# Mohammad Abu Mattar — Full Content Bundle
> Full text of the professional core pages and all case studies, then a link index to every content section. For the exhaustive list of Markdown twins, see /llms-sitemap.txt.
---
# Mohammad Abu Mattar
AWS-Certified DevOps Engineer with 7+ years specializing in high-scale cloud automation and fintech infrastructure. Expert in governing multi-account AWS environments, orchestrating production microservices, and implementing Infrastructure as Code with a focus on PCI-DSS compliance, security, and operational excellence.
## About
AWS-Certified Senior DevOps Engineer with proven expertise in managing 15+ AWS accounts and 20+ production microservices in regulated fintech environments. Specialized in implementing GitOps practices, Infrastructure as Code, and achieving 96% security posture through comprehensive compliance controls. Passionate about building robust, secure cloud solutions using Terraform, Docker, Kubernetes, and modern CI/CD practices.
## Experience
### Cloud & DevOps Manager — Motory · Full-time, Mar 2026 - Present, Al Hamra, Jeddah · Amman, Jordan
I run the cloud strategy and platform engineering for Motory, a large automotive marketplace. I manage a multi-cloud environment across AWS, Huawei Cloud, and Hetzner, staying about 70% hands-on with the architecture and code. I lead a DevOps team responsible for the reliability, scalability, and security of our production microservices serving 1M+ active users. I also drive our CI/CD practices, cost optimization efforts, and compliance initiatives in a high-availability, multi-region setup.
- **Infrastructure as Code:** Moved everything from manual console clicks to 100% Terraform. I set up GitOps using ArgoCD and Helm to keep our deployments consistent and auditable.
- **Modernization:** Led the shift from a monolith to microservices for 1M+ users. I wrote a multi-runtime Helm chart that standardized how we handle scaling, probes, and networking across all services.
- **Custom Tooling:** Built a custom Kubernetes operator in Go to solve a specific provisioning problem that standard controllers couldn't handle. This operator is fully integrated into our Helm and ArgoCD delivery flow, ensuring seamless deployments and management of our Kubernetes resources.
- **CI/CD & Delivery:** Built pipelines using Jenkins and ArgoCD that improved deployment speed by 60%. This includes a private OCI registry and a Kong API gateway. I also implemented multi-arch builds and automated chart publishing to streamline our release process.
- **Reliability & SRE:** We hit 99.999% uptime. I automated cross-region disaster recovery between the Middle East and China using Ansible and the Huawei SDK, and I run our observability stack (Prometheus/Grafana/Loki). On-call runbooks and regular DR drills are part of our routine.
- **Cost & Security:** Cut infra costs by 20% while tightening security to meet PCI-DSS and SOC2 standards. This involved identity-as-code via Keycloak and hardening our WAF and VPN. We also use KMS/CSMS for secrets management to ensure our sensitive data is protected.
- **Team Leadership:** I lead the DevOps team, focusing on the platform roadmap and internal training for our developers on K8s and Docker. I also handle vendor relationships and ensure our cloud strategy aligns with our business goals.
### Assistant Manager DevOps Engineer — Jordan Ahli Bank · Full-time, Oct 2024 - Feb 2026, Amman, Jordan
Serving as Platform Owner for the bank's cloud ecosystem, managing 15+ AWS accounts and 20+ production microservices with a focus on high availability, disaster recovery, and fintech workload optimization in a regulated financial environment. Leading security and compliance efforts with 96% security posture achievement while orchestrating GitOps practices and Infrastructure as Code implementations.
- Platform Governance & Reliability: Managing 15+ AWS accounts and 20+ production microservices focusing on high availability, disaster recovery, and fintech workload optimization in regulated environments.
- Infrastructure as Code & GitOps: Standardized cloud deployments using Terraform, implementing GitOps practices with ArgoCD via Atlantis for consistent, repeatable releases. Managed autoscaling and resource optimization for production workloads.
- Security & Compliance Leadership: Achieved 96% security posture across all AWS accounts implementing IAM Identity Center, AWS Organizations, and strict PCI-DSS compliance controls with CloudTrail, AWS Config, and Security Hub.
- Automated CI/CD: Orchestrated end-to-end delivery pipelines using AWS CodePipeline and GitHub Actions, streamlining banking workloads from development to production with automated testing and security scanning.
- Release Engineering: Leading weekly releases and hotfix strategies, ensuring zero-downtime deployments through robust rollback and go/no-go decision frameworks across dev, QA, and production.
- Production Support & Monitoring: Supporting production microservices through centralized monitoring (Prometheus, Grafana, CloudWatch), incident response workflows, and long-term platform roadmap planning.
### DevOps Engineer — cirrusgo (AWS Partner) · Full-time, Mar 2023 - Sep 2024, Amman, Jordan
cirrusgo is an AWS partner delivering cloud solutions to businesses in the MENA region.
Architected and delivered AWS hybrid and on-premises solutions for 8+ enterprise clients including fintech organizations. Designed end-to-end solution architectures balancing cloud-native AWS services with on-premises infrastructure, achieving 25-40% cost optimization while meeting regulatory requirements.
- Solution Architecture: Architected AWS hybrid and on-premises solutions for 8+ enterprise clients including fintech organizations. Designed end-to-end architectures (microservices, event-driven, serverless) and optimized cloud costs by 25-40% through right-sizing, reserved instances, and architecture refinements.
- IaC Foundation & DevOps Standards: Built foundational Infrastructure as Code using Terraform/Terragrunt patterns and established comprehensive DevOps documentation standards. Implemented multi-account, multi-environment infrastructures using AWS Organizations.
- Container Platforms & Deployment: Managed containerized workloads across AWS container services (ECS, Fargate, EKS) spanning 3 environments (dev, UAT, prod). Deployed production applications using GitOps practices and hardened container images.
- CI/CD & Automation: Implemented secure CI/CD pipelines using GitHub Actions, AWS CodePipeline/CodeBuild with canary deployments, automated testing, manual approvals, and environment promotion (dev → UAT → prod).
- Security & Compliance: Ensured security, access control, and compliance across multi-region cloud deployments (Middle East, US East, Europe) and on-premises environments with automated security scanning and monitoring.
### Software Engineer - Microservices — Nagarro · Contract, Feb 2022 - May 2022, Remote
Nagarro is a German-based software services company specializing in consulting, technology, and outsourcing.
Developed fintech microservices architectures using Spring Boot across the full SDLC, integrating PostgreSQL databases for reliable data persistence. Built secure, scalable services for financial transaction processing and data management.
- Fintech Microservices: Developed microservices architectures using Spring Boot for financial transaction processing and data management, ensuring secure and scalable services across the full SDLC.
- Database Integration: Integrated PostgreSQL databases seamlessly for end-to-end functionality and reliable data persistence in fintech applications.
- Full Stack Development: Built front-end components using Angular, HTML, and CSS while resolving production bugs and performance issues to improve system stability.
- Technical Documentation: Produced detailed technical documentation to support long-term maintainability and knowledge transfer across development teams.
### Full Stack Developer — Freelance · Full-time, Jan 2020 - Feb 2023, Amman, Jordan · Remote
As a freelance Full Stack Developer, I conducted comprehensive client consultations and designed fintech microservices with Spring Boot. Developed responsive web applications using React while managing end-to-end project delivery and client relationships.
- Client Consultations & Requirements: Conducted comprehensive client consultations to align project requirements and solutions, ensuring clear communication and alignment with business needs throughout the development lifecycle.
- Fintech Microservices & Backend Development: Designed and developed microservices using Spring Boot for fintech applications, integrating PostgreSQL and other databases seamlessly for end-to-end functionality and reliable data persistence.
- Responsive Web Development: Created responsive web interfaces and applications using React, HTML, and CSS, focusing on enhancing user experience, performance optimization, and user-friendly designs.
- Project Management: Managed project timelines, deliverables, and client expectations to ensure successful project completion and client satisfaction.
### Teacher Assistant/Lab Supervisor — Isra University · Full-time, Dec 2018 - Dec 2019, Amman, Jordan
Isra University is a private institution offering undergraduate and postgraduate programs.
At Isra University, I taught C++ programming fundamentals, facilitated lab sessions, and provided technical support to students and faculty.
- Developed and maintained C++ lab sessions to enhance students' programming skills.
- Provided technical support to students and faculty to resolve programming-related issues.
- Assisted students in developing their programming skills through hands-on lab sessions.
- Collaborated with faculty to design and update lab curricula.
- Monitored and evaluated student progress to provide constructive feedback.
### Web Developer — Greater Amman Municipality · Apprenticeship, Dec 2017 - Feb 2018, Amman, Jordan
The Greater Amman Municipality manages Amman's administrative and city planning needs.
At Greater Amman Municipality, I designed and developed web applications for administrative needs, focusing on front-end development with HTML, CSS, and JavaScript.
- Developed and maintained web applications to support administrative functions.
- Ensured user-friendly interfaces by implementing best practices in front-end development.
- Collaborated with the team to gather requirements and deliver solutions that met project goals.
- Tested and debugged web applications to ensure functionality and performance.
- Provided technical support and training to end-users.
## Education
### AWS Certified Developer – Associate — Amazon Web Services (AWS), Issued Feb 2024 · Expires Feb 2027
Validated expertise in developing and maintaining AWS-based applications, including proficiency in core AWS services, application lifecycle management, and deployment best practices.
### AWS Certified Cloud Practitioner — Amazon Web Services (AWS), Issued Oct 2023 · Expires Feb 2027
Demonstrated foundational knowledge of AWS Cloud concepts, services, pricing, security, and architecture ideal for technical and non-technical roles.
### AWS Academy Graduate - AWS Academy Cloud Foundations — Amazon Web Services (AWS), Issued Nov 2022
Completed a comprehensive introduction to AWS Cloud, covering compute, networking, databases, and storage, aligned with industry-recognized certifications.
### Advanced Software Development — Code Fellows, Issued Sep 2021
Focused on advanced programming concepts, testing, and full-stack application development using modern tools and frameworks in collaborative agile environments.
### Bachelor of Technology - BTech, Software Engineering — Isra University, Oct 2014 - June 2018
Studied core software engineering principles, data structures, algorithms, and system design. Gained hands-on experience in programming, databases, and software development life cycle (SDLC).
Achievements: First place winner in individual project at annual Technology Day contest. Contributed to establishment and growth of Faculty of Information Technology Club.
## Projects
### QuenchWorks — 0-CVE Hardened Images & Helm Charts
A from-scratch, security-first replacement for the Bitnami catalog: container images and Helm charts built entirely from source on Wolfi, hardened under a strict 0-CVE build gate, cryptographically signed, and pinned by digest. Free, independent, and fully self-hostable.
Technologies: apko, melange, Wolfi, Helm, Kubernetes, Trivy, Cosign, SLSA, Go, AstroJS
- [Live Site](https://quench-works.com/)
- [ArtifactHub (Verified Publisher)](https://artifacthub.io/orgs/quenchworks)
- [GitHub Organization](https://github.com/quenchworks)
- [Charts](https://github.com/quenchworks/charts)
- [Common (library chart)](https://github.com/quenchworks/common)
- [Website](https://github.com/quenchworks/website)
### sysdesign — System Design Knowledge for AI Agents
A Claude Code plugin that wires tradeoff-first system design knowledge into your AI agent: one skill, eleven commands, and fourteen self-contained reference files. Explain a concept, compare options, pressure-test an architecture, estimate capacity, or prep an interview — with every tradeoff stated, not hand-waved. Original prose, MIT-licensed, works fully offline.
Technologies: Claude Code, Markdown, Python, Mermaid
- [Live Site](https://sysdesign.mkabumattar.com/)
- [View Source](https://github.com/mkabumattar/sysdesign)
### Mathematics - Formula Reference
A clean, searchable web reference for mathematical formulas across algebra, geometry, trigonometry, and calculus. It cuts the clutter most references bury you in, rendering formulas with server-side KaTeX on focused topic pages with no accounts, tracking, or ads.
Technologies: AstroJS, TypeScript, Tailwind CSS, React, KaTeX, MDX
- [Live Documentation](https://mathematics.mkabumattar.com/)
- [View Source](https://github.com/MKAbuMattar/mathematics)
### NetCalc Pro
NetCalc Pro Cloud Engineering Suite is a comprehensive web application designed to simplify and enhance the process of subnetting, CIDR calculations, and VLSM. It features a Zero Trust, no-backend architecture with a Terminal Brutalist UX, allowing network engineers to seamlessly manage infrastructure, share state via Base64 URLs, and utilize a powerful set of tools without requiring a backend server.
Technologies: AstroJS, TypeScript, Tailwind CSS, Nanostores
- [Live Documentation](https://netcalc-pro.mkabumattar.com/)
### Rawi - AI CLI Documentation Tool
An intelligent CLI tool that generates comprehensive documentation for command-line applications using AI. Rawi analyzes your CLI commands and creates detailed, structured documentation automatically.
Technologies: TypeScript, Node.js, AI/ML, CLI, NPM
- [Live Documentation](https://rawi.mkabumattar.com/)
- [View Source](https://github.com/withrawi/rawi)
- [NPM Package](https://www.npmjs.com/package/rawi)
### AWS Icons - SVG Icon Library
A comprehensive, free SVG icon library of all AWS services. Constantly updated with new services and available via CDN or NPM for seamless integration. Perfect for any web project needing AWS service icons.
Technologies: SVG, CDN, NPM, Web
- [Live Documentation](https://aws-icon.mkabumattar.com/icons)
- [View Source](https://github.com/MKAbuMattar/aws-icons)
- [NPM Package](https://www.npmjs.com/package/aws-icons)
### AWS React Icons - React Components Library
AWS service icons as React components with TypeScript support. Built on top of aws-icons, providing a seamless React experience with full type definitions and easy customization.
Technologies: React, TypeScript, SVG, NPM
- [Live Documentation](https://aws-icon.mkabumattar.com/react)
- [View Source](https://github.com/MKAbuMattar/aws-react-icons)
- [NPM Package](https://www.npmjs.com/package/aws-react-icons)
### Devicons React - Programming Icons Library
A comprehensive collection of icons representing programming languages, design tools, and development software, built on top of Devicon. Perfect for React projects with 5k+ weekly downloads on NPM. Customizable size and color with optimized performance.
Technologies: React, TypeScript, SVG, NPM, Devicon
- [Live Documentation](https://devicons-react.mkabumattar.com/)
- [View Source](https://github.com/MKAbuMattar/devicons-react)
- [NPM Package](https://www.npmjs.com/package/devicons-react)
### igntui - .gitignore Generator TUI
A powerful Terminal User Interface (TUI) and CLI for generating .gitignore files from gitignore.io templates. Features smart search, multi-template selection, live preview, and intelligent caching for instant access to 571+ templates.
Technologies: Python, TUI, CLI, PyPI, curses
- [View Source](https://github.com/MKAbuMattar/igntui)
- [PyPI Package](https://pypi.org/project/igntui/)
### Asciiquarium - Python Edition
An aquarium/sea animation in ASCII art for your terminal! This is a Python reimplementation of the classic Perl asciiquarium, featuring multiple fish species, sharks, whales, ships, and sea monsters with smooth 30 FPS animation.
Technologies: Python, TUI, ASCII Art, PyPI, Animation
- [View Source](https://github.com/MKAbuMattar/asciiquarium-python)
- [PyPI Package](https://pypi.org/project/asciiquarium/)
### Notebook - Browser-Based Markdown Editor
Hi! You've found your new space for notes. It's a simple notebook that lives entirely in your browser. Since everything you type is saved automatically and tucked into the URL, your work stays private and follows you wherever you go all without needing an account.
Technologies: Web, AstroJS, Markdown, Local Storage
- [View Source](https://github.com/MKAbuMattar/notebook)
- [Try Notebook](https://notebook.mkabumattar.com/)
---
# Contact Me
- **Phone**: +962 79 0650 332
- **Email**: info@mkabumattar.com
- **Location**: Amman, Jordan
---
# Cutting a SaaS AWS Bill 41% Without Slowing Delivery
A growing SaaS ran on EKS with a full GitOps pipeline, and it was over its AWS budget nearly every month. The reflex from leadership was the usual one: freeze features until the bill comes down. That would have worked, and it would have been the wrong call. Freezing delivery to save money trades a problem you can measure for one you can't. This is how the bill came down by roughly 41% over two quarters while the team kept shipping through a 25% canary rollout on every release, and why almost none of the win came from turning things off in a panic.
The percentages here are representative of what this pattern achieves, not a
single audited client figure. The AWS and Kubernetes mechanics (tagging, Cost
Categories, Budgets, Anomaly Detection, Savings Plans, EKS node groups,
Karpenter, Argo CD, Argo Rollouts) are exactly as described. Your real savings
depend on how much waste you start with and how much of your compute is
commitment-eligible.
## Impact
The bill came down without a feature freeze. Over two quarters the monthly AWS spend dropped by roughly 41% while the team kept shipping through the same 25% canary it uses for any feature.
