><code><code>0.0.0.0/0 &#8594; 5432</code></code></pre><p>That particular rule has a remarkable ability to turn a database into a public invitation.</p><div><hr></div><h1>&#128196; SECTION 2: Building the AWS Environment with Terraform</h1><p>Now let&#8217;s move from architecture to implementation.</p><h2>&#128193; Recommended Terraform Structure</h2><p>A clean project structure could be:</p><pre><code><code>aws-terraform-lab/
&#9474;
&#9500;&#9472;&#9472; modules/
&#9474;   &#9500;&#9472;&#9472; vpc/
&#9474;   &#9500;&#9472;&#9472; ec2/
&#9474;   &#9500;&#9472;&#9472; rds/
&#9474;   &#9492;&#9472;&#9472; alb/
&#9474;
&#9500;&#9472;&#9472; environments/
&#9474;   &#9500;&#9472;&#9472; dev/
&#9474;   &#9474;   &#9500;&#9472;&#9472; main.tf
&#9474;   &#9474;   &#9492;&#9472;&#9472; terraform.tfvars
&#9474;   &#9474;
&#9474;   &#9492;&#9472;&#9472; prod/
&#9474;       &#9500;&#9472;&#9472; main.tf
&#9474;       &#9492;&#9472;&#9472; terraform.tfvars
&#9474;
&#9500;&#9472;&#9472; backend.tf
&#9500;&#9472;&#9472; provider.tf
&#9500;&#9472;&#9472; versions.tf
&#9500;&#9472;&#9472; variables.tf
&#9500;&#9472;&#9472; outputs.tf
&#9492;&#9472;&#9472; README.md</code></code></pre><p>This gives us reusable modules and separate environments.</p><div><hr></div><h2>1&#65039;&#8419; Configure the AWS Provider</h2><p>Example:</p><pre><code><code>terraform {
  required_version = "&gt;= 1.6.0"

  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~&gt; 6.0"
    }
  }
}

provider "aws" {
  region = var.aws_region
}</code></code></pre><p>Then define:</p><pre><code><code>variable "aws_region" {
  type    = string
  default = "ap-south-1"
}</code></code></pre><div><hr></div><h2>2&#65039;&#8419; Create the VPC</h2><p>Inside the VPC module:</p><pre><code><code>resource "aws_vpc" "main" {
  cidr_block           = var.vpc_cidr
  enable_dns_support   = true
  enable_dns_hostnames = true

  tags = {
    Name = var.vpc_name
  }
}</code></code></pre><p>For example:</p><pre><code><code>vpc_cidr = "10.0.0.0/16"</code></code></pre><div><hr></div><h2>3&#65039;&#8419; Create Public Subnets</h2><pre><code><code>resource "aws_subnet" "public" {
  count = length(var.public_subnets)

  vpc_id                  = aws_vpc.main.id
  cidr_block              = var.public_subnets[count.index]
  availability_zone       = var.azs[count.index]
  map_public_ip_on_launch = true

  tags = {
    Name = "public-${count.index + 1}"
  }
}</code></code></pre><p>Example variables:</p><pre><code><code>public_subnets = [
  "10.0.1.0/24",
  "10.0.2.0/24"
]

azs = [
  "ap-south-1a",
  "ap-south-1b"
]</code></code></pre><div><hr></div><h2>4&#65039;&#8419; Create Private Application Subnets</h2><pre><code><code>resource "aws_subnet" "private_app" {
  count = length(var.private_app_subnets)

  vpc_id            = aws_vpc.main.id
  cidr_block        = var.private_app_subnets[count.index]
  availability_zone = var.azs[count.index]

  tags = {
    Name = "private-app-${count.index + 1}"
  }
}</code></code></pre><div><hr></div><h2>5&#65039;&#8419; Create Database Subnets</h2><pre><code><code>resource "aws_subnet" "database" {
  count = length(var.database_subnets)

  vpc_id            = aws_vpc.main.id
  cidr_block        = var.database_subnets[count.index]
  availability_zone = var.azs[count.index]

  tags = {
    Name = "database-${count.index + 1}"
  }
}</code></code></pre><p>These subnets can later be associated with an RDS subnet group.</p><div><hr></div><h1>&#9878;&#65039; Adding the Application Load Balancer</h1><p>The ALB sits in public subnets.</p><pre><code><code>Internet
   |
Route 53
   |
ALB
   |
Target Group
   |
EC2</code></code></pre><p>Example Terraform:</p><pre><code><code>resource "aws_lb" "app" {
  name               = "production-alb"
  internal           = false
  load_balancer_type = "application"

  subnets = var.public_subnet_ids

  security_groups = [
    var.alb_security_group_id
  ]
}</code></code></pre><p>Then create a target group:</p><pre><code><code>resource "aws_lb_target_group" "app" {
  name     = "application-targets"
  port     = 80
  protocol = "HTTP"
  vpc_id   = var.vpc_id

  health_check {
    path = "/health"
  }
}</code></code></pre><p>The health check is important.</p><p>The ALB should not blindly send traffic to an unhealthy instance.</p><div><hr></div><h1>&#128421;&#65039; EC2 Application Servers</h1><p>EC2 instances belong in private application subnets.</p><p>A simplified resource:</p><pre><code><code>resource "aws_instance" "app" {
  count = 2

  ami           = var.ami_id
  instance_type = "t3.micro"

  subnet_id = var.private_subnet_ids[count.index]

  security_groups = [
    var.app_security_group_id
  ]

  tags = {
    Name = "app-${count.index + 1}"
  }
}</code></code></pre><p>In a production implementation, you would normally consider:</p><ul><li><p>Launch Templates</p></li><li><p>Auto Scaling Groups</p></li><li><p>Systems Manager</p></li><li><p>IAM instance profiles</p></li><li><p>CloudWatch monitoring</p></li><li><p>Patch management</p></li><li><p>AMI lifecycle management</p></li></ul><div><hr></div><h1>&#128452;&#65039; RDS PostgreSQL</h1><p>The database should be deployed in dedicated private database subnets.</p><pre><code><code>resource "aws_db_subnet_group" "postgres" {
  name = "postgres-subnet-group"

  subnet_ids = var.database_subnet_ids
}</code></code></pre><p>Then:</p><pre><code><code>resource "aws_db_instance" "postgres" {
  identifier = "production-postgres"

  engine         = "postgres"
  engine_version = "16"

  instance_class        = "db.t3.micro"
  allocated_storage     = 20
  storage_type          = "gp3"

  db_name  = "appdb"
  username = var.db_username
  password = var.db_password

  db_subnet_group_name = aws_db_subnet_group.postgres.name

  publicly_accessible = false

  skip_final_snapshot = false
}</code></code></pre><p>For real production workloads, credentials should <strong>not</strong> be hardcoded in Terraform variables or committed to Git.</p><p>Use services such as:</p><ul><li><p>AWS Secrets Manager</p></li><li><p>SSM Parameter Store</p></li><li><p>IAM authentication where applicable</p></li></ul><div><hr></div><h1>&#128230; S3 for Application Storage</h1><p>S3 can be used for:</p><ul><li><p>Application uploads</p></li><li><p>Reports</p></li><li><p>Backups</p></li><li><p>Logs</p></li><li><p>Static assets</p></li></ul><p>Example:</p><pre><code><code>resource "aws_s3_bucket" "application" {
  bucket = var.application_bucket_name

  tags = {
    Name        = "application-storage"
    Environment = var.environment
  }
}</code></code></pre><p>Security should include:</p><pre><code><code>resource "aws_s3_bucket_public_access_block" "application" {
  bucket = aws_s3_bucket.application.id

  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}</code></code></pre><p>The default should be:</p><blockquote><p>Private unless there is a deliberate reason to make something public.</p></blockquote><div><hr></div><h1>&#128196; SECTION 3: Remote Terraform State, Deployment Workflow and Production Thinking</h1><p>One of the most important parts of a production Terraform setup is <strong>state management</strong>.</p><p>Terraform needs to remember what infrastructure it manages.</p><p>That information lives in:</p><pre><code><code>terraform.tfstate</code></code></pre><p>Keeping this file only on your laptop becomes a problem when multiple engineers work on the same infrastructure.</p><p>Imagine:</p><pre><code><code>Engineer A &#8594; terraform apply
Engineer B &#8594; terraform apply</code></code></pre><p>at almost the same time.</p><p>Without proper state coordination, you can end up with race conditions and state corruption.</p><p>This is why teams use a remote backend.</p><div><hr></div><h1>&#9729;&#65039; Terraform Remote Backend with S3</h1><p>A common architecture is:</p><pre><code><code>Engineer A &#9472;&#9472;&#9488;
              &#9500;&#9472;&#9472;&gt; S3
Engineer B &#9472;&#9472;&#9508;     Terraform State
              |
Engineer C &#9472;&#9472;&#9496;
                  +
               Locking</code></code></pre><p>Example:</p><pre><code><code>terraform {
  backend "s3" {
    bucket         = "my-terraform-state-bucket"
    key            = "prod/terraform.tfstate"
    region         = "ap-south-1"
    encrypt        = true
    dynamodb_table = "terraform-locks"
  }
}</code></code></pre><p>The S3 bucket stores the state.</p><p>DynamoDB provides state locking for setups using the DynamoDB locking mechanism.</p><h3>Important modern note</h3><p>Recent Terraform versions also support <strong>S3-native state locking via </strong><code>use_lockfile</code>, and HashiCorp has moved toward that approach. Existing DynamoDB-based implementations may still be encountered in enterprise environments.</p><p>For example:</p><pre><code><code>terraform {
  backend "s3" {
    bucket       = "my-terraform-state-bucket"
    key          = "prod/terraform.tfstate"
    region       = "ap-south-1"
    encrypt      = true
    use_lockfile = true
  }
}</code></code></pre><p>The exact backend design should therefore match your Terraform version and organization&#8217;s standards.</p><div><hr></div><h1>&#128260; Complete Terraform Workflow</h1><p>Once the code is ready:</p><h3>Step 1: Initialize</h3><pre><code><code>terraform init</code></code></pre><p>This downloads providers, initializes modules and configures the backend.</p><div><hr></div><h3>Step 2: Format</h3><pre><code><code>terraform fmt -recursive</code></code></pre><p>Keeps Terraform files consistently formatted.</p><div><hr></div><h3>Step 3: Validate</h3><pre><code><code>terraform validate</code></code></pre><p>Checks whether the configuration is syntactically and structurally valid.</p><div><hr></div><h3>Step 4: Review the Plan</h3><pre><code><code>terraform plan</code></code></pre><p>This is one of the most important commands in a production workflow.</p><p>You should understand what Terraform wants to:</p><pre><code><code>CREATE
UPDATE
DESTROY</code></code></pre><p>Never blindly run:</p><pre><code><code>terraform apply</code></code></pre><p>because the computer confidently doing exactly what you asked is not the same thing as the computer understanding what you meant. &#128516;</p><div><hr></div><h3>Step 5: Apply</h3><pre><code><code>terraform apply</code></code></pre><p>Or:</p><pre><code><code>terraform apply tfplan</code></code></pre><p>if you generated a saved plan:</p><pre><code><code>terraform plan -out=tfplan</code></code></pre><div><hr></div><h3>Step 6: Inspect Resources</h3><pre><code><code>terraform state list</code></code></pre><p>To inspect a resource:</p><pre><code><code>terraform state show aws_instance.app</code></code></pre><p>To see outputs:</p><pre><code><code>terraform output</code></code></pre><div><hr></div><h3>Step 7: Destroy Only When Appropriate</h3><p>For a lab:</p><pre><code><code>terraform destroy</code></code></pre><p>For production, destruction should be heavily controlled.</p><p>Ideally:</p><pre><code><code>Pull Request
     &#8595;
Code Review
     &#8595;
Terraform Plan
     &#8595;
Approval
     &#8595;
Terraform Apply
     &#8595;
Validation
     &#8595;
Monitoring</code></code></pre><div><hr></div><h1>&#129513; Calling Modules from the Root Module</h1><p>A production Terraform project becomes powerful when resources are reusable.</p><p>For example:</p><pre><code><code>module "vpc" {
  source = "../../modules/vpc"

  vpc_cidr = "10.0.0.0/16"
}</code></code></pre><p>Then:</p><pre><code><code>module "ec2" {
  source = "../../modules/ec2"

  vpc_id = module.vpc.vpc_id

  private_subnet_ids = module.vpc.private_subnet_ids
}</code></code></pre><p>And:</p><pre><code><code>module "rds" {
  source = "../../modules/rds"

  vpc_id             = module.vpc.vpc_id
  database_subnet_ids = module.vpc.database_subnet_ids
}</code></code></pre><p>This creates a dependency flow:</p><pre><code><code>VPC
 |
 +----&gt; EC2
 |
 +----&gt; ALB
 |
 +----&gt; RDS
 |
 +----&gt; Security Groups</code></code></pre><p>Terraform automatically understands dependencies through references.</p><div><hr></div><h1>&#127981; How This Would Be Used in a Real DevOps Environment</h1><p>Imagine your company needs a new production environment.</p><p>Without IaC:</p><pre><code><code>Console
 &#8595;
Create VPC
 &#8595;
Create subnets
 &#8595;
Create route tables
 &#8595;
Create NAT
 &#8595;
Create security groups
 &#8595;
Create EC2
 &#8595;
Create ALB
 &#8595;
Create RDS
 &#8595;
Create S3
 &#8595;
Document everything manually</code></code></pre><p>Someone eventually forgets something.</p><p>With Terraform:</p><pre><code><code>Git Repository
      &#8595;
Terraform Modules
      &#8595;
terraform plan
      &#8595;
Code Review
      &#8595;
terraform apply
      &#8595;
AWS Infrastructure</code></code></pre><p>The infrastructure becomes:</p><p><strong>Repeatable.</strong></p><p><strong>Version controlled.</strong></p><p><strong>Reviewable.</strong></p><p><strong>Auditable.</strong></p><p><strong>Reproducible.</strong></p><p>That is the real value of Infrastructure as Code.</p><div><hr></div><h1>&#128272; Production Best Practices</h1><p>If you build this project as a portfolio or interview project, don&#8217;t stop at simply making the resources work.</p><p>Add production thinking.</p><h3>Security</h3><ul><li><p>Keep databases private.</p></li><li><p>Restrict security-group rules.</p></li><li><p>Avoid <code>0.0.0.0/0</code> unless genuinely required.</p></li><li><p>Use IAM roles instead of static AWS credentials.</p></li><li><p>Store secrets in Secrets Manager or Parameter Store.</p></li><li><p>Enable S3 public-access blocking.</p></li><li><p>Enable encryption.</p></li></ul><h3>Terraform</h3><ul><li><p>Use modules.</p></li><li><p>Use remote state.</p></li><li><p>Enable state locking.</p></li><li><p>Pin provider versions.</p></li><li><p>Use separate environments.</p></li><li><p>Review <code>terraform plan</code>.</p></li><li><p>Never commit <code>terraform.tfstate</code>.</p></li><li><p>Add <code>.terraform/</code> to <code>.gitignore</code>.</p></li></ul><p>Example:</p><pre><code><code>.terraform/
*.tfstate
*.tfstate.*
*.tfvars
crash.log</code></code></pre><p>For sensitive <code>.tfvars</code> files, use environment-specific secret management rather than committing credentials.</p><div><hr></div><h1>&#128202; What This Project Demonstrates</h1><p>This single project can demonstrate a surprising amount of DevOps knowledge:</p><pre><code><code>                    Terraform
                       |
        +--------------+--------------+
        |              |              |
       AWS          Networking      Security
        |              |              |
   +----+----+      VPC/Subnets    IAM/SG
   |    |    |
  EC2  ALB  RDS
   |         |
Private    Private
Subnet     DB Subnet
   |
   +------ S3
          |
     Remote State
          |
      S3 + Locking</code></code></pre><p>More importantly, it demonstrates that you understand <strong>why</strong> these components exist.</p><p>That distinction matters in interviews.</p><p>If an interviewer asks:</p><blockquote><p>&#8220;Why did you put EC2 in a private subnet?&#8221;</p></blockquote><p>Don&#8217;t simply answer:</p><blockquote><p>&#8220;Because it is more secure.&#8221;</p></blockquote><p>A stronger answer is:</p><blockquote><p>&#8220;The application servers don&#8217;t need direct Internet exposure, so I placed them in private subnets and exposed the application through an ALB. Outbound traffic can go through NAT when required, while inbound traffic is controlled through the load balancer and security groups.&#8221;</p></blockquote><p>That&#8217;s the difference between memorizing AWS and understanding architecture.</p><div><hr></div><h1>&#127919; Final Takeaway</h1><p>Terraform is not valuable because it lets you replace 50 console clicks with 50 lines of HCL.</p><p>Its real value is that infrastructure becomes <strong>code</strong>.</p><p>You can:</p><pre><code><code>Write
 &#8595;
Review
 &#8595;
Version
 &#8595;
Test
 &#8595;
Plan
 &#8595;
Apply
 &#8595;
Monitor
 &#8595;
Improve</code></code></pre><p>And when another engineer joins the team, they don&#8217;t have to ask:</p><blockquote><p>&#8220;Who created this VPC?&#8221;</p></blockquote><p>They can inspect the repository.</p><p>That is the beauty of Infrastructure as Code.</p><p>The architecture in this project gives you a strong foundation for expanding further into:</p><ul><li><p>Auto Scaling Groups</p></li><li><p>CloudFront</p></li><li><p>Route 53</p></li><li><p>WAF</p></li><li><p>EKS</p></li><li><p>CI/CD</p></li><li><p>GitHub Actions</p></li><li><p>Jenkins</p></li><li><p>Terraform security scanning</p></li><li><p>Terratest</p></li><li><p>Checkov</p></li><li><p>AWS Secrets Manager</p></li><li><p>CloudWatch</p></li><li><p>Prometheus</p></li><li><p>Grafana</p></li><li><p>Multi-region architecture</p></li></ul><p>&#128640; <strong>Don&#8217;t just learn Terraform commands. Build infrastructure that looks like something an actual engineering team could operate.</strong></p><p>Because in a DevOps interview, saying <em>&#8220;I know Terraform&#8221;</em> is easy.</p><p>Explaining <strong>what you built, why you designed it that way, how you secured it, and how another engineer can reproduce it</strong> is what makes the answer interesting.</p><div><hr></div><h2>&#128273; Key Takeaways</h2><ol><li><p><strong>Use Terraform modules</strong> for reusable infrastructure.</p></li><li><p><strong>Separate public, application and database subnets.</strong></p></li><li><p><strong>Keep databases private.</strong></p></li><li><p><strong>Use ALB as the controlled entry point for applications.</strong></p></li><li><p><strong>Use security groups with least-privilege rules.</strong></p></li><li><p><strong>Store Terraform state remotely.</strong></p></li><li><p><strong>Use state locking to prevent concurrent modifications.</strong></p></li><li><p><strong>Separate environments such as </strong><code>dev</code><strong> and </strong><code>prod</code><strong>.</strong></p></li><li><p><strong>Always review </strong><code>terraform plan</code><strong> before applying changes.</strong></p></li><li><p><strong>Treat infrastructure like production software: version it, review it and improve it.</strong></p></li></ol><h3>Hashtags</h3><p>#Terraform #AWS #DevOps #InfrastructureAsCode #AWSCloud #CloudEngineering #TerraformAWS #DevOpsEngineer #CloudComputing #AWSArchitecture #VPC #EC2 #RDS #ALB #S3 #IAM #InfrastructureAutomation #DevSecOps #PlatformEngineering #SRE</p><h3>Follow Me</h3><p>If you enjoyed this article and would like more practical DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/arvindverma021/?utm_source=chatgpt.com">Arvind Verma on LinkedIn</a></p>]]></content:encoded></item><item><title><![CDATA[💰 Kubernetes Cost Optimization Engine: Build a Real DevOps Project That Detects Waste, Recommends Savings, and Visualizes Kubernetes Costs]]></title><description><![CDATA[Kubernetes makes scaling applications easier.]]></description><link>https://arvindverma021.substack.com/p/kubernetes-cost-optimization-engine</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/kubernetes-cost-optimization-engine</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 07:57:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TYhx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!TYhx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 424w, /__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 848w, /__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 1272w, /__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!TYhx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png" width="1055" height="1491" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/daf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1491,&quot;width&quot;:1055,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1958771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213251470?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 424w, /__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 848w, /__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 1272w, /__u/substackcdn.com/image/fetch/$s_!TYhx!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf36f67-9c95-4f64-9e1f-5435dde2dcf2_1055x1491.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Kubernetes makes scaling applications easier.</p><p>It also makes it surprisingly easy to waste money. &#128516;</p><p>A team may have 20 workloads running perfectly, while several of them request far more CPU and memory than they actually use.</p><p>For example:</p><pre><code><code>resources:
  requests:
    cpu: "2"
    memory: "4Gi"
  limits:
    cpu: "4"
    memory: "8Gi"</code></code></pre><p>But actual usage might look like:</p><pre><code><code>CPU requested:       2 cores
CPU actually used:   300m

