Cloud Chronicles

Insights on cloud engineering, DevOps, platform engineering, FinOps, and AI — delivered with clarity and a dash of wit.

Featured Story

Browse All Articles

61 articles

8 min read

The Internet's Politest File Just Got a Doorman

Since 1994, the web's oldest defense against unwanted robots has been a text file politely asking them to leave. On 21 August, Cloudflare started writing that file for you. And on 15 September, for new ad-funded websites behind Cloudflare, the default answer to "may I train on this?" flips to no.

ai-crawlersweb-infrastructurerobots-txt
Read More
7 min read

Everyone's Editor Tried to Help at Once

GitHub went down on 17 August for seven hours and forty-seven minutes. The thing that broke was fixed in about three. The other five hours were millions of code editors, all politely asking again, forever, because nobody had taught them to wait.

cloud-infrastructureoutagesdeveloper-tools
Read More
11 min read

The Switch That Was Already On

Twitch added a switch that lets you stop Amazon from training generative AI on your channel. The switch arrived already on. And one line in the help article, which nobody quoted, says that whether your chat in someone else's stream gets used is a decision that stranger already made for you.

consumer-techai-trainingprivacy
Read More
8 min read

The Chip That Can Only Think One Thought

AMD bought a company whose pitch is four words long: The Model is The Computer. Not a slogan. They etch the model into the metal, and then you cannot change your mind.

ai-hardwareai-inferencechips
Read More
7 min read

Your Cheap Streaming Stick Has a Night Job

You did not buy a cheap streaming box. You took in a lodger who works nights. Researchers found generic Android TV boxes that rent out your home internet while you watch, then click ads on machine-written news sites once the screen goes dark. The fraud engine was built in a coding tool made for children.

consumer-techiot-securityresidential-proxy
Read More
6 min read

The GPU Money Merry-Go-Round: How the Same Dollar Gets Counted Three Times

Nvidia invests in the garages. The garages spend the money on Nvidia chips. Nvidia promises to pay for whatever capacity nobody else rents, through 2032. The same dollar rides the AI carousel three times, and everyone claps.

cloud-computingneocloudai-infrastructure
Read More
5 min read

Neocloud, Explained: The Cloud That Sells Exactly One Thing

A hyperscaler is a supermarket. A neocloud is the guy selling one incredible thing out of a garage. There are now more than a hundred garages, and the category passed $25 billion in revenue in 2025.

cloud-computingneocloudai-infrastructure
Read More
5 min read

The Tool on 20 Billion Devices Just Closed Its Inbox for the Summer

curl runs on an estimated 20 billion devices, maintained by a handful of volunteers. A flood of AI-written bug reports just closed their inbox.

open-sourceai-slopcurl
Read More
16 min read

Terraform Actions Block: The Complete Guide to Day 2 Operations in IaC

Terraform 1.14 introduced the `action` block — and it quietly solved the problem every cloud engineer has worked around for years. Invalidate a CDN. Run a database migration. Send an alert. All from within the plan/apply lifecycle, no bash scripts required. Here's the complete picture: syntax, catalog, pitfalls, and the OpenTofu fork you need to understand before you ship this to shared modules.

terraformiachashicorp
Read More
9 min read

CVSS 10.0: Cisco Catalyst SD-WAN Just Handed Attackers Your Entire Overlay

CVE-2026-20182 landed in CISA's Known Exploited Vulnerabilities catalog yesterday. CVSS 10.0. Emergency Directive 26-03. Federal agencies patch by tomorrow. UAT-8616 is not waiting for your change management window. Here's what the flaw does, who's behind it, and exactly what to run before you close this tab.

network-securityciscosdwan
Read More
15 min read

TeamPCP Poisoned the Security Tools in Your CI/CD Pipeline

The March 2026 TeamPCP campaign did not just hit application dependencies. It moved through the security and developer tooling layer itself: Trivy, Checkmarx KICS, and LiteLLM release paths. This post breaks down what appears verified, what remains reported attribution, and the controls that would have cut the chain early.

devsecopssupply-chain-securitygithub-actions
Read More
15 min read

A Trojanized kubectl Binary, One AirDrop, and a Multimillion-Dollar Kubernetes Breach

Google Cloud Threat Horizons H1 2026 details a real campaign where UNC4899 used social engineering and a trojanized kubectl-like binary to pivot from a developer workstation into cloud control paths. This post breaks down the kill chain, the control failures, and the exact audits platform teams should run now.

kubernetescloud-securitydevsecops
Read More