Skip to main content
Articles

In-Depth Guides & Analysis

Deep technical dives into cloud architecture, Kubernetes, CI/CD pipelines, and infrastructure best practices.

134 articles8 topics

Showing 1-30 of 134 articles

Page 1 of 5

Server & DevOpsSep 30, 2026

Will Your ACME Client Work With Cloudflare's New Free CA?

Cloudflare plans a free public certificate authority that will only issue to ACME clients supporting ARI, the renewal extension in RFC 9773. certbot, acme.sh, lego and Caddy support it, cert-manager keeps it behind an off-by-default flag, and Traefik does not use it.

Read article
SecuritySep 30, 2026

Visitors Already Use Post-Quantum TLS. Most Servers Do Not

About 70 percent of browser traffic reaching Cloudflare uses post-quantum TLS, but only about 15 percent of origin servers do. The gap is usually the server's OpenSSL version. Here is how to check an origin, which systems ship OpenSSL 3.5, and what to change in nginx.

Read article
SecuritySep 30, 2026

What AI Attacks Taught Cloudflare About Its Own WAF

Cloudflare let AI models attack a staging site behind its WAF. Of 607 counted requests, 558 were blocked and 48 of the 49 findings were command injection or SSRF. The test used Enterprise-only settings, so here is what a Free or Pro zone can copy.

Read article
Next.jsSep 29, 2026

Should You Move Your Next.js App to Vinext 1.0?

Cloudflare's Vinext 1.0 reimplements Next.js on Vite, and its own README still calls OpenNext the safer choice. This covers what Vinext runs, what it leaves out, why npm audit stops describing your exposure after a move, and who should switch.

Read article
Server & DevOpsSep 29, 2026

Your Images Are Probably Not What Makes LCP Slow

Cloudflare's BEACON data from 10,000 large sites shows where slow LCP comes from. On pages rated poor, downloading the LCP resource took 119 ms, while the first byte, late discovery and blocked rendering each took one and a half to two seconds.

Read article
CloudSep 28, 2026

What to Use on AWS When You Want ClickHouse Query Speed

AWS does not run ClickHouse as one of its own services, so fast analytics on AWS means ClickHouse Cloud, BYOC or a self-hosted cluster, or an AWS service that covers part of the job. This compares them with Redshift, Athena, OpenSearch and Timestream by workload, with vendor claims marked as such.

Read article
CloudSep 28, 2026

Upgrade RDS MySQL 8.0 to 8.4 With a Blue/Green Switch

RDS for MySQL 8.0 left standard support on July 31, 2026, and instances still on it are now billed for Extended Support. This shows how to reach 8.4 with a blue/green switch: what rules the method out, what 8.4 refuses that 8.0 accepted, the CLI steps, and why there is no switch-back unless you build one first.

Read article
MagentoSep 28, 2026

Why Magento 2 Indexers Get Stuck and How to Unstick Them

A Magento indexer stuck at Processing or Reindex required usually comes down to one of six causes, from cron not running the index group to a killed reindex, missing triggers or batches too big for memory. Each one comes with its check and its fix, taken from the Magento 2.4.9 source and Adobe's documentation.

Read article
MagentoSep 28, 2026

How to Upgrade Magento 2.4.8 to 2.4.9 and What Changes

Magento 2.4.9 needs PHP 8.5, OpenSearch 3 and, for MariaDB users, version 12.3, and Adobe's own pages disagree on four of its requirements. This covers the upgrade order that 2.4.8-p5 makes possible, the commands Adobe documents, the library changes that break extensions, and the security patches a fresh 2.4.9 install still lacks.

Read article
CloudSep 11, 2026

How You Overpay on AWS by Choosing the Wrong Service

Six AWS pairs where the pricier service is sized for a problem you may not have, what drives each bill, and read-only commands to check which side you are on.

Read article
CloudSep 10, 2026

Moving EKS to Production, and the Five Bills Nobody Budgets

Five recurring AWS charges that switch themselves on when an EKS cluster reaches production, what starts each one, and how to see where you stand.

