Putting an LLM on a Leash: Gates, Budgets and Prompt Injection in a Kubernetes Operator

Part 2 built a gate: a content-addressed fingerprint that says whether a Finding’s content has changed since anything expensive last looked at it. There was no expensive thing yet. This part adds it. Wiring an LLM call into a reconcile loop is about twenty lines. Everything worth writing about is the constraints around those twenty lines: what the interface looks like, what stops the call happening, what happens when the budget runs out, and what stops third-party scanner output from issuing instructions to your model. ...

28 September 2026 · 9 min · Albert Asawaroengchai

When Reconciling Twice Costs Money: CRDs, Providers, and Content-Addressed Fingerprints

Part 1 was about the week before any code: research, positioning, naming, governance. This part is the code. The thing that makes this a useful way to learn the operator pattern is the constraint. Most operator tutorials reconcile something free. If your reconcile loop runs twice when it should run once, nothing happens, nobody notices. Here, an unnecessary reconcile can mean an unnecessary LLM call, and unnecessary LLM calls are exactly the failure mode documented in the incumbents: 164 findings turning into 9,300 model calls in three days. ...

20 September 2026 · 8 min · Albert Asawaroengchai

Read the Issue Tracker, Not the README: Researching Before Building an AI Ops Tool

I had an abandoned repo sitting on GitHub called kube-quota-watch. One commit, from 2021, no code. The kind of thing you start on a Sunday and never touch again. I wanted to build something real in that space: a Kubernetes operator that ingests security and reliability signals, uses an LLM to enrich them, and helps a team act on them. The obvious move was to open the editor and start scaffolding. ...

13 September 2026 · 10 min · Albert Asawaroengchai

From Commit to Cluster: A GitOps CI/CD Pipeline with GitHub Actions and ArgoCD

There is a gap between “I understand CI/CD in theory” and “I have built one and watched it work.” This post closes that gap. We will build a complete, production-patterned GitOps pipeline from scratch — running entirely on your local machine, at zero cost — and walk through every stage from raising a pull request to deploying to production. The two repos for this tutorial are: service-demo — the application code, Helm chart, and GitHub Actions workflows gitops-demo — the GitOps source of truth: ArgoCD configuration, environment values, and infrastructure bootstrap What We Are Building Developer pushes feature branch → PR opened → CI: lint, SCA, unit tests, integration tests → Image built → pushed to GHCR → Ephemeral environment pr-{N} deployed by ArgoCD (dev cluster) → Smoke tests run against ephemeral env → CODEOWNER approves → PR merged → CD: image built from main → main-{sha} → ArgoCD syncs preprod namespace (preprod cluster) → Full test suite runs against preprod → Check run posted to merge commit (release gate) → [Manual] Release workflow triggered → Preflight: HEAD commit must have passing preprod gate → Image retagged: main-{sha} → v{X.Y.Z} (no rebuild) → ArgoCD syncs prod namespace (prod cluster) → ArgoCD syncs dev namespace (dev cluster) — same tag, same bits For this tutorial, all four environments run as Kubernetes namespaces on a single local kind cluster — simple to bootstrap and zero infrastructure cost. In production the topology is different: ephemeral environments and dev share a single dev cluster, while preprod and prod each get their own. More on this in Production Considerations. ...

28 March 2026 · 18 min · Albert Asawaroengchai