Memory requested:    4Gi
Memory actually used: 1.2Gi</code></code></pre><p>Nothing is technically broken.</p><p>The application is healthy.</p><p>The pods are running.</p><p>The users are happy.</p><p>And your cloud bill is quietly having a wonderful time. &#128184;</p><p>This is where <strong>Kubernetes Cost Optimization</strong> becomes an interesting DevOps project.</p><p>In this article, we&#8217;ll go beyond the theory and build a working <strong>Kubernetes Cost Optimization Engine</strong> using:</p><ul><li><p>&#9784;&#65039; Kubernetes</p></li><li><p>&#128202; Prometheus</p></li><li><p>&#128200; Grafana</p></li><li><p>&#128013; Python</p></li><li><p>Kubernetes Metrics API</p></li><li><p>Helm</p></li><li><p>Docker</p></li><li><p>Optional AWS EKS</p></li><li><p>Resource requests and limits</p></li><li><p>Cost estimation</p></li><li><p>Optimization recommendations</p></li></ul><p>The goal is that after reading this article, you should be able to build a basic version yourself rather than simply nodding at an architecture diagram and moving on with your life.</p><div><hr></div><h1>SECTION 1: What Are We Actually Building? &#127959;&#65039;</h1><p>Our system will continuously inspect Kubernetes workloads and answer questions like:</p><blockquote><p>Which applications are overprovisioned?</p><p>Which namespaces have almost no activity?</p><p>Which nodes are underutilized?</p><p>Which workloads could potentially reduce CPU or memory requests?</p><p>How much could those changes save?</p></blockquote><p>The architecture looks like this:</p><pre><code><code>                    Kubernetes Cluster
                           &#9474;
             &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
             &#9474;                           &#9474;
      Kubernetes Metrics             Prometheus
             &#9474;                           &#9474;
             &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                           &#8595;
                 Python Optimization Engine
                           &#9474;
             &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
             &#8595;             &#8595;             &#8595;
       Usage Analysis   Waste Detection  Cost Analysis
             &#9474;             &#9474;             &#9474;
             &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                           &#8595;
                    Recommendations
                           &#9474;
                  &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
                  &#8595;                 &#8595;
               Grafana          Report/Storage</code></code></pre><p>The workflow is:</p><pre><code><code>Kubernetes
    &#8595;
Collect CPU/Memory
    &#8595;
Analyze utilization
    &#8595;
Compare with requests
    &#8595;
Detect waste
    &#8595;
Calculate potential savings
    &#8595;
Generate recommendations
    &#8595;
Visualize in Grafana</code></code></pre><div><hr></div><h1>SECTION 2: Build the Project Step by Step &#128640;</h1><h2>1. Prerequisites</h2><p>You can build this locally using:</p><ul><li><p>Docker Desktop</p></li><li><p>Minikube</p></li><li><p>kubectl</p></li><li><p>Helm</p></li><li><p>Python 3</p></li><li><p>Git</p></li></ul><p>Or you can deploy it on an AWS EKS cluster.</p><p>For a laptop-based demonstration, I&#8217;ll use <strong>Minikube</strong>.</p><p>Check your environment:</p><pre><code><code>docker --version</code></code></pre><pre><code><code>kubectl version --client</code></code></pre><pre><code><code>helm version</code></code></pre><pre><code><code>minikube version</code></code></pre><pre><code><code>python3 --version</code></code></pre><p>Start Kubernetes:</p><pre><code><code>minikube start --cpus=4 --memory=8192</code></code></pre><p>Verify:</p><pre><code><code>kubectl get nodes</code></code></pre><p>Expected:</p><pre><code><code>NAME       STATUS   ROLES           AGE
minikube   Ready    control-plane   ...</code></code></pre><div><hr></div><h1>2. Install Metrics Server &#128202;</h1><p>The Metrics Server provides resource utilization information to Kubernetes.</p><p>Install it:</p><pre><code><code>minikube addons enable metrics-server</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods -n kube-system</code></code></pre><p>Then:</p><pre><code><code>kubectl top nodes</code></code></pre><p>You should eventually see:</p><pre><code><code>NAME       CPU(cores)   CPU%   MEMORY(bytes)   MEMORY%
minikube   450m         11%    1800Mi          22%</code></code></pre><p>And:</p><pre><code><code>kubectl top pods -A</code></code></pre><p>This gives us the foundation for workload utilization analysis.</p><div><hr></div><h1>3. Install Prometheus and Grafana &#128200;</h1><p>Create the monitoring namespace:</p><pre><code><code>kubectl create namespace monitoring</code></code></pre><p>Add the Prometheus Community Helm repository:</p><pre><code><code>helm repo add prometheus-community \
https://prometheus-community.github.io/helm-charts</code></code></pre><p>Update repositories:</p><pre><code><code>helm repo update</code></code></pre><p>Install the monitoring stack:</p><pre><code><code>helm install monitoring \
prometheus-community/kube-prometheus-stack \
-n monitoring</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods -n monitoring</code></code></pre><p>You should see components such as:</p><pre><code><code>prometheus
grafana
alertmanager
node-exporter
kube-state-metrics</code></code></pre><p>Wait until they become <code>Running</code>.</p><pre><code><code>kubectl get pods -n monitoring -w</code></code></pre><div><hr></div><h1>4. Access Grafana</h1><p>Find the Grafana service:</p><pre><code><code>kubectl get svc -n monitoring</code></code></pre><p>For Minikube, you can use:</p><pre><code><code>kubectl port-forward \
svc/monitoring-grafana \
3000:80 \
-n monitoring</code></code></pre><p>Open:</p><p>http://localhost:3000</p><p>Get the default admin password:</p><pre><code><code>kubectl get secret monitoring-grafana \
-n monitoring \
-o jsonpath="{.data.admin-password}" | base64 --decode</code></code></pre><p>Username:</p><pre><code><code>admin</code></code></pre><p>Now you have Grafana connected to the Prometheus stack.</p><div><hr></div><h1>5. Create a Sample Application</h1><p>We need workloads that our optimizer can inspect.</p><p>Create a directory:</p><pre><code><code>mkdir kubernetes-cost-optimizer
cd kubernetes-cost-optimizer</code></code></pre><p>Create:</p><pre><code><code>mkdir -p k8s optimizer</code></code></pre><p>Create a sample deployment:</p><pre><code><code>nano k8s/sample-app.yaml</code></code></pre><p>Add:</p><pre><code><code>apiVersion: apps/v1
kind: Deployment
metadata:
  name: payment-service
  namespace: default
spec:
  replicas: 2
  selector:
    matchLabels:
      app: payment-service
  template:
    metadata:
      labels:
        app: payment-service
    spec:
      containers:
        - name: payment-service
          image: nginx:1.27
          resources:
            requests:
              cpu: "1"
              memory: "1Gi"
            limits:
              cpu: "2"
              memory: "2Gi"</code></code></pre><p>Deploy:</p><pre><code><code>kubectl apply -f k8s/sample-app.yaml</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods</code></code></pre><p>Now check utilization:</p><pre><code><code>kubectl top pods</code></code></pre><p>You&#8217;ll probably discover something amusing.</p><p>The application may be requesting:</p><pre><code><code>CPU: 1 core
Memory: 1Gi</code></code></pre><p>while using considerably less.</p><p>That&#8217;s our optimization opportunity.</p><div><hr></div><h1>6. Create an Intentionally Overprovisioned Workload</h1><p>For demonstration purposes, let&#8217;s create another workload.</p><pre><code><code>apiVersion: apps/v1
kind: Deployment
metadata:
  name: catalog-service
spec:
  replicas: 3
  selector:
    matchLabels:
      app: catalog-service
  template:
    metadata:
      labels:
        app: catalog-service
    spec:
      containers:
        - name: catalog
          image: nginx:1.27
          resources:
            requests:
              cpu: "2"
              memory: "4Gi"
            limits:
              cpu: "4"
              memory: "8Gi"</code></code></pre><p>Deploy it:</p><pre><code><code>kubectl apply -f k8s/catalog.yaml</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods</code></code></pre><p>Then:</p><pre><code><code>kubectl top pods</code></code></pre><p>Now imagine this workload in a production environment with dozens of replicas.</p><p>That&#8217;s where the financial impact becomes interesting.</p><div><hr></div><h1>7. Build the Python Optimization Engine &#128013;</h1><p>Create a virtual environment:</p><pre><code><code>python3 -m venv .venv</code></code></pre><p>Activate it:</p><pre><code><code>source .venv/bin/activate</code></code></pre><p>On Windows:</p><pre><code><code>.venv\Scripts\activate</code></code></pre><p>Install dependencies:</p><pre><code><code>pip install kubernetes requests</code></code></pre><p>Create:</p><pre><code><code>touch optimizer/main.py</code></code></pre><p>The Python application will communicate with Kubernetes.</p><p>Basic structure:</p><pre><code><code>from kubernetes import client, config


def load_kubernetes():
    config.load_kube_config()


def get_pods():
    v1 = client.CoreV1Api()
    return v1.list_pod_for_all_namespaces()


def main():
    load_kubernetes()

    pods = get_pods()

    for pod in pods.items:
        print(
            pod.metadata.namespace,
            pod.metadata.name
        )


if __name__ == "__main__":
    main()</code></code></pre><p>Run:</p><pre><code><code>python optimizer/main.py</code></code></pre><p>You should see Kubernetes pods.</p><p>Congratulations, the Python application can now interrogate your cluster. &#129302;</p><div><hr></div><h1>8. Read Resource Requests</h1><p>Now we need to understand what workloads have requested.</p><p>Conceptually:</p><pre><code><code>Requested CPU
Requested Memory
        &#8595;
Compare
        &#8595;
Actual CPU
Actual Memory</code></code></pre><p>For example:</p><pre><code><code>Workload: catalog-service

CPU Request:     2 cores
CPU Usage:       300m

Memory Request:  4Gi
Memory Usage:    800Mi</code></code></pre><p>CPU utilization:</p><pre><code><code>0.3 / 2 = 15%</code></code></pre><p>That is potentially significant overprovisioning.</p><p>A production implementation should not make recommendations from one sample.</p><p>Instead, collect historical observations.</p><div><hr></div><h1>9. Use Prometheus for Historical Data</h1><p>This is where Prometheus becomes much more useful than a single <code>kubectl top</code> snapshot.</p><p>Port-forward Prometheus:</p><pre><code><code>kubectl port-forward \
svc/monitoring-kube-prometheus-prometheus \
9090:9090 \
-n monitoring</code></code></pre><p>Open:</p><p>http://localhost:9090</p><p>You can query metrics through Prometheus.</p><p>For example:</p><pre><code><code>sum(rate(container_cpu_usage_seconds_total[5m]))</code></code></pre><p>For memory:</p><pre><code><code>sum(container_memory_working_set_bytes)</code></code></pre><p>For individual workloads, you can build more targeted queries using Kubernetes labels.</p><p>The Python engine can call the Prometheus HTTP API.</p><p>Example:</p><pre><code><code>import requests

PROMETHEUS_URL = "http://localhost:9090"


def query_prometheus(query):
    response = requests.get(
        f"{PROMETHEUS_URL}/api/v1/query",
        params={"query": query},
        timeout=10
    )

    response.raise_for_status()

    return response.json()</code></code></pre><p>Then:</p><pre><code><code>query = """
sum(rate(container_cpu_usage_seconds_total[5m]))
"""

result = query_prometheus(query)

print(result)</code></code></pre><p>Now our optimizer has access to historical monitoring data.</p><div><hr></div><h1>10. Create the Optimization Logic</h1><p>This is the heart of the project.</p><p>A simple initial rule could be:</p><pre><code><code>IF utilization &lt; 30%
AND observation window &gt;= 7 days
THEN recommend resource review</code></code></pre><p>For example:</p><pre><code><code>def analyze_workload(
    requested_cpu,
    average_cpu,
    requested_memory,
    average_memory
):
    cpu_ratio = average_cpu / requested_cpu
    memory_ratio = average_memory / requested_memory

    recommendations = []

    if cpu_ratio &lt; 0.30:
        recommendations.append(
            "CPU request may be overprovisioned"
        )

    if memory_ratio &lt; 0.30:
        recommendations.append(
            "Memory request may be overprovisioned"
        )

    return recommendations</code></code></pre><p>But don&#8217;t stop there.</p><p>A stronger production implementation should consider:</p><pre><code><code>Average usage
P95 usage
P99 usage
Peak usage
Traffic patterns
Pod replicas
HPA behavior
Workload criticality</code></code></pre><p>For example:</p><pre><code><code>Average CPU = 20%
P95 CPU     = 45%
Peak CPU    = 80%</code></code></pre><p>Reducing CPU request directly to 20% would be reckless.</p><p>A better recommendation might be:</p><pre><code><code>Current request: 2 CPU
Suggested range: 0.75 - 1 CPU

Reason:
P95 utilization remains below 50%.
Peak utilization reaches 80%.</code></code></pre><p>That is much closer to how production engineering decisions should be made.</p><div><hr></div><h1>11. Add Cost Estimation &#128176;</h1><p>Now we turn resource waste into money.</p><p>For demonstration, define an estimated hourly CPU cost:</p><pre><code><code>CPU_HOURLY_COST = 0.04
MEMORY_GIB_HOURLY_COST = 0.005</code></code></pre><p>These are <strong>example values</strong>, not AWS pricing.</p><p>Calculate:</p><pre><code><code>def estimate_monthly_cost(cpu, memory):
    hours = 24 * 30

    cpu_cost = cpu * CPU_HOURLY_COST * hours

    memory_cost = (
        memory *
        MEMORY_GIB_HOURLY_COST *
        hours
    )

    return cpu_cost + memory_cost</code></code></pre><p>Then compare:</p><pre><code><code>Current configuration
        &#8595;
Estimated cost
        &#8595;
Recommended configuration
        &#8595;
Estimated cost
        &#8595;
Potential savings</code></code></pre><p>Example:</p><pre><code><code>Current monthly estimate:       $420
Optimized monthly estimate:     $250

Potential savings:              $170</code></code></pre><p>For AWS production usage, you would replace these demo calculations with actual pricing data or integrate with your cloud cost data.</p><div><hr></div><h1>12. Generate a Recommendation Report &#128203;</h1><p>The engine should produce something humans can actually understand.</p><p>Example:</p><pre><code><code>========================================
KUBERNETES COST OPTIMIZATION REPORT
========================================

Workload:
catalog-service

Namespace:
default

CPU Request:
2 cores

Average CPU:
0.3 cores

P95 CPU:
0.7 cores

Memory Request:
4Gi

Average Memory:
0.8Gi

P95 Memory:
1.4Gi

Recommendation:
Review CPU and memory requests.

Suggested CPU:
1 CPU

Suggested Memory:
2Gi

Potential optimization:
High

Estimated monthly saving:
$120
========================================</code></code></pre><p>Now the project is becoming useful.</p><div><hr></div><h1>13. Detect Underutilized Nodes &#128421;&#65039;</h1><p>Use:</p><pre><code><code>kubectl top nodes</code></code></pre><p>Example:</p><pre><code><code>NAME       CPU%   MEMORY%
node-01    18%    22%
node-02    15%    19%
node-03    21%    24%
node-04    17%    20%</code></code></pre><p>The engine can flag:</p><pre><code><code>Node utilization consistently below threshold.

Potential action:
Review workload consolidation and node-group sizing.</code></code></pre><p>But again, don&#8217;t automatically terminate nodes.</p><p>Before reducing nodes, evaluate:</p><ul><li><p>PodDisruptionBudgets</p></li><li><p>Availability Zones</p></li><li><p>Pod affinity</p></li><li><p>Anti-affinity</p></li><li><p>DaemonSets</p></li><li><p>Stateful workloads</p></li><li><p>Cluster Autoscaler/Karpenter behavior</p></li><li><p>Scheduling constraints</p></li></ul><p>Cost optimization without availability analysis is just an outage wearing a financial hat.</p><div><hr></div><h1>14. Detect Zombie Resources &#129503;</h1><p>The engine can inspect:</p><pre><code><code>kubectl get deployments -A</code></code></pre><pre><code><code>kubectl get services -A</code></code></pre><pre><code><code>kubectl get pods -A</code></code></pre><p>Look for conditions such as:</p><pre><code><code>Deployment replicas = 0
Service endpoints = 0
No recent workload activity
Unused namespace</code></code></pre><p>But the output should be:</p><pre><code><code>RECOMMENDATION

Resource:
service/old-api

Observation:
No active endpoints detected.

Action:
Review before deletion.</code></code></pre><p>Not:</p><pre><code><code>DELETE EVERYTHING!!!</code></code></pre><p>Because production is generally a poor place to test whether your Python script understands consequences.</p><div><hr></div><h1>15. Build a Grafana Dashboard &#128202;</h1><p>Now connect everything.</p><p>Create dashboard panels for:</p><h3>Cluster Cost</h3><pre><code><code>Estimated Monthly Cost</code></code></pre><h3>Potential Savings</h3><pre><code><code>Estimated Savings</code></code></pre><h3>Waste</h3><pre><code><code>Overprovisioned Workloads
Idle Resources
Underutilized Nodes</code></code></pre><h3>Top Optimization Opportunities</h3><pre><code><code>Workload          Potential Saving

catalog-service       $120
payment-service        $95
notification-api      $80</code></code></pre><h3>Namespace Cost</h3><pre><code><code>production     $8,400
staging        $2,300
testing        $1,200</code></code></pre><p>This gives developers, DevOps engineers, and management different views of the same system.</p><div><hr></div><h1>SECTION 3: Turn It Into a Production-Grade DevOps Project &#128640;</h1><p>At this point you have a working proof of concept.</p><p>But production engineering requires more.</p><h2>16. Containerize the Python Engine</h2><p>Create:</p><pre><code><code>FROM python:3.12-slim

WORKDIR /app

COPY requirements.txt .

RUN pip install --no-cache-dir -r requirements.txt

COPY optimizer ./optimizer

CMD ["python", "optimizer/main.py"]</code></code></pre><p>Create:</p><pre><code><code>requirements.txt</code></code></pre><p>with:</p><pre><code><code>kubernetes
requests</code></code></pre><p>Build:</p><pre><code><code>docker build -t kubernetes-cost-optimizer:1.0 .</code></code></pre><p>Test:</p><pre><code><code>docker run \
--rm \
kubernetes-cost-optimizer:1.0</code></code></pre><p>For Minikube, build directly into Minikube&#8217;s Docker environment:</p><pre><code><code>eval $(minikube docker-env)</code></code></pre><p>Then:</p><pre><code><code>docker build \
-t kubernetes-cost-optimizer:1.0 \
.</code></code></pre><div><hr></div><h1>17. Deploy the Optimizer to Kubernetes</h1><p>Create:</p><pre><code><code>apiVersion: apps/v1
kind: Deployment
metadata:
  name: cost-optimizer
spec:
  replicas: 1
  selector:
    matchLabels:
      app: cost-optimizer
  template:
    metadata:
      labels:
        app: cost-optimizer
    spec:
      serviceAccountName: cost-optimizer
      containers:
        - name: optimizer
          image: kubernetes-cost-optimizer:1.0
          imagePullPolicy: IfNotPresent</code></code></pre><p>Apply:</p><pre><code><code>kubectl apply -f k8s/optimizer.yaml</code></code></pre><p>Check:</p><pre><code><code>kubectl get pods</code></code></pre><p>Logs:</p><pre><code><code>kubectl logs \
deployment/cost-optimizer</code></code></pre><div><hr></div><h1>18. Give the Optimizer Kubernetes Permissions &#128272;</h1><p>The Python service needs permission to inspect Kubernetes resources.</p><p>Create a ServiceAccount:</p><pre><code><code>apiVersion: v1
kind: ServiceAccount
metadata:
  name: cost-optimizer</code></code></pre><p>Then a read-only ClusterRole:</p><pre><code><code>apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: cost-optimizer
rules:
  - apiGroups: [""]
    resources:
      - pods
      - nodes
      - namespaces
      - services
    verbs:
      - get
      - list
      - watch

  - apiGroups: ["apps"]
    resources:
      - deployments
      - replicasets
      - statefulsets
    verbs:
      - get
      - list
      - watch</code></code></pre><p>Bind it:</p><pre><code><code>apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: cost-optimizer
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: cost-optimizer
subjects:
  - kind: ServiceAccount
    name: cost-optimizer
    namespace: default</code></code></pre><p>Apply:</p><pre><code><code>kubectl apply -f k8s/rbac.yaml</code></code></pre><p>This is important.</p><p>The optimizer should initially have <strong>read-only access</strong>.</p><p>Don&#8217;t give your cost analyzer cluster-admin privileges just because YAML allows you to type the word <code>admin</code>.</p><div><hr></div><h1>19. Add GitOps</h1><p>A stronger production architecture would be:</p><pre><code><code>Developer
   &#8595;
Git Push
   &#8595;
CI Pipeline
   &#8595;
Build Docker Image
   &#8595;
Security Scan
   &#8595;
Deploy Optimizer
   &#8595;
Kubernetes
   &#8595;
Prometheus
   &#8595;
Cost Engine
   &#8595;
Recommendation
   &#8595;
Git Pull Request
   &#8595;
Engineer Approval
   &#8595;
Terraform / Helm
   &#8595;
Deployment</code></code></pre><p>The optimizer shouldn&#8217;t directly modify production resources.</p><p>Instead:</p><pre><code><code>Detect
  &#8595;
Recommend
  &#8595;
Create PR
  &#8595;
Review
  &#8595;
Approve
  &#8595;
Deploy</code></code></pre><p>This provides:</p><ul><li><p>Auditability</p></li><li><p>Review</p></li><li><p>Rollback</p></li><li><p>Version control</p></li><li><p>Change history</p></li><li><p>Safer automation</p></li></ul><div><hr></div><h1>20. Deploying on AWS EKS &#9729;&#65039;</h1><p>Once the local version works, move it to EKS.</p><p>Create an EKS cluster using your preferred approach, for example <code>eksctl</code>:</p><pre><code><code>eksctl create cluster \
--name cost-optimization-demo \
--region ap-south-1 \
--nodes 2 \
--node-type t3.large</code></code></pre><p>Verify:</p><pre><code><code>kubectl get nodes</code></code></pre><p>Then install Metrics Server if needed.</p><p>Install Prometheus and Grafana:</p><pre><code><code>helm repo add prometheus-community \
https://prometheus-community.github.io/helm-charts</code></code></pre><pre><code><code>helm repo update</code></code></pre><pre><code><code>helm install monitoring \
prometheus-community/kube-prometheus-stack \
-n monitoring \
--create-namespace</code></code></pre><p>Now you have the same monitoring foundation running on EKS.</p><p>For production, you&#8217;d typically also integrate cloud cost information and consider AWS-native cost data rather than relying entirely on a simplified CPU/memory price model.</p><div><hr></div><h1>21. The Production Architecture</h1><p>The final architecture can evolve into:</p><pre><code><code>                    AWS EKS
                       &#9474;
        &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
        &#8595;              &#8595;              &#8595;
      Pods           Nodes        Namespaces
        &#9474;              &#9474;              &#9474;
        &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                       &#8595;
                  Prometheus
                       &#9474;
                       &#8595;
             Python Optimization Engine
                       &#9474;
          &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
          &#8595;            &#8595;            &#8595;
       Usage        Waste        Cost Data
       Analysis     Detection     Analysis
          &#9474;            &#9474;            &#9474;
          &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                       &#8595;
                Recommendation
                       &#9474;
          &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
          &#8595;                         &#8595;
       Grafana                 Git Repository
          &#9474;                         &#9474;
          &#8595;                         &#8595;
      Dashboard                 Pull Request
                                    &#9474;
                                    &#8595;
                                  Review
                                    &#9474;
                                    &#8595;
                                  GitOps
                                    &#9474;
                                    &#8595;
                               Kubernetes</code></code></pre><div><hr></div><h1>&#128293; What You Can Add Next</h1><p>Once the basic engine works, there are several ways to make this a serious portfolio project.</p><h3>1. HPA Awareness</h3><p>Understand whether a workload is already autoscaling.</p><h3>2. VPA Recommendations</h3><p>Compare your recommendation engine against Kubernetes Vertical Pod Autoscaler recommendations.</p><h3>3. Spot Instance Recommendations</h3><p>Identify workloads suitable for Spot capacity.</p><h3>4. AWS Cost Integration</h3><p>Integrate actual AWS cost data instead of static pricing assumptions.</p><h3>5. Slack Alerts</h3><p>Send notifications:</p><pre><code><code>&#128680; Cost Optimization Alert

Workload:
catalog-service

Potential Monthly Savings:
$120

Recommendation:
Review CPU and memory requests.</code></code></pre><h3>6. AI Recommendations &#129302;</h3><p>Have an AI layer explain:</p><pre><code><code>Why is this workload expensive?

