Generated by All in One SEO v5.0.1.1, this is an llms.txt file, used by LLMs to index the site. # ethernetdude No hype. Just practice ## Sitemaps - [XML Sitemap](https://ethernetdude.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Contents](https://ethernetdude.com/?page_id=73) - Kapil Kanth - Contents - - [Article 01 – OCI IAM Architecture: Tenancies, Compartments, and Resource Isolation](https://ethernetdude.com/article-01-oci-iam-architecture-tenancies-compartments/) - Master OCI IAM architecture, root tenancies, compartment hierarchies, and resource isolation to build secure enterprise cloud governance models. - [Article 02 – OCI Identity Domains: Architecture, Types, and Directory Management](https://ethernetdude.com/article-02-oci-identity-domains-architecture-types/) - Explore OCI Identity Domains architecture, domain types, user provisioning, and directory management strategies for Oracle Cloud. - [Article 03 – OCI Policy Language Fundamentals: Syntax, Verbs, and Scope](https://ethernetdude.com/article-03-oci-policy-language-fundamentals/) - Learn OCI policy syntax, permission verbs (inspect, read, use, manage), subject inheritance, and resource scoping fundamentals. - [Article 04 – Resource Types and Resource Families: Precision Access Control](https://ethernetdude.com/article-04-oci-resource-types-and-families/) - Master OCI resource types and resource families for precision access control and broad administrative policy scoping. - [Article 05 – Advanced Policy Conditions and Clause Tuning: Fine-Grained Governance](https://ethernetdude.com/article-05-oci-advanced-policy-conditions/) - Tune OCI IAM policy clauses using advanced conditions, request parameters, target attributes, and fine-grained security logic. - [Article 06 – Identity Groups and Access Control Management: User Provisioning & Group Architectures](https://ethernetdude.com/article-06-oci-identity-groups-access-control/) - Design enterprise OCI identity group architectures, automate user provisioning, and manage role-based access control (RBAC). - [Article 07 – Dynamic Groups and Instance Principals: Credential-Less Service-to-Service Security](https://ethernetdude.com/article-07-oci-dynamic-groups-instance-principals/) - Implement OCI dynamic groups and instance principals to secure compute workload service-to-service calls without hardcoded API keys. - [Article 08 – Resource Principals & Workload Identity: Authorization for OKE, Functions, and Automation](https://ethernetdude.com/article-08-oci-resource-principals-workload-identity/) - Configure OCI resource principals and workload identity for OKE clusters, Oracle Functions, and serverless automation workflows. - [Article 09 – Network Sources: Restricting Access by IP and Subnet Boundaries](https://ethernetdude.com/article-09-oci-network-sources-ip-subnet-boundaries/) - Enforce network boundary security in OCI IAM by defining public IP ranges, VCN private subnets, and network source policy conditions. - [Article 10 – Identity Federation & Single Sign-On (SSO): Integrating Entra ID, Okta, and SAML 2.0](https://ethernetdude.com/article-10-oci-identity-federation-sso-entra-okta/) - Integrate OCI IAM with Microsoft Entra ID, Okta, and SAML 2.0 identity providers for seamless single sign-on (SSO) and group mapping. - [Article 11 – Multifactor Authentication (MFA), Password Policies, and Risk-Based Sign-On Rules](https://ethernetdude.com/article-11-oci-mfa-password-policies-sign-on-rules/) - Configure OCI IAM multifactor authentication (MFA), strict password policies, and adaptive risk-based sign-on policy rules. - [Article 12 – Tag-Based Access Control (TBAC) & Attribute-Based Access Control (ABAC)](https://ethernetdude.com/article-12-oci-tag-based-access-control-tbac-abac/) - Implement tag-based access control (TBAC) and attribute-based access control (ABAC) in OCI IAM for dynamic resource authorization. - [Article 13 – Security Zones & Security Guardrails: Enforcing Inviolable Policy Constraints](https://ethernetdude.com/article-13-oci-security-zones-guardrails/) - Deploy OCI Security Zones and automated security guardrails to enforce non-bypassable security posture constraints across compartments. - [Article 14 – IAM Audit Logging, Cloud Guard, and Security Posture Monitoring](https://ethernetdude.com/article-14-oci-iam-audit-logging-cloud-guard/) - Monitor OCI IAM security posture using Cloud Guard detectors, audit log events, and automated security event remediation. - [Article 15 – OCI Console Navigation & Administrative Workflows: Mastering the IAM Web