Engineer from the Netherlands. Currently building systems for a national defence organisation, mostly Kubernetes and Go, with a focus on security. Open source maintainer across the Terraform and Kubernetes ecosystems, and Tech Lead in CNCF TAG Infrastructure.
When an air-gapped GDC site is no longer available, its export can't be applied anywhere else. One controller translates those CRDs into Config Connector resources and rebuilds the entire estate in public Google Cloud.
How VoidLink stages itself without touching disk, and the Tetragon TracingPolicy that kills each stage.
What tpm2_readclock actually returns on a confidential VM, and why freshness ends up being a nonce.
A small CLI for reading and exploring OCI container images without running them.
A guide to managing Google Cloud secrets in Terraform safely using ephemeral resources and write-only arguments.
Reflecting on the implementation of S3-native state locking in Terraform, highlighting the challenges, teamwork, and community feedback that made it a success.
If you were wondering why there isn't a generic HCL formatter, this post is for you.
How does AWS Lambda work under the hood? Let's find out together!