What changed?

What should be optimized?

What could break if resources are reduced?

What is the confidence level?</code></code></pre><h3>7. Automated Pull Requests</h3><p>The engine could generate:</p><pre><code><code>resources:
  requests:
    cpu: "1000m"
    memory: "2Gi"</code></code></pre><p>and open a Git PR rather than changing production directly.</p><p>That&#8217;s a much safer path toward automation.</p><div><hr></div><h1>&#129504; How I&#8217;d Explain This Project in a DevOps Interview</h1><p>If an interviewer asks:</p><p><strong>&#8220;Tell me about a project you&#8217;ve worked on.&#8221;</strong></p><p>Don&#8217;t start by reciting 25 tools.</p><p>Explain the problem.</p><p>A concise answer could be:</p><blockquote><p>&#8220;I worked on a Kubernetes cost optimization solution that analyzes workload resource utilization against CPU and memory requests. I used Prometheus and Kubernetes metrics for usage data and built a Python-based engine to identify overprovisioned workloads, underutilized nodes, and potential savings. The recommendations were exposed through Grafana, and the architecture can integrate with GitOps so that optimization changes go through a pull request and approval process instead of directly modifying production.&#8221;</p></blockquote><p>Then expect the interviewer to ask:</p><p><strong>&#8220;How did you calculate utilization?&#8221;</strong></p><p>Explain:</p><pre><code><code>Actual usage / requested resource</code></code></pre><p>Then:</p><p><strong>&#8220;Would you automatically reduce the request?&#8221;</strong></p><p>Your answer:</p><blockquote><p>&#8220;Not immediately. I would consider historical usage, P95 or P99 utilization, peak traffic, HPA behavior, workload criticality and availability requirements. For production, I would generate a recommendation first and use GitOps approval before making changes.&#8221;</p></blockquote><p>That&#8217;s the difference between:</p><blockquote><p>&#8220;I know Kubernetes.&#8221;</p></blockquote><p>and:</p><blockquote><p>&#8220;I understand how Kubernetes is operated in production.&#8221;</p></blockquote><div><hr></div><h1>&#128193; Suggested GitHub Repository Structure</h1><p>A clean repository could look like:</p><pre><code><code>kubernetes-cost-optimizer/
&#9474;
&#9500;&#9472;&#9472; optimizer/
&#9474;   &#9500;&#9472;&#9472; main.py
&#9474;   &#9500;&#9472;&#9472; prometheus.py
&#9474;   &#9500;&#9472;&#9472; kubernetes.py
&#9474;   &#9500;&#9472;&#9472; analyzer.py
&#9474;   &#9500;&#9472;&#9472; cost.py
&#9474;   &#9492;&#9472;&#9472; reporter.py
&#9474;
&#9500;&#9472;&#9472; k8s/
&#9474;   &#9500;&#9472;&#9472; namespace.yaml
&#9474;   &#9500;&#9472;&#9472; rbac.yaml
&#9474;   &#9500;&#9472;&#9472; optimizer.yaml
&#9474;   &#9500;&#9472;&#9472; sample-app.yaml
&#9474;   &#9492;&#9472;&#9472; catalog.yaml
&#9474;
&#9500;&#9472;&#9472; grafana/
&#9474;   &#9492;&#9472;&#9472; dashboard.json
&#9474;
&#9500;&#9472;&#9472; Dockerfile
&#9500;&#9472;&#9472; requirements.txt
&#9500;&#9472;&#9472; README.md
&#9492;&#9472;&#9472; .gitignore</code></code></pre><p>Then initialize Git:</p><pre><code><code>git init</code></code></pre><pre><code><code>git add .</code></code></pre><pre><code><code>git commit -m "Initial Kubernetes cost optimizer"</code></code></pre><p>Create your GitHub repository and push:</p><pre><code><code>git branch -M main</code></code></pre><pre><code><code>git remote add origin &lt;your-repository-url&gt;</code></code></pre><pre><code><code>git push -u origin main</code></code></pre><div><hr></div><h1>&#128640; Final Takeaway</h1><p>This project is much more than:</p><p><strong>&#8220;I installed Prometheus and Grafana.&#8221;</strong></p><p>It demonstrates a complete engineering thought process:</p><pre><code><code>Problem
  &#8595;
Collect Data
  &#8595;
Analyze
  &#8595;
Detect Waste
  &#8595;
Estimate Cost
  &#8595;
Generate Recommendation
  &#8595;
Visualize
  &#8595;
Review
  &#8595;
Automate Safely</code></code></pre><p>And that&#8217;s exactly the kind of thinking that makes a DevOps project interesting.</p><p>You can start locally:</p><pre><code><code>minikube start</code></code></pre><p>Install monitoring:</p><pre><code><code>helm install monitoring \
prometheus-community/kube-prometheus-stack \
-n monitoring</code></code></pre><p>Deploy workloads:</p><pre><code><code>kubectl apply -f k8s/</code></code></pre><p>Inspect usage:</p><pre><code><code>kubectl top pods</code></code></pre><p>Run the optimizer:</p><pre><code><code>python optimizer/main.py</code></code></pre><p>Then gradually evolve it into an EKS-based platform with Prometheus, Grafana, Python automation, AWS cost data, GitOps and controlled remediation.</p><p>The end goal isn&#8217;t:</p><blockquote><p><strong>&#8220;Reduce every resource until Kubernetes screams.&#8221;</strong></p></blockquote><p>It&#8217;s:</p><blockquote><p><strong>&#8220;Understand what the workload actually needs, maintain reliability, and eliminate unnecessary cloud spend.&#8221;</strong> &#128176;&#9784;&#65039;</p></blockquote><p>Because modern DevOps isn&#8217;t just about making infrastructure work.</p><p><strong>It&#8217;s about making infrastructure reliable, observable, scalable, secure, and financially sensible.</strong> &#128640;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#Kubernetes #DevOps #AWS #EKS #FinOps #CloudCostOptimization #KubernetesCostOptimization #PlatformEngineering #CloudEngineering #Prometheus #Grafana #Python #Automation #GitOps #Terraform #SRE #CloudNative #DevSecOps #InfrastructureAsCode</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/?utm_source=chatgpt.com">Arvind Verma on LinkedIn</a></p>]]></content:encoded></item><item><title><![CDATA[🔐 Helm Security Scanner: How to Secure Kubernetes Deployments Before They Reach Production]]></title><description><![CDATA[A Helm chart can make Kubernetes deployments beautifully simple.]]></description><link>https://arvindverma021.substack.com/p/helm-security-scanner-how-to-secure</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/helm-security-scanner-how-to-secure</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 07:47:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lQVR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lQVR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lQVR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1928615,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213250660?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lQVR!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b58495-50b3-4ee1-9cd9-ce9c933aaa78_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>A Helm chart can make Kubernetes deployments beautifully simple.</p><p>One command:</p><pre><code><code>helm install my-app ./my-chart</code></code></pre><p>And suddenly Kubernetes creates Deployments, Services, ConfigMaps, Secrets, Ingress resources, RBAC permissions and everything else your application needs.</p><p>Convenient?</p><p>Absolutely.</p><p>Safe by default?</p><p><strong>Not necessarily.</strong></p><p>A Helm chart is essentially a template for generating Kubernetes manifests. If that template contains a dangerous configuration, Helm will happily package it, render it and deploy it.</p><p>Kubernetes won&#8217;t stop you simply because someone accidentally configured:</p><pre><code><code>securityContext:
  privileged: true</code></code></pre><p>Or:</p><pre><code><code>service:
  type: LoadBalancer</code></code></pre><p>Or an overly permissive RBAC policy.</p><p>This is where <strong>Helm security scanning</strong> becomes important.</p><p>Instead of discovering a security problem after deployment, the goal is simple:</p><blockquote><p><strong>Find risky Kubernetes configurations before they reach the cluster.</strong> &#128269;</p></blockquote><p>That idea fits naturally into a DevSecOps pipeline:</p><pre><code><code>Developer
    &#8595;
Git Push
    &#8595;
CI/CD Pipeline
    &#8595;
Helm Chart
    &#8595;
Security Scan
    &#8595;
Policy Validation
    &#8595;
   &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
   &#9474; Secure Chart? &#9474;
   &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
       Yes &#9474; No
           &#9474;
           &#8595;
        Deploy       &#10060; Block
           &#8595;
      Kubernetes
           &#8595;
       Monitor</code></code></pre><p>And this is much more useful than discovering during a production incident that your container has been running with excessive privileges for three months.</p><p>Humanity has invented CI/CD specifically so we can stop doing that.</p><div><hr></div><h1>SECTION 1: Why Helm Charts Need Security Scanning &#128737;&#65039;</h1><h2>What Exactly Is a Helm Chart?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!LVEy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!LVEy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg" width="774" height="548" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:548,&quot;width&quot;:774,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!LVEy!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3543491-ee47-47d7-bca6-f7e6a457db3e_774x548.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!iRqQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!iRqQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg" width="600" height="355" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:355,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!iRqQ!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F156d6db2-0209-4c7c-b9e4-14e21709643a_600x355.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!q6a6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!q6a6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg" width="1456" height="1101" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1101,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!q6a6!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9582f0e-64ff-4a08-be8a-527033a79b9f_2464x1864.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!DNmL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!DNmL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg" width="1400" height="1980" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1980,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!DNmL!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f70eefe-912c-426f-8ed9-66b32aa1069e_1400x1980.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!djh_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!djh_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg" width="1290" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!djh_!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781e5ada-ec55-4c95-9bf7-47abee62f117_1290x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Helm is commonly described as the <strong>package manager for Kubernetes</strong>.</p><p>A Helm chart can contain templates for:</p><ul><li><p>Deployments</p></li><li><p>Services</p></li><li><p>Ingress</p></li><li><p>ConfigMaps</p></li><li><p>Secrets</p></li><li><p>ServiceAccounts</p></li><li><p>RBAC</p></li><li><p>Jobs</p></li><li><p>StatefulSets</p></li><li><p>PersistentVolumes</p></li><li><p>NetworkPolicies</p></li></ul><p>A typical structure might look like:</p><pre><code><code>my-app/
&#9500;&#9472;&#9472; Chart.yaml
&#9500;&#9472;&#9472; values.yaml
&#9500;&#9472;&#9472; templates/
&#9474;   &#9500;&#9472;&#9472; deployment.yaml
&#9474;   &#9500;&#9472;&#9472; service.yaml
&#9474;   &#9500;&#9472;&#9472; ingress.yaml
&#9474;   &#9500;&#9472;&#9472; serviceaccount.yaml
&#9474;   &#9492;&#9472;&#9472; configmap.yaml
&#9492;&#9472;&#9472; charts/</code></code></pre><p>The important part is that <strong>values and templates eventually become Kubernetes resources</strong>.</p><p>For example:</p><pre><code><code>containers:
  - name: app
    image: myapp:latest
    securityContext:
      privileged: true</code></code></pre><p>That single configuration can introduce a serious security concern.</p><p>The chart may still:</p><ul><li><p>Lint successfully</p></li><li><p>Package successfully</p></li><li><p>Pass CI</p></li><li><p>Deploy successfully</p></li></ul><p>From Kubernetes&#8217; perspective, the deployment may be perfectly valid.</p><p>But from a security perspective?</p><p>That&#8217;s another conversation.</p><div><hr></div><h2>&#128680; Common Risks in Helm Charts</h2><p>Security scanning can look for configuration patterns such as:</p><h3>1. Privileged Containers</h3><pre><code><code>securityContext:
  privileged: true</code></code></pre><p>A privileged container has significantly greater access to the underlying host.</p><p>This should be treated as a deliberate exception, not a casual configuration.</p><div><hr></div><h3>2. Running as Root</h3><p>For example:</p><pre><code><code>securityContext:
  runAsUser: 0</code></code></pre><p>Running workloads as non-root is generally preferred where possible.</p><p>A hardened configuration might look more like:</p><pre><code><code>securityContext:
  runAsNonRoot: true
  allowPrivilegeEscalation: false</code></code></pre><p>The exact configuration depends on the workload, but the principle is straightforward:</p><blockquote><p><strong>Give containers only the privileges they actually need.</strong></p></blockquote><div><hr></div><h3>3. Overly Permissive RBAC</h3><p>For example:</p><pre><code><code>rules:
  - apiGroups: ["*"]
    resources: ["*"]
    verbs: ["*"]</code></code></pre><p>This is basically the Kubernetes equivalent of handing someone every key to the building and saying:</p><blockquote><p>&#8220;Please don&#8217;t accidentally use the dangerous ones.&#8221;</p></blockquote><p>RBAC should follow <strong>least privilege</strong>.</p><div><hr></div><h3>4. Hardcoded Secrets</h3><p>Something like:</p><pre><code><code>password: "MySecret123"</code></code></pre><p>inside a Git repository is a bad idea.</p><p>Even Kubernetes <code>Secret</code> objects deserve careful handling because standard Kubernetes Secrets are encoded rather than magically encrypted everywhere.</p><p>Production environments commonly use external secret-management solutions and appropriate encryption/access controls.</p><div><hr></div><h3>5. Unsafe Service Exposure</h3><p>For example:</p><pre><code><code>type: LoadBalancer</code></code></pre><p>isn&#8217;t inherently insecure.</p><p>But it may expose an application externally when that isn&#8217;t intended.</p><p>The scanner should help identify the configuration for human review.</p><div><hr></div><h3>6. Missing Security Contexts</h3><p>A workload without appropriate security controls may have unnecessary privileges or weaker isolation.</p><p>Security scanning helps make these issues visible before deployment.</p><div><hr></div><h1>SECTION 2: Building a Helm Security Scanning Pipeline &#128269;</h1><p>The important concept here is that there isn&#8217;t one magical &#8220;Helm Security Scanner&#8221; that solves Kubernetes security.</p><p>Instead, teams can combine multiple tools depending on what they want to validate.</p><p>Common options include:</p><ul><li><p><strong>Trivy</strong> for vulnerabilities and configuration scanning</p></li><li><p><strong>Kube-score</strong> for Kubernetes best-practice checks</p></li><li><p><strong>Checkov</strong> for IaC and configuration security</p></li><li><p><strong>Kubescape</strong> for Kubernetes security posture</p></li><li><p><strong>OPA / Kyverno</strong> for policy enforcement</p></li></ul><p>The tooling can vary.</p><p>The <strong>security gates</strong> are what matter.</p><div><hr></div><h2>Step 1: Scan the Helm Chart</h2><p>A useful first step is to render the Helm chart.</p><pre><code><code>helm template my-app ./my-chart &gt; rendered.yaml</code></code></pre><p>Now you have the Kubernetes manifests generated by Helm.</p><p>That is important because the source template isn&#8217;t always the final configuration.</p><p>You want to inspect what Kubernetes will actually receive.</p><p>Then tools such as Trivy can scan the resulting configuration.</p><p>For example:</p><pre><code><code>trivy config rendered.yaml</code></code></pre><p>Depending on the configuration, you may find issues involving:</p><ul><li><p>Privileged containers</p></li><li><p>Missing security controls</p></li><li><p>Secrets</p></li><li><p>RBAC</p></li><li><p>Network exposure</p></li><li><p>Image configuration</p></li><li><p>Resource settings</p></li></ul><div><hr></div><h2>Step 2: Validate Kubernetes Best Practices</h2><p>You can also use tools such as kube-score to identify potential Kubernetes configuration problems.</p><p>Conceptually:</p><pre><code><code>Helm Chart
    &#8595;
helm template
    &#8595;
Rendered YAML
    &#8595;
Kubernetes best-practice checks
    &#8595;
Security findings</code></code></pre><p>This is useful because security isn&#8217;t only about CVEs.</p><p>A deployment can have <strong>zero known software vulnerabilities</strong> and still be badly configured.</p><p>That&#8217;s an important distinction.</p><div><hr></div><h2>Step 3: Add Policy Enforcement</h2><p>Scanning tells you:</p><blockquote><p>&#8220;There is a problem.&#8221;</p></blockquote><p>Policy enforcement can tell you:</p><blockquote><p><strong>&#8220;This deployment isn&#8217;t allowed.&#8221;</strong></p></blockquote><p>That&#8217;s where tools such as OPA or Kyverno become useful.</p><p>For example, you might define a policy:</p><pre><code><code>Containers must not run privileged.</code></code></pre><p>Or:</p><pre><code><code>Images must come from approved registries.</code></code></pre><p>Or:</p><pre><code><code>Production workloads must define resource requests and limits.</code></code></pre><p>Or:</p><pre><code><code>Applications must not use hostNetwork unless explicitly approved.</code></code></pre><p>Now security isn&#8217;t simply a recommendation.</p><p>It becomes an <strong>enforceable engineering rule</strong>.</p><div><hr></div><h2>&#127959;&#65039; A Practical CI/CD Design</h2><p>A production-oriented pipeline could look like this:</p><pre><code><code>             Git Push
                 &#8595;
          Build Application
                 &#8595;
           Build Image
                 &#8595;
         Scan Container Image
                 &#8595;
           Helm Lint
                 &#8595;
        Helm Template Render
                 &#8595;
        &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
        &#9474; Security Scanning &#9474;
        &#9474;     Trivy         &#9474;
        &#9474;   Kube-score      &#9474;
        &#9474;   Kubescape       &#9474;
        &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                  &#8595;
          Policy Validation
             OPA / Kyverno
                  &#8595;
             Security Gate
             &#8601;           &#8600;
          PASS            FAIL
           &#8595;                &#8595;
        Deploy            BLOCK
           &#8595;
      Kubernetes
           &#8595;
       Monitoring</code></code></pre><p>This approach moves security <strong>left</strong>.</p><p>Instead of:</p><pre><code><code>Deploy &#8594; Discover vulnerability &#8594; Panic</code></code></pre><p>you want:</p><pre><code><code>Code &#8594; Scan &#8594; Validate &#8594; Deploy</code></code></pre><p>Much less exciting at 2 AM.</p><div><hr></div><h1>SECTION 3: What This Looks Like in a Real DevOps Environment &#128640;</h1><p>Imagine you&#8217;re working on a microservices platform.</p><p>A developer creates a Helm chart for an API.</p><p>The application works perfectly in development.</p><p>The developer creates a pull request.</p><p>The CI/CD pipeline starts.</p><p>Everything looks normal.</p><p>Then the security scanner reports:</p><pre><code><code>HIGH

Deployment/api

Container running with elevated privileges.