None of it came from a panic switch-off. Every lever was reversible and canary-guarded, so the savings held without trading away reliability or delivery speed, and cost turned into a normal signal that shows up in pull requests instead of a quarterly fire drill.
## The problem
The bill was growing faster than revenue, which is the signal that matters. Nobody could say where the money went, because nothing was labeled. A single line item for "EC2" across a dozen teams and six node groups tells you nothing you can act on. When finance asked engineering to explain a spike, the honest answer was "we're not sure," and that answer is what turns a cost conversation into a feature freeze.
There was also a dashboard, and everyone pointed at it as proof they were "doing FinOps." A dashboard shows you the number. It does not change anyone's behavior, and it definitely does not tell an engineer that the node group they oversized last sprint is the reason the graph bent upward. Visibility without attribution is just a prettier version of not knowing.
The last piece was fear. Every proposed saving came with "will this break production?" and without data nobody could answer, so nothing happened. The goal was to make cost a normal, reversible engineering decision instead of a quarterly emergency, and to do it without touching the delivery pipeline the team depended on.
## Constraints
A few limits shaped the whole approach.
- **No feature freeze.** Delivery velocity was the business. Any optimization that slowed shipping was off the table.
- **No reliability regressions.** Saving money by removing redundancy or headroom was not a real saving.
- **Keep the delivery model.** Full GitOps, dev to staging to production promotion, and 25% canary rollouts all had to stay exactly as they were.
- **Data stays isolated.** The data tier runs in subnets with no internet route, and that boundary was non-negotiable.
- **Respect confidentiality.** Real dollar figures stay private, so success is reported as percentages and unit economics.
## Architecture
The SaaS runs entirely on a single EKS cluster per environment, across three availability zones. Each VPC has three tiers of subnets: three public subnets for ingress and NAT, three private subnets for the EKS worker nodes, and three isolated subnets with no internet route for the data tier. Everything the product needs runs in the cluster.
_EKS platform architecture_
Compute is split into purpose-built managed node groups rather than one big pool, which is what makes both scheduling and cost control tractable. There are separate node groups for the frontend, the backend, data and ETL work, observability, the GitOps controllers, and the internal dashboards, plus a Spot-backed group for batch and preview workloads. Karpenter handles just-in-time node provisioning on top, so capacity follows demand instead of sitting idle.
The whole platform toolchain lives in the cluster, scheduled onto those node groups: Keycloak for single sign-on across the dashboards, Argo CD, and Grafana; SonarQube and Trivy in the delivery path; Argo CD and Argo Rollouts for GitOps and progressive delivery; and Prometheus with Grafana for observability.
The data tier (RDS with a multi-AZ standby, plus ElastiCache) lives in the
isolated subnets. Those subnets have no NAT and no internet gateway route, so
the databases cannot reach the internet and the internet cannot reach them.
Nodes talk to them only over private VPC routes.
Cost work fails when it lives only in a finance spreadsheet, so the first move was to make spend attributable. A small, enforced tag taxonomy flows into AWS Cost Categories, which maps raw line items to teams and products, and from there into Budgets, Cost Anomaly Detection, and per-team showback.
_Cost attribution and guardrail flow_
The taxonomy was deliberately small. Five mandatory tags, not twenty, because a taxonomy nobody follows is worse than none. `Environment`, `CostCenter`, `Application`, and `Owner` covered almost every question we needed to answer, and `ManagedBy` flagged anything created by hand instead of through code. On EKS those tags also propagate to node groups and volumes, so cluster compute is attributable per team, not lumped under one anonymous bill.
Enforcement matters more than intent, so the tags were governed centrally. AWS Organizations Tag Policies defined the allowed keys and values, Service Control Policies blocked non-compliant resources, and consolidated billing plus the Cost and Usage Report gave one clean view across every account.
_Governance and reporting topology_
Chargeback is tempting, but it needs near-perfect tagging and it starts turf
wars early. We started with showback: show each team its own spend, let
central finance keep paying the bill, and move to chargeback only once the
tags were trustworthy. Awareness drove most of the savings before any money
changed hands internally.
## Delivery: GitOps and progressive rollout
None of the cost work was allowed to disturb delivery, so it helps to see what delivery looks like. Every change runs through the same GitOps pipeline. CI builds and tests, SonarQube enforces a quality gate, and Trivy scans the image and the IaC. Only a clean build pushes to ECR and bumps the image digest in the GitOps manifests repository. Argo CD notices the change and syncs it to the cluster.
_GitOps delivery pipeline_
Nothing goes fully live at once. Argo Rollouts takes over at the cluster and shifts traffic in steps, starting at 25%, then pausing to check analysis metrics before it widens. If the metrics stay healthy it promotes; if they degrade it rolls back on its own, with no human in the loop. That single behavior is what let the cost changes ship safely, because a right-sized deployment that misbehaved would be caught at 25% of traffic, not 100%.
Environments follow the same path every time. A feature or preview environment spins up per pull request on the Spot-backed node group, merges auto-deploy to dev, the same image digest promotes to staging for integration tests, and only then does it reach production behind the canary.
_Environments and promotion_
The canary itself is a few lines of Argo Rollouts config, and it is the same for a feature change or a cost change.
```yaml title="rollout.yaml"
apiVersion: argoproj.io/v1alpha1
kind: Rollout
metadata:
name: frontend
spec:
strategy:
canary:
steps:
- setWeight: 25
- pause: {duration: 10m}
- setWeight: 50
- pause: {duration: 10m}
- setWeight: 100
```
## Implementation
The baseline was code. Rather than tag resources by hand, every provider inherited a default set of tags, so new infrastructure was attributable from the moment it existed.
```hcl title="provider.tf"
provider "aws" {
region = "us-east-1"
default_tags {
tags = {
Environment = "Prod"
CostCenter = "1001"
ManagedBy = "Terraform"
}
}
}
```
Then came the guardrails, automated so nobody had to remember to check a dashboard. A monthly budget with a forecast alert catches planned overspend before the month ends, and Cost Anomaly Detection catches the surprise 3am spike.
```bash title="Budget + anomaly guardrails"
aws budgets create-budget \
--account-id 111122223333 \
--budget '{
"BudgetName": "MonthlyCost",
"BudgetLimit": { "Amount": "50000", "Unit": "USD" },
"TimeUnit": "MONTHLY",
"BudgetType": "COST"
}'
aws ce create-anomaly-monitor \
--anomaly-monitor '{
"MonitorName": "CoreServices",
"MonitorType": "DIMENSIONAL",
"MonitorDimension": "SERVICE"
}'
```
With attribution and guardrails in place, the actual optimization ran as normal GitOps changes, each behind the canary, each with a one-commit rollback.
1. **Find the waste.** Use Cost Explorer grouped by the new tags, plus Kubernetes right-sizing signals from the metrics stack, to rank the most over-provisioned node groups and workloads.
2. **Right-size node groups in reversible steps.** Drop one instance size or one replica at a time, ship it through the 25% canary, and watch the SLOs. The old manifest is one revert away.
3. **Let Karpenter consolidate.** Enable consolidation so underused nodes are drained and replaced with fewer, better-packed ones, and move interruptible and preview work to the Spot node group.
4. **Put dev and staging to sleep.** Scale non-production node groups to zero overnight and on weekends. Nothing runs when nobody is working.
5. **Commit last, not first.** Only after cluster usage was stable did we buy Compute Savings Plans, so we committed to real baseline usage rather than to waste.
The commitment step is where teams most often lose money, by chasing the deepest discount for a workload they are about to change. The rule we used was simple: match the commitment to the roadmap, not to the current instance.
_Choosing the right commitment_
The team was midway through moving several backend services to Graviton for better price-performance. A three-year EC2 Instance Savings Plan on the old family would have looked cheaper on paper and then stranded the moment those services migrated. A Compute Savings Plan gave up a few points of discount but stayed flexible across families, regions, Fargate, and Lambda, which matters even more on EKS where node groups change shape often. That small premium was cheap insurance.
## Results
Over two quarters, the monthly bill came down by roughly 41%, and delivery never paused. Every cost change went out through the same 25% canary as any feature. The breakdown, as representative shares of the total reduction, looked like this.
| Lever | Share of the saving | Nature of the change |
| :------------------------------------------------- | :------------------ | :------------------------- |
| Right-sizing node groups + Karpenter consolidation | Largest | Reversible, canary-guarded |
| Scheduling dev and staging to sleep | Large | Fully reversible |
| Compute Savings Plans matched to the roadmap | Meaningful | 1-year, flexible |
| Spot for batch, preview, and CI | Meaningful | Interruption-tolerant only |
| Storage cleanup and lifecycle policies | Smaller | One-time plus ongoing |
The more durable result was cultural. Cost stopped being a quarterly fire drill. Teams could see their own node-group spend, cost showed up in pull requests as a normal signal, and the "will this break?" fear faded because every change had a canary and a rollback. Treat the percentage as illustrative and the mechanics as the real deliverable.
## Lessons
Attribution is the whole game. Nothing else worked until spend had an owner, because you cannot optimize a shared cluster you cannot see per team. The five-tag taxonomy, enforced in code and propagated to node groups, paid for itself before a single node was resized.
Progressive delivery is what makes cost work safe. On a normal deploy model, right-sizing production feels risky enough that teams avoid it. With a 25% canary and automated rollback, a bad resize is a non-event, so the team actually did the work instead of flinching.
Commit to usage, not to hope. The most expensive mistake in cloud cost work is a long, rigid commitment bought early to chase a headline discount. Buy commitments after usage is stable, prefer flexibility while the architecture is still moving, and treat the discount rate as secondary to not stranding the plan.
If I did it again, I would wire a pull-request cost estimate in on day one. Putting the number in front of the engineer at the moment they change a manifest moved behavior more than any dashboard did.
## Frequently Asked Questions
> **Why not just freeze features until the bill comes down?**
A freeze trades a measurable problem for an unmeasurable one. You save some money and lose delivery velocity, customer momentum, and team morale, none of which show up cleanly on the bill. Almost all of the saving here came from waste and mismatched commitments, not from doing less, so the freeze would have hurt the business while barely touching the real cost drivers.
> **How do you right-size EKS node groups without causing incidents?**
Treat it like any other change. Drop one size or one replica at a time, ship it through the same 25% Argo Rollouts canary as a feature, and watch the SLOs during the pause windows. Let Karpenter consolidate underused nodes rather than doing it by hand. Because every step is a GitOps commit, the rollback is a one-line revert, so a bad resize is caught at 25% of traffic and reverted, not discovered in a postmortem.
> **Why start the canary at 25% instead of a smaller slice?**
Twenty-five percent is a deliberate balance. It is a big enough slice that real traffic patterns and enough metric volume show up quickly, so the analysis step can make an honest call, but small enough that a bad release only touches a quarter of users before it rolls back. Smaller first steps are reasonable for very high-risk changes, but 25% gave this team fast, trustworthy signal without much blast radius.
> **How does the isolated data tier stay reachable if it has no internet?**
The isolated subnets have no NAT and no internet gateway route, so the databases cannot reach the internet and vice versa. The application nodes in the private subnets reach RDS and ElastiCache over private VPC routes only. Anything the data tier genuinely needs from an AWS service goes through VPC endpoints, which keep that traffic on the AWS network rather than the public internet.
> **Does the GitOps and canary setup make cost work harder?**
It makes it safer, which in practice makes it happen. Every cost change is a normal pull request that flows dev to staging to production behind the canary, with SonarQube and Trivy gates on the way. There is no separate risky "cost project," just ordinary changes with the same guardrails as everything else, so teams approve them quickly.
> **What is the single highest-impact first step?**
Enforced tagging. Until spend is attributable per team, product, environment, and node group, every other optimization is guesswork. A small mandatory taxonomy, applied through Terraform default tags and AWS Organizations tag policies, turns the bill from one opaque number into a map you can act on.
## References
- [Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/what-is-eks.html)
- [Karpenter](https://karpenter.sh/)
- [Argo CD](https://argo-cd.readthedocs.io/)
- [Argo Rollouts (progressive delivery)](https://argo-rollouts.readthedocs.io/)
- [Argo CD image rollouts walkthrough](https://medium.com/@anandctx/argocd-image-rollouts-a9d91943195d)
- [Keycloak](https://www.keycloak.org/documentation)
- [SonarQube](https://docs.sonarsource.com/sonarqube-server/latest/)
- [Trivy](https://trivy.dev/)
- [AWS Cost Categories](https://docs.aws.amazon.com/cost-management/latest/userguide/manage-cost-categories.html)
- [AWS Budgets](https://docs.aws.amazon.com/cost-management/latest/userguide/budgets-managing-costs.html)
- [AWS Cost Anomaly Detection](https://docs.aws.amazon.com/cost-management/latest/userguide/manage-ad.html)
- [AWS Savings Plans](https://docs.aws.amazon.com/savingsplans/latest/userguide/)
- [Terraform AWS provider default_tags](https://registry.terraform.io/providers/hashicorp/aws/latest/docs#default_tags)
---
# Migrating a Monolith to Kubernetes Without a Big-Bang Cutover
Almost every failed "let's move off the monolith" project shares one detail: the plan was a big-bang cutover. Rewrite in parallel, pick a weekend, flip the switch, and pray. This is the opposite of that. A large application moved onto EKS one service at a time using the strangler-fig pattern, with a routing facade in front, traffic shifting gradually per route, and a working rollback at every single step. No freeze, no weekend gamble, and no moment where the whole thing was in the air.
## Impact
The application reached Kubernetes with no big-bang moment. Every route moved gradually behind a facade with a working rollback, so no single step was ever high stakes and delivery never froze.
The gains were structural rather than a one-time event. Each extracted service got independent deploys and its own scaling, so teams stopped blocking each other and the hot paths no longer forced the whole application to scale with them.
## The problem
The monolith itself was not the enemy. It ran fine, the team knew it, and it paid the bills. The problem was that it had become the bottleneck for everything else. Deploys were all-or-nothing, so one risky change held up every other team's work. Scaling meant scaling the entire application even when only one part was hot. And onboarding a new engineer meant handing them the whole thing at once.
The tempting fix, a full rewrite with a cutover, is where teams get hurt. You freeze features to build the replacement, the replacement drifts from the original as the original keeps changing, and the cutover becomes a single high-stakes event with no safe rollback. If anything goes wrong at 2am on migration night, the only option is a panicked revert of everything.
The goal was to get the benefits of independent services without ever betting the business on one cutover. That means the old and new systems have to run side by side, in production, for as long as it takes.
## Constraints
- **No big-bang cutover.** At no point could correctness depend on a single switch-flip.
- **No feature freeze.** The monolith kept shipping features throughout the migration.
- **A rollback at every step.** Each increment had to be revertible in minutes, not hours.
- **No shared-database free-for-all.** Extracted services own their data; the goal was decoupling, not a distributed monolith on one schema.
- **Prove parity before deleting anything.** Old code stayed until the new path was verified against it.
## Architecture
Before the migration, the shape was familiar: an Application Load Balancer in front of a monolith running across an Auto Scaling group, all talking to one shared relational database.
_Before: monolith on EC2_
The target keeps the monolith running, containerized, inside an EKS cluster, and puts a routing facade in front of everything. The facade is the heart of the pattern. It looks at each request and decides whether that path has been migrated to a new service or still belongs to the monolith. Extracted services get their own data stores; the monolith keeps its shared database until its remaining parts are small.
_After: strangler facade on EKS_
The name comes from the strangler fig, a plant that grows around a tree and gradually replaces it. The new system grows around the monolith, taking over one responsibility at a time, until the original is either gone or small enough to leave alone. Nothing about it requires a dramatic finish.
## The routing facade
The facade is where the safety comes from. Every request enters through it, and a route table decides the destination. A path that has been migrated goes to the new service; everything else defaults to the monolith. Crucially, migration of a single route is itself gradual: you shift a small percentage of that route's traffic to the new service, watch it, and widen only when it holds. If the new service misbehaves, the facade falls straight back to the monolith, which is still running and still correct.
_Strangler routing_
In practice the facade can be an ingress with weighted routing, an API gateway, or a service mesh. The mechanism matters less than the property: per-path routing plus per-path traffic weight plus instant fallback.
```yaml title="facade-route.yaml (illustrative weighted routing)"
# /users is being migrated: 10% to the new service, 90% still to the monolith.
http:
- match:
- uri:
prefix: /users
route:
- destination: {host: users-service}
weight: 10
- destination: {host: monolith}
weight: 90
- route: # default: everything else stays on the monolith
- destination: {host: monolith}
weight: 100
```
## Implementation
The migration ran as a loop, not a project plan with an end date. Each pass picked one seam, extracted it, shifted traffic, verified, and cleaned up.
_Extraction sequence_
1. **Containerize the monolith first.** Before extracting anything, get the monolith itself running in EKS behind the facade. Now old and new live in the same place, and the facade is the only thing in front.
2. **Pick a loosely-coupled seam.** Choose a capability with a clear boundary and a data set it mostly owns, for example users or billing. Avoid the tangled core on the first pass; early wins build trust.
