<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>platform-engineering on Youssef El Jirari</title><link>https://eljirari.me/tags/platform-engineering/</link><description>Recent content in platform-engineering on Youssef El Jirari</description><generator>Hugo -- gohugo.io</generator><language>en</language><atom:link href="https://eljirari.me/tags/platform-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>Cilium vs Calico vs Flannel: Choose the Network You Can Operate</title><link>https://eljirari.me/posts/kubernetes-cni/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/kubernetes-cni/</guid><description>When people compare Kubernetes CNIs, the discussion quickly becomes a feature matrix.
Does it support NetworkPolicy? BGP? eBPF? Encryption? Observability?
Those are useful questions, but I think they miss the first one:
What networking problem does this cluster actually need the CNI to solve?
A three-node K3s cluster and a large multi-tenant Kubernetes platform do not need the same network architecture.
Start with what the CNI does A pod needs an IP address and it needs to communicate with other pods.</description></item><item><title>Azure Landing Zones: Centralize the Guardrails, Not Every Decision</title><link>https://eljirari.me/posts/azure-landing-zones/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://eljirari.me/posts/azure-landing-zones/</guid><description>An Azure landing zone is sometimes presented as a collection of subscriptions, policies and management groups that you deploy before application teams arrive.
That is technically true, but it undersells the problem.
The real objective is to make it possible for many teams to use Azure independently without every team having to redesign identity, networking, security, governance and operations from zero.
Why a landing zone appears With one subscription and one team, governance can be informal.</description></item></channel></rss>