Dom Fradley
- ▸ ai-capex-audit-platform-team.md · 28 jul 2026
The AI capex audit lands on the platform team
Markets stopped applauding AI infrastructure spend this month and started asking what it returns. That question travels down the org chart until it reaches whoever can answer it, and the Terraform tooling that answers it shipped in the last two weeks.
read → - ▸ azure-iac-july-2026.md · 27 jul 2026
This month in Azure IaC: AVM landing zones go GA, azurerm 4.81, OpenTofu 1.12
A short monthly round-up of what changed in Terraform, the Azure provider and the wider IaC world, in plain English, with why each one matters. July 2026.
read → - ▸ pricing-the-design.md · 27 jul 2026
Your architect should be able to price the design
A cloud design that ships without a cost is half a design. Why owning the number produces better architecture, and the one question a leader should always ask.
read → - ▸ identity-is-the-perimeter.md · 26 jul 2026
Identity is your security perimeter now
The firewall stopped being the front door a while ago. In a cloud estate, identity is where an attacker gets in or gets stopped, so it's where the design attention belongs.
read → - ▸ virtual-wan-vs-hub-and-spoke.md · 25 jul 2026
Virtual WAN vs hub-and-spoke: a cost-of-management decision
Virtual WAN gets picked because it sounds like the grown-up option. Here's the actual trade against hub-and-spoke, and how to decide it on arithmetic rather than instinct.
read → - ▸ is-your-cloud-under-control.md · 24 jul 2026
Five questions that tell you if your cloud is under control
You don't need to read Terraform to know whether your cloud estate is in good shape. Five plain questions, and what a confident answer sounds like.
read → - ▸ cloud-cost-as-a-design-decision.md · 23 jul 2026
Make your Azure bill predictable: cost as a design decision
A shocking cloud bill is usually a governance gap, not a pricing problem. Here's how to make spend a design decision so the invoice stops surprising you.
read → - ▸ find-public-storage.md · 22 jul 2026
Find your public-facing storage before someone else does
A storage account open to the public is a common way cloud data leaks. Find every one across your estate in about thirty seconds with one query.
read → - ▸ allowed-locations-policy.md · 21 jul 2026
Keep Azure in the right regions: the allowed-locations policy
Stop resources landing in the wrong region. Azure's built-in allowed-locations policy is a real compliance control you can assign in a few lines of Terraform.
read → - ▸ resource-locks-prevent-deletion.md · 20 jul 2026
Stop someone deleting prod: resource locks in one line
Someone runs az group delete on the wrong resource group and prod is gone. A resource lock is the cheapest insurance in Azure, and it's one command.
read → - ▸ budget-alerts-as-code.md · 19 jul 2026
Never get surprised by the Azure bill: budget alerts as code
The worst way to learn your spend doubled is the invoice. A monthly budget with an alert, in a few lines of Terraform, turns a surprise into an email at 80%.
read → - ▸ enforce-azure-tags-as-code.md · 18 jul 2026
Untagged Azure resources: find them today, enforce tags as code tomorrow
Every Azure estate drifts into untagged chaos. Two moves any admin can run this week: find every untagged resource with one query, then stop it happening again with a policy defined as code.
read → - ▸ what-is-infrastructure-as-code.md · 17 jul 2026
Infrastructure as Code, explained: why serious Azure teams stopped clicking around
You start in the Azure portal, clicking. It works, right up until you need to do it again. A friendly on-ramp to Infrastructure as Code, and the idea that changes how you build.
read →