3. **Build the service with its own data.** Give the extracted service its own database rather than pointing it at the monolith's schema. Backfill and keep it in sync during the transition, but the target is independent ownership.
4. **Route to it gradually.** Add the path to the facade and shift a small slice of traffic, then widen. Watch latency and error rates during each step, and keep the monolith path warm as a fallback.
5. **Verify parity, then delete.** Once the new service matches the monolith's behavior under real traffic, remove that code from the monolith. Deleting the old path is what makes the win permanent.
6. **Repeat, and know when to stop.** Move to the next seam. Stop when what remains is small and stable enough that extracting it would cost more than it returns.
The most dangerous shortcut is pointing a new service at the monolith's
database so you can "extract later." That gives you two services coupled
through one schema, which is a distributed monolith: all of the network
overhead, none of the independence. Give the service its own data, even if
that means a sync period during the transition.
Data is the genuinely hard part, and it is worth being honest about that. Moving stateless request handling is straightforward; moving the data it owns without downtime is not. The workable approach is to give the new service its own store, backfill it, keep it in sync while both paths run, and cut the monolith's write path over only once the new service is authoritative and verified. Where strict consistency is required during the overlap, treat the monolith as the source of truth until the very last step.
Measure the migration by how much of the monolith is gone, not by how many
services exist. A useful signal is the share of production traffic served by
extracted services and the amount of code deleted from the monolith. Services
created without code removed from the original is motion without progress.
## Results
The application moved onto EKS without a single cutover event and without a feature freeze. Because each route shifted gradually with a live fallback, no migration step was a high-stakes moment; the riskiest change only ever touched a small slice of one path at a time. Independent deploys arrived for each extracted service, so teams stopped blocking each other, and the hot paths could scale on their own instead of forcing the whole application to scale with them.
The migration also did not finish in the storybook sense, and that was the right outcome. A stable, low-change remainder of the monolith stayed in place, containerized and behind the facade, because extracting it would have cost more than it returned. Treat "the monolith is gone" as a possible ending, not the goal.
## Lessons
The facade is the whole safety story. Because every request always had a valid destination and an instant fallback, no step was irreversible. That single property is what let the team move quickly instead of cautiously.
Extract the easy seams first. The instinct to start with the messy core is a trap. Early, low-risk extractions build the tooling and the team's confidence, so the hard ones later are routine instead of terrifying.
Data ownership is the real migration. The service boundary is easy; the data boundary is the work. Any plan that hand-waves the database is a plan to build a distributed monolith.
Give yourself permission to stop. The goal was never zero monolith. It was independent, deployable, scalable services for the parts that needed it, and a small stable remainder for the parts that did not.
## Frequently Asked Questions
> **What exactly is the strangler-fig pattern?**
It is an incremental migration approach where a new system grows around an old one and takes over its responsibilities one at a time, until the old system is replaced or reduced to a small remainder. A routing facade sits in front and directs each request to either the new component or the old one, so both run in production together and you never need a single cutover.
> **Why not just rewrite and cut over on a weekend?**
Because a cutover is a single high-stakes event with no safe rollback. You freeze features to build the replacement, it drifts from the original as the original keeps changing, and if anything breaks on migration night your only option is reverting everything at once. Strangler-fig keeps the old system live the whole time, so every step is small and reversible.
> **What makes a good first service to extract?**
Low coupling and a clear data owner. Pick a capability with a clean boundary that mostly owns its own data, like users or billing, so you are not untangling shared state on your first attempt. Early, low-risk wins build the tooling and the confidence you will need for the harder seams later.
> **How do you handle the shared database?**
Give each extracted service its own store rather than pointing it at the monolith's schema. Backfill it and keep it in sync while both paths run, then cut the monolith's write path over only once the new service is authoritative and verified. Sharing one database across services is a distributed monolith and defeats the point of the migration.
> **How do you know when the migration is done?**
When the remaining monolith is small and stable enough that extracting more would cost more than it returns. Track the share of production traffic served by extracted services and the amount of code deleted from the monolith. Done does not have to mean zero monolith; a low-change remainder behind the facade is a perfectly good ending.
## References
- [Martin Fowler: StranglerFigApplication](https://martinfowler.com/bliki/StranglerFigApplication.html)
- [Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/what-is-eks.html)
- [AWS Prescriptive Guidance: strangler fig pattern](https://docs.aws.amazon.com/prescriptive-guidance/latest/modernization-decomposing-monoliths/strangler-fig.html)
- [Kubernetes Ingress](https://kubernetes.io/docs/concepts/services-networking/ingress/)
- [Database decomposition patterns](https://microservices.io/patterns/data/database-per-service.html)
---
# QuenchWorks: Building a 0-CVE Container Image and Helm Chart Catalog
When Bitnami moved its long-trusted catalog behind a paid tier, thousands of teams woke up to a supply-chain problem they didn't choose. The free images they had pinned in production would stop getting updates, and the migration clock started that morning. QuenchWorks is my answer to that: a from-scratch, security-first catalog of container images and Helm charts, built entirely from source, hardened under a strict zero-CVE build gate, signed, and free. This is how it's put together and why each decision earns its place.
## Impact
QuenchWorks is real and in production use, not a proof of concept. It replaced Bitnami for common workloads with a catalog that is built from source, provable, and free.
Everything below is verifiable: pull any image and check its signature, SBOM, and provenance yourself. The build gate stays green because the base is small enough that there is almost nothing to be vulnerable in, so the numbers hold instead of drifting the week after launch.
## The problem
The Bitnami catalog was popular for good reasons. It was broad, it was versioned, and it was maintained well enough that most teams never thought about it. Its weaknesses only became obvious once access changed: you didn't control the build, you couldn't prove what was inside a given image, and continued free access was never actually guaranteed.
That last point is the one that bites. When an upstream catalog changes its terms, every `image:` line you pinned becomes a liability at once. You either pay, fork, or scramble. And even before that day comes, an opaque image is its own quiet risk. If you can't see how a layer was produced, you can't reason about what a scanner finds inside it, and you can't answer a security review with anything better than "we trust the vendor."
Most hardened-image alternatives fix one slice of this and charge for the rest. I wanted the whole thing: a catalog broad enough to actually replace Bitnami for common workloads, provable rather than "trust us," and free with no pull limits and no lock-in. If it couldn't be all three, it wasn't worth building.
## Constraints
A handful of hard limits shaped every later decision.
- **Zero fixable CVEs, enforced by the build.** Not a nightly report someone reads later. A gate that fails the build so a vulnerable image never ships in the first place.
- **Built from source.** No repackaging of someone else's opaque binary layers. If it's in the image, we produced it.
- **Provable.** Every image needs a bill of materials and build provenance that a consumer can verify without trusting me.
- **Free to run and maintain.** The whole system builds on free CI, so cost can never be the reason it slips behind a paywall later.
- **Multi-arch.** amd64 and arm64, because production is both now, not one or the other.
Those constraints pull against each other. Zero fixable CVEs across 150+ images sounds impossible if you picture a fat base image. Building everything from source sounds slow. The architecture is what makes them coexist.
## Architecture
The catalog is a pipeline, not a pile of Dockerfiles. Each image is declared as an `apko` plus `melange` spec, built from source on Wolfi, scanned against a zero-fixable-CVE gate, signed, and only then published pinned by digest. Charts sit on a shared library chart and reference those images by digest.
_QuenchWorks build pipeline_
The single decision that makes the zero-CVE gate realistic is the base. QuenchWorks builds on **Wolfi**, a glibc Linux undistro designed for containers. Most images start with no shell, no package manager, and a tiny set of packages. There's simply very little in the image that can be vulnerable, so keeping the gate green is a fight you can actually win instead of an endless race against a bloated base.
The image itself is assembled declaratively. `melange` builds signed APK packages from source, and `apko` composes those packages plus the Wolfi base into an OCI image with no Dockerfile involved. Because the whole thing is declared, the contents are known, reproducible, and easy to record as a bill of materials.
_Image composition with melange and apko_
The zero-CVE gate and the minimal base are the same decision viewed twice. You
don't reach zero fixable CVEs by patching harder. You reach it by shipping so
little that there's almost nothing to patch.
A catalog is never done, though, because CVEs are disclosed against packages long after an image ships. So the pipeline runs in reverse on a schedule. A nightly Trivy rescan checks every published image, and when a fix lands upstream the affected image rebuilds, re-enters the gate, gets re-signed, and republishes under a new digest. The catalog trends toward zero drift without anyone babysitting it.
_Nightly rescan and self-heal loop_
## Implementation
Each image is a pair of specs. `melange` describes how to build the package from source, and `apko` describes how to assemble the final image. Here's the shape of both, trimmed for clarity.
```yaml title="melange.yaml"
package:
name: my-app
version: 1.2.3
environment:
contents:
packages:
- build-base
pipeline:
- uses: fetch
with:
uri: https://example.com/my-app-${{package.version}}.tar.gz
expected-sha256: '...'
- uses: autoconf/configure
- uses: autoconf/make
- uses: autoconf/make-install
```
```yaml title="apko.yaml"
contents:
repositories:
- https://packages.wolfi.dev/os
packages:
- my-app
- ca-certificates-bundle
accounts:
users:
- username: nonroot
uid: 65532
run-as: 65532
archs:
- x86_64
- aarch64
entrypoint:
command: /usr/bin/my-app
```
The gate is one Trivy call, and it's deliberately strict about what counts. It only fails on CVEs that have a fix available, because a vulnerability with no upstream patch isn't something a rebuild can clear. Everything fixable has to be at zero before the image is allowed out.
```bash title="0-CVE gate"
# Fail the build if any FIXABLE HIGH/CRITICAL vulnerability is present
trivy image --ignore-unfixed --severity HIGH,CRITICAL \
--exit-code 1 ghcr.io/quenchworks/my-app:latest
```
Once an image passes, it gets signed and attested before it's pushed for real. Signing is keyless with Cosign, so there's no long-lived private key to leak, and the SBOM and SLSA provenance ride along as attestations.
1. **Build from source.** `melange` produces signed APKs; `apko` assembles the image with the Wolfi base, nonroot user, and read-only root filesystem defaults.
2. **Gate on zero fixable CVEs.** Trivy runs in comprehensive mode. One fixable HIGH or CRITICAL fails the pipeline, so a vulnerable image never reaches the registry.
3. **Sign and attest.** Cosign signs the image keyless, then attaches an SPDX SBOM and a SLSA build-provenance attestation.
4. **Publish pinned by digest.** The image is pushed, and the Helm charts reference it by `sha256:` digest, never by a movable tag.
5. **Rescan nightly.** A scheduled Trivy run watches for new fixes and triggers the self-heal rebuild loop.
On the delivery side, charts are the second half of the story. Every chart builds on a shared `quench-common` library chart, so common concerns like security context, probes, and labels live in one place instead of being copy-pasted 120 times. Each chart pins its image by digest.
_Chart topology_
Pinning by digest instead of tag is what makes the catalog trustworthy in practice. A tag can be moved; a digest can't. When a consumer pins a QuenchWorks chart, they get exactly the bytes that passed the gate.
```yaml title="values.yaml"
image:
repository: ghcr.io/quenchworks/postgresql
# Pinned by digest, not tag. This is the exact image that passed the gate.
digest: 'sha256:abc123...'
```
The proof only matters if consumers can check it, so verification is a first-class step, not an afterthought. Anyone can verify an image's signature and attestations before it runs, and an admission policy can enforce that in the cluster so unsigned or unverifiable images never schedule.
```bash title="Verify before you run"
cosign verify \
--certificate-identity-regexp '^https://github.com/quenchworks/' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
ghcr.io/quenchworks/postgresql@sha256:abc123...
```
_Consumer verification workflow_
## Results
The catalog is real and in use, not a proof of concept.
- **150+ container images** built from source on Wolfi, each gated to zero fixable CVEs.
- **120+ production Helm charts** on the shared `quench-common` library, every one pinned to its image by digest.
- Every image **cosign-signed** with an SPDX SBOM and SLSA provenance, published under an **ArtifactHub verified-publisher** organization.
- **Multi-arch** (amd64 and arm64), nonroot, and read-only root filesystem by default.
- A **nightly rescan and self-heal rebuild loop** that keeps the catalog current as upstream ships fixes.
- **Free and independent.** No subscription, no registry pull limits, no lock-in.
The counts above are current catalog figures. Per-image build times and scan times vary by package, so I'd treat any single number there as indicative rather than a benchmark.
## Lessons
The biggest lesson is that the base image choice decides everything downstream. Trying to reach zero CVEs on a fat base is a treadmill; starting from Wolfi's minimal surface turns the gate into something you can keep green for months. If I'd started anywhere else, the self-heal loop would be firing constantly and the whole thing would feel like bailing water.
The second lesson is that provenance costs far less than it's worth. Signing and generating SBOMs added very little build time, but they change the catalog's whole posture. It stops being "trust me" and becomes "verify it yourself," which is the entire point of replacing an opaque upstream. If I were doing it again, I'd wire verification into the consumer docs even earlier, because an unverified signed image is only half the value.
The one thing I'd watch more carefully next time is chart sprawl. The `quench-common` library chart paid for itself immediately, but library conventions need to be locked down early. Once a few charts drift from the shared patterns, every future change gets more expensive.
## Frequently Asked Questions
> **How is 'zero CVE' actually possible across 150+ images?**
It's zero _fixable_ CVEs, and it's mostly a consequence of the base. Wolfi images ship with almost nothing beyond what the app needs, so there's very little surface for a vulnerability to live in. The Trivy gate then fails any build with a fixable HIGH or CRITICAL, so a vulnerable image can't ship. Vulnerabilities with no upstream fix are tracked but don't block, because a rebuild can't clear them.
> **Why pin charts to images by digest instead of a tag?**
A tag is a movable pointer; a digest is the content itself. If you pin `:latest` or even `:1.2.3`, the bytes behind that tag can change. Pinning `sha256:...` guarantees you get exactly the image that passed the gate and was signed. It's the difference between "probably the right image" and "provably the right image."
> **How do I verify an image before running it?**
Use `cosign verify` with the QuenchWorks certificate identity and OIDC issuer, as shown above. That checks the keyless signature against the transparency log. You can also verify the SBOM and SLSA provenance attestations, and enforce all of it in-cluster with an admission policy so nothing unsigned ever schedules.
> **What happens when a new CVE is disclosed after an image ships?**
The nightly Trivy rescan catches it. If the CVE is fixable, the affected image rebuilds from source, goes back through the gate, gets re-signed, and republishes under a new digest. You pick up the fix by moving your pin to the new digest. Nobody has to notice the CVE manually for the loop to run.
> **Is QuenchWorks really free, and what's the catch?**
It's free, with no subscription and no registry pull limits. The catch, if you call it one, is that you verify and pin things yourself rather than outsourcing trust to a vendor relationship. That's a feature for most teams: you get provenance you can audit instead of a support contract you have to believe.
> **Can I use the charts without adopting the whole catalog?**
Yes. The charts and images are independent. You can pull a single hardened image by digest, or install one chart, without buying into everything. The `quench-common` library chart is an implementation detail of the charts, not something you have to adopt in your own repos.
## References
- [QuenchWorks catalog and website](https://quench-works.com/)
- [QuenchWorks on GitHub](https://github.com/quenchworks)
- [Wolfi undistro](https://github.com/wolfi-dev)
- [apko](https://github.com/chainguard-dev/apko) and [melange](https://github.com/chainguard-dev/melange)
- [Trivy vulnerability scanner](https://trivy.dev/)
- [Sigstore Cosign](https://docs.sigstore.dev/)
- [SPDX](https://spdx.dev/) and [SLSA provenance](https://slsa.dev/)
- [ArtifactHub](https://artifacthub.io/)
---
# Content sections
# Blog Posts
108 entries.
- [Testing Terraform: Static Analysis, Native Tests, and Terratest](https://mkabumattar.com/blog/post/terraform-testing-terratest-native-tests) — A practical testing strategy for Terraform modules: the testing pyramid, tflint static analysis, native terraform test with provider mocking, Terratest integration tests in Go, safe teardown, and a GitHub Actions pipeline with OIDC.
- [tRPC: End-to-End Type-Safe APIs in TypeScript Without Codegen](https://mkabumattar.com/blog/post/trpc-end-to-end-typesafe-apis) — How tRPC gives full-stack TypeScript teams end-to-end type safety with no code generation: routers, Zod validation, React Query, auth middleware, the v11 features (FormData, SSE, streaming), and when to pick it over REST or GraphQL.
- [FinOps in Practice: How to Build a Cloud Cost Accountability Culture on AWS](https://mkabumattar.com/blog/post/finops-cloud-cost-accountability-aws) — How to run FinOps as a real practice on AWS: a lean tagging taxonomy enforced with Terraform and Organizations, automated budgets and anomaly detection, showback vs chargeback, and matching Savings Plans to your architecture roadmap.
