- ▸ firewall-rules-nobody-can-explain.md · 17 sep 2026
Don't migrate a firewall rule nobody can explain
FireMon's June 2026 analysis of 9.2 million firewall policy checks found 69% of rules unused and 45% with no owner or documentation. Migrations usually copy that kind of ruleset into the new landing zone, because a copied rule breaks nothing on cutover night. Rebuild it from sixty days of VNet flow logs instead, and give a flow a rule only when somebody can say what it is for.
read → - ▸ lift-and-shift-end-date.md · 18 aug 2026
Lift-and-shift with a written end date
Rehost or re-architect gets argued as a matter of taste, and the deciding variable is commercial rather than technical: how long the workload has left, and whether it will change while it lasts. Lift-and-shift is a legitimate move with a written end date and a liability without one. Here is how to make that date something the estate can answer for itself.
read → - ▸ clickops-to-code.md · 3 aug 2026
From ClickOps to code, without the big-bang rewrite
Hand-built estates stay hand-built because everyone prices the fix as a rewrite. You can put Terraform in charge of what already exists, in place, without rebuilding any of it. Here's the order of attack.
read →