Interface](https://ethernetdude.com/article-15-oci-console-navigation-iam-workflows/) - Navigate the OCI web console efficiently to manage IAM policies, identity domains, administrative workflows, and access audits. - [Article 16 – API Keys, Auth Tokens, OAuth2 Clients, and Service User Authentication](https://ethernetdude.com/article-16-oci-api-keys-auth-tokens-oauth2/) - Configure OCI API signing keys, auth tokens, SMTP credentials, and OAuth2 client credentials for automated service access. - [Article 17 – OCI IAM Cross-Tenancy Access & Compartment Delegation Architectures](https://ethernetdude.com/article-17-oci-cross-tenancy-access-architecture/) - Architect secure cross-tenancy authorization in OCI IAM using endorse, admit, and define policy statements across separate tenancies. - [Article 18 – IAM Troubleshooting & Diagnostic Mechanics: Resolving Production Access Failures](https://ethernetdude.com/article-18-oci-iam-troubleshooting-break-fix/) - Diagnose and resolve common OCI IAM access failures, policy evaluation syntax errors, and scope mismatch issues. - [Article 19 – OCI IAM Comprehensive Knowledge Assessment and Scenario Guide](https://ethernetdude.com/article-19-oci-iam-knowledge-assessment-exam/) - Test your Oracle Cloud Infrastructure IAM expertise with a comprehensive 19-topic scenario assessment and detailed answer guide. - [Article 01 – OCI Networking Architecture: VCNs, Subnets, Gateways, and VNICs](https://ethernetdude.com/article-01-oci-networking-architecture-vcns-subnets-gateways-and-vnics/) - 1. Introduction to OCI Network Virtualization Oracle Cloud Infrastructure (OCI) approaches network virtualization differently from first-generation public ... - [Article 02 – Subnets, CIDR Sizing, and IP Address Management (IPAM)](https://ethernetdude.com/article-02-subnets-cidr-sizing-and-ip-address-management-ipam/) - 1. Introduction to OCI IP Address Management Proper Classless Inter-Domain Routing (CIDR) design and IP Address Management (IPAM) are the foundation of ent... - [Article 03 – OCI Route Tables and Routing Mechanics](https://ethernetdude.com/article-03-oci-route-tables-and-routing-mechanics/) - 1. Introduction to OCI VCN Routing In Oracle Cloud Infrastructure (OCI), traffic flow inside a Virtual Cloud Network (VCN) is controlled by software-define... - [Article 04 – Security Lists vs. Network Security Groups (NSGs): Stateful and Stateless Filtering](https://ethernetdude.com/article-04-security-lists-vs-network-security-groups-nsgs-stateful-and-stateless-filtering/) - 1. Introduction to OCI Firewall Architecture Oracle Cloud Infrastructure (OCI) provides two software-defined firewall mechanisms to control packet ingress ... - [Article 05 – Internet Connectivity: Internet Gateways, NAT Gateways, and Egress Control](https://ethernetdude.com/article-05-internet-connectivity-internet-gateways-nat-gateways-and-egress-control/) - 1. Introduction to Edge Connectivity in OCI Public cloud workloads require controlled mechanisms to interact with external networks. In Oracle Cloud Infras... - [Article 06 – OCI Service Gateway (SGW) & Private Service Access](https://ethernetdude.com/article-06-oci-service-gateway-sgw-private-service-access/) - 1. Introduction to Private Oracle Service Egress Modern cloud security frameworks demand that sensitive data inside private database servers, analytics clu... - [Article 07 – Local VCN Peering: LPG and Intra-Region Traffic](https://ethernetdude.com/article-07-local-vcn-peering-lpg-and-intra-region-traffic/) - 1. Introduction to Intra-Region VCN Peering As cloud environments grow, organizations separate workloads into multiple Virtual Cloud Networks (VCNs) to enf... - [Article 08 – Dynamic Routing Gateway (DRG v2) & Hub-and-Spoke Architecture](https://ethernetdude.com/article-08-dynamic-routing-gateway-drg-v2-hub-and-spoke-architecture/) - 1. Introduction to OCI DRG v2 As enterprise cloud footprints grow to dozens of Virtual Cloud Networks (VCNs) spanning hybrid on-premises environments, poin... - [Article 09 – Cross-Region VCN Peering: RPC and Global Backbone Architecture](https://ethernetdude.com/article-09-cross-region-vcn-peering-rpc-and-global-backbone-architecture/) - 1. Introduction to Global Cross-Region Connectivity Global enterprise cloud architectures often deploy workloads across multiple Oracle Cloud Infrastructur... - [Article 10 – Site-to-Site VPN: IPsec Tunnels, BGP Routing, and High Availability](https://ethernetdude.com/article-10-site-to-site-vpn-ipsec-tunnels-bgp-routing-and-high-availability/) - 1. Introduction