Putting an LLM on a Leash: Gates, Budgets and Prompt Injection in a Kubernetes Operator
Part 2 built a gate: a content-addressed fingerprint that says whether a Finding’s content has changed since anything expensive last looked at it. There was no expensive thing yet. This part adds it. Wiring an LLM call into a reconcile loop is about twenty lines. Everything worth writing about is the constraints around those twenty lines: what the interface looks like, what stops the call happening, what happens when the budget runs out, and what stops third-party scanner output from issuing instructions to your model. ...
When Reconciling Twice Costs Money: CRDs, Providers, and Content-Addressed Fingerprints
Part 1 was about the week before any code: research, positioning, naming, governance. This part is the code. The thing that makes this a useful way to learn the operator pattern is the constraint. Most operator tutorials reconcile something free. If your reconcile loop runs twice when it should run once, nothing happens, nobody notices. Here, an unnecessary reconcile can mean an unnecessary LLM call, and unnecessary LLM calls are exactly the failure mode documented in the incumbents: 164 findings turning into 9,300 model calls in three days. ...
Read the Issue Tracker, Not the README: Researching Before Building an AI Ops Tool
I had an abandoned repo sitting on GitHub called kube-quota-watch. One commit, from 2021, no code. The kind of thing you start on a Sunday and never touch again. I wanted to build something real in that space: a Kubernetes operator that ingests security and reliability signals, uses an LLM to enrich them, and helps a team act on them. The obvious move was to open the editor and start scaffolding. ...
Every Check Green, and GitHub Still Refuses to Merge
Here is a failure that will cost you an afternoon if you have not seen it before. You open a pull request. Every required status check goes green. There are no unresolved review threads. The GitHub UI says the branch has no conflicts. You click merge, and: X Pull request ... is not mergeable: the base branch policy prohibits the merge. No indication of which policy. No indication of which rule. You push another commit, wait for CI again, try again, and get the identical message. Meanwhile other pull requests in the same repository merge without complaint, so it looks like something specific to this branch, or like GitHub is having a bad day. ...
From Commit to Cluster: A GitOps CI/CD Pipeline with GitHub Actions and ArgoCD
There is a gap between “I understand CI/CD in theory” and “I have built one and watched it work.” This post closes that gap. We will build a complete, production-patterned GitOps pipeline from scratch — running entirely on your local machine, at zero cost — and walk through every stage from raising a pull request to deploying to production. The two repos for this tutorial are: service-demo — the application code, Helm chart, and GitHub Actions workflows gitops-demo — the GitOps source of truth: ArgoCD configuration, environment values, and infrastructure bootstrap What We Are Building Developer pushes feature branch → PR opened → CI: lint, SCA, unit tests, integration tests → Image built → pushed to GHCR → Ephemeral environment pr-{N} deployed by ArgoCD (dev cluster) → Smoke tests run against ephemeral env → CODEOWNER approves → PR merged → CD: image built from main → main-{sha} → ArgoCD syncs preprod namespace (preprod cluster) → Full test suite runs against preprod → Check run posted to merge commit (release gate) → [Manual] Release workflow triggered → Preflight: HEAD commit must have passing preprod gate → Image retagged: main-{sha} → v{X.Y.Z} (no rebuild) → ArgoCD syncs prod namespace (prod cluster) → ArgoCD syncs dev namespace (dev cluster) — same tag, same bits For this tutorial, all four environments run as Kubernetes namespaces on a single local kind cluster — simple to bootstrap and zero infrastructure cost. In production the topology is different: ephemeral environments and dev share a single dev cluster, while preprod and prod each get their own. More on this in Production Considerations. ...
OpenClaw Journey
The world of AI is shifting from chatbots that talk to agents that do. Over the past few months I’ve been building a self-hosted “24/7 Jarvis” that lives on my local hardware. This post is the full story — from picking the right OS to shipping a fully automated deployment pipeline. All the code lives in the openclaw-journey repo. The README is a TL;DR if you’re in a hurry; this post goes deeper. ...
Test Showcase
This post exercises the full range of text and code rendering. Everything here is drawn from the actual configuration files used to build and style this blog — no contrived examples. Typography Regular paragraph text at 1.05rem / Inter. The quick brown fox jumps over the lazy dog. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Proin commodo, urna vel gravida scelerisque, neque velit aliquam nunc, nec sodales risus libero at dolor. ...