Guides · AI & DevOps
AI & DevOps
AI coding agents can now write Terraform, open pull requests, and talk to your cluster — which raises exactly the questions this cluster answers: what to let them do, how to keep secrets and production out of their reach, and where human engineering judgment still earns its keep. Everything here is written from the practitioner side: we use these tools daily on real client infrastructure, with guardrails. If AI wrote your infrastructure and you're not sure it's production-grade, that's precisely what our audit checks.
Start here
AI for DevOps: The Complete Guide for Startups
Start here: where AI genuinely helps across the infrastructure lifecycle, the trust ladder from suggestion to apply, what to standardise, and the failure modes worth avoiding.
Read the full guide →
Run Claude Code on Bedrock, Vertex, or Foundry in CI
Route Claude Code GitHub Actions through your own AWS, GCP, or Azure account: OIDC trust setup per cloud, the secrets you need, and one public-repo trap.
Read the guide →
Claude Code in GitLab CI/CD: What the Setup Actually Takes
Claude Code runs in GitLab CI, but the integration is beta and GitLab-maintained. What you get out of the box, what you build yourself, and whether it's worth it.
Read the guide →
Claude Code in GitHub Actions: Setup, Triggers, and Hardening
Connect Claude Code to GitHub with /install-github-app, then harden it: App permissions, trigger rules, OIDC cloud auth, cost caps, and injection defenses.
Read the guide →
What to Actually Automate with Claude Code in CI
Automation mode runs Claude on a schedule or any GitHub event. The hard part isn't the workflow — it's knowing which recurring tasks survive being unattended.
Read the guide →
AI for DevOps: The Complete Guide for Startups
Where AI genuinely helps across the infrastructure lifecycle, the trust ladder from suggest to apply, and how a 5-25 engineer team adopts it safely.
Read the guide →
AGENTS.md vs CLAUDE.md vs Cursor Rules for Teams
How AGENTS.md, CLAUDE.md, and Cursor rules differ, how to layer them in a monorepo, and IaC rule examples for Terraform and Kubernetes teams.
Read the guide →
Can an AI Agent Manage Your Kubernetes Cluster?
AI agents are excellent at Kubernetes triage and log digging, risky at writes. How to scope RBAC for agents and why incidents still need humans.
Read the guide →
AI Code Review Tools in 2026: Do They Catch Real Bugs?
CodeRabbit, Greptile, and Copilot PR review compared: what AI review reliably catches, what it misses, and whether AI should review AI-written code.
Read the guide →
AI Coding Assistants for Large Codebases and Monorepos
How AI coding tools handle 500k-line monorepos: agentic search vs embeddings, what breaks with mixed app and Terraform code, and repo structure that helps.
Read the guide →
Are AI Coding Assistants SOC 2 Compliant? What Auditors Ask
What SOC 2 auditors actually ask about Cursor, Copilot, and Claude Code — vendor terms, zero-data-retention, approved-tool policy, and audit evidence.
Read the guide →
Best AI Coding Tools for Terraform and Kubernetes Work
Claude Code, Cursor, Copilot, Codex, and Antigravity compared for Terraform and Kubernetes: context handling, plan/apply loops, guardrails, price.
Read the guide →
Can AI Agents Safely Run Terraform? Guardrails That Work
AI agents can write Terraform safely, but apply needs guardrails: plan-only credentials, OPA policy checks, sandbox accounts, and human approval gates.
Read the guide →
Who Runs the Infrastructure an AI Assistant Wrote?
Your AI assistant generated the Terraform, Helm charts, and pipelines. Here is who owns the state, IAM, cost, and 3am pages once that stack is running.
Read the guide →
Google Antigravity for DevOps Work: An Honest First Look
What Google Antigravity 2.0 offers for Terraform and Kubernetes work, how it compares to Cursor and Claude Code, and what to lock down before cloud access.
Read the guide →
How to Keep Secrets Out of AI Coding Tools
Ignore-file configs, runtime secret injection, and CI scanning with gitleaks and TruffleHog to keep credentials out of AI coding assistant context.
Read the guide →
MCP Servers for AWS and Kubernetes: A Safe Setup Guide
How to wire AWS and Kubernetes MCP servers safely: scoped IAM roles, read-only kubeconfigs, audit logging, and the operations you should never grant.
Read the guide →
Using Parallel AI Agents for Infrastructure Migrations
How to fan out parallel AI subagents across Terraform provider upgrades, K8s API sweeps, and base-image bumps — with review gates that make it safe.
Read the guide →
Self-Hosted LLM Coding Assistants: When They Make Sense
Ollama and open models vs cloud APIs with zero data retention: the quality trade-offs, real GPU costs, and when self-hosting actually pays off.
Read the guide →
Making a Vibe-Coded App Production-Ready: The Checklist
A production-readiness checklist for AI-built apps: auth, secrets, backups, monitoring, rate limits, and infrastructure-as-code, from an SRE's lens.
Read the guide →
Will AI Replace DevOps Engineers? A 2026 Reality Check
A task-by-task look at what AI has automated in DevOps, what it only augments, and what founders should actually change about infrastructure hiring.
Read the guide →
Other topics
Compliance & Certifications
SOC 2, ISO 27001, HIPAA, PCI, GDPR — what each standard actually requires from your infrastructure.
Cloud Cost
Why cloud bills balloon and the specific fixes that reliably cut 30–50%.
Kubernetes & Delivery
GitOps, Kubernetes, IaC, and deployment patterns that let small teams ship like big ones.
Hiring & Strategy
Fractional vs full-time, provider comparisons, and what DevOps should cost a startup.
Newsletter
One practical DevOps guide a week
Real numbers, honest trade-offs, no vendor fog — same as everything here. Unsubscribe anytime.
Ready to stop worrying about your infrastructure?
A 15-minute call is enough to tell you exactly what we'd do and what it costs. No pitch deck, no pressure.