to OCI Site-to-Site VPN Connecting on-premises enterprise data centers to Oracle Cloud Infrastructure (OCI) requires secure, encrypted netw... - [Article 11 – OCI FastConnect: Dedicated Private Connectivity & Virtual Circuits](https://ethernetdude.com/article-11-oci-fastconnect-dedicated-private-connectivity-virtual-circuits/) - 1. Introduction to Enterprise Dedicated Connectivity While IPSec Site-to-Site VPN offers encrypted connectivity over the public internet, enterprise worklo... - [Article 12 – Flexible Load Balancer (Layer 7): HTTP, HTTPS, and SSL Offloading](https://ethernetdude.com/article-12-flexible-load-balancer-layer-7-http-https-and-ssl-offloading/) - 1. Introduction to Layer 7 Load Balancing Modern web applications demand intelligent traffic management, high availability across Availability Domains, SSL... - [Article 19 – OCI Networking Comprehensive Knowledge Assessment and Exam Guide](https://ethernetdude.com/article-19-oci-networking-comprehensive-knowledge-assessment-and-exam-guide/) - Instructions This standalone knowledge assessment tests your architectural mastery of Oracle Cloud Infrastructure (OCI) Networking across all 18 topics in ... - [Article 18 – Networking Troubleshooting & Diagnostic Mechanics: Break-Fix Lab](https://ethernetdude.com/article-18-networking-troubleshooting-diagnostic-mechanics-break-fix-lab/) - 1. Introduction to Network Diagnostic Engineering Even meticulously designed Oracle Cloud Infrastructure (OCI) network architectures encounter operational ... - [Article 17 – OCI Network Observability: VCN Flow Logs, Network Visualizer, and Route Analyzer](https://ethernetdude.com/article-17-oci-network-observability-vcn-flow-logs-network-visualizer-and-route-analyzer/) - 1. Introduction to OCI Network Observability Operating enterprise cloud infrastructure requires continuous visibility into network traffic patterns, perfor... - [Article 16 – Web Application Firewall (WAF) & Edge Network Security](https://ethernetdude.com/article-16-web-application-firewall-waf-edge-network-security/) - 1. Introduction to Layer 7 Perimeter Protection Public-facing web applications and APIs are continuously targeted by sophisticated application-layer cyber ... - [Article 15 – OCI DNS Services, Private DNS, and Hybrid Name Resolution](https://ethernetdude.com/article-15-oci-dns-services-private-dns-and-hybrid-name-resolution/) - 1. Introduction to Enterprise Cloud DNS Reliable Domain Name System (DNS) resolution is critical for enterprise cloud operations. Compute instances, micros... - [Article 14 – Advanced Routing: Transit Hub VCNs and Next-Gen Firewall Insertion](https://ethernetdude.com/article-14-advanced-routing-transit-hub-vcns-and-next-gen-firewall-insertion/) - 1. Introduction to Centralized Transit Security Architecture Enterprise security compliance often mandates that all network traffic—whether moving between ... - [Article 13 – Network Load Balancer (Layer 4): Ultra-Low Latency & High-Throughput Distribution](https://ethernetdude.com/article-13-network-load-balancer-layer-4-ultra-low-latency-high-throughput-distribution/) - 1. Introduction to Layer 4 Network Load Balancing While Layer 7 load balancers analyze HTTP/HTTPS application payloads, high-performance network architectu... - [05. Remote Repo and Github](https://ethernetdude.com/05-remote-repo-and-github/) - we need a secondary, off-site location for our repository. We need a Remote. While there are options like Bitbucket & GitHub is basically the industry standard. - [06. Forks, Pull Request & Code Reviews](https://ethernetdude.com/06-forks-pull-request-code-reviews/) - Avoid pushing directly to main—one typo can break production. Learn forks, pull requests, and peer reviews to follow a safe, industry-standard workflow. - [01. Getting Started with Version Control](https://ethernetdude.com/getting-started-with-version-control/) - Track & version control configs efficiently with Git. Learn Git vs GitHub, installation on Windows, Mac, Linux, and verify setup using CLI step by step. - [02. The Three Trees & Local Tracking](https://ethernetdude.com/the-three-trees-local-tracking/) - If there's one command we will use constantly, it's git status. Any time you have a doubt about what's going on with your files, just run it. - [03. Reading History & Undoing Mistakes](https://ethernetdude.com/03-reading-history-undoing-mistakes/) - Fix Git mistakes with confidence. Learn git log, diff, stash, revert, and reset to track changes, recover files, and safely undo broken commits. - [04. Branching, Merging & