Blog
Notes on data, cloud, DevOps, AI, security, and automation.
-
AWS vs. GCP vs. Azure: Org Hierarchy, Identity, and Key Management, Mapped
The same three problems — organize accounts, control identity and permissions, manage encryption keys — solved three ways. A side-by-side Rosetta stone of Organizations/OUs/SCPs, folders/projects/IAM bindings, and management groups/RBAC, plus KMS vs Cloud KMS vs Key Vault — and where the mental model breaks.
-
Apple's AI Pivot: Gemini-Powered Siri, Private Cloud Compute, and What's Next
Apple's 2026 AI strategy — a multi-billion-dollar Gemini deal powering a rebuilt Siri, on-device models behind Private Cloud Compute, a multi-model iOS 27, and an AI hardware roadmap. What's confirmed and what's next.
-
Claude Fable 5: Anthropic Ships a Mythos-Class Model to Everyone
Anthropic released Claude Fable 5 — the first publicly available Mythos-class model, made safe for general use with classifier safeguards that fall back to Opus 4.8. What it is, days-long agentic work, SOTA coding/vision/science, how the safeguards work, pricing, and how it relates to Mythos 5.
-
Google Gemini Spark: The 24/7 Personal AI Agent — What It Is and How to Use It
Gemini Spark is Google's always-on personal AI agent from I/O 2026 — it runs 24/7 on Google Cloud and takes proactive action across Gmail, Workspace, and the web. What it is, why it's needed, and how to use it via Tasks, Schedules, and Skills.
-
Spec-Driven Agents on AWS: Building with Kiro, MCP, and Bedrock AgentCore
A practical, end-to-end workflow for building production AI agents on AWS: write the spec in Kiro (requirements → design → tasks), expose tools over MCP, and deploy and operate on Bedrock AgentCore — and why this combination turns weeks of plumbing into days.
-
The AWS AI Agent Stack: Strands vs. Bedrock Agents vs. AgentCore
AWS ships three things with "agent" in the name — Strands Agents, Bedrock Agents, and Bedrock AgentCore — and they're constantly confused. What each one actually is, how they relate, and a clear decision guide for when to use which.
-
Anthropic's Claude Mythos: The AI That Finds Zero-Days at Scale
Anthropic's Claude Mythos Preview autonomously found 23,000+ potential vulnerabilities across 1,000 open-source projects — including decades-old flaws in OpenBSD, FFmpeg, and FreeBSD. What it is, what it can do, how to get access via Project Glasswing, and why it matters for defenders.
-
Grok Build 0.1: xAI's Fast, Cheap Coding Model vs. Claude and Gemini
xAI's grok-build-0.1 is a coding model built for agentic software work — 100+ tokens/sec at $1/$2 per million. What it does, how it compares to Claude and Gemini coding models, and whether the Grok Build CLI competes with Claude Code and Google's Antigravity CLI.
-
Workflows vs. Agents vs. Subagents: Choosing the Right Tool in Agentic Coding
"Agent," "subagent," and "workflow" get used interchangeably — but they solve different problems. What each one is, when to reach for it, how to combine them, and the token and control trade-offs nobody mentions up front.
-
AWS DevOps Agent: What It Is, When to Use It, and How
AWS's new frontier agent acts like an always-on SRE — it investigates incidents the moment they fire, correlates telemetry with code and deploys to find root cause, and recommends fixes that stop recurrence. What it is, the scenarios it fits, and how it works.
-
Terraform vs. OpenTofu in 2026: Where the Fork Stands
Three years after the license change, the two have genuinely diverged. Licensing, current versions, the widening feature gap (state encryption, Stacks, ephemeral resources), migration, and how to choose.
-
The Modern Data Stack, Demystified (2026)
What the modern data stack actually is in 2026 — the layers and leading tools, ELT vs. ETL, the lakehouse and Apache Iceberg, the Fivetran + dbt Labs merger, DuckDB, and AI text-to-SQL.
-
Hosting a Static Site on S3 + CloudFront: Architecture and Economics
A practical guide to hosting a fast, secure, dirt-cheap static website on Amazon S3 and CloudFront — the reference architecture, caching and security headers, the real costs, and when not to.
-
Shipping Faster with Agentic AI Workflows
Agentic AI is moving from single chat turns to orchestrated multi-agent workflows. The patterns that work — fan-out, pipelines, adversarial verification — where they help, and the guardrails they need.
-
Least Privilege for AI Agents: A Practical Playbook
AI agents now hold credentials and run commands. A practical least-privilege playbook: scoped, short-lived credentials, read-only defaults, sandboxing, human gates, and audit.
-
AWS Well-Architected in Practice: The Six Pillars, Minus the Buzzwords
A jargon-free tour of the AWS Well-Architected Framework's six pillars — operational excellence, security, reliability, performance, cost, and sustainability — and how to actually run a review.
-
Claude Code vs. OpenAI Codex CLI: A 2026 Field Guide
A deep, balanced comparison of Anthropic's Claude Code and OpenAI's Codex CLI — models, context, sandboxing, MCP, agents and subagents — and which agentic terminal fits coding, writing, research, workflows, and CI.
-
Google Antigravity CLI: Gemini CLI's Replacement, and How It Compares to Claude Code
Google is retiring Gemini CLI for consumer/Pro/Ultra and replacing it with the Go-based, multi-agent Antigravity CLI. What's new, the June 18, 2026 cutoff, and how it stacks up against Claude Code.
-
What's New in Claude Opus 4.8 and Claude Code
Adaptive thinking and effort controls, a fast mode that's 2.5× faster and ~3× cheaper, a 1M-token context — plus Claude Code's dynamic workflows, agent teams, skills, and hooks. A practical rundown.
-
Security in the Age of AI: The Year Agents Started Deleting Production
AI agents now run commands, touch production, and call cloud APIs. Real 2025 incidents where AI wiped databases and infrastructure — and the security, audit, and monitoring controls that prevent it.
-
Why Cloud, AI, Security & Terraform Certifications Still Matter in the Age of AI
AI raises the floor, but expertise is still the ceiling. Why certified professionals aren't going anywhere — with concrete examples drawn from real AWS, Azure, GCP, Kubernetes, HashiCorp, and Anthropic certifications.