- [QuenchWorks: A Zero-CVE, Built-From-Source Replacement for the Bitnami Catalog](https://mkabumattar.com/blog/post/quenchworks-zero-cve-bitnami-alternative-wolfi) — When Broadcom moved the free Bitnami catalog to a legacy tier, thousands of teams lost their supply of maintained, hardened container images overnight. QuenchWorks is my answer: over 150 container images and 120 Helm charts, rebuilt from source on Wolfi, scanned to zero fixable CVEs, cosign-signed, and pinned by digest. Here is why I built it and how it actually works.
- [GitHub Actions Reusable Workflows: Build a Shared CI Library Across All Your Repos](https://mkabumattar.com/blog/post/github-actions-reusable-workflows-shared-ci-library) — Learn how to simplify and secure your CI/CD at scale using GitHub Actions reusable workflows. This practical guide walks you through the differences between reusable workflows and composite actions, OIDC keyless authentication, and versioning strategies. You will also learn advanced testing methods, like "Patch-on-Test," to build a secure, fast, and centralized pipeline library your developers will love.
- [Kubernetes Networking Demystified: CNI Plugins, Network Policies, and Pod-to-Pod Communication](https://mkabumattar.com/blog/post/kubernetes-networking-cni-plugins-policies-guide) — A friendly, technical guide to Kubernetes networking. We cover how CNI plugins like Calico and Cilium work, how to write Network Policies, and how to debug those annoying connectivity issues.
- [Service Mesh Deep Dive: Istio vs. Linkerd](https://mkabumattar.com/blog/post/service-mesh-istio-vs-linkerd) — Trying to figure out service mesh? This article compares Istio and Linkerd on Kubernetes, looking at how they handle traffic, security, and more. Find out which one might be the best fit for you.
- [GitOps vs. Traditional IaC for Kubernetes: A Comparative Analysis](https://mkabumattar.com/blog/post/gitops-vs-traditional-iac-kubernetes-deployment) — Explore GitOps vs. Traditional IaC for Kubernetes. This report compares pull-based GitOps (ArgoCD, Flux) with push-based IaC (Terraform), covering workflows, drift detection, security, and rollbacks. Understand how these approaches manage Kubernetes infrastructure and application configurations for enhanced consistency and reliability.
- [Serverless Observability: A Comprehensive Guide to AWS Lambda Monitoring](https://mkabumattar.com/blog/post/aws-lambda-observability-guide) — Master AWS Lambda monitoring with this comprehensive guide to serverless observability. Learn how CloudWatch, X-Ray, and Datadog help you track performance, troubleshoot issues, and optimize costs for your serverless applications. Get practical tips and best practices for building resilient Lambda functions.
- [Designing SLOs and Error Budgets: Your Blueprint for Sustainable Reliability](https://mkabumattar.com/blog/post/designing-slos-error-budgets-reliability-blueprint) — Learn how to design effective SLOs and error budgets to balance innovation with reliability. This comprehensive guide covers SLIs, monitoring, business goals, and best practices for sustained service health.
- [Edge Computing: AWS Lambda@Edge vs. Cloudflare Workers – A Practical Guide](https://mkabumattar.com/blog/post/edge-computing-aws-lambda-at-edge-vs-cloudflare-workers-practical-guide) — Dive into edge computing with our practical guide comparing AWS Lambda@Edge and Cloudflare Workers. Discover their strengths, weaknesses, and ideal use cases for serverless, low-latency applications. Learn how these CDN-integrated platforms optimize performance for web apps and IoT, helping you choose the right solution.
- [Navigating the Future of Cloud with Multi-Cloud IaC: Pulumi and Crossplane](https://mkabumattar.com/blog/post/multi-cloud-iac-pulumi-crossplane-future-cloud) — Explore multi-cloud Infrastructure as Code with Pulumi and Crossplane. Learn how these tools enhance agility, reduce vendor lock-in, and shape the future of cloud management.
- [Building Resilient Systems: Immutable Infrastructure with Packer and Terraform](https://mkabumattar.com/blog/post/immutable-infrastructure-packer-terraform-guide) — Discover how immutable infrastructure, powered by Packer and Terraform, transforms IT. Learn to build resilient, secure, and scalable systems by replacing, not updating, your infrastructure. This guide covers core concepts, hands-on workflows, and best practices for modern DevOps.
- [Unlocking Scalability: A Comprehensive Guide to Modular Terraform for IaC](https://mkabumattar.com/blog/post/modular-terraform-scalable-iac-guide) — Master scalable Infrastructure as Code with modular Terraform. Learn best practices for design, versioning, testing, and state management to build robust, consistent, and automated cloud infrastructure.
- [Unmasking Hidden Costs: Your Guide to AWS Cost Optimization Cleanup Strategies](https://mkabumattar.com/blog/post/aws-cost-optimization-cleanup-strategies) — Unlock significant savings in AWS by implementing effective cleanup strategies. This guide covers identifying hidden costs, practical cleanup actions for EC2, EBS, S3, RDS, and more, and how to leverage automation with Cost Explorer, Cloud Custodian, and spot instances for continuous optimization. Learn to reduce waste and maximize your AWS investment.
- [Chaos Engineering: Testing Resiliency with Chaos Monkey and Gremlin](https://mkabumattar.com/blog/post/chaos-engineering-resiliency-testing-monkey-gremlin) — Master Chaos Engineering to build resilient systems. Explore how Chaos Monkey and Gremlin inject faults in AWS and Kubernetes, turning potential outages into proactive learning. Discover best practices, experiment types, and frequently asked questions for robust software testing.
- [What's the Deal with Shift-Left Security, and Why Should You Care?](https://mkabumattar.com/blog/post/shift-left-security-sast-dast-sca-cicd) — Learn how to implement shift-left security by integrating SAST, DAST, and SCA into your CI/CD pipeline. Enhance application security, reduce costs, and accelerate development with practical guidance and tool examples like SonarQube, Trivy, and OWASP ZAP.
- [Container Image Signing with Cosign: A Hands-On Guide to Secure Your Supply Chain](https://mkabumattar.com/blog/post/container-image-signing-cosign-guide) — Secure your software supply chain with Cosign. This hands-on guide covers container image signing, keyless and KMS methods, CI/CD automation, Kubernetes deployment verification, and advanced security best practices.
- [GraphRAG Explained: Building Knowledge-Grounded LLM Systems](https://mkabumattar.com/blog/post/graphrag-explained-building-knowledge-grounded-llm-systems) — Think of GraphRAG as the "detective" upgrade for AI. Learn how using Knowledge Graphs helps LLMs connect distant dots, stop hallucinations, and reason through complex data in ways standard RAG just can't.
- [The Resilience of Timbernetes: A Comprehensive Analysis of In-Place Pod Vertical Scaling in Kubernetes 1.35](https://mkabumattar.com/blog/post/kubernetes-1-35-in-place-pod-vertical-scaling-guide) — Discover how Kubernetes 1.35 "Timbernetes" revolutionizes resource management with In-Place Pod Vertical Scaling. This expert report explores the shift from "restart-to-scale" to a dynamic update model, focusing on benefits for JVM and stateful services. Learn how the kubelet, VPA, and cgroups v2 work together to enable zero-downtime scaling, improve node utilization, and manage memory shrink hazards. Essential reading for DevOps and platform engineers looking to optimize Kubernetes workloads.
- [Taming the Chaos: Let's Sort Out Those Flaky CI/CD Pipelines](https://mkabumattar.com/blog/post/troubleshooting-flaky-ci-cd-pipelines) — Learn practical strategies for troubleshooting and preventing flaky CI/CD pipelines. Identify common causes, use debugging tools like GitHub Actions and act, and implement best practices for a more stable development workflow.
- [The Democratization of Container Security: Docker Hardened Images](https://mkabumattar.com/blog/post/democratization-docker-hardened-images-container-security) — Explore how Docker democratized container security by open-sourcing 1,000+ Hardened Images under Apache 2.0. Learn about distroless containers, 95% smaller attack surfaces, SBOM/VEX integration, and how to migrate to secure-by-default images using multi-stage builds.
- [Database DevOps: Making PostgreSQL and MongoDB CI/CD Feel Natural](https://mkabumattar.com/blog/post/database-devops-ci-cd-postgresql-mongodb) — Ready to ditch manual database updates? Learn how Database DevOps and CI/CD can transform PostgreSQL and MongoDB management for faster, more reliable releases.
- [Microsoft’s Prompt Orchestration Markup Language (POML): Structuring the Future of AI Interaction](https://mkabumattar.com/blog/post/microsoft-poml-orchestrating-ai-prompts-for-llms) — Ready to ditch manual database updates? Learn how Database DevOps and CI/CD can transform PostgreSQL and MongoDB management for faster, more reliable releases.
- [Compliance as Code: Making Security Easier with Terraform and InSpec](https://mkabumattar.com/blog/post/compliance-as-code-nist-iso-27001-gdpr-terraform-inspec) — Learn how to use Compliance as Code with Terraform and InSpec to automatically follow NIST, ISO 27001, and GDPR. Understand the benefits, challenges, and real-world uses of this modern way to handle security and regulatory compliance.
- [Low-Code vs. Custom Code: Let's Talk About Speed and Tech Debt](https://mkabumattar.com/blog/post/low-code-vs-custom-code-speed-tech-debt) — Explore the crucial balance between development speed and technical debt when choosing between low-code and custom code. Learn when each approach shines, especially for internal tools like Retool.
- [AIOps: Making DevOps Even Better with Smart AI Tools](https://mkabumattar.com/blog/post/aiops-enhancing-devops-with-ai) — Learn how AIOps is transforming DevOps with AI-driven automation, predictive analytics, and intelligent incident management. Explore key tools, benefits, and practical guidance for modern IT operations.
- [Centralized Logging with Loki, Grafana, and Fluent Bit: Making Sense of Your Systems](https://mkabumattar.com/blog/post/centralized-logging-loki-grafana-fluent-bit) — Learn how to set up centralized logging with Loki, Grafana, and Fluent Bit for Kubernetes and microservices. This comprehensive guide covers deployment, configuration, and troubleshooting for a robust observability solution.
- [Karpenter vs. Cluster Autoscaler on AWS: Picking the Right Tool for Your Kubernetes Scaling](https://mkabumattar.com/blog/post/karpenter-vs-cluster-autoscaler-aws-kubernetes-scaling) — Compare Karpenter and Cluster Autoscaler on AWS for Kubernetes scaling. Understand their architecture, performance, cost efficiency, and choose the right tool for your needs.
- [Unlocking the Secrets: HashiCorp Vault vs. AWS Secrets Manager vs. SOPS - Which Reigns Supreme](https://mkabumattar.com/blog/post/secrets-management-vault-secrets-manager-sops) — Compare HashiCorp Vault, AWS Secrets Manager, and SOPS for secrets management. Understand their features, security, automation, and best practices to choose the right tool.
- [The AI Revolution in DevOps: How Smart Tech is Changing Incident Response](https://mkabumattar.com/blog/post/ai-powered-devops-incident-response-llms) — Explore how AI and Large Language Models (LLMs) are revolutionizing DevOps incident response. Learn about practical applications, benefits, challenges, and future trends. Includes FAQs.
- [Platform Engineering: Building Internal Developer Platforms (IDPs)](https://mkabumattar.com/blog/post/platform-engineering-building-internal-developer-platforms) — Learn how platform engineering and Internal Developer Platforms (IDPs) are revolutionizing software development. Discover benefits, challenges, best practices, and the Spotify case study. Simplify complexity and boost developer productivity!
- [The Real Talk on Microservices vs. Monoliths](https://mkabumattar.com/blog/post/0076-the-dark-side-of-microservices-when-to-avoid-them) — Microservices aren't always the answer. Discover the hidden complexities, challenges faced by Amazon Prime Video, and when sticking with monoliths might be the smarter architectural choice. Learn about trade-offs and avoid tech debt.
- [GitHub Actions vs. GitLab CI for Monorepos: Which One Wins?](https://mkabumattar.com/blog/post/github-actions-vs-gitlab-ci-for-monorepos) — Comparing GitHub Actions and GitLab CI for monorepo management. Analyze features, CI/CD pipelines, parallel jobs, caching, secrets management, and real-world experiences to choose the best platform.
- [Full-Stack Observability with OpenTelemetry: Getting a Clear View of Your Systems](https://mkabumattar.com/blog/post/full-stack-observability-opentelemetry) — Learn how to get a full view of your complex systems using OpenTelemetry. This guide covers the basics, benefits, using it with Prometheus and Grafana, and answers common questions.
- [Navigating Growth: Building a Secure and Scalable AWS Environment with a Multi-Account Architecture and Control Tower](https://mkabumattar.com/blog/post/multi-account-aws-control-tower) — Learn how to leverage a multi-account AWS architecture with AWS Control Tower for enhanced security, compliance, and streamlined management. Discover best practices and FAQs.
- [Policy as Code with Open Policy Agent: A Technical and Governance Perspective](https://mkabumattar.com/blog/post/policy-as-code-opa-guide) — Learn how to use Policy as Code with Open Policy Agent (OPA) to boost your cloud governance, security, and compliance. This guide covers the basics, benefits, how to integrate with Terraform and Kubernetes, common challenges, and real-world examples.
- [Zero Trust Architecture in DevOps Pipelines: Secure Your CI/CD Workflows](https://mkabumattar.com/blog/post/zero-trust-devops-pipelines-securing-ci-cd) — Learn how to integrate Zero Trust Architecture into DevOps CI/CD pipelines using AWS, IAM, and micro-segmentation. Secure deployments without slowing innovation. Perfect for teams prioritizing speed and security.
- [10+ Secret Git Commands That Will Save Hours Every Week](https://mkabumattar.com/blog/post/10-secret-git-commands-to-save-time) — Discover 10+ secret Git commands that will save hours every week! Learn advanced Git techniques for undoing mistakes, managing commits, automating workflows, and optimizing repositories. Perfect for DevOps and GitHub users.
- [Streamlining GitHub Organization Management with Terraform](https://mkabumattar.com/blog/post/streamlining-github-organization-management-with-terraform) — Learn how to manage a large GitHub organization efficiently using Terraform. Discover key Terraform resources for automating user access, team structures, and repository configurations.
- [Getting Addicted to Coding: Why We Love Programming More Than Sleep](https://mkabumattar.com/blog/post/getting-addicted-to-coding) — Discover why programming is so addicting and how to maintain a healthy balance while pursuing your passion for coding. Learn about the thrill of problem-solving, instant feedback, and tips to avoid burnout.
- [Deploying Infrastructure with Terraform in CI/CD Pipelines](https://mkabumattar.com/blog/post/deploying-infrastructure-with-terraform-in-ci-cd-pipelines) — Learn how to deploy infrastructure using Terraform in a CI/CD pipeline. Discover how Terraform fits into DevOps workflows and how to create a CI/CD pipeline with GitHub Actions for Terraform automation.
- [AI is Not Real: A Software Engineering Perspective](https://mkabumattar.com/blog/post/ai-is-not-real) — Modern AI is not intelligent in the human sense. It is large-scale statistical pattern matching and mathematical optimization. Here is what that means for the systems we build, why probabilistic chains fail, and how hybrid architectures make them reliable.
- [When to Use Serverless?](https://mkabumattar.com/blog/post/when-to-use-serverless) — Discover when to use serverless architecture in your projects. Learn about its advantages, real-world success stories, and scenarios where serverless is the best fit. Explore the pros and cons to make informed decisions.
- [Why You Should Not Use Else Statements in Your Code](https://mkabumattar.com/blog/post/why-you-should-not-use-else-statements) — Discover why avoiding else statements can lead to cleaner, more maintainable code. Learn about guard clauses, establishing contracts, and handling new conditions efficiently. Explore practical examples and best practices in software engineering.
- [How to Avoid Over-Engineering Your Code?](https://mkabumattar.com/blog/post/how-to-avoid-over-engineering-your-code) — Learn how to avoid over-engineering your code in software development. Discover the causes, symptoms, and practical strategies to maintain simplicity and align with business needs. Stay focused on creating efficient, maintainable software.
- [Software Engineering Principles Every Developer Should Know](https://mkabumattar.com/blog/post/software-engineering-principles-every-developer-should-know) — Explore essential software engineering principles every developer should know, including DRY, KISS, and YAGNI. Learn how these principles promote code reusability, simplicity, and focus on essential functionality. Plus, discover code examples in Python to illustrate these principles in action.
- [Phases of the Modernization Process](https://mkabumattar.com/blog/post/phases-of-the-modernization-process) — Discover the key phases of the modernization process. Learn how to align with business goals, understand dependencies, involve customers, and future-proof your IT infrastructure.
- [Unlocking the Power of React Context API: Demystifying State Management](https://mkabumattar.com/blog/post/react-context-api-state-management) — Explore the world of React Context API and gain insights into its use for state management. Learn how to use it to build a simple state management system.
- [Becoming an AWS Pro: A Deep Dive into Amazon Elastic Container Service](https://mkabumattar.com/blog/post/aws-ecs-deep-dive) — Ready to elevate your AWS DevOps skills with Amazon Elastic Container Service? Explore ECS versus EC2, discover its versatile use cases, and embark on a journey from traditional on-premises servers to EC2 instances, and finally to the seamless world of ECS Fargate.
