Posts
All the articles I've posted.
From 12 to 60 Gbps with DPDK, when we tried to become a 5G-edge box
The sixth post in the CertaScale series. When private cloud proved a hard sell, the owners pivoted to 5G edge, and edge means line-rate on commodity hardware. Our kernel data path topped out around 12 Gbps on 100 Gbps NICs. Taking it out of the kernel with DPDK, hugepages, poll-mode drivers, and userspace-bound NICs got the same servers to roughly 60 Gbps.
Running VMs inside pods in 2016, before Kata existed
The fifth post in the CertaScale series, and the one the earlier posts kept promising: running full virtual machines inside Kubernetes pods in 2016, before Kata Containers existed and before RuntimeClass was a thing. A pod is just a namespace boundary and a lifecycle. Put KVM inside it and a VM schedules, migrates, and dies like a pod.
A flat network, GCP-style, on early Kubernetes
The fourth post in the CertaScale series, and the idea I'm proudest of: a flat overlay borrowed from how Google Cloud addresses machines. /32 addresses plus routes, an address operator handing out CRDs from a pool, and the reason we built all of it — moving a workload between nodes without it losing its IP.
Giving Kubernetes an enterprise network
The third post in the CertaScale series. Our customer was building a private cloud that had to drop into any enterprise's network, so we spoke the language every enterprise already speaks and extended it to Kubernetes pods: VLANs, static and DHCP addressing, and RFC 4594 QoS.
Finding ovn-kubernetes when it was seven days old
The second post in the CertaScale series. Handed a failed project and a title, I inherited a broken Vagrant file that created a single bridge, panic-googled my way to a week-old repo, learned OVS internals the hard way, and rewrote our side from Python to Go when the team changed.
The private cloud we built before it was cool
From 2016 to 2019 I helped build a private cloud on top of very early Kubernetes, with a drag-and-drop canvas, VMs running inside pods before Kata existed, and an enterprise-grade network layer I led, from GCP-style flat overlays to a 12-to-60 Gbps DPDK data path. The company is gone. The story shouldn't be.
I can run AI models on my gaming PC now
I bought a powerful GPU for gaming a couple of years ago. It turns out a Radeon 7900 XTX is also a perfectly good reason to run language models locally.
Designing agentic AI on Bedrock, a real-world journey
A support-ticket classifier that started as one enormous prompt costing $145k a year, went through a pile of overbuilt architectures, and ended as a deterministic pipeline with no agent in it at all, costing $744. Here's every wrong turn and what actually broke.
Shift-left, or catching bugs before they cost
In 2015 I gave a talk about building better CI with Jenkins pipelines. Ten years and half a dozen CI tools later, the tooling has changed completely and the core idea hasn't moved an inch. Here's the shift-left setup I run today, and why it's the same lesson I was giving in a conference room a decade ago.
Quantum computing, from someone who has to stay skeptical
I worked on a quantum computing platform. Here's the honest version of what quantum can and can't do today, and what it costs to run a real circuit yourself.