Notes from the racks
Every article tagged .
Written by platform engineers
Field-tested, not theoretical
New analysis every month
6 articles
security/
5 min read
A baseline firewall policy for a three-tier application
The inbound and outbound rules to start from for web, application and data tiers — and the two that are almost always too permissive.
Sep 4, 2026
security/
4 min read
Locking down SSH without locking yourself out
Bastion patterns, break-glass access and the order to apply firewall changes in so you keep a way back into your own servers.
Sep 4, 2026
compliance/
4 min read
Egress filtering: why outbound rules matter more than you think
Inbound rules stop an intrusion starting. Outbound rules decide how much it costs you once one already has.
Sep 4, 2026
Security & Compliance in the Cloud/
4 min read
How NIS2 ready are you?
Navigate the complexities of NIS2 Directive, ensure the security of your organization and achieve compliance.
Aug 23, 2026
security/
4 min read
The 30-minute hardening baseline for a public VM
The short list of changes that removes almost all opportunistic attacks against an internet-facing Linux VM, with the commands to apply them.
Aug 23, 2026
compliance/
5 min read
What "EU cloud" has to actually mean
Data residency is the easy half of the problem. The questions that decide whether an EU region is genuinely EU, and what to put in your DPA.
Aug 23, 2026
Infrastructure notes, once a month
Release notes, capacity updates and the occasional deep dive. No fluff, unsubscribe any time.
You're subscribed. Infrastructure notes land in your inbox once a month. Unsubscribe any time.