Recommendation:
Set privileged: false
and remove unnecessary capabilities.</code></code></pre><p>The pipeline stops.</p><pre><code><code>&#10060; Deployment blocked</code></code></pre><p>The developer fixes the chart:</p><pre><code><code>securityContext:
  privileged: false
  allowPrivilegeEscalation: false
  runAsNonRoot: true</code></code></pre><p>The pipeline runs again.</p><pre><code><code>Security Scan
      &#8595;
PASS
      &#8595;
Policy Validation
      &#8595;
PASS
      &#8595;
Deploy</code></code></pre><p>That is the real value.</p><p>The security problem was discovered <strong>before production</strong>.</p><div><hr></div><h1>&#128272; Don&#8217;t Scan Only Helm</h1><p>One common mistake is thinking:</p><blockquote><p>&#8220;We scanned our Helm chart, so we&#8217;re secure.&#8221;</p></blockquote><p>No.</p><p>Kubernetes security has multiple layers.</p><p>A mature DevSecOps pipeline can include:</p><pre><code><code>Source Code
     &#8595;
SAST
     &#8595;
Dependency Scan
     &#8595;
Container Image Scan
     &#8595;
Helm Configuration Scan
     &#8595;
Kubernetes Policy Validation
     &#8595;
Infrastructure Scan
     &#8595;
Deployment
     &#8595;
Runtime Monitoring</code></code></pre><p>Different tools answer different questions.</p><h3>Code scanning</h3><blockquote><p>Is the application code vulnerable?</p></blockquote><h3>Dependency scanning</h3><blockquote><p>Are our libraries vulnerable?</p></blockquote><h3>Image scanning</h3><blockquote><p>Does the container contain vulnerable packages?</p></blockquote><h3>Helm/Kubernetes scanning</h3><blockquote><p>Is the workload configured securely?</p></blockquote><h3>IaC scanning</h3><blockquote><p>Is the infrastructure configuration safe?</p></blockquote><h3>Policy enforcement</h3><blockquote><p>Is this deployment allowed?</p></blockquote><h3>Runtime monitoring</h3><blockquote><p>What is actually happening in production?</p></blockquote><p>Security becomes much stronger when these layers work together.</p><div><hr></div><h1>&#127919; Production Best Practices</h1><p>If you&#8217;re implementing Helm security scanning, a few practices make a significant difference.</p><h2>1. Scan Before Deployment</h2><p>Don&#8217;t wait until Kubernetes receives the manifests.</p><p>Make security scanning a CI/CD gate.</p><div><hr></div><h2>2. Render Helm Templates</h2><p>Don&#8217;t only inspect:</p><pre><code><code>templates/</code></code></pre><p>Generate the final manifests:</p><pre><code><code>helm template</code></code></pre><p>Then scan those.</p><div><hr></div><h2>3. Fail on Critical Findings</h2><p>Not every finding should necessarily stop deployment.</p><p>Define severity thresholds.</p><p>For example:</p><pre><code><code>LOW       &#8594; Warning
MEDIUM    &#8594; Review
HIGH      &#8594; Block
CRITICAL  &#8594; Block</code></code></pre><p>The exact policy should match your organization&#8217;s risk model.</p><div><hr></div><h2>4. Don&#8217;t Hardcode Secrets</h2><p>Avoid:</p><pre><code><code>password: "production-password"</code></code></pre><p>Use an appropriate secret-management mechanism.</p><p>Examples include:</p><ul><li><p>AWS Secrets Manager</p></li><li><p>HashiCorp Vault</p></li><li><p>External Secrets</p></li><li><p>Cloud-native secret-management integrations</p></li></ul><div><hr></div><h2>5. Use Least Privilege</h2><p>Apply least privilege to:</p><ul><li><p>Containers</p></li><li><p>ServiceAccounts</p></li><li><p>RBAC</p></li><li><p>IAM</p></li><li><p>Network access</p></li></ul><p>Every permission should have a reason.</p><div><hr></div><h2>6. Pin Container Images</h2><p>Avoid blindly using:</p><pre><code><code>image: myapp:latest</code></code></pre><p>Prefer controlled versions or immutable image references.</p><p>For stronger supply-chain controls, image digests can be used:</p><pre><code><code>image: myapp@sha256:&lt;digest&gt;</code></code></pre><p>This helps ensure you&#8217;re deploying the exact artifact you intended.</p><div><hr></div><h2>7. Combine Scanning With Policy</h2><p>Scanning gives visibility.</p><p>Policy gives enforcement.</p><p>Together:</p><pre><code><code>Scanner &#8594; Detect
Policy  &#8594; Prevent</code></code></pre><p>That combination is far more powerful.</p><div><hr></div><h1>&#9888;&#65039; Common Mistakes</h1><h3>&#10060; &#8220;Helm lint passed, so we&#8217;re secure.&#8221;</h3><p>Helm lint validates chart structure and syntax. It isn&#8217;t a complete security assessment.</p><h3>&#10060; &#8220;The container is running, therefore it&#8217;s safe.&#8221;</h3><p>A successfully running container can still have excessive privileges.</p><h3>&#10060; &#8220;Kubernetes Secrets are automatically secure.&#8221;</h3><p>Secrets require appropriate encryption, access control and lifecycle management.</p><h3>&#10060; &#8220;One security tool is enough.&#8221;</h3><p>Different tools identify different classes of problems.</p><h3>&#10060; &#8220;We&#8217;ll fix security findings later.&#8221;</h3><p>Later has an unfortunate habit of becoming:</p><p><strong>never.</strong></p><p>Security controls are much easier to enforce before deployment than during a production incident.</p><div><hr></div><h1>&#129504; The DevSecOps Mindset</h1><p>The biggest change isn&#8217;t installing another scanner.</p><p>It&#8217;s changing the question.</p><p>Traditional approach:</p><blockquote><p><strong>&#8220;Can we deploy this?&#8221;</strong></p></blockquote><p>DevSecOps approach:</p><blockquote><p><strong>&#8220;Can we deploy this safely?&#8221;</strong></p></blockquote><p>That distinction matters.</p><p>A deployment pipeline shouldn&#8217;t only answer:</p><pre><code><code>Does it build?
Does it test?
Does it deploy?</code></code></pre><p>It should also answer:</p><pre><code><code>Is it secure?
Is it compliant?
Does it follow our policies?
Does it expose unnecessary access?
Are the permissions appropriate?</code></code></pre><p>That&#8217;s where Helm security scanning becomes part of a bigger engineering strategy.</p><div><hr></div><h1>&#128640; Final Takeaway</h1><p>Helm makes Kubernetes deployments easier.</p><p>But easier deployment also means insecure configurations can be deployed faster.</p><p>That&#8217;s why a production-grade Kubernetes platform should treat security scanning as part of the delivery process, not an optional activity after deployment.</p><p>A practical workflow is:</p><pre><code><code>Developer
   &#8595;
Git
   &#8595;
CI/CD
   &#8595;
Helm
   &#8595;
Render
   &#8595;
Security Scan
   &#8595;
Policy Validation
   &#8595;
Security Gate
   &#8595;
Kubernetes
   &#8595;
Monitor</code></code></pre><p>The goal isn&#8217;t to find every possible problem with a giant pile of security tools.</p><p>The goal is to <strong>automatically catch meaningful risks before they become production problems.</strong></p><p>Because in production, security isn&#8217;t just about having the right tools.</p><p>It&#8217;s about having the right <strong>controls at the right point in the delivery lifecycle.</strong> &#128272;</p><p><strong>Scan early.<br>Enforce consistently.<br>Deploy securely.</strong></p><p>And preferably, don&#8217;t wait for your production cluster to become the security team&#8217;s next interesting Tuesday. &#128516;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#DevSecOps #Kubernetes #Helm #KubernetesSecurity #CloudSecurity #DevOps #AWS #EKS #Terraform #CICD #Trivy #Kubescape #Kyverno #OPA #ContainerSecurity #CloudNative #DevOpsEngineering #PlatformEngineering #CyberSecurity #InfrastructureAsCode</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🚀 It Is NOT Too Late to Restart Your Career. Ever.]]></title><description><![CDATA[There is a sentence that quietly destroys more careers than failure ever could:]]></description><link>https://arvindverma021.substack.com/p/it-is-not-too-late-to-restart-your</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/it-is-not-too-late-to-restart-your</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 07:20:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AUZh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!AUZh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!AUZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1963907,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213249070?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!AUZh!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d426a1-dffd-4f57-9d62-70678b639935_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>There is a sentence that quietly destroys more careers than failure ever could:</p><blockquote><p><strong>&#8220;I&#8217;m too late.&#8221;</strong></p></blockquote><p>Too late to learn technology.<br>Too late to switch careers.<br>Too late to enter AI.<br>Too late to apply for better jobs.<br>Too late to start again.<br>Too late because someone else is already ahead.</p><p>And once you start believing that story, something dangerous happens.</p><p>You stop trying.</p><p>Not because you lack ability.</p><p>Not because you lack potential.</p><p>But because you convince yourself that the timeline has already expired.</p><p>The truth is much less dramatic:</p><p><strong>There is no universal deadline for rebuilding your career.</strong></p><p>People change careers at 25.</p><p>Others do it at 30.</p><p>Some at 40.</p><p>Some discover what they actually want much later.</p><p>And yes, starting again can be uncomfortable. You may have to become a beginner again. You may watch people younger than you move faster. You may compare your Chapter 1 with somebody else&#8217;s Chapter 15.</p><p>Human beings are remarkably talented at making themselves miserable with comparisons. &#128514;</p><p>But career growth isn&#8217;t a race with one starting line and one finish line.</p><p>It is a journey.</p><p>And sometimes, the person who takes the longer route develops something incredibly valuable along the way:</p><p><strong>Perspective.</strong></p><div><hr></div><h1>SECTION 1: The Biggest Career Lie Is &#8220;I&#8217;m Too Late&#8221; &#129504;</h1><p>Think about how often people use age or lost time as a reason not to begin.</p><blockquote><p>&#8220;I should have started earlier.&#8221;</p><p>&#8220;Everyone else already has experience.&#8221;</p><p>&#8220;The industry has changed.&#8221;</p><p>&#8220;I&#8217;m too old to learn this.&#8221;</p><p>&#8220;I wasted several years.&#8221;</p><p>&#8220;If I had started five years ago, I&#8217;d be successful by now.&#8221;</p></blockquote><p>Maybe.</p><p>But there&#8217;s a problem with spending too much time thinking about that:</p><p><strong>Those years are already gone.</strong></p><p>You can&#8217;t negotiate with yesterday.</p><p>You can only decide what happens next.</p><div><hr></div><h2>The Career Timeline Doesn&#8217;t Have to Be Linear</h2><p>We are often taught an imaginary career formula:</p><pre><code><code>Education
   &#8595;
First Job
   &#8595;
Promotion
   &#8595;
Senior Role
   &#8595;
Management
   &#8595;
Success</code></code></pre><p>Real careers rarely look like that.</p><p>They look more like:</p><pre><code><code>Learn
 &#8595;
Try
 &#8595;
Fail
 &#8595;
Change direction
 &#8595;
Start again
 &#8595;
Learn more
 &#8595;
Get rejected
 &#8595;
Try again
 &#8595;
Build something
 &#8595;
Improve
 &#8595;
Opportunity
 &#8595;
Growth</code></code></pre><p>There are pauses.</p><p>Detours.</p><p>Failures.</p><p>Unexpected opportunities.</p><p>Periods where absolutely nothing seems to be working.</p><p>And then, sometimes, one decision changes everything.</p><p>That&#8217;s why comparing your career to somebody else&#8217;s timeline is often meaningless.</p><p>Their circumstances aren&#8217;t yours.</p><p>Their responsibilities aren&#8217;t yours.</p><p>Their opportunities aren&#8217;t yours.</p><p>Their starting point isn&#8217;t yours.</p><p>The only useful comparison is:</p><blockquote><p><strong>&#8220;Am I better prepared than I was six months ago?&#8221;</strong></p></blockquote><p>That question can actually help you.</p><div><hr></div><h2>&#127793; Starting Again Doesn&#8217;t Mean Starting From Zero</h2><p>This is one of the most important things to understand.</p><p>When you change careers, it may <em>look</em> like you&#8217;re starting from zero.</p><p>You&#8217;re not.</p><p>You carry your previous experience with you.</p><p>Suppose someone spent several years in a non-technical career and later moved into technology.</p><p>They may initially lack technical experience.</p><p>But they may already have:</p><ul><li><p>Communication skills</p></li><li><p>Discipline</p></li><li><p>Problem-solving ability</p></li><li><p>Professional maturity</p></li><li><p>Stakeholder management</p></li><li><p>Team experience</p></li><li><p>Decision-making skills</p></li><li><p>Understanding of workplace dynamics</p></li></ul><p>Then they add technical skills.</p><p>The result isn&#8217;t:</p><p><strong>Old experience &#8594; deleted.</strong></p><p>It&#8217;s:</p><p><strong>Old experience + new skills &#8594; new professional profile.</strong></p><p>That&#8217;s a very different equation.</p><div><hr></div><h1>SECTION 2: Career Growth Is Usually a Cycle, Not a Straight Line &#128260;</h1><p>The infographic captures something many people don&#8217;t talk about enough.</p><p><strong>Success is rarely linear.</strong></p><p>A much more realistic career cycle looks like this:</p><pre><code><code>Learn
  &#8595;
Practice
  &#8595;
Build
  &#8595;
Fail
  &#8595;
Improve
  &#8595;
Repeat
  &#8595;
Grow</code></code></pre><p>Notice something uncomfortable in the middle?</p><p><strong>Fail.</strong></p><p>Yes.</p><p>The part everyone conveniently removes from their LinkedIn success story.</p><p>Nobody posts:</p><blockquote><p>&#8220;Today I spent six hours debugging something that turned out to be a typo.&#8221;</p></blockquote><p>Nobody posts:</p><blockquote><p>&#8220;Applied to 47 jobs. Rejected by 43.&#8221;</p></blockquote><p>Nobody posts:</p><blockquote><p>&#8220;Studied for three months and still didn&#8217;t understand Kubernetes.&#8221;</p></blockquote><p>But these experiences are normal.</p><div><hr></div><h2>&#128683; Rejection Doesn&#8217;t Mean You&#8217;re Finished</h2><p>Imagine applying for a job and getting rejected.</p><p>There are two possible interpretations.</p><h3>Interpretation 1:</h3><blockquote><p>&#8220;I&#8217;m not good enough.&#8221;</p></blockquote><h3>Interpretation 2:</h3><blockquote><p>&#8220;Something about my current profile wasn&#8217;t strong enough for this opportunity. What can I improve?&#8221;</p></blockquote><p>The first interpretation attacks your identity.</p><p>The second gives you something to work on.</p><p>That difference matters.</p><p>A rejection can tell you:</p><ul><li><p>Your technical knowledge needs improvement.</p></li><li><p>Your communication needs work.</p></li><li><p>Your resume isn&#8217;t demonstrating impact.</p></li><li><p>Your interview answers are too theoretical.</p></li><li><p>You don&#8217;t have enough project experience.</p></li><li><p>You need stronger system-design knowledge.</p></li><li><p>You applied for a role that wasn&#8217;t the right fit.</p></li></ul><p>None of these mean:</p><p><strong>&#8220;Your career is over.&#8221;</strong></p><p>They mean:</p><p><strong>&#8220;Here is the next thing to improve.&#8221;</strong></p><div><hr></div><h2>&#128187; This Is Especially True in Technology</h2><p>Technology changes ridiculously fast.</p><p>A few years ago, someone might have focused heavily on:</p><ul><li><p>Traditional servers</p></li><li><p>Manual deployments</p></li><li><p>VM-based infrastructure</p></li></ul><p>Then came:</p><ul><li><p>Cloud</p></li><li><p>Containers</p></li><li><p>Kubernetes</p></li><li><p>Infrastructure as Code</p></li><li><p>GitOps</p></li><li><p>DevSecOps</p></li><li><p>Observability</p></li><li><p>AI</p></li></ul><p>And now AI is changing how engineers write code, troubleshoot systems and automate workflows.</p><p>If you look at the entire industry and think:</p><blockquote><p>&#8220;I&#8217;m already behind.&#8221;</p></blockquote><p>you&#8217;ll never start.</p><p>Instead, break it down.</p><p>You don&#8217;t need to master everything.</p><p>You need to learn <strong>the next useful thing.</strong></p><p>For example:</p><pre><code><code>Linux
  &#8595;
Git
  &#8595;
Cloud
  &#8595;
Docker
  &#8595;
Kubernetes
  &#8595;
Terraform
  &#8595;
CI/CD
  &#8595;
Monitoring
  &#8595;
Automation
  &#8595;
AI-assisted engineering</code></code></pre><p>You don&#8217;t need to learn all of it tomorrow.</p><p>You need to keep moving.</p><div><hr></div><h1>&#128736;&#65039; Build Real Skills, Not Just Motivation</h1><p>Motivation is useful.</p><p>But motivation has a terrible attendance record.</p><p>It shows up Monday morning.</p><p>By Wednesday, it has disappeared.</p><p>That&#8217;s why <strong>systems beat motivation</strong>.</p><p>Instead of saying:</p><blockquote><p>&#8220;I will completely transform my career this year.&#8221;</p></blockquote><p>try:</p><blockquote><p>&#8220;I will study for one hour every day.&#8221;</p></blockquote><p>Instead of:</p><blockquote><p>&#8220;I need to become an expert.&#8221;</p></blockquote><p>try:</p><blockquote><p>&#8220;I will build one practical project this month.&#8221;</p></blockquote><p>Instead of:</p><blockquote><p>&#8220;I need to get a better job.&#8221;</p></blockquote><p>try:</p><blockquote><p>&#8220;I will apply to five relevant positions every week and improve my resume based on feedback.&#8221;</p></blockquote><p>Small actions compound.</p><div><hr></div><h1>SECTION 3: Your Comeback Doesn&#8217;t Need to Look Impressive at the Beginning &#128640;</h1><p>One of the hardest parts about restarting is accepting that your beginning may look ordinary.</p><p>You may know very little.</p><p>Your first project may be terrible.</p><p>Your first interview may go badly.</p><p>Your first application may get rejected.</p><p>Your first attempt at something may make you wonder why you ever started.</p><p>That&#8217;s normal.</p><p>The beginning isn&#8217;t supposed to look impressive.</p><p>It&#8217;s supposed to <strong>exist</strong>.</p><div><hr></div><h2>&#128293; The &#8220;Small Progress&#8221; Strategy</h2><p>Imagine someone wants to move into DevOps.</p><p>Instead of trying to learn 20 technologies simultaneously, they could follow a simple progression:</p><h3>Month 1</h3><p>Learn Linux + Git.</p><p>Build basic scripting skills.</p><h3>Month 2</h3><p>Learn AWS fundamentals.</p><p>Deploy something simple.</p><h3>Month 3</h3><p>Learn Docker.</p><p>Containerize an application.</p><h3>Month 4</h3><p>Learn Kubernetes.</p><p>Deploy the application.</p><h3>Month 5</h3><p>Learn Terraform.</p><p>Provision the infrastructure.</p><h3>Month 6</h3><p>Build CI/CD.</p><p>Automate deployment.</p><p>After six months, they don&#8217;t necessarily become a senior engineer.</p><p>That&#8217;s not the point.</p><p>They become <strong>far more capable than they were six months earlier.</strong></p><p>And that is how confidence is built.</p><p>Not through motivational quotes.</p><p>Through evidence.</p><div><hr></div><h1>&#129504; Confidence Comes From Keeping Promises to Yourself</h1><p>This is something people underestimate.</p><p>You don&#8217;t build confidence by repeatedly telling yourself:</p><blockquote><p>&#8220;I am capable.&#8221;</p></blockquote><p>You build confidence by doing things that prove it.</p><p>You say:</p><blockquote><p>&#8220;I&#8217;ll study for an hour.