Read article
SecuritySep 9, 2026

A cPanel Account With Email Access Can Reach Root, and Every Supported Version Is Affected

CVE-2026-67401 lets an authenticated cPanel account holder with mail privileges create arbitrary files and run code as root. cPanel lists all supported versions as affected and has shipped patched builds. The precondition is an ordinary customer account, which on a hosting platform anyone can buy.

Read article
SecuritySep 8, 2026

The Magento Hotfix Is Out, and Adobe Wants Your Payment Gateway Keys Rotated Too

Adobe published APSB26-146 on 7 September for CVE-2026-75650, a CVSS 10.0 unauthenticated code execution flaw it confirms is being exploited. The fix is a composer hotfix rather than a version bump, and Adobe's own remediation asks you to rotate credentials at your payment provider as well.

Read article
SecuritySep 7, 2026

Who Holds REPLICATION on Your Postgres, and Why CVE-2026-6471 Makes It Matter

CVE-2026-6471 turns a PostgreSQL replication grant into code execution on the database host. It needs an account you already created, the patch has been out since 13 August, and the useful question is not the version number but who in your database still holds REPLICATION.

Read article
SecuritySep 6, 2026

A Magento Zero-Day Is Being Exploited Now, and the First Victim Was Fully Patched

StyleSmuggler is an unauthenticated remote code execution flaw in every current version of Magento Open Source and Adobe Commerce. Attacks started on September 4 and the first confirmed victim was fully up to date. Written while no patch existed; Adobe has since shipped one as CVE-2026-75650.

Read article
CloudSep 4, 2026

What Your Startup Runs, and What You Are Paying For

Two lists settle the cloud question for an early team: what the product runs, and what the platform is priced around. DigitalOcean and AWS on Kubernetes.

Read article
Server & DevOpsAug 29, 2026

The GitHub to GitLab Migration Nobody Warns You About

GitLab imports your repositories, reviews and history almost completely. It imports none of your GitHub Actions. What moves, what you rewrite, and when.

Read article
SecurityAug 25, 2026

How to Give Applications AWS Credentials Without Storing Any

Every long-lived access key in your account is a copy waiting to leak, and no amount of rotation discipline fixes that. The alternative is to have no key at all, because each place an application normally needs credentials already has a mechanism that hands it fresh ones on demand. This walks through instance profiles on EC2, task roles on ECS, EKS Pod Identity and IRSA on Kubernetes, and OIDC federation for a CI pipeline, with the trust policy shape for each. It also covers the one condition in the CI trust policy that decides whether the whole thing is secure or theatre.

Read article
CloudAug 25, 2026

How to Reach a Private RDS Without a Bastion Host

A jump host with a public IP and an open SSH port is the most commonly attacked thing in a lot of AWS accounts, and it exists only so somebody can occasionally run a query. Systems Manager forwards a local port through a managed node to any host that node can reach, so the database stays in its private subnet and nothing accepts inbound connections. This covers the exact command, the agent version and permissions it needs, how it works with no NAT gateway at all, and how to drop the stored database password as well.

Read article
Server & DevOpsAug 25, 2026

How to Recover an EC2 Instance You Can No Longer SSH Into

When a box stops answering there is an order to work through, and two of the options only exist if somebody enabled them on a calm afternoon months earlier. This covers what the status checks are telling you, reading console output, the serial console and everything it needs configured in advance, and the volume detach and reattach route as the last resort. The part worth reading before you need it is which mechanisms have prerequisites, because that decides what is available to you at 2am.

Read article
SecurityAug 25, 2026

How to Make an S3 Bucket That Cannot Be Deleted by Accident

Protecting a bucket against a mistake and protecting it against a stolen credential are two different jobs, and the settings that do one do not do the other. This walks through versioning, MFA delete and Object Lock in both of its modes, what each one can and cannot be undone by, and where an attacker with the right permission walks straight through your protection. Several of these settings cannot be reversed once enabled, including one where AWS says the only remaining way to delete the data is to close the account, so the warnings sit next to the commands.

Read article
CloudAug 25, 2026

How to Stop Paying for NAT Gateway Traffic You Do Not Need

A large share of NAT gateway spend on a typical account is traffic to AWS services that could have reached those services privately, and it shows up as one anonymous line on the bill. This shows how to tell AWS-bound traffic from internet-bound traffic in Cost Explorer, how to find the exact destination in flow logs, and which endpoint type actually removes the charge. It also covers the traps, including why a bucket in another Region keeps going out through the NAT after you add the endpoint.