- [Building a Code Generative AI Model: Empowering Code Writing with AI](https://mkabumattar.com/blog/post/building-a-code-generative-ai-model-empowering-code-writing-with-ai) — Explore the process of building a Code Generative AI model as a software engineer. Understand how AI can write code, follow step-by-step instructions to create your AI, and find answers to common queries about AI-generated code.
- [Understanding Generative AI in Depth](https://mkabumattar.com/blog/post/understanding-generative-ai-in-depth) — Discover the captivating realm of Generative AI in this comprehensive guide designed for seasoned software engineers. Delve into the nuances of Generative AI, differentiate it from conventional AI and machine learning, explore practical use cases, and find answers to frequently asked questions.
- [The ORM Dilemma: To Use or Not to Use](https://mkabumattar.com/blog/post/why-not-to-use-orm-in-nodejs) — Explore the intricacies of utilizing Object-Relational Mapping (ORM) in Node.js, TypeScript, and Express. Seasoned software engineers dissect the pros and cons, offering invaluable insights into when and why you should consider alternatives to ORM for your database operations.
- [Mastering Caching Strategies with Redis Cache: Boosting Performance in Node.js and TypeScript](https://mkabumattar.com/blog/post/mastering-caching-strategies-redis-nodejs-typescript) — Explore the world of caching in Redis and supercharge your Node.js and TypeScript applications with advanced caching strategies. Learn about Cache-Aside, Read-Through, Write-Through, and Write-Behind patterns, as well as the Redis cache key strategy. Discover the power of Redis caching for turbocharging your applications.
- [Scaling Up, Staying Strong: Hands-On AWS CloudFormation Techniques for Building Resilient and Scalable Systems](https://mkabumattar.com/blog/post/scaling-up-staying-strong-hands-on-aws-cloudformation-techniques-for-building-resilient-and-scalable-systems) — In today's rapidly evolving digital landscape, building resilient and scalable systems is crucial for businesses to meet growing demands and maintain high availability. Cloud native architecture, combined with the powerful capabilities of Amazon Web Services (AWS), offers an ideal solution for achieving these objectives. In this article, we will explore how AWS CloudFormation, a powerful infrastructure as code tool, enables organizations to build resilient and scalable systems through a hands-on approach.
- [Unleashing the Magic: Best Practices for Infrastructure Automation in a Cloud Native AWS Environment](https://mkabumattar.com/blog/post/unleashing-the-magic-best-practices-for-infrastructure-automation-in-a-cloud-native-aws-environment) — In the realm of Cloud Native AWS environments, mastering infrastructure automation is essential to unlock the full potential of your magical kingdom. From security spells to optimizing performance, this section will reveal the best practices and secret enchantments for achieving seamless infrastructure automation. Join us on this enchanting journey as we explore the spells and rituals that will transform your Cloud Native AWS environment into a well-oiled, high-performing realm.
- [Orchestrating Infrastructure with Terraform: Unleashing the Magic of Infrastructure Provisioning](https://mkabumattar.com/blog/post/orchestrating-infrastructure-with-terraform-unleashing-the-magic-of-infrastructure-provisioning) — In the realm of infrastructure orchestration, Terraform emerges as a versatile sorcerer's apprentice, allowing you to create and manage your infrastructure across multiple cloud providers. With Terraform, you can wave your magical wand and provision resources on AWS by writing infrastructure configurations in a declarative language. Join us on a journey through the enchanting world of Terraform and witness the power of infrastructure provisioning magic.
- [Simplifying Application Deployment with AWS SAM: Unleashing the Power of Serverless Magic](https://mkabumattar.com/blog/post/simplifying-application-deployment-with-aws-sam-unleashing-the-power-of-serverless-magic) — When it comes to deploying serverless applications, AWS SAM (Serverless Application Model) emerges as your trusty sidekick, simplifying the process and harnessing the full power of serverless architecture. SAM templates enable you to define and deploy your serverless functions, APIs, and event sources with ease, turning your serverless wishes into reality.
- [Leveraging AWS CloudFormation for Infrastructure as Code (IaC): The Mighty Sword of Automation](https://mkabumattar.com/blog/post/leveraging-aws-cloudformation-for-infrastructure-as-code-iac-the-mighty-sword-of-automation) — In the realm of cloud computing, Cloud Native Infrastructure stands tall as a modern sorcery, empowering developers to design and deploy applications tailored explicitly for the cloud. By harnessing the full potential of AWS services, Cloud Native Infrastructure enables the creation of highly scalable, resilient, and efficient applications. It's like building castles in the sky, aided by an army of cloud-based minions ready to fulfill your every command!
- [Unleashing the Power of Cloud Native Infrastructure on AWS: Building Castles in the Sky](https://mkabumattar.com/blog/post/unleashing-the-power-of-cloud-native-infrastructure-on-aws-building-castles-in-the-sky) — In the realm of cloud computing, Cloud Native Infrastructure stands tall as a modern sorcery, empowering developers to design and deploy applications tailored explicitly for the cloud. By harnessing the full potential of AWS services, Cloud Native Infrastructure enables the creation of highly scalable, resilient, and efficient applications. It's like building castles in the sky, aided by an army of cloud-based minions ready to fulfill your every command!
- [Understanding Infrastructure as Code (IaC): Unleashing the Magic of Code-Driven Infrastructure Management](https://mkabumattar.com/blog/post/understanding-infrastructure-as-code-iac-unleashing-the-magic-of-code-driven-infrastructure-management) — In the realm of modern technology, infrastructure management has undergone a revolutionary transformation with the emergence of Infrastructure as Code (IaC). Imagine having the power to conjure and control your entire infrastructure using the magic of code. Welcome to the enchanting world of IaC, where manual configurations and tedious clicking are replaced with the elegance and efficiency of code-driven infrastructure management.
- [Mastering Infrastructure Automation: Harnessing the Power of IaC in a Cloud Native AWS Environment](https://mkabumattar.com/blog/post/mastering-infrastructure-automation-harnessing-the-power-of-iac-in-a-cloud-native-aws-environment) — In today's fast-paced digital landscape, building scalable and resilient systems is crucial for businesses to meet growing demands and maintain high availability. Cloud native infrastructure, combined with the powerful capabilities of Amazon Web Services (AWS), offers an ideal solution for achieving these objectives.
- [Decoding REST API Architecture: A Comprehensive Guide for Developers](https://mkabumattar.com/blog/post/decoding-rest-api-architecture-a-comprehensive-guide-for-developers) — Hey there, fellow developers! Buckle up because we're about to dive into the crazy world of REST API architecture.
- [TypeScript vs. JSDoc: Exploring the Pros and Cons of Static Type Checking in JavaScript](https://mkabumattar.com/blog/post/typescript-vs-jsdoc-exploring-the-pros-and-cons-of-static-type-checking-in-javascript) — Static type checking has become an essential aspect of modern JavaScript development, ensuring code reliability, catching errors early, and improving overall code quality.
- [RESTful API vs. GraphQL: Which API is the Right Choice for Your Project?](https://mkabumattar.com/blog/post/restful-api-vs-graphql-which-api-is-the-right-choice-for-your-project) — Consider yourself a software engineer working on a brand-new customer project. Your customer has requested you to develop an application that has to analyze and show a lot of data in real-time. You've made the decision to create an API to manage the data, but you're unsure of the best kind to utilize. Which API should you use the tried-and-true RESTful API or the more recent, customized GraphQL API?
- [Mastering AWS Architecture: A Comprehensive Guide to the Well-Architected Framework](https://mkabumattar.com/blog/post/mastering-aws-architecture-a-comprehensive-guide-to-the-well-architected-framework) — This article provides an overview of the AWS Well-Architected Framework, a set of best practices for designing and operating reliable, efficient, secure, and sustainable systems on AWS. The framework consists of five pillars: Operational Excellence, Security, Reliability, Performance Efficiency, and Cost Optimization, with Sustainability being the sixth pillar. The article explores each pillar and explains how organizations can apply the framework to optimize their AWS infrastructure. It also provides examples of how AWS services can be used to improve the efficiency, security, reliability, cost-effectiveness, and sustainability of cloud systems.
- [Get Started with Building ReactJS and Docker: A Complete Guide](https://mkabumattar.com/blog/post/get-started-with-building-reactjs-and-docker-a-complete-guide) — This article is a complete guide for building and deploying a React JS application with Docker, including prerequisites, environment setup, building, containerizing, deployment, and best practices. It also includes an example of running a React JS application with Docker Compose.
- [Building a Customizable Image Slider in React Using Hooks, SCSS, and TypeScript](https://mkabumattar.com/blog/post/building-a-customizable-image-slider-in-react-using-hooks-scss-and-typescript) — This article will guide you through the process of creating a React slider component using Hooks, SCSS, and TypeScript. By the end of this tutorial, you will have a functional and customizable slider that can be easily integrated into your project.
- [How To Run MySQL in a Docker Container: A Step-by-Step Guide with Customization Tips](https://mkabumattar.com/blog/post/how-to-run-mysql-in-a-docker-container-a-step-by-step-guide-with-customization-tips) — Learn how to run a MySQL database in a Docker container with this step-by-step guide. The article covers starting a container, connecting to it, customizing its configuration, and using volumes for data persistence. Get tips for optimizing and customizing your setup. Ideal for developers, sysadmins and database administrators.
- [How To Install Docker On Linux In 4 Easy Steps!](https://mkabumattar.com/blog/post/how-to-install-docker-on-linux-in-4-easy-steps) — This article guides you through the simple process of installing Docker on Linux in 4 easy steps. From updating the package index to running your first Docker container, you'll learn everything you need to get started with this powerful platform. By the end, you'll be able to take advantage of all the benefits Docker has to offer.
- [How to Avoid Common Cloud Services Mistakes](https://mkabumattar.com/blog/post/how-to-avoid-common-cloud-services-mistakes) — This article will cover common mistakes made when implementing cloud services and offer solutions to avoid them. The introduction will explain the importance of avoiding these mistakes. The article will then discuss specific mistakes such as not fully understanding the service, not securing resources, lack of monitoring, no disaster recovery plan, vendor lock-in and lack of compliance, outdated software, scalability issues, cost concerns, lack of exit strategy, migration and backup/recovery plan. The conclusion will summarize key points and provide additional resources.
- [How to Deploy a Spring Boot Application to AWS CloudFormation](https://mkabumattar.com/blog/post/how-to-deploy-a-spring-boot-application-to-aws-cloudformation) — This article will guide you on how to deploy a Spring Boot application to AWS CloudFormation. It covers steps from creating a CloudFormation template, packaging the application into a deployable artifact, updating the stack with the new version of the application and discussing about continuous deployment for automatic updates. This guide is intended for developers who have an existing Spring Boot application and want to deploy it on AWS.
- [Introduction to Spring Boot Framework](https://mkabumattar.com/blog/post/introduction-to-spring-boot-framework) — For creating web apps and microservices, many developers utilize the Spring Boot framework. The fact that it is built on top of the Spring Framework and offers a number of advantages makes it a desirable option for developers. You will learn about Spring Boot in this blog article, as well as why it is such a great tool for creating web apps and how to create a basic Spring Boot application.
- [How To Setup Bastion Host on AWS using CloudFormation Template](https://mkabumattar.com/blog/post/how-to-setup-bastion-host-on-aws-using-cloudformation-template) — Learn how to set up a secure Bastion Host on AWS using CloudFormation templates. This tutorial covers all the steps needed to create a VPC, subnets, security groups, and instances, and test the Internet connectivity. Detailed instructions and sample code are included.
- [How To Setup Bastion Host on AWS using AWS CLI](https://mkabumattar.com/blog/post/how-to-setup-bastion-host-on-aws-using-aws-cli) — In this post, we will learn the best practices of setting up a Bastion Host on AWS using the AWS CLI for secure and remote access to EC2 instances within a Virtual Private Cloud (VPC). We will guide you through creating a VPC, subnets, internet gateway, and configuring the Bastion Host with the appropriate permissions. This post is intended for those who are familiar with AWS and have some basic knowledge of networking and SSH.
- [How to Setup Jenkins on AWS Using CloudFormation](https://mkabumattar.com/blog/post/how-to-setup-jenkins-on-aws-using-cloudformation) — We will be using CloudFormation to setup Jenkins on AWS. CloudFormation is a service that helps you model and set up your AWS resources so that you can spend less time managing those resources and more time focusing on your applications that run in AWS.
- [How to CI/CD AWS With Github using Jenkins](https://mkabumattar.com/blog/post/how-to-ci-cd-aws-with-github-using-jenkins) — In this post, I will show you how to setup a CI/CD pipeline using Jenkins and Github to deploy a simple PHP application to Devlopment and Production environments on AWS. With this setup, you can deploy your application to AWS with a single click.
- [How to Install Jenkins on AWS EC2 Instance](https://mkabumattar.com/blog/post/install-jenkins-on-aws-ec2-instance) — In this post, I will show you how to Create an EC2 Instance on AWS and install Jenkins on it.
- [Run TypeScript Without Compiling](https://mkabumattar.com/blog/post/run-typescript-without-compiling) — We can run TypeScript without compiling it to JavaScript. This is useful for debugging and testing. In this post, I will show you how to do it.
- [React With Redux Toolkit](https://mkabumattar.com/blog/post/react-with-redux-toolkit) — In this post, we will learn how to use Redux Toolkit to manage the state of our React application.
- [What is DevOps?](https://mkabumattar.com/blog/post/what-is-devops) — DevOps is a set of practices that combines software development (Dev) and information technology operations (Ops). It aims to shorten the systems development life cycle and provide continuous delivery with high software quality.
- [How To Connect A EBS Volume To An Windows EC2 Instance Using Powershell/GUI](https://mkabumattar.com/blog/post/how-to-connect-a-ebs-volume-to-an-windows-ec2-instance-using-powershell-gui) — In this post, we will learn how to connect a EBS volume to an Windows EC2 instance using Powershell/GUI
- [How To Connect A Two EC2 Instances Database and Files Transfer Using AWS CLI](https://mkabumattar.com/blog/post/how-to-connect-a-two-ec2-instances-database-and-files-transfer-using-aws-cli) — In this post, I will show you how to connect a two EC2 instances database and files transfer using AWS CLI. I will use AWS CLI to create a VPC, EC2 instances, EBS, EFS, and security groups. I will use the EC2 instances to connect to the database and files transfer.
- [Understanding Software Versioning: A Comprehensive Guide](https://mkabumattar.com/blog/post/how-version-number-software-works) — Explore the essentials of software versioning, including semantic versioning, rules, formats, and tools to manage dependencies and releases effectively.
- [How To Connect A Two EC2 Instances Data Transfer Using AWS CLI Without AWS EFS](https://mkabumattar.com/blog/post/how-to-connect-a-two-ec2-instances-data-transfer-using-aws-cli-without-aws-efs) — In this post, I will show you how to connect a two EC2 instances data transfer using AWS CLI without AWS EFS.
- [How To Create a AWS S3 Bucket Using AWS CLI](https://mkabumattar.com/blog/post/how-to-create-a-aws-s3-bucket-using-aws-cli) — In this post, I will show you how to create a AWS S3 bucket using AWS CLI.
- [How To Create a DynamoDB Table Using AWS CLI](https://mkabumattar.com/blog/post/how-to-create-a-dynamodb-table-using-aws-cli) — In this article, we will learn how to create a DynamoDB table using AWS CLI. We will also learn how to add items to the table and how to query the table.
- [What is a CI/CD?](https://mkabumattar.com/blog/post/what-is-a-ci-cd) — Continuous Integration and Continuous Delivery are two of the most important concepts in DevOps. In this article, we will discuss what is a CI/CD and how it can help you to improve your software development process.
- [Setup Nextjs Tailwind CSS Styled Components with TypeScript](https://mkabumattar.com/blog/post/setup-nextjs-tailwind-css-styled-components-with-typescript) — In this post, we will setup Nextjs Tailwind CSS Styled Components with TypeScript.
- [How to Connect to AWS RDS MySQL Database to EC2 Instance With PHP By Using PDO](https://mkabumattar.com/blog/post/how-to-connect-to-aws-rds-mysql-database-to-ec2-instance-with-php-by-using-pdo) — In this post, we will learn how to connect to AWS RDS MySQL Database to EC2 Instance With PHP By Using PDO.
- [How to Install and Configure Node.js on EC2 Instance Amazon Linux 2](https://mkabumattar.com/blog/post/how-to-install-and-configure-nodejs-on-ec2-instance-amazon-linux-2) — Node.js does not exist in the default Amazon Linux 2 repository. So, we need to add the Node.js repository to the system. In this post, we will learn how to install and configure Node.js on EC2 Instance Amazon Linux 2.