&#8221;</p></blockquote><p>Then you study.</p><p>You say:</p><blockquote><p>&#8220;I&#8217;ll build this project.&#8221;</p></blockquote><p>Then you build it.</p><p>You say:</p><blockquote><p>&#8220;I&#8217;ll apply for this role.&#8221;</p></blockquote><p>Then you apply.</p><p>Every completed promise becomes evidence.</p><p>Eventually your brain starts saying:</p><blockquote><p><strong>&#8220;Maybe I actually can do this.&#8221;</strong></p></blockquote><p>That&#8217;s how confidence grows.</p><p>Slowly.</p><p>Quietly.</p><p>Almost invisibly.</p><p>Until one day you look back and realize you&#8217;re no longer the person who started.</p><div><hr></div><h1>&#127757; Your Past Doesn&#8217;t Have to Become Your Identity</h1><p>Maybe you took a career break.</p><p>Maybe you changed industries.</p><p>Maybe you made poor decisions.</p><p>Maybe you spent years preparing for something that didn&#8217;t work out.</p><p>Maybe you started later than your friends.</p><p>Maybe you were rejected repeatedly.</p><p>Maybe your career hasn&#8217;t gone according to plan.</p><p>None of those things automatically determine what happens next.</p><p>Your past is information.</p><p>It isn&#8217;t a permanent sentence.</p><p>The question isn&#8217;t:</p><blockquote><p><strong>&#8220;Why didn&#8217;t I start earlier?&#8221;</strong></p></blockquote><p>The better question is:</p><blockquote><p><strong>&#8220;What can I do with the time I have now?&#8221;</strong></p></blockquote><p>That question puts you back in control.</p><div><hr></div><h1>&#127919; A Practical Comeback Framework</h1><p>If you&#8217;re genuinely considering restarting or changing your career, keep it simple.</p><h3>1. Choose one direction</h3><p>Don&#8217;t chase ten careers simultaneously.</p><p>Pick one.</p><h3>2. Identify the required skills</h3><p>Look at actual job descriptions.</p><p>Find the recurring requirements.</p><h3>3. Learn the fundamentals</h3><p>Don&#8217;t jump directly into advanced topics because LinkedIn told you they&#8217;re &#8220;hot.&#8221;</p><p>Fundamentals matter.</p><h3>4. Build practical projects</h3><p>Knowledge becomes much stronger when you actually use it.</p><h3>5. Document your work</h3><p>GitHub.</p><p>Projects.</p><p>Technical articles.</p><p>Case studies.</p><p>Anything that demonstrates what you can do.</p><h3>6. Apply before you feel completely ready</h3><p>You probably won&#8217;t.</p><p>Almost nobody does.</p><h3>7. Collect feedback</h3><p>Interview rejection can become useful information if you analyze it.</p><h3>8. Improve continuously</h3><p>Don&#8217;t restart from zero every few months.</p><p>Build on what you&#8217;ve already learned.</p><div><hr></div><h1>&#128161; Stop Measuring Your Life Against Someone Else&#8217;s Clock</h1><p>Someone might become a software engineer at 21.</p><p>Someone else at 28.</p><p>Someone might become a manager at 32.</p><p>Another person might discover entrepreneurship at 40.</p><p>Someone might completely change careers at 45.</p><p>There isn&#8217;t one correct timeline.</p><p>There is only <strong>your timeline</strong>.</p><p>And yes, some people will be ahead of you.</p><p>That&#8217;s unavoidable.</p><p>But someone being ahead doesn&#8217;t mean you&#8217;re finished.</p><p>A runner doesn&#8217;t stop running because another runner started earlier.</p><p>They keep moving.</p><div><hr></div><h1>&#10084;&#65039; Sometimes the Most Important Decision Is Simply to Restart</h1><p>A career comeback doesn&#8217;t always begin with a huge decision.</p><p>Sometimes it begins with something incredibly ordinary:</p><p>Opening the laptop.</p><p>Watching one lesson.</p><p>Reading one chapter.</p><p>Writing one script.</p><p>Building one project.</p><p>Applying for one job.</p><p>Sending one message.</p><p>Trying one more time.</p><p>That small action may not change your life tomorrow.</p><p>But repeated actions can change your trajectory.</p><p>And trajectory matters.</p><div><hr></div><h1>&#128640; Final Takeaway</h1><p>If you&#8217;re currently thinking:</p><blockquote><p><strong>&#8220;It&#8217;s too late for me.&#8221;</strong></p></blockquote><p>pause.</p><p>Maybe you&#8217;re not too late.</p><p>Maybe you&#8217;re simply at a different starting point.</p><p>You don&#8217;t need to erase your past.</p><p>You don&#8217;t need to compete with someone else&#8217;s timeline.</p><p>You don&#8217;t need to become successful overnight.</p><p>You need to start moving again.</p><p><strong>Learn.</strong></p><p><strong>Practice.</strong></p><p><strong>Build.</strong></p><p><strong>Fail.</strong></p><p><strong>Improve.</strong></p><p><strong>Repeat.</strong></p><p>That&#8217;s how careers are rebuilt.</p><p>That&#8217;s how confidence is created.</p><p>That&#8217;s how comebacks happen.</p><p>And perhaps the most important lesson is this:</p><blockquote><p><strong>Your biggest advantage isn&#8217;t your age.</strong></p></blockquote><p>It&#8217;s your:</p><p><strong>Adaptability.</strong><br><strong>Consistency.</strong><br><strong>Curiosity.</strong><br><strong>Willingness to learn.</strong><br><strong>Ability to keep going.</strong></p><p>The person who started five years ago may have more experience today.</p><p>But that doesn&#8217;t tell you where you&#8217;ll be five years from now.</p><p>So stop asking:</p><blockquote><p>&#10060; &#8220;Am I too late?&#8221;</p></blockquote><p>Start asking:</p><blockquote><p>&#9989; <strong>&#8220;What can I build from here?&#8221;</strong></p></blockquote><p>Because life isn&#8217;t always about who starts fastest.</p><p><strong>It&#8217;s about who keeps moving forward.</strong> &#128640;</p><p>And sometimes, the comeback you think is impossible becomes the chapter you&#8217;re most proud of. &#10084;&#65039;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#CareerGrowth #CareerChange #CareerRestart #NeverGiveUp #Motivation #GrowthMindset #Learning #Upskilling #TechCareers #DevOps #SoftwareEngineering #CloudComputing #AI #FutureOfWork #ProfessionalGrowth #CareerDevelopment #Mindset #Success #ContinuousLearning #Inspiration</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🤖 AI Is Humanity’s Greatest Tool, Not Humanity’s Greatest Threat]]></title><description><![CDATA[There is a question that keeps appearing everywhere:]]></description><link>https://arvindverma021.substack.com/p/ai-is-humanitys-greatest-tool-not</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/ai-is-humanitys-greatest-tool-not</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 06:59:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-wvr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!-wvr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!-wvr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2051009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213247449?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-wvr!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76aa20bd-a72e-406a-b7c1-5869e1676582_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>There is a question that keeps appearing everywhere:</p><blockquote><p><strong>&#8220;Will AI replace humans?&#8221;</strong></p></blockquote><p>It is understandable.</p><p>AI can write code.<br>AI can analyze data.<br>AI can generate images.<br>AI can summarize documents.<br>AI can automate repetitive work.<br>AI can help engineers troubleshoot systems.</p><p>And every time AI becomes capable of something new, the same fear returns:</p><p><strong>&#8220;What happens to us?&#8221;</strong></p><p>But perhaps we are asking the wrong question.</p><p>The more important question is:</p><blockquote><p><strong>&#8220;Will humans learn how to use AI effectively?&#8221;</strong></p></blockquote><p>Because AI did not create humans.</p><p><strong>Humans created AI.</strong></p><p>And that distinction matters.</p><p>AI can process information incredibly quickly. It can recognize patterns, generate content, automate workflows and assist with complex tasks.</p><p>But it doesn&#8217;t wake up in the morning and decide:</p><blockquote><p>&#8220;Today I&#8217;m going to build something meaningful.&#8221;</p></blockquote><p>It needs direction.</p><p>It needs context.</p><p>It needs objectives.</p><p>It needs someone to decide what problem is worth solving.</p><p>That is where humans still matter enormously.</p><p>And perhaps the future isn&#8217;t going to be <strong>Humans vs AI</strong>.</p><p>Perhaps it will be:</p><p><strong>Humans + AI.</strong> &#128640;</p><div><hr></div><h1>SECTION 1: AI Is Powerful, But It Doesn&#8217;t Replace Human Purpose &#129504;</h1><p>Think about what makes humans valuable.</p><p>It isn&#8217;t just the ability to calculate.</p><p>Machines have been calculating faster than humans for decades.</p><p>It isn&#8217;t just memory.</p><p>Computers can store and retrieve vastly more information than we can.</p><p>It isn&#8217;t simply speed.</p><p>Machines can process enormous amounts of information far faster than humans.</p><p>Human value comes from a combination of things:</p><ul><li><p>&#129504; Intelligence</p></li><li><p>&#127912; Creativity</p></li><li><p>&#10084;&#65039; Emotion</p></li><li><p>&#128081; Leadership</p></li><li><p>&#127757; Vision</p></li><li><p>&#127919; Judgment</p></li><li><p>&#128161; Curiosity</p></li><li><p>&#129309; Collaboration</p></li></ul><p>AI can assist with many of these areas, but the <strong>purpose behind them</strong> still comes from people.</p><p>Imagine telling an AI:</p><blockquote><p>&#8220;Build something useful.&#8221;</p></blockquote><p>Useful for whom?</p><p>Solving what problem?</p><p>Under what constraints?</p><p>At what cost?</p><p>With what ethical considerations?</p><p>Those questions require context.</p><p>And context comes from humans.</p><div><hr></div><h2>AI Is a System, Not a Magical Brain</h2><p>One of the biggest misconceptions about AI is that it somehow &#8220;knows everything.&#8221;</p><p>It doesn&#8217;t.</p><p>An AI system generates outputs based on its training, available context, tools and instructions.</p><p>That&#8217;s why the quality of the instruction matters.</p><p>Consider two prompts.</p><h3>Prompt 1:</h3><blockquote><p>&#8220;Write some Python code.&#8221;</p></blockquote><h3>Prompt 2:</h3><blockquote><p>&#8220;Write a Python script that reads application logs, identifies HTTP 5xx spikes, groups them by endpoint, generates a CSV report and handles malformed log entries without crashing.&#8221;</p></blockquote><p>The second instruction provides:</p><ul><li><p>Context</p></li><li><p>Requirements</p></li><li><p>Expected behavior</p></li><li><p>Constraints</p></li><li><p>Output format</p></li></ul><p>Naturally, it gives the system a much better direction.</p><p>This is why <strong>prompting isn&#8217;t simply about typing questions.</strong></p><p>It is increasingly about learning how to communicate requirements clearly.</p><div><hr></div><h2>&#127919; A Prompt Is a Command</h2><p>For technical professionals, this becomes particularly interesting.</p><p>Imagine you&#8217;re a DevOps engineer troubleshooting an EKS workload.</p><p>Instead of asking:</p><blockquote><p>&#8220;Why is my Kubernetes application failing?&#8221;</p></blockquote><p>you could provide:</p><pre><code><code>Cluster: EKS
Namespace: production
Pod status: Running
Service status: Active
HTTP response: 503
Recent change: deployment v2.4.1
Ingress: ALB
Recent logs: ...
Events: ...</code></code></pre><p>Now the AI has something useful to work with.</p><p>It can help you:</p><ul><li><p>Identify possible causes</p></li><li><p>Generate diagnostic commands</p></li><li><p>Interpret logs</p></li><li><p>Compare configurations</p></li><li><p>Suggest troubleshooting paths</p></li><li><p>Create scripts</p></li><li><p>Document the incident</p></li></ul><p>But notice something important.</p><p><strong>You provided the context.</strong></p><p>AI didn&#8217;t magically discover your production architecture.</p><p>You directed it.</p><p>That is where the skill shifts.</p><div><hr></div><h1>SECTION 2: The Biggest Opportunity Is Not Replacing People, But Amplifying Them &#128640;</h1><p>Imagine two engineers.</p><h3>Engineer A</h3><p>Uses AI occasionally.</p><p>Writes everything manually.</p><p>Searches documentation for every small problem.</p><p>Creates repetitive scripts from scratch.</p><p>Spends hours formatting reports.</p><h3>Engineer B</h3><p>Uses AI as an engineering assistant.</p><p>They still understand the systems.</p><p>But they use AI to:</p><ul><li><p>Generate boilerplate</p></li><li><p>Analyze logs</p></li><li><p>Create scripts</p></li><li><p>Explain unfamiliar code</p></li><li><p>Draft Terraform</p></li><li><p>Generate Kubernetes manifests</p></li><li><p>Summarize incidents</p></li><li><p>Create documentation</p></li><li><p>Explore possible solutions</p></li><li><p>Automate repetitive tasks</p></li></ul><p>The difference isn&#8217;t that Engineer B knows less.</p><p>It is that Engineer B has created <strong>leverage</strong>.</p><p>And leverage is one of the most powerful ideas in engineering.</p><div><hr></div><h2>&#128187; AI + Software Engineering</h2><p>Consider a common development task.</p><p>You need to create an API endpoint.</p><p>Traditionally:</p><pre><code><code>Requirement
   &#8595;
Design
   &#8595;
Write code
   &#8595;
Debug
   &#8595;
Test
   &#8595;
Document</code></code></pre><p>With AI assistance:</p><pre><code><code>Requirement
   &#8595;
Human defines architecture
   &#8595;
AI generates first draft
   &#8595;
Human reviews
   &#8595;
AI helps test/debug
   &#8595;
Human validates
   &#8595;
Production</code></code></pre><p>The human isn&#8217;t removed.</p><p>The human&#8217;s <strong>time is redistributed</strong>.</p><p>Instead of spending an hour writing boilerplate, you might spend more time thinking about:</p><blockquote><p>&#8220;Is this actually the right architecture?&#8221;</p></blockquote><p>That&#8217;s a much better use of engineering time.</p><div><hr></div><h2>&#9729;&#65039; AI + DevOps</h2><p>This becomes even more interesting in DevOps.</p><p>A DevOps engineer can use AI to assist with:</p><h3>Kubernetes</h3><pre><code><code>kubectl outputs
      &#8595;
AI analysis
      &#8595;
Potential causes
      &#8595;
Recommended checks</code></code></pre><h3>Terraform</h3><pre><code><code>Infrastructure requirement
        &#8595;
AI-generated starting point
        &#8595;
Engineer review
        &#8595;
terraform plan
        &#8595;
Validation</code></code></pre><h3>CI/CD</h3><p>AI can help interpret:</p><ul><li><p>Pipeline failures</p></li><li><p>Build logs</p></li><li><p>Test failures</p></li><li><p>Dependency problems</p></li><li><p>Deployment errors</p></li></ul><h3>Observability</h3><p>AI can help correlate:</p><ul><li><p>Metrics</p></li><li><p>Logs</p></li><li><p>Traces</p></li><li><p>Deployment events</p></li></ul><p>The key word is <strong>assist</strong>.</p><p>AI should not become an excuse to stop understanding your infrastructure.</p><p>If you blindly copy an AI-generated Kubernetes manifest into production, you haven&#8217;t adopted AI.</p><p>You&#8217;ve simply automated the act of making mistakes.</p><div><hr></div><h2>&#129504; The New Competitive Skill: Knowing What to Ask</h2><p>The AI era changes the definition of productivity.</p><p>Previously:</p><blockquote><p><strong>&#8220;Can you do this manually?&#8221;</strong></p></blockquote><p>was often the question.</p><p>Increasingly:</p><blockquote><p><strong>&#8220;Can you define the problem clearly enough for AI to help you solve it?&#8221;</strong></p></blockquote><p>becomes important.</p><p>This requires:</p><h3>1. Clear thinking</h3><p>Understand the problem before asking AI to solve it.</p><h3>2. Strong communication</h3><p>Give precise requirements and constraints.</p><h3>3. Technical fundamentals</h3><p>You still need to recognize whether the generated answer makes sense.</p><h3>4. Problem-solving</h3><p>AI can suggest ten solutions.</p><p>You still need to choose the appropriate one.</p><h3>5. Judgment</h3><p>Not every technically possible solution should be implemented.</p><p>That last one is especially important in production engineering.</p><div><hr></div><h1>SECTION 3: The People Who Learn to Collaborate With AI Will Have an Advantage &#129309;</h1><p>There is a dangerous misconception:</p><blockquote><p><strong>&#8220;AI will replace smart people.&#8221;</strong></p></blockquote><p>The more realistic risk is different.</p><p><strong>People who use AI effectively may become significantly more productive than people who refuse to adapt.</strong></p><p>Think about what happened with previous technological shifts.</p><p>Calculators didn&#8217;t eliminate mathematicians.</p><p>IDEs didn&#8217;t eliminate programmers.</p><p>Cloud didn&#8217;t eliminate infrastructure engineers.</p><p>Automation didn&#8217;t eliminate engineers.</p><p>Instead, the nature of the work changed.</p><p>The same thing is happening with AI.</p><div><hr></div><h1>&#129302; AI Without Human Direction Is Limited</h1><p>Imagine giving an AI incredible computational capabilities but no meaningful objective.</p><p>What should it build?</p><p>Where should it go?</p><p>What should it prioritize?</p><p>What trade-offs should it make?</p><p>The AI can execute.</p><p>But humans provide:</p><p><strong>Vision.</strong></p><p><strong>Direction.</strong></p><p><strong>Purpose.</strong></p><p><strong>Decision-making.</strong></p><p><strong>Responsibility.</strong></p><p>This is why the most valuable combination isn&#8217;t:</p><pre><code><code>Human
   OR
AI</code></code></pre><p>It is:</p><pre><code><code>Human Intelligence
        +
Artificial Intelligence
        &#8595;
