Read the Issue Tracker, Not the README: Researching Before Building an AI Ops Tool

I had an abandoned repo sitting on GitHub called kube-quota-watch. One commit, from 2021, no code. The kind of thing you start on a Sunday and never touch again. I wanted to build something real in that space: a Kubernetes operator that ingests security and reliability signals, uses an LLM to enrich them, and helps a team act on them. The obvious move was to open the editor and start scaffolding. ...

13 September 2026 · 10 min · Albert Asawaroengchai

When Reconciling Twice Costs Money: CRDs, Providers, and Content-Addressed Fingerprints

Part 1 was about the week before any code: research, positioning, naming, governance. This part is the code. The thing that makes this a useful way to learn the operator pattern is the constraint. Most operator tutorials reconcile something free. If your reconcile loop runs twice when it should run once, nothing happens, nobody notices. Here, an unnecessary reconcile can mean an unnecessary LLM call, and unnecessary LLM calls are exactly the failure mode documented in the incumbents: 164 findings turning into 9,300 model calls in three days. ...

20 September 2026 · 8 min · Albert Asawaroengchai

Putting an LLM on a Leash: Gates, Budgets and Prompt Injection in a Kubernetes Operator

Part 2 built a gate: a content-addressed fingerprint that says whether a Finding’s content has changed since anything expensive last looked at it. There was no expensive thing yet. This part adds it. Wiring an LLM call into a reconcile loop is about twenty lines. Everything worth writing about is the constraints around those twenty lines: what the interface looks like, what stops the call happening, what happens when the budget runs out, and what stops third-party scanner output from issuing instructions to your model. ...

28 September 2026 · 9 min · Albert Asawaroengchai