- [How to Create a AWS RDS MySQL Database and Connect to it using MySQL Workbench](https://mkabumattar.com/blog/post/how-to-create-a-aws-rds-mysql-database-and-connect-to-it-using-mysql-workbench) — RDS is a managed service that makes it easy to set up, operate, and scale a relational database in the cloud. It provides cost-efficient and resizable capacity while automating time-consuming administration tasks such as hardware provisioning, database setup, patching and backups. It frees you to focus on your applications so you can give them the fast performance, high availability, security, and compatibility they need.
- [How to Run an Apache Web Server Using Docker on an AWS EC2 Instance](https://mkabumattar.com/blog/post/how-to-run-an-apache-web-server-using-docker-on-an-aws-ec2-instance) — We will learn how to create an AWS EC2 instance using AWS CLI in this tutorial. We will also discover how to set up an AWS EC2 instance so that it functions with the Apache web server. We will also discover how to set up an AWS EC2 instance so that it functions with WordPress.
- [How To Create An AWS EC2 Instance Using AWS CLI](https://mkabumattar.com/blog/post/how-to-create-an-aws-ec2-instance-using-aws-cli) — We will learn how to create an AWS EC2 instance using AWS CLI in this tutorial. We will also discover how to set up an AWS EC2 instance so that it functions with the Apache web server. We will also discover how to set up an AWS EC2 instance so that it functions with WordPress.
- [How to Install WordPress on Amazon Linux 2](https://mkabumattar.com/blog/post/how-to-install-wordpress-on-amazon-linux-2) — We will learn how to install WordPress on Amazon Linux 2 in this tutorial. We will also discover how to set up WordPress so that it functions with the Apache web server. We will also discover how to set up WordPress so that it functions with PHP and MariaDB.
- [How to Install PHP and MariaDB on Amazon Linux 2](https://mkabumattar.com/blog/post/how-to-install-php-and-mariadb-on-amazon-linux-2) — We will learn how to set up PHP and MariaDB on Amazon Linux 2 in this tutorial. We will also discover how to set up PHP so that it functions with the Apache web server. We will also discover how to set up MariaDB so that it functions with PHP.
- [How to Install Apache Web Server on Amazon Linux 2](https://mkabumattar.com/blog/post/how-to-install-apache-web-server-on-amazon-linux-2) — We will learn how to install and setup FireWall on Amazon Linux 2 in this tutorial. We will also discover how to set up FireWall so that it functions with the Amazon Linux 2.
- [How to Install and Setup FireWall on Amazon Linux 2](https://mkabumattar.com/blog/post/how-to-install-and-setup-firewall-on-amazon-linux-2) — We will learn how to install and setup FireWall on Amazon Linux 2 in this tutorial. We will also discover how to set up FireWall so that it functions with the Amazon Linux 2.
- [Git SSH Keys for GitHub, GitLab, and Bitbucket on Windows](https://mkabumattar.com/blog/post/git-ssh-keys-for-github-gitlab-and-bitbucket-on-windows) — Git connects to remotes by default via HTTPS, which requires you to enter your login and password every time you run a command like Git pull or git push, using the SSH protocol. You may connect to servers and authenticate to access their services. The three services listed allow Git to connect through SSH rather than HTTPS. Using public-key encryption eliminates the need to type a login and password for each Git command.
- [Customization Windows Terminal With Starship](https://mkabumattar.com/blog/post/customization-windows-terminal-with-starship) — Customization Windows Terminal With Starship, Windows Terminal is a new, modern, fast, efficient, powerful, and productive terminal application for users of command-line tools and shells like Command Prompt, PowerShell, and WSL.
- [VIM Cheat Sheet](https://mkabumattar.com/blog/post/vim-cheat-sheet) — VIM is a highly configurable, powerful text editor available on most Linux distributions. Ideal for editing files via the command line, its modal design offers distinct modes for various tasks. This cheat sheet provides a quick reference for VIM’s essential commands and features.
- [Introduction to Linux CLI](https://mkabumattar.com/blog/post/introduction-to-linux-cli) — Introduction to Linux command-line interface CLI, Linux is a Unix-like computer operating system assembled under the model of free and open-source software development and distribution.
- [How To Create A Custom VPC Using AWS CLI](https://mkabumattar.com/blog/post/how-to-create-a-custom-vpc-using-aws-cli) — In the sample that follows, an IPv4 CIDR block, a public subnet, and a private subnet are all created using AWS CLI instructions. You can run an instance in the public subnet and connect to it once the VPC and subnets have been configured. Additionally, you may start an instance on the private subnet and link to it from the instance on the public network.
- [Setting up JWT Authentication in TypeScript with Express, MongoDB, Babel, Prettier, ESLint, and Husky - Part 2](https://mkabumattar.com/blog/post/setting-up-jwt-authentication-in-typescript-with-express-mongodb-babel-prettier-eslint-and-husky-part-2) — Setting up JWT Authentication in Typescript with Express, MongoDB, Babel, Prettier, ESLint, and Husky: Part 2.
- [Setting up Node.js, Express, Prettier, ESLint, and Husky application with Babel and TypeScript - Part 1](https://mkabumattar.com/blog/post/setting-up-node-js-express-prettier-eslint-and-husky-application-with-babel-and-typescript-part-1) — Setting up Node JS, Express, Prettier, ESLint and Husky Application with Babel and Typescript: Part 1.
- [Setting up Node JS, Express, MongoDB, Prettier, ESLint and Husky Application with Babel and authentication as an example](https://mkabumattar.com/blog/post/setting-up-node-js-express-mongodb-prettier-eslint-and-husky-application-with-babel-and-authentication-as-an-example) — Setting up Node JS, Express, MongoDB, Prettier, ESLint and Husky Application with Babel and authentication as an example.
- [Dotfiles: A Git-Based Strategy for Configuration Management](https://mkabumattar.com/blog/post/dotfiles) — Discover the ultimate strategy for managing your dotfiles using a bare Git repository, simplifying the process of keeping your configuration files synchronized and secure across multiple machines.
- [Git SSH Keys for GitHub, GitLab, and Bitbucket on Linux](https://mkabumattar.com/blog/post/git-ssh-keys-for-github-gitlab-and-bitbucket-on-linux) — Git connects to remotes by default via HTTPS, which requires you to enter your login and password every time you run a command like Git pull or git push, using the SSH protocol. You may connect to servers and authenticate to access their services. The three services listed allow Git to connect through SSH rather than HTTPS. Using public-key encryption eliminates the need to type a login and password for each Git command.
# Case Studies
3 entries.
- [Migrating a Monolith to Kubernetes Without a Big-Bang Cutover](https://mkabumattar.com/case-studies/post/monolith-to-kubernetes-strangler-migration) — Using the strangler-fig pattern to move a large monolith onto EKS service by service, with a routing facade, gradual traffic shifting, and a rollback at every step.
- [Cutting a SaaS AWS Bill 41% Without Slowing Delivery](https://mkabumattar.com/case-studies/post/aws-cost-optimization-saas-case-study) — A FinOps case study on a SaaS running on EKS with full GitOps and progressive delivery: how tagging, right-sizing node groups, and Savings Plans matched to the roadmap cut the AWS bill without freezing feature work.
- [QuenchWorks: Building a 0-CVE Container Image and Helm Chart Catalog](https://mkabumattar.com/case-studies/post/quenchworks-zero-cve-catalog) — How a from-scratch catalog replaced Bitnami with 150+ container images and 120+ Helm charts built from source on Wolfi, gated to zero fixable CVEs, signed, and pinned by digest.
# Quick Reference Cheatsheets
39 entries.
- [Linux Networking](https://mkabumattar.com/cheatsheets/linux-networking) — The commands you reach for to diagnose and manage Linux networks. ip for interfaces and routes, ss for sockets, dig for DNS, traceroute for paths, and tcpdump for packets.
- [kubectl](https://mkabumattar.com/cheatsheets/kubectl) — kubectl is the command-line tool for talking to a Kubernetes cluster. Use it to deploy apps, inspect and manage resources, stream logs, and debug running pods.
- [Terraform Cheatsheet](https://mkabumattar.com/cheatsheets/terraform) — Practical Terraform cheatsheet covering essential CLI commands, state management, import, workspaces, and key HCL patterns for variables, locals, outputs, dynamic blocks, and more. Perfect for daily IaC workflows.
- [AWS CLI](https://mkabumattar.com/cheatsheets/aws-cli) — An expert reference for the AWS CLI covering configuration precedence, EC2 lifecycle control, recursive S3 operations, JMESPath querying, output formatting, and secure SSM sessions.
- [Docker Swarm](https://mkabumattar.com/cheatsheets/docker-swarm) — Comprehensive Docker Swarm reference guide covering swarm initialization, node management, services, stacks, overlay networking, secrets, configs, rolling updates, and cluster monitoring.
- [Chef](https://mkabumattar.com/cheatsheets/chef) — Comprehensive Chef reference guide covering installation, cookbooks, recipes, resources, knife commands, server management, and automation workflows for infrastructure configuration management.
- [Docker Compose](https://mkabumattar.com/cheatsheets/docker-compose) — Comprehensive Docker Compose reference guide covering services, volumes, networks, ports, environment variables, commands, configurations, and container orchestration best practices.
- [Dockerfile](https://mkabumattar.com/cheatsheets/dockerfile) — Comprehensive Dockerfile reference guide covering FROM, RUN, COPY, EXPOSE, CMD, ENTRYPOINT, environment variables, build optimization, best practices, and container image construction.
- [PostgreSQL](https://mkabumattar.com/cheatsheets/postgresql) — Comprehensive PostgreSQL reference guide covering psql commands, database creation, tables, queries, functions, joins, transactions, indexes, and advanced SQL operations.
- [Redis](https://mkabumattar.com/cheatsheets/redis) — Comprehensive Redis reference guide covering commands, data types, keys, strings, lists, sets, hashes, sorted sets, transactions, pub/sub, and caching strategies.
- [Ansible](https://mkabumattar.com/cheatsheets/0028-ansible) — Comprehensive Ansible cheatsheet covering playbooks, inventories, roles, tasks, variables, handlers, ad-hoc commands, modules, and configuration options.
- [SSH](https://mkabumattar.com/cheatsheets/0027-ssh) — Comprehensive SSH cheatsheet covering OpenSSH client usage, authentication methods, port forwarding, key management, X11 forwarding, and configuration options. Includes real-world examples and security best practices.
- [VS Code](https://mkabumattar.com/cheatsheets/vscode) — Complete VS Code keyboard shortcuts reference including command palette, navigation, editing, debugging, multicursor operations, and advanced features for macOS and Windows/Linux
- [Go](https://mkabumattar.com/cheatsheets/go) — Go is a statically typed, compiled programming language designed for simplicity, efficiency, and concurrent programming. It's ideal for building fast, scalable server applications and system tools.
- [TOML](https://mkabumattar.com/cheatsheets/toml) — TOML (Tom's Obvious, Minimal Language) is a configuration file format designed to be minimal, readable, and unambiguous. It's commonly used for application configuration, package manifests, and data serialization.
- [Markdown](https://mkabumattar.com/cheatsheets/markdown) — Markdown is a lightweight markup language designed for creating formatted text using a simple, readable syntax. It's widely used for documentation, READMEs, blogs, and content creation across the web.
- [JSON](https://mkabumattar.com/cheatsheets/json) — JSON (JavaScript Object Notation) is a lightweight, text-based data format used for data exchange. It supports objects, arrays, strings, numbers, booleans, and null values, making it universal across all programming languages.
- [YAML](https://mkabumattar.com/cheatsheets/yaml) — YAML (YAML Ain't Markup Language) is a human-friendly data serialization language commonly used for configuration files, data exchange, and infrastructure-as-code. It emphasizes readability and uses indentation to structure data.
- [RegEx](https://mkabumattar.com/cheatsheets/regex) — Regular expressions (regex or regexp) are patterns used to match character combinations in strings. They are powerful tools for pattern matching, validation, and text processing across many programming languages.
- [JavaScript](https://mkabumattar.com/cheatsheets/javascript) — JavaScript is a versatile, high-level programming language that powers the web. It supports object-oriented, functional, and event-driven programming paradigms.
- [Vim](https://mkabumattar.com/cheatsheets/vim) — Vim is a highly configurable text editor built to make creating and changing any kind of text very efficient. It is included as "vi" with most UNIX systems.
- [Python](https://mkabumattar.com/cheatsheets/python) — Python is an interpreted, high-level programming language known for its readability and simplicity. It supports multiple programming paradigms including procedural, object-oriented, and functional programming.
- [Bash](https://mkabumattar.com/cheatsheets/bash) — Bash is a Unix shell and command language written by Brian Fox for the GNU Project as a free software replacement for the Bourne shell.
- [Dart](https://mkabumattar.com/cheatsheets/dart) — Dart is a statically-typed, strongly null-safe programming language optimized for building fast, multi-platform applications with excellent null safety, async/await, and object-oriented features.
- [Docker](https://mkabumattar.com/cheatsheets/docker) — Docker is a containerization platform for building, shipping, and running applications in isolated environments. This cheatsheet covers essential Docker CLI commands.
- [Git](https://mkabumattar.com/cheatsheets/git) — Git is a distributed version control system for tracking code changes, collaborating with teams, and managing project history.
- [Tmux](https://mkabumattar.com/cheatsheets/tmux) — Tmux is a terminal multiplexer that allows you to manage multiple terminal sessions, windows, and panes within a single screen. Essential commands for session, window, and pane management.
- [Helm](https://mkabumattar.com/cheatsheets/helm) — Helm is the package manager for Kubernetes that simplifies deploying, managing, and upgrading applications through reusable charts. This cheatsheet covers essential Helm CLI commands and workflows.
- [Kubernetes](https://mkabumattar.com/cheatsheets/kubernetes) — Kubernetes is an open-source container orchestration platform for automating deployment, scaling, and management of containerized applications.
- [Screen](https://mkabumattar.com/cheatsheets/screen) — GNU Screen is a terminal multiplexer that allows you to manage multiple terminal sessions, windows, and panes within a single screen. Essential commands for session, window management and splitting.
- [Curl](https://mkabumattar.com/cheatsheets/curl) — cURL is a command-line tool for making HTTP requests, transferring data using URLs, and testing APIs. Essential commands for web development and API testing.
- [Cron](https://mkabumattar.com/cheatsheets/cron) — Cron is a time-based job scheduler in Unix/Linux that allows you to run scripts or commands periodically. Essential crontab syntax, scheduling patterns, and management commands.
- [AWK](https://mkabumattar.com/cheatsheets/awk) — AWK is a powerful text processing language that allows pattern scanning and data extraction. Essential for processing text files, extracting columns, and performing calculations on text data.
- [Netstat](https://mkabumattar.com/cheatsheets/netstat) — Complete netstat reference covering network connections, listening ports, routing tables, and network statistics with practical examples
- [Netcat](https://mkabumattar.com/cheatsheets/nc) — Complete netcat reference covering TCP/UDP connections, file transfers, server testing, port scanning, banner grabbing, and network troubleshooting with practical examples
- [Grep](https://mkabumattar.com/cheatsheets/grep) — Complete grep reference with pattern matching, regular expressions, flags, context options, and practical examples for searching text files
- [Find](https://mkabumattar.com/cheatsheets/find) — Complete find reference with file searching, filtering by type/size/time, permissions, advanced operations, and practical examples for locating files
- [Chmod](https://mkabumattar.com/cheatsheets/chmod) — Complete chmod reference with numeric and symbolic permissions, special bits, directory permissions, and practical examples for managing file access
- [Sed](https://mkabumattar.com/cheatsheets/sed) — Complete sed reference with substitution, addressing, deletion, insertion, transformations, in-place editing, and real-world examples for text manipulation
# Code Snippets
15 entries.
- [Bash Retry Function: Automatically Retry Failing Commands with Exponential Backoff](https://mkabumattar.com/codesnippets/post/bash-retry-function-exponential-backoff) — A reusable Bash function that retries any failing command with configurable attempts and exponential backoff. Ideal for wrapping flaky network calls, AWS CLI commands, or deployment scripts in CI/CD pipelines.
- [Node.js Environment Variable Validation with Zod at Startup](https://mkabumattar.com/codesnippets/post/nodejs-env-validation-zod-startup) — Stop trusting process.env blindly. This Node.js and TypeScript snippet validates every environment variable at startup with a Zod schema, coerces strings into real types, and refuses to boot on bad config so you catch mistakes before a single request is served.
- [AWS EC2 Instance Management with Boto3: Start, Stop, and Query Instances](https://mkabumattar.com/codesnippets/post/aws-ec2-instance-management-boto3-python) — Learn how to automate AWS EC2 instance management using Python and Boto3. This guide covers authentication with IAM roles, starting and stopping instances, using waiters, filtering by tags, running bulk operations, and handling API errors. Practical code examples included for DevOps engineers and cloud developers
- [Redis Caching Patterns: Cache-Aside, Write-Through & Cache Invalidation](https://mkabumattar.com/codesnippets/post/redis-caching-patterns-architecture) — Master production-ready Redis caching patterns with practical examples. Learn cache-aside (lazy loading), write-through, consistency patterns, TTL strategies, and cache invalidation techniques to reduce database load and improve application performance.
