The Policy-as-Code Decision That Doesn't Bite You Until Later
The policy-as-code choice between OPA and Cedar feels low-stakes at ten accounts. It stops feeling that way at 500.
zopdev writing tagged terraform. Engineering and FinOps notes, post-mortems, and benchmarks.
The policy-as-code choice between OPA and Cedar feels low-stakes at ten accounts. It stops feeling that way at 500.
Fourteen new MCP tools let an agent create, dry-run and manage IaC pull-request policies. The two withheld tools are the ones that bypass the gate.
The autoscaler decision you made at 50 nodes becomes a structural liability at 10,000. By the time the cluster grows to enterprise scale, the choice is load-bearing infrastructure. Replacing it…
Policy as Code works cleanly until it meets ten teams, and then it breaks in ways the pilot never predicted. The first three months feel like a governance win. Policies deploy, violations get caught,…
HashiCorp's August 2023 switch from the Mozilla Public License to the Business Source License forced every infrastructure team running Terraform to make a governance decision they had not budgeted…
At 500 managed resources, infrastructure drift stops being a maintenance nuisance and becomes a misdiagnosis engine that corrupts incident response at the root.
Every time a team ships before governance is ready, they do not pay once. They pay every quarter the gap stays open.
Free cloud credits do not reduce your infrastructure costs. They defer them, invisibly, until expiration forces a full-price reckoning on a codebase that was never designed with billing in mind.
At 500 Terraform resources, the bottleneck is never Terraform. It is the organization running it.
Visibility without workflow integration is a cost center, not a cost cure. Most engineering organizations have invested in dashboards, tagging policies, and cost explorer tools. The spend keeps…
HashiCorp's August 2023 relicensing of Terraform from MPL-2.0 to the Business Source License 1.1 was not a routine legal update. It was a governance event that forced every infrastructure team to…
Ad-hoc policy management breaks down precisely at the point where account count and resource sprawl outpace human review cycles. Below 50 resources across two or three accounts, a shared spreadsheet…
At 200 resources, the architectural assumptions baked into every IaC tool become load-bearing walls, and some of those walls crack.
Prompt engineering entered DevOps not as an experiment but as a pressure valve: teams shipping faster than their tooling could support needed a way to extract precise, repeatable outputs from AI…
HashiCorp's August 2023 switch from the Mozilla Public License 2.0 to the Business Source License 1.1 drew a hard line between commercial and community use of Terraform, and that line fractured a…
HashiCorp's August 2023 relicense of Terraform from MPL-2.0 to the Business Source License forced every infrastructure team to make a governance decision, not a technical one.
Platform engineering teams are paying $180,000 per year in duplicate tooling costs without a line item that names it (ZopDev, "The IDP Tax"). That cost has a name: the IDP tax. It accumulates because…
Most IDPs ship as friction-reducers and land as a new category of sprint tax. The promise is a self-service portal that abstracts infrastructure complexity. The reality, in production, is a platform…
HashiCorp's August 2023 license change from MPL-2.0 to the Business Source License forced every team running Terraform in production to make a governance decision they had not budgeted for. The BSL…
Most engineering organizations budget precisely for building an Internal Developer Platform and budget nothing for operating one. The build cost is visible: headcount, tooling licenses, sprint…
Every Internal Developer Platform we have seen hits the same wall: feature shipping slows down at the three-month mark, not because the platform was built wrong, but because the forces that made…
IaC tools built for single-team deployments fail structurally at 200 accounts because the failure modes are architectural, not configurational.
Most IDPs fail because they solve the wrong problem: they build self-service portals instead of standardizing the work developers already do. We measured this in production. Teams spend six months…
Traditional cloud alerting creates more work than it prevents because engineers spend 60-90 minutes per day triaging notifications that describe problems without fixing them. The mechanism is…
Self-Service Terraform: 8 Modules That Killed 60% of Our Platform Tickets Platform teams do not fail because they hire the wrong people. They fail because the right people spend most of their time…
Configuration drift is the gap between what Terraform declares and what runs in production. AWS Config detects it in 15 minutes. Most teams find it in 72 hours. Here is how to close that gap.
One post a week. Sundays. No "10 ways to think about cloud" listicles, just the engineering and FinOps notes we'd want to read.
See. Find. Fix. Automatic.
Connect your first cloud account in under 5 minutes. See your first remediation in under 7. No credit card required.