Zero Trust - The VPN Is Not the Castle Wall

Security still shows up in architecture reviews as a network diagram with a thick line around “us” and a thinner one around “them.” VPN on, you are inside. Inside, the payment API will talk to the reporting API because they share a subnet and a long-lived service account someone checked in years ago.

That model has been fraying for a while — cloud, contractors, WFH laptops that never see the office again — and the slide decks all say “zero trust” now. I have been trying to translate the buzzword into things a .NET team can actually change without waiting for a five-year platform programme.

Read More

Error Budgets - Permission to Ship, Permission to Stop

We spent the first half of the year getting better at how code lands in prod — pipelines, GitOps, flags so deploy and release are not the same button. The question that keeps coming up in incident reviews is different: when are we allowed to keep shipping, and when should we put the brakes on?

Uptime dashboards full of green do not answer that. Neither does “we should be more careful.” What finally helped our team was treating reliability like a budget you can spend, not a vibe you argue about after every outage.

Read More

Feature Flags - Deploy Dark, Release When Ready

We got better at shipping code this year. Pipelines build, tests run, images land in the registry, and — if you bought into the GitOps story — the cluster eventually matches Git. That is deploy. What still bites us is treating deploy and release as the same button.

I spent the last couple of sprints putting Microsoft.FeatureManagement in front of a few half-finished ASP.NET Core endpoints. Not because flags are fashionable. Because product wanted a quiet soak with internal users, and ops wanted a kill switch that did not involve a Friday rollback train.

Read More

GitOps - Stop kubectl-apply-ing Your Way to Prod

Our deploy pipeline used to end with a job that ran kubectl apply -f against a folder of rendered YAML. It worked. Until it didn’t. Someone would fix a ConfigMap by hand at 11pm, forget to commit it, and three days later the next pipeline run would “helpfully” overwrite the fix. Or the opposite: Git said one thing, the cluster said another, and nobody could tell which was deliberate.

I have been watching the GitOps wave for a while — Flux from Weaveworks, Argo CD from the Intuit folks, now both under the CNCF umbrella. This week Argo CD shipped 2.0. That felt like a good moment to write down what actually changed in how I think about deploys.

Read More

After SolarWinds - Who Builds Your Binaries?

For most of my career, “supply chain” meant the warehouse people fretted about. Then SolarWinds happened. A signed Orion update carried a backdoor. Thousands of customers installed it because the signature looked fine and the vendor looked trusted. Suddenly the question was not only “is our code secure?” but “is the machine that builds our code secure?”

I spent a weekend walking our .NET services with that question in mind. Spoiler: we had strong opinions about TLS and JWT, and almost no opinions about NuGet restore on the build agent.

Read More

Correlation IDs - Following One Request Through the Noise

Last Tuesday I got a Slack ping at 9:40pm: “payments are slow, can you look?” I opened Kibana, typed status:500, and watched a waterfall of red. Five services. Three pods each. Everyone logging something useful. Nobody logging the same something. Twenty minutes later I still could not answer the only question that mattered — which user action started this mess?

That is the night I stopped treating correlation IDs as a nice-to-have and started treating them like a seatbelt.

Read More