<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Youssef El Jirari</title><link>https://eljirari.me/</link><description>Recent content on Youssef El Jirari</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 30 Aug 2023 22:53:30 +0100</lastBuildDate><atom:link href="https://eljirari.me/index.xml" rel="self" type="application/rss+xml"/><item><title>IPAM: Why We Need It and Why It Gets Hard at Scale</title><link>https://eljirari.me/posts/ipam-at-scale/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/ipam-at-scale/</guid><description>IP address management looks unnecessary when the environment is small.
You have a few VNets, somebody keeps a spreadsheet with the CIDRs, and before creating a new network you check that the range is not already used. It works.
Then the cloud estate grows.
You have tens or hundreds of subscriptions, multiple regions, separate production and non-production environments, connectivity hubs, private endpoints, on-premises networks and different teams deploying infrastructure independently. At that point, the problem is no longer which CIDR should I use?</description></item><item><title>Cilium vs Calico vs Flannel: Choose the Network You Can Operate</title><link>https://eljirari.me/posts/kubernetes-cni/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/kubernetes-cni/</guid><description>When people compare Kubernetes CNIs, the discussion quickly becomes a feature matrix.
Does it support NetworkPolicy? BGP? eBPF? Encryption? Observability?
Those are useful questions, but I think they miss the first one:
What networking problem does this cluster actually need the CNI to solve?
A three-node K3s cluster and a large multi-tenant Kubernetes platform do not need the same network architecture.
Start with what the CNI does A pod needs an IP address and it needs to communicate with other pods.</description></item><item><title>Azure Landing Zones: Centralize the Guardrails, Not Every Decision</title><link>https://eljirari.me/posts/azure-landing-zones/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/azure-landing-zones/</guid><description>An Azure landing zone is sometimes presented as a collection of subscriptions, policies and management groups that you deploy before application teams arrive.
That is technically true, but it undersells the problem.
The real objective is to make it possible for many teams to use Azure independently without every team having to redesign identity, networking, security, governance and operations from zero.
Why a landing zone appears With one subscription and one team, governance can be informal.</description></item><item><title>Shipping Fast vs Quality Code Is the Wrong Trade-off</title><link>https://eljirari.me/posts/shipping-fast-vs-quality/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/shipping-fast-vs-quality/</guid><description>Engineering discussions often frame delivery as a choice:
Do we ship fast, or do we do it properly?
I do not think that is the useful question.
Teams obviously need to ship. A perfect system that arrives six months too late has little value. But moving quickly by removing every quality control usually does not create sustained speed either. It creates deferred work that eventually appears as incidents, fragile deployments and engineers afraid to change the system.</description></item><item><title>It Compiled, But Will It Run? PE Files and .NET Dependency Resolution on Windows</title><link>https://eljirari.me/posts/dotnet-pe-dependencies/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/dotnet-pe-dependencies/</guid><description>A successful build proves that the compiler found what it needed at build time.
It does not prove that the application will find everything it needs when it runs on another Windows machine.
I learned this while working on binary dependency exploration for .NET applications. The objective sounded simple: take every binary we compile and verify that its dependencies can actually be resolved.
Then native DLLs, NuGet packages, .NET Framework, modern .</description></item><item><title>Containers: The Backstory</title><link>https://eljirari.me/posts/containers-thebackstory/</link><pubDate>Wed, 30 Aug 2023 22:53:30 +0100</pubDate><guid>https://eljirari.me/posts/containers-thebackstory/</guid><description>Back in my student days, I first bumped into Docker. It was all the rage then, and honestly, it blew my mind. The idea that you could take a piece of code, make it work anywhere in its own little space, separate from the computer&amp;rsquo;s main system – that was pretty cool. Later on, I found out Docker wasn&amp;rsquo;t the first to come up with this container and isolation stuff. In this blog post, I want to take you on a little trip back in time to check out who started it all.</description></item></channel></rss>