- [PostgreSQL Query Optimization: Indexes, EXPLAIN ANALYZE & Execution Plans](https://mkabumattar.com/codesnippets/post/postgresql-query-optimization-indexes-explain) — Master PostgreSQL query optimization with practical examples. Learn EXPLAIN ANALYZE interpretation, effective index strategies, query rewriting, and connection pooling to identify and fix slow queries in production microservices.
- [Multi-Environment Secret Management with HashiCorp Vault](https://mkabumattar.com/codesnippets/post/hashicorp-vault-multi-environment-secrets) — Manage secrets securely across dev, staging, and production with HashiCorp Vault. This snippet demonstrates dynamic secret generation, rotation, and cross-environment secret syncing patterns.
- [Top 7 Open Source OCR Models for Document Processing](https://mkabumattar.com/codesnippets/post/top-7-open-source-ocr-models) — Explore the best open source OCR models for converting documents, images, and PDFs to text. Compare olmOCR, PaddleOCR, OCRFlux, and more with performance benchmarks and implementation guides.
- [Why printf Beats echo in Linux Scripts](https://mkabumattar.com/codesnippets/post/printf-beats-echo-linux-scripts) — Learn why printf is superior to echo for output in Linux scripts. Discover the reliability issues with echo, the advantages of printf, and when to use each command for better scripting practices.
- [Essential Bash Variables for Every Script](https://mkabumattar.com/codesnippets/post/essential-bash-variables) — Master the most useful Bash special parameters and environment variables. Learn how to use $0, $?, $@, $UID, $EUID, and XDG variables to write more robust and portable scripts.
- [Per-App Shell History for Zsh](https://mkabumattar.com/codesnippets/post/zsh-per-app-history) — Keep your Zsh history organized across different terminal applications. This snippet automatically creates separate history files for each terminal emulator you use.
- [Per-App Shell History for Bash](https://mkabumattar.com/codesnippets/post/bash-per-app-history) — Keep your Bash history organized across different terminal applications. This snippet automatically creates separate history files for each terminal emulator you use.
- [Optimizing your python code with __slots__?](https://mkabumattar.com/codesnippets/post/python-slots-optimization) — Discover how Python `__slots__` can reduce memory usage by up to 40% in data-heavy applications. Perfect for MLOps pipelines and big data processing where millions of objects consume precious memory resources.
- [List S3 Buckets](https://mkabumattar.com/codesnippets/post/python-list-s3-buckets) — Automate AWS S3 interactions. This Python snippet uses Boto3 to easily list all S3 buckets in your account.
- [AWS Secrets Manager](https://mkabumattar.com/codesnippets/post/nodejs-aws-secrets-manager) — Access secrets securely in your Node.js apps. This snippet demonstrates fetching sensitive data from AWS Secrets Manager.
- [Check S3 Bucket Existence](https://mkabumattar.com/codesnippets/post/bash-s3-bucket-exists) — Validate AWS S3 bucket presence in your scripts. This Bash snippet efficiently checks if a bucket exists before proceeding with operations.
# DevTips
14 entries.
- [Kubernetes Namespaces: Organize, Isolate, and Secure Multi-Team Clusters](https://mkabumattar.com/devtips/post/kubernetes-namespaces-organize-isolate-multi-team) — Sharing one Kubernetes cluster across teams without the chaos. This dev tip walks through layered namespace isolation: ResourceQuotas, LimitRanges, default-deny NetworkPolicies, and namespace-scoped RBAC, with copy-paste manifests and a Terraform example.
- [Helm Charts: Templating & Multi-Environment Kubernetes Deployments](https://mkabumattar.com/devtips/post/helm-charts-kubernetes-multi-environment) — Master Helm Charts for Kubernetes deployments. Learn templating, values overrides, conditional logic, chart dependencies, and GitOps workflows to manage complex microservices across dev, staging, and production environments.
- [Structured Logging & Log Aggregation with ELK Stack](https://mkabumattar.com/devtips/post/structured-logging-elk-stack) — Learn centralized logging for microservices using Elasticsearch, Logstash, and Kibana. This guide covers structured logging best practices, log pipeline setup, Kibana dashboards, alerting strategies, and log retention policies for production observability.
- [Container Image Vulnerability Scanning in CI/CD with Trivy](https://mkabumattar.com/devtips/post/container-image-vulnerability-scanning-trivy) — Learn how to automate container image vulnerability scanning in your CI/CD pipeline using Trivy. This guide covers setup, integration strategies, policy enforcement, and remediation workflows to secure your container supply chain.
- [Policy-as-Code Governance with OPA/Rego](https://mkabumattar.com/devtips/post/policy-as-code-opa-rego) — Learn how to enforce infrastructure standards across your DevOps pipeline using Open Policy Agent (OPA). This guide covers policy writing in Rego, integration with Terraform and Kubernetes, and automating compliance checks in CI/CD pipelines.
- [Setting Up GitHub Copilot Agent Skills in Your Repository](https://mkabumattar.com/devtips/post/github-copilot-agent-skills-setup) — Learn how to create custom Agent Skills for GitHub Copilot following the agentskills.io open standard. This guide walks you through folder structure, SKILL.md configuration, progressive disclosure, and enabling the feature to teach Copilot specialized capabilities.
- [7 Reasons Learning the Linux Terminal is Worth It (Even for Beginners)](https://mkabumattar.com/devtips/post/7-reasons-learning-linux-terminal-worth-it-beginners) — Discover why learning the Linux terminal is essential for developers. From remembering commands to automation benefits, explore 7 compelling reasons that make terminal skills invaluable in modern computing.
- [Docker Is Eating Your Disk Space (And How PruneMate Fixes It)](https://mkabumattar.com/devtips/post/docker-disk-space-prunemate) — Your Docker host is slowly filling up with unused images, orphaned volumes, and stale build cache. Manual cleanup feels risky, and you might accidentally delete the wrong thing. Here's how PruneMate automates Docker maintenance across your home lab with scheduled cleanup, remote host support, and a clean interface that shows exactly what you're deleting before you commit.
- [Understanding Kubernetes Services: ClusterIP vs NodePort vs LoadBalancer](https://mkabumattar.com/devtips/post/kubernetes-services-clusterip-nodeport-loadbalancer) — Confused about Kubernetes Service types? Learn when to use ClusterIP, NodePort, and LoadBalancer. This guide explains how each service type works, their best use cases, and why choosing the right one matters for your application's accessibility, security, and scalability in production.
- [Managing Terraform at Scale with Terragrunt](https://mkabumattar.com/devtips/post/terraform-terragrunt-wrappers) — Struggling with repetitive Terraform code across environments? Learn how Terragrunt and other wrappers help you keep your infrastructure DRY, manage state files, and scale your Terraform projects without the headaches. This guide covers why wrappers matter, how to implement them, and the benefits of cleaner code and easier multi-environment management.
- [HashiCorp Pulls the Plug on CDKTF](https://mkabumattar.com/devtips/post/cdktf-deprecation-hashicorp-terraform) — HashiCorp just deprecated CDKTF as of December 10, 2025. If you built your infrastructure in TypeScript, Python, or Go to avoid HCL, here's what you need to know about your migration options and why vendor lock-in just bit again.
- [Tracing Microservices with OpenTelemetry](https://mkabumattar.com/devtips/post/tracing-microservices-opentelemetry) — Struggling to monitor your microservices? Learn how OpenTelemetry can help you trace requests across distributed systems. This guide covers the basics of setting up OpenTelemetry, visualizing traces, and quickly identifying bottlenecks or errors. Improve your system's reliability and gain clear insights into your microservices architecture!
- [Organizing Terraform with Modules](https://mkabumattar.com/devtips/post/organizing-terraform-modules) — Tired of messy Terraform code? Learn how to organize your infrastructure projects using modules. This guide explains why modules are essential for managing growing infrastructure, how to create and use them for reusable components, and the benefits of cleaner code, faster updates, and improved team collaboration. Keep your Terraform projects tidy and efficient!
- [Securing CI/CD with IAM Roles](https://mkabumattar.com/devtips/post/securing-cicd-with-iam-roles) — Learn how to secure your CI/CD pipeline by implementing IAM roles with least privilege. This guide explains why it's crucial, how to set up environment-specific roles, and the benefits of enhanced security, early issue detection, and easier audits. Keep your software delivery process safe and robust!
# Flashcards
8 entries.
- [AWS SysOps Administrator Associate Flashcards (SOA-C02)](https://mkabumattar.com/flashcards/post/aws-sysops-administrator-associate-flashcards) — Full exam coverage for the AWS Certified SysOps Administrator Associate (SOA-C02) exam using spaced repetition. Covers monitoring, reliability, deployment, security, networking, and cost optimization.
- [LPIC-2 Linux Engineer Flashcards](https://mkabumattar.com/flashcards/post/lpic-2-linux-engineer-flashcards) — Full exam coverage for the LPIC-2 Linux Engineer certification (Exam 201 & 202) using spaced repetition. Covers kernel, boot, storage, networking, security, DNS, web, email, and more.
- [AWS Certified Developer Associate Flashcards (DVA-C02)](https://mkabumattar.com/flashcards/post/aws-certified-developer-associate-flashcards) — Full exam coverage for the AWS Certified Developer – Associate (DVA-C02) exam using spaced repetition. Covers Development, Security, Deployment, Troubleshooting, and AWS SDK/CLI/APIs.
- [Red Hat System Administration I Flashcards (RH124)](https://mkabumattar.com/flashcards/post/redhat-system-administration-rh124-flashcards) — Full course coverage for Red Hat System Administration I (RH124-9.0) using spaced repetition. Covers CLI, files, users, processes, networking, storage, DNF, systemd, logging, and shell scripting.
- [AWS Solutions Architect Associate Flashcards (SAA-C03)](https://mkabumattar.com/flashcards/post/aws-solutions-architect-associate-flashcards) — Full exam coverage for the AWS Certified Solutions Architect – Associate (SAA-C03) exam. Covers all four domains Resilient, High-Performing, Secure, and Cost-Optimized Architectures.
- [AWS Cloud Practitioner Flashcards (CLF-C02)](https://mkabumattar.com/flashcards/post/aws-cloud-practitioner-flashcards) — Full exam coverage for the AWS Certified Cloud Practitioner (CLF-C02) exam using spaced repetition. Covers Cloud Concepts, Security, Technology, and Billing.
- [AWS Beginner Flashcards](https://mkabumattar.com/flashcards/post/aws-beginner-flashcards) — Core AWS concepts across Compute, Storage, Networking, Databases, IAM, Serverless, Monitoring, and High Availability for beginners using spaced repetition.
- [JavaScript Intermediate Flashcards](https://mkabumattar.com/flashcards/post/javascript-intermediate-flashcards) — Intermediate and advanced JavaScript concepts for deeper mastery using spaced repetition.
# Glossary Index
4 entries.
- [Networking Fundamentals](https://mkabumattar.com/glossary/post/networking-fundamentals) — Core networking terms every developer and engineer should know, from IP addressing and DNS to protocols, routing, and the OSI model.
- [Linux Server Administration](https://mkabumattar.com/glossary/post/linux-server-administration) — Essential terms every Linux system administrator and DevOps engineer should know.
- [Containers & Kubernetes](https://mkabumattar.com/glossary/post/containers-and-kubernetes) — Essential terms every DevOps engineer should know about containers and Kubernetes.
- [DevOps Basics](https://mkabumattar.com/glossary/post/devops-basics) — Essential terms every DevOps and cloud engineer should know.
# Quizzes
60 entries.
- [Rust: Ownership, Borrowing & Memory Safety](https://mkabumattar.com/quizzes/post/rust-fundamentals-quiz) — Test your knowledge of Rust fundamentals covering ownership, borrowing, lifetimes, traits, pattern matching, error handling, and memory-safe systems programming without a garbage collector.
- [System Design & Architecture: Scalability & Resilience](https://mkabumattar.com/quizzes/post/system-design-architecture-quiz) — Master system design: scalability, reliability, performance, trade-offs, distributed systems patterns, and architectural decisions for production systems.
- [Testing Strategies: Unit, Integration, E2E](https://mkabumattar.com/quizzes/post/testing-strategies-quiz) — Master comprehensive testing: unit testing, integration testing, end-to-end testing, mocking, fixtures, coverage goals, and CI/CD integration.
- [TypeScript Advanced: Types, Generics, Utility Types](https://mkabumattar.com/quizzes/post/typescript-advanced-quiz) — Master TypeScript: advanced types, generics, utility types, decorators, and type-safe patterns for scalable codebases.
- [Kubernetes Advanced: Production Operations & Scaling](https://mkabumattar.com/quizzes/post/kubernetes-advanced-quiz) — Master Kubernetes at scale: stateful applications, networking, storage, security policies, autoscaling, and production troubleshooting.
- [WebAssembly (WASM): Performance & Interoperability](https://mkabumattar.com/quizzes/post/webassembly-wasm-quiz) — Master WebAssembly: near-native performance in browser, non-browser use cases, toolchains (Rust, C++), and integration with JavaScript.
- [Multi-Cloud Strategy & Architecture](https://mkabumattar.com/quizzes/post/multicloud-strategy-quiz) — Master multi-cloud deployments: AWS, Azure, GCP, vendor lock-in prevention, cost optimization, disaster recovery across clouds.
- [Azure Advanced: App Service, Functions, Container Instances](https://mkabumattar.com/quizzes/post/azure-advanced-quiz) — Master Azure at scale: App Service, Azure Functions, Container Instances, Azure SQL, CI/CD pipelines, and enterprise cloud patterns.
- [Advanced Frontend Patterns: State Management & Performance](https://mkabumattar.com/quizzes/post/advanced-frontend-patterns-quiz) — Master advanced frontend architecture: state management (Redux, Zustand), performance optimization, code splitting, lazy loading, and responsive design patterns.
- [AWS Advanced: EC2, RDS, Lambda, CloudFormation](https://mkabumattar.com/quizzes/post/aws-advanced-quiz) — Master AWS at scale: EC2 instance types, RDS databases, Lambda functions, CloudFormation infrastructure as code, and AWS architecture patterns.
- [Flutter: Cross-Platform Mobile Development](https://mkabumattar.com/quizzes/post/flutter-mobile-quiz) — Build native iOS/Android apps with Flutter: widgets, state management, navigation, performance, and publishing to app stores.
- [Production Backend: Scaling, Monitoring & Reliability](https://mkabumattar.com/quizzes/post/production-backend-scaling-quiz) — Run production backend systems: scaling patterns, monitoring, error handling, logging, resilience, capacity planning, and incident response.
- [Astro: Building Fast Web Experiences](https://mkabumattar.com/quizzes/post/astro-fundamentals-quiz) — Build lightning-fast websites with Astro: island architecture, partial hydration, content collections, integrations, and zero JavaScript by default.
- [Async JavaScript: Promises, Async/Await, Event Loop](https://mkabumattar.com/quizzes/post/async-javascript-promises-quiz) — Master asynchronous JavaScript: callbacks, Promises, async/await, event loop, microtasks. Essential for modern backend and frontend development.
- [React Native: Cross-Platform Mobile Development](https://mkabumattar.com/quizzes/post/react-native-mobile-quiz) — Build native iOS/Android apps with React Native: components, navigation, state management, performance optimization, and deploying to app stores.
- [Database Design & Patterns](https://mkabumattar.com/quizzes/post/database-design-patterns-quiz) — Master database design: normalization, indexing, query optimization, ACID, transactions, sharding, replication, and enterprise patterns for scalable systems.
- [Advanced CSS: Layouts, Modern Features & Performance](https://mkabumattar.com/quizzes/post/advanced-css-layouts-quiz) — Master advanced CSS: Grid, custom properties, animations, transforms, performance optimization. Build sophisticated, responsive layouts with modern techniques.
- [Vue.js Fundamentals: Reactive Components & Templates](https://mkabumattar.com/quizzes/post/vuejs-fundamentals-quiz) — Master Vue.js basics: reactive data, templates, components, directives (v-if, v-for), event handling, and computed properties. Build interactive UIs with Vue.
- [Responsive Web Design: Mobile-First & Breakpoints](https://mkabumattar.com/quizzes/post/responsive-design-quiz) — Master responsive design: mobile-first approach, media queries, flexible layouts, viewport settings, and testing. Build sites that work on all devices.
- [Advanced API Architecture & Design Patterns](https://mkabumattar.com/quizzes/post/advanced-api-architecture-quiz) — Master advanced API design: REST, gRPC, webhooks, API versioning, caching strategies, pagination, and enterprise patterns for scalable integrations.
- [Infrastructure Patterns: IaC, Provisioning & Orchestration](https://mkabumattar.com/quizzes/post/infrastructure-patterns-quiz) — Master infrastructure patterns: Infrastructure as Code, provisioning, configuration management, orchestration. Design scalable, maintainable infrastructure.
- [Node.js & Express Fundamentals: Building Server Applications](https://mkabumattar.com/quizzes/post/nodejs-express-fundamentals-quiz) — Master Node.js and Express basics: server creation, routing, middleware, request/response handling, error handling, and REST API development.