Greater Capability</code></code></pre><p>The image captures this idea beautifully.</p><p>AI doesn&#8217;t have to be viewed as an enemy.</p><p>It can be viewed as a <strong>powerful assistant</strong>.</p><div><hr></div><h1>&#128680; But There Is One Important Warning</h1><p>Using AI doesn&#8217;t automatically make someone better.</p><p>You can use AI badly.</p><p>For example:</p><blockquote><p>&#8220;Generate a secure AWS architecture.&#8221;</p></blockquote><p>AI generates something.</p><p>You deploy it.</p><p>Later you discover:</p><ul><li><p>Excessive IAM permissions</p></li><li><p>Publicly exposed resources</p></li><li><p>Poor network segmentation</p></li><li><p>Missing encryption</p></li><li><p>No disaster recovery</p></li><li><p>Expensive architecture</p></li></ul><p>The problem wasn&#8217;t AI.</p><p>The problem was <strong>blind trust</strong>.</p><p>AI-generated output still needs:</p><p><strong>Review &#8594; Testing &#8594; Validation &#8594; Human judgment</strong></p><p>Especially when dealing with:</p><ul><li><p>Production systems</p></li><li><p>Security</p></li><li><p>Infrastructure</p></li><li><p>Financial decisions</p></li><li><p>Customer data</p></li><li><p>Compliance</p></li><li><p>Critical applications</p></li></ul><p>AI should accelerate your thinking.</p><p>It shouldn&#8217;t replace it.</p><div><hr></div><h1>&#127793; How Professionals Can Prepare for the AI Era</h1><p>You don&#8217;t need to become an AI researcher.</p><p>But you should become <strong>AI-literate</strong>.</p><p>Start with practical use cases.</p><h3>For Developers &#128187;</h3><p>Use AI for:</p><ul><li><p>Code generation</p></li><li><p>Refactoring</p></li><li><p>Testing</p></li><li><p>Debugging</p></li><li><p>Documentation</p></li><li><p>Code explanation</p></li></ul><h3>For DevOps Engineers &#9729;&#65039;</h3><p>Use AI for:</p><ul><li><p>Terraform generation</p></li><li><p>Kubernetes troubleshooting</p></li><li><p>Log analysis</p></li><li><p>CI/CD debugging</p></li><li><p>Shell scripting</p></li><li><p>Incident documentation</p></li><li><p>Automation</p></li></ul><h3>For Cloud Engineers &#127760;</h3><p>Use AI for:</p><ul><li><p>Architecture exploration</p></li><li><p>Cost analysis</p></li><li><p>Configuration review</p></li><li><p>Documentation</p></li><li><p>Troubleshooting</p></li></ul><h3>For Everyone &#129504;</h3><p>Learn how to:</p><ul><li><p>Give good context</p></li><li><p>Write precise instructions</p></li><li><p>Verify outputs</p></li><li><p>Protect sensitive information</p></li><li><p>Break large problems into smaller ones</p></li><li><p>Use AI as a thinking partner</p></li></ul><div><hr></div><h1>&#128293; The Future Belongs to Adaptable Humans</h1><p>The world is changing quickly.</p><p>New AI tools appear almost every week.</p><p>Some will disappear.</p><p>Others will become part of everyday workflows.</p><p>Trying to predict exactly which tool will dominate five years from now is probably a fantastic way to waste five years.</p><p>The better strategy is to develop skills that survive tool changes.</p><p>Learn:</p><p><strong>How to think.</strong></p><p><strong>How to solve problems.</strong></p><p><strong>How to communicate.</strong></p><p><strong>How to learn.</strong></p><p><strong>How to evaluate information.</strong></p><p><strong>How to use technology effectively.</strong></p><p>Those skills remain valuable regardless of which AI model happens to be fashionable next month.</p><div><hr></div><h1>&#128640; Final Takeaway</h1><p>AI isn&#8217;t humanity&#8217;s greatest threat.</p><p>Neither is it humanity&#8217;s greatest solution.</p><p><strong>It&#8217;s a tool.</strong></p><p>A remarkably powerful one.</p><p>But a tool is only as valuable as the person using it.</p><p>A great engineer with AI can potentially accomplish far more than that engineer working alone.</p><p>A poor engineer with AI can simply produce bad work faster.</p><p>That&#8217;s the uncomfortable part.</p><p>AI increases capability.</p><p>It doesn&#8217;t automatically increase judgment.</p><p>So instead of asking:</p><blockquote><p>&#10060; <strong>&#8220;Will AI replace humans?&#8221;</strong></p></blockquote><p>Perhaps we should ask:</p><blockquote><p>&#9989; <strong>&#8220;Will humans learn how to work with AI effectively?&#8221;</strong></p></blockquote><p>Because the future probably won&#8217;t belong to people who compete with machines.</p><p>It will belong to people who understand how to <strong>collaborate with them</strong>.</p><p>The equation is surprisingly simple:</p><p><strong>&#129504; Human intelligence + &#129302; AI capability = &#128640; Limitless possibilities</strong></p><p>Not because AI replaces human intelligence.</p><p>But because humans finally have another powerful tool to amplify it.</p><p><strong>Adapt. Learn. Evolve.</strong></p><p>The technology will keep changing.</p><p>The people who keep learning will change with it. &#127757;&#10024;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#ArtificialIntelligence #AI #GenerativeAI #ChatGPT #ClaudeAI #AIAutomation #FutureOfWork #Technology #Innovation #SoftwareEngineering #DevOps #CloudComputing #Kubernetes #Programming #Productivity #AIEngineering #MachineLearning #DigitalTransformation #CareerGrowth #Learning</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🚨 Capgemini DevOps L1 Interview Experience: 9 Questions That Tested Real Project Knowledge]]></title><description><![CDATA[Recently, a candidate shared their Capgemini L1 DevOps interview experience, where the discussion focused heavily on Terraform, AWS VPC, VPC Peering, Amazon EKS, and Terraform Remote Backend.]]></description><link>https://arvindverma021.substack.com/p/capgemini-devops-l1-interview-experience</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/capgemini-devops-l1-interview-experience</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Sat, 29 Aug 2026 06:12:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!H6pE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!H6pE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!H6pE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1981535,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213244033?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!H6pE!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb7433d-a3ac-44e0-b562-b10c39c027cf_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The interviewer wasn&#8217;t simply asking:</p><blockquote><p><em>&#8220;What is Terraform?&#8221;</em></p></blockquote><p>They were asking about <strong>how Terraform was actually used in the candidate&#8217;s project.</strong></p><p>That distinction matters.</p><p>So let&#8217;s break down the questions, what the interviewer was really trying to understand, and how you can prepare for similar interviews.</p><div><hr></div><h3>SECTION 1: Terraform Wasn&#8217;t Just a Definition Question &#127959;&#65039;</h3><p>The first major theme was <strong>Terraform</strong>.</p><p>And honestly, that&#8217;s exactly where many DevOps candidates get caught.</p><p>They know:</p><blockquote><p><em>&#8220;Terraform is an Infrastructure as Code tool.&#8221;</em></p></blockquote><p>Correct.</p><p>But the interviewer doesn&#8217;t necessarily want the textbook answer.</p><p>They want to know whether you&#8217;ve actually used it.</p><div><hr></div><h3>1&#65039;&#8419; &#8220;How have you used Terraform for deployment in your project?&#8221;</h3><p>This looks simple.</p><p>But there&#8217;s a lot hidden inside the question.</p><p>The interviewer is trying to understand:</p><ul><li><p>What infrastructure did you provision?</p></li><li></li><li><p>Why did you use Terraform?</p></li><li></li><li><p>How was the code structured?</p></li><li></li><li><p>Where was the state stored?</p></li><li></li><li><p>How did you manage environments?</p></li><li></li><li><p>Did you use modules?</p></li><li></li><li><p>How did you handle changes?</p></li><li></li><li><p>Did you run Terraform manually or through CI/CD?</p></li><li></li></ul><h3>A concise candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I used Terraform to provision AWS infrastructure such as VPC, subnets, IAM, EKS and supporting resources. I kept the infrastructure code modular and stored the Terraform state remotely in S3 with state locking.&#8221;</strong></em></p></blockquote><p>That&#8217;s generally a better interview answer than giving a five-minute lecture on Infrastructure as Code.</p><p>If the interviewer wants more, they&#8217;ll ask.</p><p>And they usually will.</p><div><hr></div><h3>2&#65039;&#8419; Terraform Folder Structure and Modules</h3><p>The next questions were:</p><blockquote><p><em><strong>&#8220;How did you structure your Terraform folders?&#8221;</strong></em></p></blockquote><p>and</p><blockquote><p><em><strong>&#8220;How did you use Terraform modules?&#8221;</strong></em></p></blockquote><p>This is where the interviewer starts moving from theory toward implementation.</p><p>A typical production-oriented structure could look like:</p><pre><code>terraform/
&#9474;
&#9500;&#9472;&#9472; backend.tf
&#9500;&#9472;&#9472; provider.tf
&#9500;&#9472;&#9472; versions.tf
&#9500;&#9472;&#9472; variables.tf
&#9500;&#9472;&#9472; main.tf
&#9500;&#9472;&#9472; outputs.tf
&#9474;
&#9500;&#9472;&#9472; modules/
&#9474;   &#9500;&#9472;&#9472; vpc/
&#9474;   &#9500;&#9472;&#9472; eks/
&#9474;   &#9500;&#9472;&#9472; iam/
&#9474;   &#9492;&#9472;&#9472; ecr/
&#9474;
&#9492;&#9472;&#9472; environments/
    &#9500;&#9472;&#9472; dev/
    &#9500;&#9472;&#9472; staging/
    &#9492;&#9472;&#9472; prod/</code></pre><p>The exact structure can vary between organizations.</p><p>The important thing is being able to explain <strong>why</strong> you structured it that way.</p><h3>Candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I separated reusable infrastructure into modules such as VPC and EKS. The root configuration called those modules and passed environment-specific variables to them. This helped keep the code reusable and easier to maintain.&#8221;</strong></em></p></blockquote><p>Notice something.</p><p>The answer isn&#8217;t:</p><blockquote><p><em>&#8220;Terraform modules are reusable blocks of Terraform configuration&#8230;&#8221;</em></p></blockquote><p>That&#8217;s the documentation answer.</p><p>Instead:</p><blockquote><p><em><strong>&#8220;I used modules for this purpose in my project.&#8221;</strong></em></p></blockquote><p>That&#8217;s the experience answer.</p><div><hr></div><h3>3&#65039;&#8419; How Do You Call a Terraform Module?</h3><p>You may also get a follow-up like:</p><blockquote><p><em><strong>&#8220;How do you call a module from the root configuration?&#8221;</strong></em></p></blockquote><p>For example:</p><pre><code>module &#8220;vpc&#8221; {
  source = &#8220;./modules/vpc&#8221;</code></pre><pre><code>  vpc_cidr = var.vpc_cidr
}</code></pre><p>Then the interviewer may ask:</p><blockquote><p><em>&#8220;What does </em><code>source</code><em> mean?&#8221;</em></p></blockquote><p>You should be able to explain it simply:</p><blockquote><p><em><strong>&#8220;It tells Terraform where the module code is located. It can be a local path or a remote module source.&#8221;</strong></em></p></blockquote><p>That&#8217;s it.</p><p>Don&#8217;t turn a simple question into a conference keynote.</p><div><hr></div><h3>SECTION 2: AWS Networking and EKS &#127760;&#9729;&#65039;</h3><p>The second major area was AWS networking.</p><p>This is important because Kubernetes doesn&#8217;t exist in isolation.</p><p>In a real AWS environment, your EKS cluster depends heavily on the underlying networking architecture.</p><div><hr></div><h3>4&#65039;&#8419; How Did You Implement a VPC With Public and Private Subnets?</h3><p>This is one of those questions where diagrams are often more useful than definitions.</p><p>A simplified architecture could look like:</p><pre><code>VPC
                     |
        &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
        |                         |
 Public Subnets             Private Subnets
        |                         |
   Load Balancer              EKS Nodes
        |                         |
     Internet              Application Pods</code></pre><p>Typically:</p><p><strong>Public subnet</strong></p><p>Has a route to an Internet Gateway.</p><p><strong>Private subnet</strong></p><p>Doesn&#8217;t have a direct route to the Internet Gateway for outbound internet access. It may use a NAT Gateway for outbound connectivity.</p><h3>Candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I used public subnets for internet-facing components such as the load balancer and private subnets for application workloads such as EKS worker nodes. The private subnets used NAT for required outbound connectivity.&#8221;</strong></em></p></blockquote><p>That&#8217;s a strong answer because it connects:</p><p><strong>AWS networking &#8594; security &#8594; application architecture.</strong></p><div><hr></div><h3>5&#65039;&#8419; How Do You Identify Whether a Subnet Is Public or Private?</h3><p>This question sounds basic.</p><p>But interviewers often use simple questions to see whether you understand the underlying concept.</p><p>The easiest way to explain it:</p><blockquote><p><em><strong>&#8220;I check the subnet&#8217;s route table. If it has a route to an Internet Gateway, it&#8217;s considered public. If it doesn&#8217;t have a direct Internet Gateway route and uses NAT for outbound connectivity, it&#8217;s private.&#8221;</strong></em></p></blockquote><p>For example:</p><pre><code>Public Subnet
      &#8595;
Route Table
      &#8595;
0.0.0.0/0
      &#8595;
Internet Gateway</code></pre><p>versus:</p><pre><code>Private Subnet
      &#8595;
Route Table
      &#8595;
0.0.0.0/0
      &#8595;
NAT Gateway
      &#8595;
Internet Gateway</code></pre><p>This distinction becomes particularly important when designing EKS environments.</p><div><hr></div><h3>6&#65039;&#8419; What Is VPC Peering?</h3><p>Then came <strong>VPC Peering</strong>.</p><p>A simple answer:</p><blockquote><p><em><strong>&#8220;VPC Peering provides private network connectivity between two VPCs using private IP addresses.&#8221;</strong></em></p></blockquote><p>But again, the interesting part is the follow-up:</p><blockquote><p><em><strong>&#8220;How have you implemented it in your project?&#8221;</strong></em></p></blockquote><p>A practical scenario could be:</p><pre><code>VPC A
Application
   |
   | VPC Peering
   |
VPC B
Database / Shared Service</code></pre><p>For communication to work, you generally need to consider:</p><ul><li><p>CIDR ranges</p></li><li></li><li><p>Peering connection</p></li><li></li><li><p>Route tables</p></li><li></li><li><p>Security groups</p></li><li></li><li><p>Network ACLs where applicable</p></li><li></li><li><p>DNS requirements</p></li><li></li></ul><h3>Candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I used VPC Peering to allow private communication between resources in separate VPCs. After creating the peering connection, I configured routes on both sides and allowed the required traffic through security groups.&#8221;</strong></em></p></blockquote><p>The key phrase is:</p><p><strong>&#8220;both sides.&#8221;</strong></p><p>Creating the peering connection alone doesn&#8217;t magically make traffic flow.</p><p>Networking, unfortunately, still expects configuration.</p><div><hr></div><h3>7&#65039;&#8419; How Have You Used Amazon EKS in Your Project?</h3><p>This is where your project explanation becomes extremely important.</p><p>If you say:</p><blockquote><p><em>&#8220;I have worked on EKS.&#8221;</em></p></blockquote><p>expect:</p><blockquote><p><em><strong>&#8220;What exactly did you do?&#8221;</strong></em></p></blockquote><p>You should be prepared to discuss things such as:</p><pre><code>AWS VPC
   &#8595;
EKS Control Plane
   &#8595;
Worker Nodes / Node Groups
   &#8595;
Pods
   &#8595;
Services
   &#8595;
Ingress / Load Balancer</code></pre><p>You might also discuss:</p><ul><li><p>Kubernetes deployments</p></li><li></li><li><p>Services</p></li><li></li><li><p>ConfigMaps</p></li><li></li><li><p>Secrets</p></li><li></li><li><p>Ingress</p></li><li></li><li><p>Helm</p></li><li></li><li><p>IAM</p></li><li></li><li><p>Load Balancer Controller</p></li><li></li><li><p>Autoscaling</p></li><li></li><li><p>Monitoring</p></li><li></li><li><p>CI/CD integration</p></li><li></li></ul><h3>Candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I used EKS to run containerized applications. I worked with deployments, services and ingress, and integrated the cluster with AWS networking and load balancing. I also used Terraform to provision the underlying infrastructure.&#8221;</strong></em></p></blockquote><p>That&#8217;s much more useful than:</p><blockquote><p><em>&#8220;EKS is a managed Kubernetes service.&#8221;</em></p></blockquote><p>Again, technically correct.</p><p>But interviewers are interested in what <strong>you actually did</strong>.</p><div><hr></div><h3>SECTION 3: EKS Upgrades, Remote State and the Real Interview Lesson &#128640;</h3><h3>8&#65039;&#8419; How Do You Perform an EKS Cluster Upgrade?</h3><p>This is where the interview starts testing operational maturity.</p><p>An EKS upgrade shouldn&#8217;t be treated like:</p><pre><code>Click Upgrade
Wait
Done</code></pre><p>A production upgrade needs planning.</p><p>A simplified process:</p><pre><code>Check Current Version
        &#8595;
Review Compatibility
        &#8595;
Check Add-ons
        &#8595;
Backup / Validate Workloads
        &#8595;
Upgrade Control Plane
        &#8595;
Upgrade Add-ons
        &#8595;
Upgrade Node Groups
        &#8595;
Validate Applications
        &#8595;
Monitor</code></pre><h3>Candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I first check the current Kubernetes version and compatibility of workloads and add-ons. Then I upgrade the control plane, followed by compatible add-ons and worker nodes. After the upgrade, I validate workloads, networking and application health.&#8221;</strong></em></p></blockquote><p>The interviewer may then ask:</p><blockquote><p><em>&#8220;What can go wrong?&#8221;</em></p></blockquote><p>Be ready for:</p><ul><li><p>Deprecated APIs</p></li><li></li><li><p>Incompatible add-ons</p></li><li></li><li><p>Node compatibility</p></li><li></li><li><p>Workload disruption</p></li><li></li><li><p>Ingress issues</p></li><li></li><li><p>CSI driver issues</p></li><li></li><li><p>Admission webhook problems</p></li><li></li><li><p>Application compatibility</p></li><li></li></ul><p>This is why Kubernetes upgrades are operational exercises, not just version changes.</p><div><hr></div><h3>9&#65039;&#8419; Terraform Remote Backend</h3><p>Another important question:</p><blockquote><p><em><strong>&#8220;Which remote backend have you used?&#8221;</strong></em></p></blockquote><p>A common AWS setup is:</p><pre><code>Terraform
    |
    &#8595;
S3 Bucket
    |
Terraform State</code></pre><p>The state should generally not live only on an engineer&#8217;s laptop in a team environment.</p><p>A remote backend provides centralized state storage and enables team workflows.</p><h3>Candidate-style answer:</h3><blockquote><p><em><strong>&#8220;I used an S3 backend to store Terraform state remotely. This allowed the team to work with shared state instead of keeping the state file locally.&#8221;</strong></em></p></blockquote><p>Then the interviewer might ask:</p><blockquote><p><em><strong>&#8220;How did you prevent concurrent Terraform operations?&#8221;</strong></em></p></blockquote><p>That&#8217;s where state locking becomes important.</p><p>Depending on the Terraform/AWS setup and Terraform version, locking can be handled using supported backend locking mechanisms. The important interview concept is:</p><blockquote><p><em><strong>Prevent multiple Terraform operations from modifying the same state concurrently.</strong></em></p></blockquote><p>Because:</p><pre><code>Engineer A
terraform apply
        &#8595;
       State
        &#8593;
terraform apply
Engineer B</code></pre><p>without proper coordination can create a very unpleasant afternoon.</p><div><hr></div><h3>&#128287; How Did You Configure S3 for Terraform State?</h3><p>A typical backend configuration might look conceptually like:</p><pre><code>terraform {
  backend &#8220;s3&#8221; {
    bucket = &#8220;terraform-state-bucket&#8221;
    key    = &#8220;project/terraform.tfstate&#8221;
    region = &#8220;ap-south-1&#8221;
  }