Read article
CloudAug 25, 2026

How to Set Up Budgets and Anomaly Detection Before the Bill Surprises You

Finding out about a spend problem from the invoice means finding out weeks late. AWS gives you two different mechanisms for catching it earlier, and they are not interchangeable. A budget fires when a number you chose is crossed, while Cost Anomaly Detection models what your spend normally looks like and tells you when the shape changes. This walks through setting up both from the CLI, the delay each one carries between the spend happening and the alert arriving, who should be on which notification, and the charges neither one will catch for you.

Read article
CloudAug 25, 2026

How to Choose Between ALB, NLB and CloudFront for Your Traffic

The three services sit at different layers, accept different protocols, and a handful of the choices you make when you create them cannot be changed afterwards. This is what each one is actually for, where the protocol list makes the decision for you, the two cases where the right answer is a pair of them working together, and the settings that mean rebuilding rather than editing if you get them wrong.

Read article
CloudAug 25, 2026

How to Run Multi AZ So It Actually Survives an AZ Failure

Most AWS accounts are multi AZ on paper already, and then a zone has a bad day and the site goes down anyway. Spreading a deployment across zones and keeping it serving when one disappears are two different properties. This covers what the managed services really do during a zone failure, including which failovers reset every open connection and how long each one takes, the single points that quietly survive a multi AZ design, and the commands to rehearse all of it on purpose.

Read article
Server & DevOpsAug 25, 2026

How to Migrate a Server to AWS Without a Big Bang Cutover

A big bang cutover is a plan with exactly one attempt in it. The incremental version costs a little more elapsed time and keeps a working rollback available until the very last step. This walks through the inventory that decides whether the cutover is clean, continuous replication that runs while the old server keeps serving, a dress rehearsal you can repeat, the DNS time to live arithmetic you have to do backwards from the cutover date, and the single action that ends the rollback window for good.

Read article
SecurityAug 25, 2026

How to Set Up Least Privilege IAM Without Blocking Your Own Team

Least privilege earns its reputation for costing a week of tickets whenever someone writes the minimal policy first and discovers what was missing by breaking people's work. The order that avoids that is the reverse. Cap the blast radius, let the team work, collect evidence about what was actually used, and tighten against the evidence. This covers the AWS reporting that supplies the evidence, exactly what data each report is built from and what it silently omits, and the checks that catch an over-tightened policy before it ships.

Read article
Server & DevOpsAug 25, 2026

How to Upgrade PostgreSQL Major Versions With Almost No Downtime

An in-place major upgrade takes your database down for as long as the upgrade runs, and once it has started there is no way back. Logical replication turns that into a cutover you can measure in seconds, with the old server still consistent and still able to take traffic if the first minute goes badly. The method works because the new server is built and caught up while the old one keeps serving. The risk is entirely in what logical replication declines to carry across, so this guide spends most of its time on sequences, DDL, large objects and tables without a replica identity.

Read article
Server & DevOpsAug 25, 2026

How to Change a Schema on a Busy MySQL Table Without Locking It

A plain ALTER on a large InnoDB table can hold up every writer until it finishes, which on a busy table means an outage nobody scheduled. Modern MySQL does far more instantly than most teams realise, so the first job is checking whether you need a tool at all. When you do, the copy-and-swap approach builds a shadow table, keeps it in step from the binary log, and swaps the two at the end. This guide covers what the table has to look like for that to work, and how to stop a migration safely once it is running.

Read article
Server & DevOpsAug 25, 2026

How to Run Ephemeral CI Runners on Your Own Hardware

A build that passes because of something left behind by the previous build is not a passing build, it is a coincidence. Ephemeral runners remove that class of problem by giving every job a machine that has never run anything else. GitHub supports this directly through single-use runner registration and just-in-time configuration, so the runner deregisters itself after one job and your automation disposes of the host. This guide covers both approaches, the Kubernetes version, and the one situation where self-hosted runners are the wrong answer.

Read article