- [React Fundamentals: Components, Hooks & State Management](https://mkabumattar.com/quizzes/post/react-fundamentals-quiz) — Master React basics: components, JSX, hooks (useState, useEffect), state management, props, and event handling. Build modern interactive UIs with React.
- [HTML Semantics & Web Accessibility](https://mkabumattar.com/quizzes/post/html-semantics-accessibility-quiz) — Master HTML semantics and web accessibility: semantic tags, ARIA attributes, WCAG guidelines, keyboard navigation, screen readers. Build inclusive web experiences.
- [API Security & Authentication: Protecting Your APIs](https://mkabumattar.com/quizzes/post/api-security-authentication-quiz) — Master API security fundamentals: authentication, authorization, OAuth2, JWT, API keys, HTTPS, rate limiting, CORS, and common vulnerabilities. Secure your APIs against attacks.
- [Observability Stack: Monitoring, Logging & Tracing](https://mkabumattar.com/quizzes/post/observability-stack-quiz) — Master observability fundamentals: monitoring with metrics, structured logging, distributed tracing, and observability practices. Learn to build observable systems and debug production issues.
- [CSS Fundamentals: Selectors, Box Model & Styling](https://mkabumattar.com/quizzes/post/css-fundamentals-quiz) — Master CSS fundamentals: selectors, box model, properties, layout basics, and styling techniques. Build the foundation for web design and responsive layouts.
- [GraphQL Fundamentals: Queries, Mutations & Schema Design](https://mkabumattar.com/quizzes/post/graphql-fundamentals-quiz) — Master GraphQL foundations: queries, mutations, subscriptions, and schema design.
- [GitOps at Scale: ArgoCD, Flux & Multi-Cluster Deployments](https://mkabumattar.com/quizzes/post/gitops-at-scale-quiz) — Master GitOps patterns for multi-cluster Kubernetes deployments using ArgoCD and Flux v2.
- [Istio: Service Mesh Fundamentals](https://mkabumattar.com/quizzes/post/istio-service-mesh-fundamentals-quiz) — Master the fundamentals of Service Mesh, traffic routing, and mutual TLS security within a Kubernetes environment.
- [Elasticsearch: Full-Text Search Engine Fundamentals](https://mkabumattar.com/quizzes/post/elasticsearch-search-engine-fundamentals-quiz) — Test your knowledge on full-text search, document indexing, and log analysis using Elasticsearch and Kibana.
- [MongoDB: NoSQL Database Fundamentals](https://mkabumattar.com/quizzes/post/mongodb-nosql-fundamentals-quiz) — Master NoSQL fundamentals, BSON document structure, and the MongoDB aggregation pipeline.
- [SQL: Query Fundamentals & Database Concepts](https://mkabumattar.com/quizzes/post/sql-query-fundamentals-quiz) — Master the fundamentals of Relational Databases, from basic SELECT statements to complex JOIN operations and database normalization.
- [Go: Programming Fundamentals & Concurrency](https://mkabumattar.com/quizzes/post/golang-programming-fundamentals-quiz) — Master the language of the cloud. Test your knowledge on Go syntax, types, and concurrency patterns.
- [Redis: In-Memory Caching & Data Structures](https://mkabumattar.com/quizzes/post/redis-caching-fundamentals-quiz) — Master the fundamentals of Redis, including in-memory data structures, caching patterns, and high-performance messaging.
- [Nginx: Web Server Fundamentals](https://mkabumattar.com/quizzes/post/nginx-web-server-fundamentals-quiz) — Test your knowledge of Nginx configuration, reverse proxying, load balancing, and SSL/TLS termination.
- [Packer: Infrastructure Image Building Fundamentals](https://mkabumattar.com/quizzes/post/packer-image-building-fundamentals-quiz) — Master automated machine image creation with this quiz on Packer builders, provisioners, and HCL templates.
- [HashiCorp Vault: Secrets Management Fundamentals](https://mkabumattar.com/quizzes/post/vault-secrets-management-quiz) — Master secrets management with this quiz on HashiCorp Vault engines, dynamic secrets, and the seal/unseal process.
- [Google Cloud Platform: GCP Essentials](https://mkabumattar.com/quizzes/post/gcp-essentials-quiz) — Master the fundamentals of Google Cloud, including Project hierarchy, Compute Engine, GKE, and IAM.
- [Azure: Cloud Services & Architecture Fundamentals](https://mkabumattar.com/quizzes/post/azure-architecture-essentials-quiz) — Master the fundamentals of Microsoft Azure, from core services like VMs and Networking to Azure DevOps and Resource Management.
- [Prometheus & Grafana: Monitoring & Observability Fundamentals](https://mkabumattar.com/quizzes/post/prometheus-grafana-monitoring-quiz) — Test your monitoring and observability skills with this quiz on Prometheus metrics, PromQL, Grafana dashboards, and alerting logic.
- [Helm: Kubernetes Package Management Essentials](https://mkabumattar.com/quizzes/post/helm-kubernetes-package-management-quiz) — Master Kubernetes package management with this quiz on Helm Charts, templates, values overrides, and release management.
- [GitLab CI/CD: Pipeline Automation Fundamentals](https://mkabumattar.com/quizzes/post/gitlab-cicd-pipeline-quiz) — Test your mastery of GitLab CI/CD fundamentals, including .gitlab-ci.yml structure, Runner architecture, Pipeline stages, and environment management.
- [GitHub Actions: Workflow Automation Essentials](https://mkabumattar.com/quizzes/post/github-actions-workflow-automation-quiz) — Master GitHub Actions fundamentals with this quiz covering Workflows, YAML syntax, the Actions Marketplace, Matrix builds, and secure secret management.
- [Jenkins: CI/CD Automation & Pipeline Management](https://mkabumattar.com/quizzes/post/jenkins-automation-fundamentals-quiz) — Test your knowledge of Jenkins fundamentals with this comprehensive quiz covering pipeline as code, Jenkinsfile syntax, agents, stages, build automation, plugins, distributed builds, Blue Ocean, and CI/CD best practices with Jenkins.
- [Terragrunt: Infrastructure as Code Management](https://mkabumattar.com/quizzes/post/terragrunt-iac-management-quiz) — Test your knowledge of Terragrunt fundamentals with this comprehensive quiz covering DRY principles, remote state management, module dependencies, configuration inheritance, run-all commands, hooks, and best practices for managing Terraform at scale.
- [CI/CD: Pipeline Automation Essentials](https://mkabumattar.com/quizzes/post/cicd-pipeline-essentials-quiz) — Test your knowledge of CI/CD fundamentals with this comprehensive quiz covering continuous integration, continuous delivery, pipelines, deployment strategies, automated testing, Infrastructure as Code, and DevOps best practices.
- [Git: Version Control Fundamentals](https://mkabumattar.com/quizzes/post/git-version-control-fundamentals-quiz) — Test your knowledge of Git fundamentals with this comprehensive quiz covering commits, branches, merging, rebasing, remote repositories, staging, conflict resolution, and version control best practices.
- [Kubernetes: Container Orchestration Essentials](https://mkabumattar.com/quizzes/post/kubernetes-orchestration-essentials-quiz) — Test your knowledge of Kubernetes fundamentals with this comprehensive quiz covering Pods, Services, Deployments, StatefulSets, storage, networking, RBAC, autoscaling, and container orchestration best practices.
- [TypeScript: Typed JavaScript Fundamentals](https://mkabumattar.com/quizzes/post/typescript-fundamentals-quiz) — Test your knowledge of TypeScript fundamentals with this comprehensive quiz covering static typing, interfaces, generics, type guards, enums, classes, advanced types, and TypeScript best practices.
- [JavaScript: Language Fundamentals & Modern Features](https://mkabumattar.com/quizzes/post/javascript-fundamentals-quiz) — Test your knowledge of JavaScript fundamentals with this comprehensive quiz covering variables, data types, functions, promises, DOM manipulation, ES6 features, closures, and modern JavaScript programming best practices.
- [Python: Programming Fundamentals & Best Practices](https://mkabumattar.com/quizzes/post/python-programming-fundamentals-quiz) — Test your knowledge of Python fundamentals with this comprehensive quiz covering data types, functions, loops, conditionals, list comprehensions, classes, exception handling, and Python programming best practices.
- [ArgoCD: GitOps Automation with Kubernetes](https://mkabumattar.com/quizzes/post/argocd-gitops-automation-quiz) — Test your knowledge of ArgoCD fundamentals with this comprehensive quiz covering GitOps principles, application deployment, sync policies, health status, ApplicationSets, and continuous delivery best practices for Kubernetes.
- [PowerShell: Windows Scripting Fundamentals](https://mkabumattar.com/quizzes/post/powershell-scripting-fundamentals-quiz) — Test your knowledge of PowerShell fundamentals with this comprehensive quiz covering cmdlets, pipelines, objects, variables, execution policies, functions, scripting best practices, and Windows automation.
- [Bash: Shell Scripting Fundamentals](https://mkabumattar.com/quizzes/post/bash-shell-scripting-fundamentals-quiz) — Test your knowledge of Bash scripting fundamentals with this comprehensive quiz covering variables, conditionals, loops, functions, I/O redirection, special parameters, and shell scripting best practices.
- [Linux: System Administration Fundamentals](https://mkabumattar.com/quizzes/post/linux-system-administration-fundamentals-quiz) — Test your knowledge of Linux fundamentals with this comprehensive quiz covering essential commands, file system navigation, permissions, process management, package managers, and Linux administration best practices.
- [Docker: Containerization Fundamentals](https://mkabumattar.com/quizzes/post/docker-containerization-fundamentals-quiz) — Test your knowledge of Docker fundamentals with this comprehensive quiz covering containers, images, Dockerfiles, networking, volumes, Docker Compose, and containerization best practices.
- [Ansible: Configuration Management & Automation](https://mkabumattar.com/quizzes/post/ansible-automation-fundamentals-quiz) — Test your knowledge of Ansible fundamentals with this comprehensive quiz covering playbooks, modules, inventory management, handlers, roles, and automation best practices.
- [AWS: Cloud Services & Architecture Fundamentals](https://mkabumattar.com/quizzes/post/aws-architecture-essentials-quiz) — Test your knowledge of AWS fundamentals with this comprehensive quiz covering key services, architecture, security, and best practices.
- [Terraform: Infrastructure as Code Essentials](https://mkabumattar.com/quizzes/post/terraform-essentials-quiz) — Test your knowledge of Terraform fundamentals with this quiz covering key concepts and best practices.
# Roadmaps
6 entries.
- [Frontend Developer Beginner to Expert](https://mkabumattar.com/roadmaps/post/frontend-developer-roadmap) — A comprehensive roadmap to master frontend development from HTML, CSS, and JavaScript fundamentals to modern frameworks, state management, performance, and accessibility.
- [Release Engineer Beginner to Expert](https://mkabumattar.com/roadmaps/post/release-engineer-roadmap) — A comprehensive roadmap to master Release Engineering from version control and CI/CD fundamentals to advanced cloud automation, Infrastructure as Code, and GitOps delivery on AWS.
- [Site Reliability Engineer Beginner to Expert](https://mkabumattar.com/roadmaps/post/site-reliability-engineer-roadmap) — A comprehensive roadmap to master Site Reliability Engineering from Linux and networking fundamentals to advanced SLOs, observability, incident management, and automation on AWS.
- [Solutions Architect Beginner to Expert](https://mkabumattar.com/roadmaps/post/solutions-architect-roadmap) — A comprehensive roadmap to master Solutions Architecture from cloud fundamentals to advanced AWS design patterns, security, compliance, and scalable distributed systems.
- [DevOps Engineer Beginner to Expert](https://mkabumattar.com/roadmaps/post/devops-engineer-roadmap) — A comprehensive roadmap to master DevOps engineering from Linux fundamentals to advanced cloud-native and platform engineering concepts.
- [JavaScript Beginner to Expert](https://mkabumattar.com/roadmaps/post/javascript-developer-roadmap) — A comprehensive roadmap to master JavaScript from core language fundamentals to frontend, Node.js backend, and modern ecosystem tooling.
# Series
40 series.
- [Advanced Frontend Techniques](https://mkabumattar.com/series/advanced-frontend-techniques) — 3 posts (Quizzes)
- [Amazon Linux 2 LAMP Stack Setup](https://mkabumattar.com/series/amazon-linux-2-lamp-stack-setup) — 4 posts (Blog)
- [APIs & Advanced Architecture](https://mkabumattar.com/series/apis--advanced-architecture) — 3 posts (Quizzes)
- [AWS Automation](https://mkabumattar.com/series/aws-automation) — 3 posts (Codesnippets)
- [AWS Bastion Host Setup](https://mkabumattar.com/series/aws-bastion-host-setup) — 2 posts (Blog)
- [AWS CLI Guides](https://mkabumattar.com/series/aws-cli-guides) — 4 posts (Blog)
- [AWS EC2 Interconnection](https://mkabumattar.com/series/aws-ec2-interconnection) — 2 posts (Blog)
- [Backend Programming](https://mkabumattar.com/series/backend-programming) — 3 posts (Quizzes)
- [Bash Snippets](https://mkabumattar.com/series/bash-snippets) — 1 post (Codesnippets)
- [CI/CD & GitOps](https://mkabumattar.com/series/cicd--gitops) — 6 posts (Quizzes)
- [Cloud Platforms & Architecture](https://mkabumattar.com/series/cloud-platforms--architecture) — 4 posts (Quizzes)
- [Container Security & DevSecOps](https://mkabumattar.com/series/container-security--devsecops) — 1 post (Devtips)
- [Containers & Kubernetes](https://mkabumattar.com/series/containers--kubernetes) — 4 posts (Quizzes)
- [Database Optimization](https://mkabumattar.com/series/database-optimization) — 1 post (Codesnippets)
- [Databases & Data Persistence](https://mkabumattar.com/series/databases--data-persistence) — 4 posts (Quizzes)
- [DevOps & CI/CD Pipelines](https://mkabumattar.com/series/devops--cicd-pipelines) — 8 posts (Blog, Devtips)
- [DevOps & Infrastructure as Code](https://mkabumattar.com/series/devops--infrastructure-as-code) — 4 posts (Quizzes)
- [Docker Essentials](https://mkabumattar.com/series/docker-essentials) — 3 posts (Blog)
- [Frontend Essentials](https://mkabumattar.com/series/frontend-essentials) — 4 posts (Quizzes)
- [Frontend Frameworks & Mobile](https://mkabumattar.com/series/frontend-frameworks--mobile) — 4 posts (Quizzes)
- [Git SSH Keys Setup](https://mkabumattar.com/series/git-ssh-keys-setup) — 2 posts (Blog)
- [Infrastructure & Governance](https://mkabumattar.com/series/infrastructure--governance) — 1 post (Devtips)
- [Infrastructure as Code Mastery](https://mkabumattar.com/series/infrastructure-as-code-mastery) — 6 posts (Blog)
- [Jenkins CI/CD with AWS](https://mkabumattar.com/series/jenkins-cicd-with-aws) — 3 posts (Blog)
- [Kubernetes & Container Orchestration](https://mkabumattar.com/series/kubernetes--container-orchestration) — 1 post (Devtips)
- [Kubernetes Deep Dive](https://mkabumattar.com/series/kubernetes-deep-dive) — 4 posts (Blog, Devtips)
- [Kubernetes Operations](https://mkabumattar.com/series/kubernetes-operations) — 1 post (Devtips)
- [Linux & System Administration](https://mkabumattar.com/series/linux--system-administration) — 4 posts (Quizzes)
- [Linux Essentials](https://mkabumattar.com/series/linux-essentials) — 3 posts (Blog, Codesnippets, Devtips)
- [Mastering Terraform](https://mkabumattar.com/series/mastering-terraform) — 8 posts (Blog, Devtips)
- [Monitoring, Security & Infrastructure](https://mkabumattar.com/series/monitoring-security--infrastructure) — 5 posts (Quizzes)
- [Node.js Backend Essentials](https://mkabumattar.com/series/nodejs-backend-essentials) — 1 post (Codesnippets)
- [Node.js Express TypeScript Setup](https://mkabumattar.com/series/nodejs-express-typescript-setup) — 2 posts (Blog)
- [Observability & Monitoring](https://mkabumattar.com/series/observability--monitoring) — 1 post (Devtips)
- [Performance & Scaling](https://mkabumattar.com/series/performance--scaling) — 1 post (Codesnippets)
- [Programming Languages](https://mkabumattar.com/series/programming-languages) — 1 post (Quizzes)
- [QuenchWorks](https://mkabumattar.com/series/quenchworks) — 1 post (Case studies)
- [Secret Management](https://mkabumattar.com/series/secret-management) — 1 post (Codesnippets)
- [Shell Mastery](https://mkabumattar.com/series/shell-mastery) — 2 posts (Codesnippets)
- [Spring Boot on AWS](https://mkabumattar.com/series/spring-boot-on-aws) — 2 posts (Blog)