}</code></pre><p>But production considerations go beyond simply creating a bucket.</p><p>You should think about:</p><h3>&#128272; Security</h3><p>Restrict who can access the state.</p><h3>&#128450;&#65039; Versioning</h3><p>Enable S3 versioning so previous state versions can be recovered when appropriate.</p><h3>&#128274; Encryption</h3><p>Encrypt the state at rest.</p><h3>&#128101; IAM</h3><p>Give Terraform only the permissions it actually needs.</p><h3>&#128680; Protection</h3><p>Prevent accidental deletion of the state bucket.</p><p>Remember:</p><p><strong>Terraform state can contain sensitive infrastructure information.</strong></p><p>Treating it like an ordinary file is asking for trouble.</p><div><hr></div><h3>&#127919; What This Interview Experience Actually Teaches</h3><p>The biggest takeaway from these questions isn&#8217;t:</p><blockquote><p><em>&#8220;Study Terraform.&#8221;</em></p></blockquote><p>or:</p><blockquote><p><em>&#8220;Study AWS.&#8221;</em></p></blockquote><p>or:</p><blockquote><p><em>&#8220;Study EKS.&#8221;</em></p></blockquote><p>You should absolutely study them.</p><p>But there&#8217;s another layer.</p><h3>Learn every technology at three levels.</h3><h3>Level 1: Definition</h3><blockquote><p><em>What is Terraform?</em></p></blockquote><p>You should know this.</p><h3>Level 2: Implementation</h3><blockquote><p><em>How did you use Terraform in your project?</em></p></blockquote><p>You absolutely need this.</p><h3>Level 3: Troubleshooting</h3><blockquote><p><em>Terraform apply failed halfway. What did you do?</em></p></blockquote><p>This is where many candidates struggle.</p><p>The same applies to EKS.</p><h3>Definition:</h3><blockquote><p><em>What is EKS?</em></p></blockquote><h3>Implementation:</h3><blockquote><p><em>How did you deploy applications on EKS?</em></p></blockquote><h3>Troubleshooting:</h3><blockquote><p><em>Pods are running but users receive 503. How would you investigate?</em></p></blockquote><p>That&#8217;s the progression interviewers use to separate:</p><p><strong>knowledge</strong></p><p>from</p><p><strong>experience.</strong></p><div><hr></div><h3>&#129504; Build Your Project Story Before the Interview</h3><p>If you&#8217;re preparing for a DevOps interview, don&#8217;t just prepare individual questions.</p><p>Prepare your <strong>project story</strong>.</p><p>You should be able to explain:</p><pre><code>AWS
                     |
                   VPC
              &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
              &#8595;             &#8595;
          Public          Private
          Subnets         Subnets
              &#8595;             &#8595;
             ALB           EKS
                            &#8595;
                          Pods
                            &#8595;
                           App
                            &#8595;
                           RDS</code></pre><p>Then explain how Terraform fits into it:</p><pre><code>Git
 &#8595;
Terraform
 &#8595;
VPC
 &#8595;
EKS
 &#8595;
AWS Resources</code></pre><p>Then explain how CI/CD fits:</p><pre><code>Developer
   &#8595;
Git
   &#8595;
CI Pipeline
   &#8595;
Build
   &#8595;
Security Scan
   &#8595;
Docker Image
   &#8595;
Registry
   &#8595;
CD
   &#8595;
EKS</code></pre><p>Then explain what happens when something breaks.</p><p>That&#8217;s when your interview preparation becomes much stronger.</p><div><hr></div><h3>&#128640; The Most Important Interview Rule</h3><p>If you claim:</p><blockquote><p><em><strong>&#8220;I worked on EKS.&#8221;</strong></em></p></blockquote><p>be prepared for at least 10 follow-up questions.</p><p>If you claim:</p><blockquote><p><em><strong>&#8220;I used Terraform.&#8221;</strong></em></p></blockquote><p>be prepared to explain:</p><ul><li><p>Folder structure</p></li><li></li><li><p>Modules</p></li><li></li><li><p>Variables</p></li><li></li><li><p>Outputs</p></li><li></li><li><p>State</p></li><li></li><li><p>Backend</p></li><li></li><li><p>Locking</p></li><li></li><li><p>Workspaces or environment strategy</p></li><li></li><li><p>Drift</p></li><li></li><li><p>Failed applies</p></li><li></li><li><p>CI/CD integration</p></li><li></li></ul><p>If you claim:</p><blockquote><p><em><strong>&#8220;I worked on AWS networking.&#8221;</strong></em></p></blockquote><p>be ready for:</p><ul><li><p>VPC</p></li><li></li><li><p>Subnets</p></li><li></li><li><p>Route tables</p></li><li></li><li><p>Internet Gateway</p></li><li></li><li><p>NAT Gateway</p></li><li></li><li><p>Security Groups</p></li><li></li><li><p>NACLs</p></li><li></li><li><p>VPC Peering</p></li><li></li><li><p>DNS</p></li><li></li><li><p>Load Balancers</p></li><li></li></ul><p>Because experienced interviewers don&#8217;t necessarily stop at the first answer.</p><p>They keep digging.</p><p>And eventually they reach the question every candidate should be prepared for:</p><blockquote><p><em><strong>&#8220;Okay, but what did YOU actually do?&#8221;</strong></em></p></blockquote><p>That is the question that matters.</p><div><hr></div><h3>&#128161; Final Takeaway</h3><p>This Capgemini L1 interview experience is a good reminder that <strong>DevOps interviews are increasingly becoming project-oriented</strong>.</p><p>You don&#8217;t need to give a 10-minute answer to every question.</p><p>In fact, don&#8217;t.</p><p>A good interview answer is usually:</p><p><strong>Short &#8594; Specific &#8594; Based on your experience &#8594; Open for follow-up.</strong></p><p>For example:</p><blockquote><p><em><strong>&#8220;I used Terraform to provision VPC and EKS infrastructure. I separated reusable components into modules and stored the state remotely in S3.&#8221;</strong></em></p></blockquote><p>Then stop.</p><p>Let the interviewer ask:</p><blockquote><p><em>&#8220;Why modules?&#8221;</em></p></blockquote><p>Answer that.</p><p>Then:</p><blockquote><p><em>&#8220;Why S3?&#8221;</em></p></blockquote><p>Answer that.</p><p>Then:</p><blockquote><p><em>&#8220;How did you handle state locking?&#8221;</em></p></blockquote><p>Answer that.</p><p>This creates a natural technical conversation instead of sounding like you&#8217;ve memorized a DevOps encyclopedia.</p><p>And that&#8217;s the real lesson:</p><p><strong>Don&#8217;t prepare only answers. Prepare the story behind your answers.</strong> &#127919;</p><p>Because in a DevOps interview, knowing what a tool does is useful.</p><p>Knowing <strong>how you used it, why you used it, what went wrong, and how you fixed it</strong> is what makes your experience believable.</p><div><hr></div><h3>&#128278;Hashtags</h3><p>#DevOps #DevOpsInterview #Capgemini #AWS #Terraform #Kubernetes #EKS #AWSVPC #VPCCPeering #TerraformModules #TerraformBackend #CloudEngineering #SRE #DevOpsEngineer #KubernetesInterview #AWSInterview #TerraformInterview #CloudComputing #InfrastructureAsCode #CI_CD</p><h3>&#128075; Follow Me</h3><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[😂 DevOps Would Be Easy If Production Didn’t Exist]]></title><description><![CDATA[DevOps looks beautiful on a whiteboard.]]></description><link>https://arvindverma021.substack.com/p/devops-would-be-easy-if-production</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/devops-would-be-easy-if-production</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Fri, 28 Aug 2026 05:50:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sMgi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!sMgi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!sMgi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1870397,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213102196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sMgi!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53743af3-f5f1-4c20-80a4-17d08fb9f2bb_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>You draw a few boxes:</p><pre><code><code>Developer
   &#8595;
Git
   &#8595;
CI/CD
   &#8595;
Docker
   &#8595;
Kubernetes
   &#8595;
AWS
   &#8595;
Production</code></code></pre><p>Everything is automated.</p><p>Everything is scalable.</p><p>Everything is secure.</p><p>Everything is observable.</p><p>Then you actually deploy it.</p><p>Five minutes later:</p><p><strong>503.</strong></p><p>Then someone asks:</p><blockquote><p>&#8220;Who changed the security group?&#8221;</p></blockquote><p>Nobody knows.</p><p>Someone checks Grafana.</p><p>Someone checks Kubernetes.</p><p>Someone blames DNS.</p><p>Someone says, &#8220;It works on my machine.&#8221;</p><p>And suddenly the entire DevOps philosophy becomes a group therapy session. &#128514;</p><p>The truth is, every DevOps engineer eventually develops a slightly unhealthy relationship with production.</p><p>We automate because humans make mistakes.</p><p>Then we create so much automation that we need another human to understand the automation.</p><p>We introduce Kubernetes to solve scaling problems.</p><p>Then we spend Friday evening debugging why a Service has no endpoints.</p><p>We introduce Terraform to make infrastructure predictable.</p><p>Then Terraform tells us:</p><blockquote><p>&#8220;I know what you asked for. Unfortunately, AWS has other plans.&#8221;</p></blockquote><p>Welcome to DevOps.</p><p>Here are some painfully familiar DevOps truths, with the jokes removed just enough to reveal the engineering lesson underneath.</p><div><hr></div><h1>SECTION 1: Linux, Docker, Kubernetes and the Art of Making Simple Things Complicated &#128039;&#128051;&#9784;&#65039;</h1><h2>&#128039; Linux: <code>chmod 777</code> When Security Becomes Someone Else&#8217;s Problem</h2><p>Every Linux engineer eventually encounters this magical command:</p><pre><code><code>chmod 777 file</code></code></pre><p>Permission denied?</p><pre><code><code>chmod 777</code></code></pre><p>Problem solved.</p><p>Except it wasn&#8217;t.</p><p>You just changed:</p><pre><code><code>Owner       &#8594; Read Write Execute
Group       &#8594; Read Write Execute
Everyone    &#8594; Read Write Execute</code></code></pre><p>You&#8217;ve effectively said:</p><blockquote><p>&#8220;Security is tomorrow&#8217;s problem.&#8221;</p></blockquote><p>And tomorrow&#8217;s problem becomes:</p><blockquote><p>&#8220;Why can every process on this server modify this file?&#8221;</p></blockquote><p>In production, permissions should follow <strong>least privilege</strong>.</p><p>Instead of:</p><pre><code><code>chmod 777</code></code></pre><p>you might need something like:</p><pre><code><code>chmod 640 file</code></code></pre><p>or change ownership:</p><pre><code><code>chown appuser:appgroup file</code></code></pre><p>The real DevOps lesson isn&#8217;t memorizing <code>chmod</code>.</p><p>It&#8217;s understanding:</p><p><strong>Who needs access? What access do they need? Why?</strong></p><p>Security isn&#8217;t a command.</p><p>It&#8217;s a design decision.</p><div><hr></div><h1>&#128051; Docker: &#8220;It Works on My Machine.&#8221;</h1><p>This sentence has probably caused more infrastructure discussions than most architecture documents.</p><p>Developer:</p><blockquote><p>&#8220;The application works perfectly.&#8221;</p></blockquote><p>DevOps:</p><blockquote><p>&#8220;Where?&#8221;</p></blockquote><p>Developer:</p><blockquote><p>&#8220;My laptop.&#8221;</p></blockquote><p>DevOps:</p><blockquote><p>&#8220;Which version of Python?&#8221;</p></blockquote><p>Developer:</p><blockquote><p>&#8220;I don&#8217;t know.&#8221;</p></blockquote><p>DevOps:</p><blockquote><p>&#8220;Which dependency version?&#8221;</p></blockquote><p>Developer:</p><blockquote><p>&#8220;I think latest.&#8221;</p></blockquote><p>And there goes the afternoon.</p><p>Docker helps solve this by packaging the application with its dependencies into a consistent image.</p><pre><code><code>Application
+
Dependencies
+
Runtime
+
Configuration
        &#8595;
      Image
        &#8595;
     Container</code></code></pre><p>Now the environment becomes much more predictable.</p><p>But Docker doesn&#8217;t eliminate every problem.</p><p>You can still have:</p><ul><li><p>Wrong environment variables</p></li><li><p>Network issues</p></li><li><p>Volume permissions</p></li><li><p>Architecture differences</p></li><li><p>Resource constraints</p></li><li><p>Incorrect health checks</p></li><li><p>Bad container configuration</p></li></ul><p>So Docker doesn&#8217;t mean:</p><blockquote><p>&#8220;Nothing can go wrong.&#8221;</p></blockquote><p>It means:</p><blockquote><p><strong>&#8220;At least we&#8217;re failing in a more consistent way.&#8221;</strong> &#128514;</p></blockquote><div><hr></div><h1>&#9784;&#65039; Kubernetes: Making Simple Things Distributed Since 2014</h1><p>You wanted to run an application.</p><p>Without Kubernetes:</p><pre><code><code>Run application</code></code></pre><p>With Kubernetes:</p><pre><code><code>Deployment
 &#8595;
ReplicaSet
 &#8595;
Pod
 &#8595;
Container
 &#8595;
Service
 &#8595;
Ingress
 &#8595;
Load Balancer
 &#8595;
DNS</code></code></pre><p>And then you ask:</p><blockquote><p>&#8220;Why isn&#8217;t my application accessible?&#8221;</p></blockquote><p>Kubernetes replies with the emotional equivalent of:</p><blockquote><p>&#8220;Define accessible.&#8221;</p></blockquote><p>But there&#8217;s a reason Kubernetes exists.</p><p>Production applications need:</p><ul><li><p>High availability</p></li><li><p>Scaling</p></li><li><p>Service discovery</p></li><li><p>Rolling deployments</p></li><li><p>Self-healing</p></li><li><p>Load balancing</p></li><li><p>Resource management</p></li><li><p>Automated scheduling</p></li></ul><p>The complexity is the price of managing distributed systems.</p><p>A good DevOps engineer doesn&#8217;t try to eliminate that complexity completely.</p><p>They learn to <strong>control it</strong>.</p><div><hr></div><h1>SECTION 2: Terraform, GitOps, DNS and the Infrastructure Circus &#127959;&#65039;&#127760;</h1><h2>&#127959;&#65039; Terraform: Destroying Infrastructure Consistently</h2><p>Terraform promises something beautiful:</p><blockquote><p>Infrastructure as Code.</p></blockquote><p>Instead of manually creating infrastructure:</p><pre><code><code>Click
Click
Click
Click
Forget what you clicked</code></code></pre><p>you write:</p><pre><code><code>resource "aws_instance" "app" {
  ...
}</code></code></pre><p>Then:</p><pre><code><code>terraform plan
terraform apply</code></code></pre><p>Beautiful.</p><p>Repeatable.</p><p>Version-controlled.</p><p>Until someone changes something manually in AWS.</p><p>Now Terraform says:</p><pre><code><code>Drift detected.</code></code></pre><p>And you&#8217;re sitting there wondering:</p><blockquote><p>&#8220;Who touched production?&#8221;</p></blockquote><p>Terraform is valuable because infrastructure should be:</p><ul><li><p>Reproducible</p></li><li><p>Reviewable</p></li><li><p>Version-controlled</p></li><li><p>Consistent</p></li><li><p>Auditable</p></li></ul><p>But Terraform isn&#8217;t magic.</p><p>You still need:</p><ul><li><p>Remote state</p></li><li><p>State locking</p></li><li><p>Modules</p></li><li><p>Code reviews</p></li><li><p>Environment separation</p></li><li><p>Secrets management</p></li><li><p>Drift detection</p></li><li><p>Proper lifecycle management</p></li></ul><p>Otherwise you&#8217;ve simply moved your infrastructure mistakes from the AWS Console into Git.</p><p>Which, admittedly, is progress.</p><div><hr></div><h1>&#128260; GitOps: Because Humans Shouldn&#8217;t Touch Production</h1><p>GitOps follows a simple idea:</p><pre><code><code>Git
 &#8595;
Desired State
 &#8595;
Controller
 &#8595;
Production</code></code></pre><p>Instead of:</p><pre><code><code>kubectl edit deployment</code></code></pre><p>at 2 AM while production is on fire, you change the configuration in Git.</p><p>Then the GitOps controller reconciles the environment.</p><p>Tools such as Argo CD make this approach practical for Kubernetes.</p><p>The real advantage isn&#8217;t just automation.</p><p>It&#8217;s <strong>auditability</strong>.</p><p>You can answer:</p><ul><li><p>Who changed it?</p></li><li><p>What changed?</p></li><li><p>When?</p></li><li><p>Why?</p></li><li><p>Which commit introduced it?</p></li></ul><p>Compare that with:</p><blockquote><p>&#8220;I think someone changed something in the cluster.&#8221;</p></blockquote><p>That sentence should make every production engineer slightly nervous.</p><p>GitOps doesn&#8217;t remove humans.</p><p>It removes unnecessary <strong>human interaction with production</strong>.</p><p>That&#8217;s a much healthier relationship.</p><div><hr></div><h1>&#127760; DNS: It&#8217;s Always DNS. Except When It Isn&#8217;t.</h1><p>Every DevOps incident has approximately this conversation:</p><blockquote><p>&#8220;Application looks healthy.&#8221;</p><p>&#8220;Load balancer looks healthy.&#8221;</p><p>&#8220;Security groups are fine.&#8221;</p><p>&#8220;Pods are running.&#8221;</p></blockquote><p>Pause.</p><p>Someone says:</p><blockquote><p><strong>&#8220;Check DNS.&#8221;</strong></p></blockquote><p>Suddenly everyone nods.</p><p>DNS gets blamed for:</p><ul><li><p>Wrong records</p></li><li><p>TTL issues</p></li><li><p>Missing records</p></li><li><p>Incorrect routing policies</p></li><li><p>Health check problems</p></li><li><p>Private/public DNS confusion</p></li><li><p>DNS propagation misunderstandings</p></li></ul><p>But sometimes DNS isn&#8217;t the problem.</p><p>The application is broken.</p><p>The load balancer is broken.</p><p>The certificate is expired.</p><p>The security group is wrong.</p><p>Yet someone still says:</p><blockquote><p>&#8220;It&#8217;s probably DNS.&#8221;</p></blockquote><p>Because apparently DNS has become the DevOps equivalent of blaming the weather.</p><p>The lesson?</p><p><strong>Don&#8217;t troubleshoot based on reputation. Troubleshoot based on evidence.</strong></p><div><hr></div><h1>&#128202; Monitoring: Staring at Graphs Until the Problem Fixes Itself</h1><p>You install:</p><ul><li><p>Prometheus</p></li><li><p>Grafana</p></li><li><p>CloudWatch</p></li><li><p>ELK</p></li><li><p>Loki</p></li><li><p>Alertmanager</p></li></ul><p>Your dashboard looks magnificent.</p><p>Thirty-seven graphs.</p><p>Fourteen colors.</p><p>CPU.</p><p>Memory.</p><p>Latency.</p><p>Requests.</p><p>Errors.</p><p>Network traffic.</p><p>Pod restarts.</p><p>Then production breaks.</p><p>And you&#8217;re staring at the dashboard thinking:</p><blockquote><p>&#8220;One of these graphs knows something.&#8221;</p></blockquote><p>Monitoring isn&#8217;t about collecting every possible metric.</p><p>It&#8217;s about answering useful questions.</p><h3>Is the system healthy?</h3><p>Metrics.</p><h3>What happened?</h3><p>Logs.</p><h3>Where did the request fail?</h3><p>Traces.</p><p>That&#8217;s why modern observability usually combines:</p><pre><code><code>Metrics
   +
Logs
   +
Traces
   &#8595;
Observability</code></code></pre><p>The goal isn&#8217;t more dashboards.</p><p>The goal is <strong>faster diagnosis</strong>.</p><div><hr></div><h1>&#128184; Observability: Paying Money to Find Out Why We&#8217;re Losing Money</h1><p>This joke hurts because there&#8217;s some truth in it.</p><p>Cloud observability costs money.</p><p>Logs consume storage.</p><p>Metrics consume storage.</p><p>Traces generate enormous amounts of data.</p><p>And if you configure everything to:</p><pre><code><code>Collect everything
Forever
At maximum detail</code></code></pre><p>your observability bill may become its own production incident.</p><p>Good observability requires decisions.</p><p>For example:</p><ul><li><p>What should be retained?</p></li><li><p>What should be sampled?</p></li><li><p>Which logs are valuable?</p></li><li><p>Which metrics matter?</p></li><li><p>Which traces need high-cardinality data?</p></li><li><p>How long should data be retained?</p></li></ul><p>Observability should reduce <strong>MTTR</strong>, not simply increase your AWS bill.</p><div><hr></div><h1>SECTION 3: AWS, Databases, Ansible and the Beautiful Reality of Production &#9729;&#65039;&#128293;</h1><h2>&#9729;&#65039; AWS: Everything Is Scalable, Including the Bill</h2><p>AWS gives you almost unlimited flexibility.</p><p>Need more compute?</p><p>Scale.</p><p>Need more storage?</p><p>Scale.</p><p>Need another database?</p><p>Create one.</p><p>Need another region?</p><p>Create one.</p><p>Need another NAT Gateway?</p><p>Please continue.</p><p>And then the monthly bill arrives.</p><pre><code><code>Engineer:
&#8220;We made the system highly available.&#8221;

