- ▸ half-built-landing-zone.md · 7 sep 2026
What to finish first in a half-built landing zone
A platform with sound foundations underneath it and four unfinished corners on top, with workloads still landing while you decide what to fix. Ranking the gaps by risk gives you an order you cannot defend the first time delivery comes asking for your engineers. Ranking them by how much each one costs to close after another quarter gives you one you can.
read → - ▸ lift-and-shift-end-date.md · 18 aug 2026
Lift-and-shift with a written end date
Rehost or re-architect gets argued as a matter of taste, and the deciding variable is commercial rather than technical: how long the workload has left, and whether it will change while it lasts. Lift-and-shift is a legitimate move with a written end date and a liability without one. Here is how to make that date something the estate can answer for itself.
read → - ▸ llm-endpoints-new-public-storage.md · 13 aug 2026
LLM endpoints are the new public storage accounts
Credential theft aimed at AI services rose 376% in a quarter, and Microsoft is in court with a group that resold stolen Azure OpenAI access. The LLM endpoint is this decade's default-shaped misconfiguration: deployed like an experiment, billed like a utility, and secured with a key from demo day. The three ways to host a model in Azure, and the controls you already own that make a stolen key worthless.
read → - ▸ tfpolicy-quiet-successor.md · 10 aug 2026
tfpolicy: HashiCorp's quiet successor to Sentinel
HashiCorp's new tfpolicy framework puts Terraform governance in Terraform's own language, in public beta now. Sentinel is still supported, and there is a new AI tool for converting Sentinel policies to the new format. Here is how a decision maker should read that, and the questions to ask before the beta hardens.
read → - ▸ azure-policy-out-of-the-box.md · 6 aug 2026
Azure Policy out of the box: 5,000 guardrails you already own
Microsoft ships just over 5,000 ready-written policy rules and about 270 grouped rule-sets with every Azure subscription, mapped to ISO 27001, NIST, PCI DSS and the UK OFFICIAL controls. They cost nothing to run, and the assignment count in your own subscription is a two-minute check.
read → - ▸ clickops-to-code.md · 3 aug 2026
From ClickOps to code, without the big-bang rewrite
Hand-built estates stay hand-built because everyone prices the fix as a rewrite. You can put Terraform in charge of what already exists, in place, without rebuilding any of it. Here's the order of attack.
read → - ▸ ai-capex-audit-platform-team.md · 28 jul 2026
The AI capex audit lands on the platform team
Markets stopped applauding AI infrastructure spend this month and started asking what it returns. That question travels down the org chart until it reaches whoever can answer it, and the Terraform tooling that answers it shipped in the last two weeks.
read → - ▸ is-your-cloud-under-control.md · 24 jul 2026
Five questions that tell you if your cloud is under control
You don't need to read Terraform to know whether your cloud estate is in good shape. Five plain questions, and what a confident answer sounds like.
read → - ▸ cloud-cost-as-a-design-decision.md · 23 jul 2026
Make your Azure bill predictable: cost as a design decision
A shocking cloud bill is usually a governance gap, not a pricing problem. Here's how to make spend a design decision so the invoice stops surprising you.
read →