Finance:
&#8220;How highly available?&#8221;

Engineer:
&#8220;Very.&#8221;

Finance:
&#8220;Apparently.&#8221;</code></code></pre><p>AWS architecture isn&#8217;t just about scalability.</p><p>It&#8217;s about <strong>cost-aware scalability</strong>.</p><p>You need to think about:</p><ul><li><p>Instance sizing</p></li><li><p>Auto Scaling</p></li><li><p>Reserved capacity</p></li><li><p>Spot instances</p></li><li><p>NAT Gateway costs</p></li><li><p>Data transfer</p></li><li><p>Storage</p></li><li><p>Database sizing</p></li><li><p>Idle resources</p></li><li><p>EKS costs</p></li></ul><p>A system that can handle 10x traffic but costs 20x more when traffic is normal isn&#8217;t necessarily a great architecture.</p><div><hr></div><h1>&#128452;&#65039; Production Database: The World&#8217;s Most Expensive Test Environment</h1><p>Everyone is brave in development.</p><pre><code><code>DROP TABLE</code></code></pre><p>No problem.</p><p>Production?</p><p>Suddenly everyone becomes extremely philosophical.</p><blockquote><p>&#8220;Let&#8217;s first understand the impact.&#8221;</p></blockquote><p>Correct.</p><p>Production databases deserve respect because they contain something more valuable than infrastructure:</p><p><strong>customer data.</strong></p><p>Good production database practices include:</p><ul><li><p>Automated backups</p></li><li><p>Point-in-time recovery</p></li><li><p>Multi-AZ where appropriate</p></li><li><p>Read replicas where needed</p></li><li><p>Encryption</p></li><li><p>Access controls</p></li><li><p>Monitoring</p></li><li><p>Query optimization</p></li><li><p>Disaster recovery testing</p></li></ul><p>And perhaps the most important rule:</p><blockquote><p><strong>Never test your theory directly on production data.</strong></p></blockquote><p>Production is not where you discover whether your SQL query works.</p><p>That&#8217;s what staging is for.</p><div><hr></div><h1>&#129302; Ansible: Turning 3 Hours of Work Into 6 Hours of YAML</h1><p>Ansible is actually extremely useful.</p><p>You can automate:</p><ul><li><p>Package installation</p></li><li><p>Configuration</p></li><li><p>User management</p></li><li><p>Service deployment</p></li><li><p>Server hardening</p></li><li><p>Application configuration</p></li></ul><p>Instead of manually configuring 100 servers:</p><pre><code><code>Server 1
Server 2
Server 3
...
Server 100</code></code></pre><p>you write automation once.</p><p>Then:</p><pre><code><code>Playbook
   &#8595;
100 Servers</code></code></pre><p>The joke comes when someone writes a 900-line playbook to perform something that could have been handled by a small script.</p><p>Automation isn&#8217;t automatically good simply because it&#8217;s automation.</p><p>The goal is:</p><blockquote><p><strong>Reduce repetitive human work while improving consistency.</strong></p></blockquote><p>If your automation is harder to understand than the manual process, congratulations.</p><p>You&#8217;ve automated the confusion.</p><div><hr></div><h1>&#129504; The Common Thread Behind All These Tools</h1><p>Look at the technologies again:</p><pre><code><code>Linux
Docker
Kubernetes
Terraform
GitOps
DNS
Monitoring
Observability
AWS
Database
Ansible</code></code></pre><p>They look completely different.</p><p>But they&#8217;re all solving variations of the same problem:</p><blockquote><p><strong>How do we run reliable systems without depending on humans doing everything manually?</strong></p></blockquote><p>Linux gives us the foundation.</p><p>Docker gives us packaging.</p><p>Kubernetes gives us orchestration.</p><p>Terraform gives us infrastructure as code.</p><p>GitOps gives us controlled delivery.</p><p>AWS gives us infrastructure at scale.</p><p>Monitoring tells us something is wrong.</p><p>Observability helps us understand why.</p><p>Ansible automates configuration.</p><p>And humans...</p><p>Humans create the architecture.</p><p>Then occasionally break it.</p><p>Then automate the fix.</p><p>Then automate the automation.</p><p>Then create a dashboard to monitor the automation.</p><p>This is DevOps. &#128514;</p><div><hr></div><h1>&#128680; The Real DevOps Lesson</h1><p>The jokes are funny because they contain pieces of reality.</p><p>But there&#8217;s a serious lesson underneath them.</p><p>Being a DevOps engineer isn&#8217;t about knowing 50 tools.</p><p>It&#8217;s about making good decisions when those tools interact.</p><p>When production breaks, nobody cares that you memorized the Kubernetes definition.</p><p>They care whether you can answer:</p><pre><code><code>What happened?
     &#8595;
What is impacted?
     &#8595;
What changed?
     &#8595;
What evidence do we have?
     &#8595;
How do we mitigate it?
     &#8595;
What caused it?
     &#8595;
How do we prevent it?</code></code></pre><p>That&#8217;s engineering.</p><p>Not memorizing commands.</p><p>Not collecting certifications.</p><p>Not adding another tool to your resume because someone on LinkedIn said it&#8217;s &#8220;the future.&#8221;</p><p><strong>Solving real production problems is the actual skill.</strong> &#128640;</p><div><hr></div><h1>&#127919; Final Takeaways</h1><h3>&#128039; Linux</h3><p>Don&#8217;t use <code>chmod 777</code> because you&#8217;re too tired to understand permissions.</p><h3>&#128051; Docker</h3><p>If it works on your machine, make sure your machine isn&#8217;t the only environment where it works.</p><h3>&#9784;&#65039; Kubernetes</h3><p>Complexity is often the price of operating distributed systems at scale.</p><h3>&#127959;&#65039; Terraform</h3><p>Infrastructure should be reproducible, reviewable and controlled.</p><h3>&#128260; GitOps</h3><p>Production changes should be intentional, traceable and reversible.</p><h3>&#127760; DNS</h3><p>Check DNS, but don&#8217;t blame DNS without evidence.</p><h3>&#128202; Observability</h3><p>More data isn&#8217;t automatically better observability.</p><h3>&#9729;&#65039; AWS</h3><p>Scalability without cost awareness is just an expensive achievement.</p><h3>&#128452;&#65039; Database</h3><p>Production data deserves more respect than your development database.</p><h3>&#129302; Ansible</h3><p>Automation should reduce complexity, not create a YAML-based civilization.</p><div><hr></div><h1>&#128640; Final Thought</h1><p>DevOps has a funny way of teaching humility.</p><p>You start by saying:</p><blockquote><p><strong>&#8220;I&#8217;m going to automate everything.&#8221;</strong></p></blockquote><p>Then production teaches you:</p><blockquote><p><strong>&#8220;First understand everything.&#8221;</strong></p></blockquote><p>And eventually you realize the real objective isn&#8217;t to eliminate humans from engineering.</p><p>It&#8217;s to eliminate <strong>unnecessary manual work, prevent avoidable mistakes, recover quickly when things fail, and build systems that can survive reality.</strong></p><p>Because infrastructure doesn&#8217;t care about your architecture diagram.</p><p>Production doesn&#8217;t care about your certification.</p><p>And AWS certainly doesn&#8217;t care about your budget.</p><p><strong>The system either works or it doesn&#8217;t.</strong></p><p>Our job is to make sure it works more often than it doesn&#8217;t. &#128516;&#128640;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#DevOps #DevOpsEngineer #Linux #Docker #Kubernetes #Terraform #GitOps #AWS #CloudComputing #Ansible #Observability #Monitoring #SRE #PlatformEngineering #DevSecOps #CloudEngineering #InfrastructureAsCode #CICD #ProductionEngineering #TechHumor</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, and Software Engineering content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item><item><title><![CDATA[🚀 12 DevOps Scenario-Based Interview Questions That Test How You Think in Production]]></title><description><![CDATA[Most DevOps interviews don&#8217;t become difficult when the interviewer asks:]]></description><link>https://arvindverma021.substack.com/p/12-devops-scenario-based-interview</link><guid isPermaLink="false">https://arvindverma021.substack.com/p/12-devops-scenario-based-interview</guid><dc:creator><![CDATA[Arvind Verma]]></dc:creator><pubDate>Fri, 28 Aug 2026 05:42:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0bl9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0bl9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_webp, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0bl9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2067755,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://arvindverma021.substack.com/i/213101636?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_424, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_848, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_1272, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0bl9!, /__u/arvindverma021.substack.com/w_1456, /__u/arvindverma021.substack.com/c_limit, /__u/arvindverma021.substack.com/f_auto, /__u/arvindverma021.substack.com/q_auto:good, /__u/arvindverma021.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d38042b-1556-4f7e-ac1f-17f710ac2623_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most DevOps interviews don&#8217;t become difficult when the interviewer asks:</p><blockquote><p><strong>&#8220;What is Kubernetes?&#8221;</strong></p></blockquote><p>They become difficult when the interviewer says:</p><blockquote><p><strong>&#8220;Your Kubernetes pods are running, but users are getting 503. What do you do?&#8221;</strong></p></blockquote><p>Now there is no definition to memorize.</p><p>You have to <strong>think</strong>.</p><p>You have to decide what to check first, what not to touch, how to minimize impact, and how to explain your reasoning.</p><p>That is exactly what modern DevOps interviews are increasingly testing.</p><p>I recently came across a set of <strong>12 scenario-based DevOps questions</strong> covering CI/CD, Kubernetes, Terraform, AWS, monitoring, security, databases, networking, cost optimization, scaling, and system design.</p><p>What makes these questions interesting is that they aren&#8217;t really testing whether you remember commands.</p><p>They&#8217;re testing whether you can behave like a <strong>production engineer</strong>.</p><p>So let&#8217;s break them down the way you should approach them in an interview. &#127919;</p><div><hr></div><h1>SECTION 1: The First 4 Scenarios Every DevOps Engineer Should Be Ready For &#129489;&#8205;&#128187;</h1><h2>1&#65039;&#8419; CI/CD Pipeline Failure</h2><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Your CI/CD pipeline failed during deployment. What would you do?&#8221;</strong></p></blockquote><p>A weak answer:</p><blockquote><p>&#8220;I will check Jenkins.&#8221;</p></blockquote><p>That&#8217;s not enough.</p><p>A better approach is to explain your troubleshooting sequence.</p><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;First, I check the failed stage and logs. Then I verify whether it&#8217;s a code, build, dependency, security scan, or deployment issue. If production is impacted, I stop further deployment and roll back if required.&#8221;</strong></p></blockquote><p>That&#8217;s enough for the first answer.</p><p>If the interviewer asks for more:</p><pre><code><code>Pipeline Failed
      &#8595;
Check Failed Stage
      &#8595;
Read Logs
      &#8595;
Identify Root Cause
      &#8595;
Fix / Rollback
      &#8595;
Re-run Safely</code></code></pre><h3>Real production scenario</h3><p>Imagine a deployment pipeline contains:</p><pre><code><code>Git
 &#8595;
Build
 &#8595;
Unit Tests
 &#8595;
SonarQube
 &#8595;
Docker Build
 &#8595;
Trivy Scan
 &#8595;
Push Image
 &#8595;
Deploy to Kubernetes</code></code></pre><p>The pipeline fails at Trivy.</p><p>You shouldn&#8217;t immediately start debugging Kubernetes.</p><p>The application hasn&#8217;t even reached Kubernetes.</p><p>This is one of the simplest but most important DevOps habits:</p><blockquote><p><strong>Troubleshoot from the point of failure, not from the technology you happen to know best.</strong></p></blockquote><div><hr></div><h1>2&#65039;&#8419; Kubernetes Pod Failure</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Pods are continuously going into CrashLoopBackOff. How do you troubleshoot?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I check the pod logs and describe output first. Then I check events, configuration, secrets, probes and resource limits. Based on the error, I fix the root cause and restart the workload.&#8221;</strong></p></blockquote><p>Useful commands include:</p><pre><code><code>kubectl get pods
kubectl describe pod &lt;pod&gt;
kubectl logs &lt;pod&gt;
kubectl logs &lt;pod&gt; --previous
kubectl get events</code></code></pre><p>The particularly useful command is:</p><pre><code><code>kubectl logs &lt;pod&gt; --previous</code></code></pre><p>because the container may have already crashed.</p><h3>Real production example</h3><p>Suppose:</p><pre><code><code>Pod
 &#8595;
Application starts
 &#8595;
Database connection fails
 &#8595;
Container exits
 &#8595;
Kubernetes restarts it
 &#8595;
Container exits again</code></code></pre><p>Eventually:</p><pre><code><code>CrashLoopBackOff</code></code></pre><p>The problem isn&#8217;t Kubernetes.</p><p>Kubernetes is doing exactly what you asked it to do.</p><p>The application is repeatedly crashing.</p><p>That&#8217;s why understanding the <strong>difference between symptom and root cause</strong> matters.</p><div><hr></div><h1>3&#65039;&#8419; Terraform Apply Failed Halfway</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Terraform apply failed after creating some infrastructure. What will you do?&#8221;</strong></p></blockquote><p>This is a classic production question.</p><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I wouldn&#8217;t immediately destroy everything. First I would check the Terraform state and determine which resources were successfully created. Then I would identify the failed resource, fix the underlying issue and run plan again before applying.&#8221;</strong></p></blockquote><p>The important principle:</p><blockquote><p><strong>Don&#8217;t panic. Don&#8217;t blindly destroy.</strong></p></blockquote><p>Check:</p><pre><code><code>terraform state list
terraform plan</code></code></pre><p>Then investigate the failed resource.</p><p>For example:</p><pre><code><code>VPC              &#9989;
Subnets           &#9989;
Security Groups   &#9989;
EKS               &#10060;</code></code></pre><p>You don&#8217;t want to recreate the VPC simply because EKS failed.</p><p>Terraform&#8217;s state helps it understand what already exists under management.</p><h3>Real production scenario</h3><p>A common failure could be:</p><pre><code><code>Terraform
   &#8595;
Creates VPC
   &#8595;
Creates subnets
   &#8595;
Creates IAM
   &#8595;
EKS creation fails</code></code></pre><p>After fixing the EKS issue:</p><pre><code><code>terraform plan</code></code></pre><p>should show what Terraform still needs to create or modify.</p><p>The goal is <strong>safe recovery</strong>, not starting from zero.</p><div><hr></div><h1>4&#65039;&#8419; Monitoring and Incident Handling</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;You receive a production alert. What do you do?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;First I confirm the impact and severity. Then I check metrics, logs and recent deployments or infrastructure changes. I identify the affected component, mitigate the issue if possible, and then investigate the root cause.&#8221;</strong></p></blockquote><p>A simple flow:</p><pre><code><code>Alert
 &#8595;
Confirm Impact
 &#8595;
Check Metrics
 &#8595;
Check Logs
 &#8595;
Check Recent Changes
 &#8595;
Identify Root Cause
 &#8595;
Mitigate
 &#8595;
Monitor Recovery
 &#8595;
Prevent Recurrence</code></code></pre><h3>Real production example</h3><p>Suppose:</p><pre><code><code>CPU = 95%</code></code></pre><p>Don&#8217;t immediately restart everything.</p><p>Ask:</p><ul><li><p>Which service?</p></li><li><p>Which pod?</p></li><li><p>Which node?</p></li><li><p>Did traffic increase?</p></li><li><p>Was there a deployment?</p></li><li><p>Is one endpoint consuming excessive CPU?</p></li><li><p>Are requests stuck?</p></li><li><p>Is autoscaling working?</p></li></ul><p>This is the difference between:</p><p><strong>&#8220;I know Prometheus.&#8221;</strong></p><p>and</p><p><strong>&#8220;I know how to investigate production.&#8221;</strong></p><div><hr></div><h1>SECTION 2: AWS, Security, Database and Networking Scenarios &#9729;&#65039;&#128272;</h1><h2>5&#65039;&#8419; DevSecOps Security Failure</h2><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Your security scan finds a critical vulnerability in the container image. What do you do?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I check the vulnerability and affected package first. If it&#8217;s critical and exploitable, I block the deployment, upgrade or replace the vulnerable dependency, rebuild the image and scan it again.&#8221;</strong></p></blockquote><p>Typical flow:</p><pre><code><code>Docker Build
     &#8595;
Trivy Scan
     &#8595;
Vulnerability Found
     &#8595;
Block Deployment
     &#8595;
Fix Dependency
     &#8595;
Rebuild
     &#8595;
Scan Again
     &#8595;
Deploy</code></code></pre><p>This is where tools such as <strong>Trivy, SonarQube and dependency scanners</strong> become part of CI/CD rather than separate security activities.</p><p>The important point is not knowing the scanner command.</p><p>It&#8217;s understanding:</p><blockquote><p><strong>Where should security checks happen in the delivery lifecycle?</strong></p></blockquote><div><hr></div><h1>6&#65039;&#8419; AWS Region Failure</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Your primary AWS region goes down. What happens?&#8221;</strong></p></blockquote><p>This isn&#8217;t simply an AWS question.</p><p>It&#8217;s a <strong>disaster recovery architecture</strong> question.</p><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I would route traffic to the secondary region using health checks and failover mechanisms. The exact approach depends on the RTO, RPO and whether the application is active-active or active-passive.&#8221;</strong></p></blockquote><p>For example:</p><pre><code><code>                Route 53
                    |
          &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
          &#8595;                   &#8595;
      Region A             Region B
      Primary              Standby
          &#8595;                   &#8595;
       EKS/ECS              EKS/ECS
          &#8595;                   &#8595;
       Database            Database</code></code></pre><p>Possible AWS components include:</p><ul><li><p>Route 53</p></li><li><p>CloudFront</p></li><li><p>S3</p></li><li><p>RDS</p></li><li><p>EKS</p></li><li><p>Auto Scaling</p></li><li><p>Cross-region replication</p></li></ul><p>But don&#8217;t start throwing AWS services at the interviewer like you&#8217;re filling a shopping cart.</p><p>First establish:</p><p><strong>What is the business requirement?</strong></p><p>Then design for it.</p><div><hr></div><h1>7&#65039;&#8419; Database Performance Problem</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;The application is slow because database queries are taking too long. What do you check?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I check database CPU, connections, slow queries, locks and indexes. Then I identify the expensive queries and optimize them. If read traffic is high, I also consider read replicas.&#8221;</strong></p></blockquote><p>Typical investigation:</p><pre><code><code>Application
    &#8595;
High Latency
    &#8595;
Database Metrics
    &#8595;
Slow Queries
    &#8595;
Execution Plan
    &#8595;
Indexes / Query Optimization
    &#8595;
Retest</code></code></pre><p>You shouldn&#8217;t immediately increase the database instance size.</p><p>Sometimes the problem is:</p><pre><code><code>SELECT *
FROM orders;</code></code></pre><p>being executed millions of times.</p><p>Adding bigger hardware doesn&#8217;t magically turn bad queries into good queries.</p><div><hr></div><h1>8&#65039;&#8419; Kubernetes Networking Failure</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Two services cannot communicate inside Kubernetes. What would you check?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I check the Service selector, endpoints, DNS resolution, network policies and connectivity between the pods.&#8221;</strong></p></blockquote><p>A useful flow:</p><pre><code><code>Pod A
 &#8595;
Service
 &#8595;
Selector
 &#8595;
Endpoints
 &#8595;
Pod B</code></code></pre><p>Check:</p><pre><code><code>kubectl get svc
kubectl get endpoints
kubectl describe svc &lt;service&gt;
kubectl get networkpolicy</code></code></pre><p>A very common issue is a selector mismatch.</p><p>For example:</p><pre><code><code>selector:
  app: backend</code></code></pre><p>but the pods have:</p><pre><code><code>labels:
  app: api</code></code></pre><p>The Service exists.</p><p>The Pods exist.</p><p>Everything looks healthy.</p><p>But the Service has <strong>no endpoints</strong>.</p><p>And then everyone blames Kubernetes for the crime.</p><div><hr></div><h1>SECTION 3: Scaling, Cost, Containers and System Design &#128640;</h1><h2>9&#65039;&#8419; Cloud Cost Optimization</h2><h3>Interviewer:</h3><blockquote><p><strong>&#8220;How would you reduce unnecessary AWS costs?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I first identify the major cost contributors using Cost Explorer. Then I look for idle resources, oversized instances, unattached volumes and unnecessary environments. After that I right-size resources and automate cleanup where possible.&#8221;</strong></p></blockquote><p>A practical approach:</p><pre><code><code>AWS Cost Explorer
       &#8595;
Find Expensive Services
       &#8595;
Analyze Utilization
       &#8595;
Identify Waste
       &#8595;
Right-size
       &#8595;
Automate Cleanup
       &#8595;
Monitor Cost</code></code></pre><p>Typical areas:</p><ul><li><p>EC2</p></li><li><p>EBS</p></li><li><p>NAT Gateway</p></li><li><p>RDS</p></li><li><p>EKS</p></li><li><p>Data transfer</p></li><li><p>Load Balancers</p></li><li><p>Unused Elastic IPs</p></li></ul><p>Cost optimization isn&#8217;t:</p><blockquote><p>&#8220;Use cheaper instances.&#8221;</p></blockquote><p>It&#8217;s:</p><blockquote><p><strong>&#8220;Understand what you&#8217;re paying for and whether the workload actually needs it.&#8221;</strong></p></blockquote><div><hr></div><h1>&#128287; Sudden Traffic Spike</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Traffic suddenly increases 10x. How will your application handle it?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I would use load balancing and autoscaling. For Kubernetes, I would configure HPA and ensure the cluster has enough node capacity. I would also check database and downstream service limits because scaling only the application layer may not solve the bottleneck.&#8221;</strong></p></blockquote><p>That&#8217;s an important senior-level point.</p><p>Imagine:</p><pre><code><code>Traffic
  &#8595;
Load Balancer
  &#8595;
Kubernetes
  &#8595;
100 Pods
  &#8595;
Database</code></code></pre><p>You scale from:</p><pre><code><code>10 Pods &#8594; 100 Pods</code></code></pre><p>But your database can only handle 20 concurrent connections.</p><p>Congratulations.</p><p>You&#8217;ve successfully created a much faster way to overload your database. &#128514;</p><p>Real scalability means considering the <strong>entire system</strong>.</p><div><hr></div><h1>1&#65039;&#8419;1&#65039;&#8419; Container Orchestration Issue</h1><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Your Kubernetes workloads are not scaling properly. What do you check?&#8221;</strong></p></blockquote><h3>Candidate-style answer:</h3><blockquote><p><strong>&#8220;I check HPA metrics, resource requests and limits, pod scheduling and node capacity. If pods can&#8217;t be scheduled, I check node availability, taints, affinity and resource constraints.&#8221;</strong></p></blockquote><p>This is important because:</p><pre><code><code>HPA says:
Create 20 Pods</code></code></pre><p>doesn&#8217;t mean Kubernetes magically has somewhere to put them.</p><p>You could have:</p><pre><code><code>HPA
 &#8595;
20 replicas requested
 &#8595;
Nodes don't have capacity
 &#8595;
Pods Pending</code></code></pre><p>Then you need to investigate cluster capacity and potentially use <strong>Cluster Autoscaler or Karpenter</strong>, depending on the architecture.</p><div><hr></div><h1>1&#65039;&#8419;2&#65039;&#8419; Real-World System Design</h1><p>The final scenario is often the most interesting.</p><h3>Interviewer:</h3><blockquote><p><strong>&#8220;Design a scalable, secure and highly available application.&#8221;</strong></p></blockquote><p>This isn&#8217;t a question with one correct architecture.</p><p>You need to think in layers.</p><p>A possible architecture:</p><pre><code><code>                    Users
                      &#8595;
                  Route 53
                      &#8595;
                 CloudFront
                      &#8595;
                    WAF
                      &#8595;
                     ALB
                      &#8595;
                    EKS
              &#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
              &#8595;               &#8595;
           Service         Service
              &#8595;               &#8595;
             Pods            Pods
              &#9474;               &#9474;
              &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;
                      &#8595;
                    RDS
                      &#9474;
                      &#8595;
                     S3</code></code></pre><p>Then add:</p><pre><code><code>Monitoring
Prometheus
Grafana
CloudWatch
Logging
Alerting</code></code></pre><p>Security:</p><pre><code><code>IAM
Secrets Manager
KMS
Network Policies
Private Subnets
Security Groups
WAF</code></code></pre><p>Availability:</p><pre><code><code>Multi-AZ
Auto Scaling
Health Checks
Backups
Disaster Recovery</code></code></pre><p>The interviewer isn&#8217;t expecting you to list 40 AWS services.</p><p>They want to see whether you understand:</p><p><strong>traffic &#8594; application &#8594; infrastructure &#8594; database &#8594; security &#8594; observability &#8594; recovery.</strong></p><div><hr></div><h1>&#129504; The Golden Flow for Almost Any Production Incident</h1><p>One of the most useful things you can remember for scenario-based interviews is this:</p><pre><code><code>1. Detect
      &#8595;
2. Understand Impact
      &#8595;
3. Check Recent Changes
      &#8595;
4. Gather Evidence
      &#8595;
5. Identify Bottleneck
      &#8595;
6. Mitigate
      &#8595;
7. Find Root Cause
      &#8595;
8. Fix Permanently
      &#8595;
9. Monitor
      &#8595;
10. Prevent Recurrence</code></code></pre><p>This works for:</p><ul><li><p>Kubernetes failures</p></li><li><p>AWS incidents</p></li><li><p>CI/CD problems</p></li><li><p>Database issues</p></li><li><p>Networking problems</p></li><li><p>Infrastructure failures</p></li><li><p>Performance incidents</p></li></ul><p>You don&#8217;t need to memorize 100 troubleshooting flows.</p><p>You need to understand the <strong>engineering mindset behind them</strong>.</p><div><hr></div><h1>&#127919; What Interviewers Are Actually Testing</h1><p>These questions appear to be about:</p><p><strong>Terraform.</strong></p><p><strong>Kubernetes.</strong></p><p><strong>AWS.</strong></p><p><strong>CI/CD.</strong></p><p><strong>Monitoring.</strong></p><p>But underneath, they&#8217;re testing something else.</p><h3>Can you troubleshoot?</h3><p>Can you move from:</p><pre><code><code>Symptom &#8594; Evidence &#8594; Root Cause</code></code></pre><h3>Can you prioritize?</h3><p>Do you know what to check first?</p><h3>Can you make safe decisions?</h3><p>Will you run:</p><pre><code><code>terraform destroy</code></code></pre><p>because something failed?</p><p>Hopefully not.</p><h3>Can you communicate?</h3><p>Can you explain your reasoning without turning a two-minute answer into a 25-minute Kubernetes documentary?</p><h3>Can you think about production impact?</h3><p>A technically correct fix can still be a terrible production decision.</p><div><hr></div><h1>&#128640; The DevOps Engineer Mindset</h1><p>The strongest candidates don&#8217;t answer scenario questions by listing tools.</p><p>They think in terms of:</p><pre><code><code>Customer Impact
      &#8595;
Service Health
      &#8595;
Infrastructure
      &#8595;
Dependencies
      &#8595;
Root Cause
      &#8595;
Recovery
      &#8595;
Prevention</code></code></pre><p>That&#8217;s what separates:</p><blockquote><p><strong>&#8220;I have worked with Kubernetes.&#8221;</strong></p></blockquote><p>from:</p><blockquote><p><strong>&#8220;I have operated applications on Kubernetes.&#8221;</strong></p></blockquote><p>The first describes tool exposure.</p><p>The second describes <strong>production experience</strong>.</p><p>And that&#8217;s exactly what interviewers are trying to discover.</p><div><hr></div><h1>&#128161; Final Takeaways</h1><p>If you&#8217;re preparing for DevOps interviews, don&#8217;t spend all your time memorizing:</p><blockquote><p>&#8220;What is Kubernetes?&#8221;</p></blockquote><p>Prepare for:</p><blockquote><p><strong>&#8220;Kubernetes is running, but the application is unavailable. What do you do?&#8221;</strong></p></blockquote><p>Don&#8217;t just learn:</p><blockquote><p>&#8220;What is Terraform state?&#8221;</p></blockquote><p>Prepare for:</p><blockquote><p><strong>&#8220;Terraform failed after creating half the infrastructure. How do you recover?&#8221;</strong></p></blockquote><p>Don&#8217;t just learn:</p><blockquote><p>&#8220;What is HPA?&#8221;</p></blockquote><p>Prepare for:</p><blockquote><p><strong>&#8220;Traffic increased 10x and your pods aren&#8217;t scaling. What do you check?&#8221;</strong></p></blockquote><p>Don&#8217;t just learn:</p><blockquote><p>&#8220;What is monitoring?&#8221;</p></blockquote><p>Prepare for:</p><blockquote><p><strong>&#8220;Users are reporting latency, but there are no application errors. How do you investigate?&#8221;</strong></p></blockquote><p>That&#8217;s where DevOps interviews become interesting.</p><p>And honestly, that&#8217;s where the job becomes interesting too. &#128640;</p><p><strong>Tools can be learned.</strong></p><p><strong>Commands can be memorized.</strong></p><p>But the ability to calmly investigate a production problem, make a safe decision, communicate clearly, and prevent the same incident from happening again...</p><p><strong>That&#8217;s what makes you valuable as a DevOps Engineer.</strong> &#127919;</p><div><hr></div><h2>&#128278;Hashtags</h2><p>#DevOps #DevOpsInterview #DevOpsEngineer #Kubernetes #AWS #Terraform #CICD #Docker #EKS #CloudComputing #DevSecOps #SRE #PlatformEngineering #Linux #Prometheus #Grafana #GitLab #ProductionEngineering #CloudEngineer #InterviewPreparation</p><h2>&#128075; Follow Me</h2><p>If you enjoyed this article and would like more practical <strong>DevOps, Cloud, Kubernetes, AWS, Terraform, CI/CD, Software Engineering, and career content</strong>, feel free to connect with me on LinkedIn:</p><p><strong>LinkedIn:</strong><br><a href="https://www.linkedin.com/in/arvindverma021/">https://www.linkedin.com/in/arvindverma021/</a></p>]]></content:encoded></item></channel></rss>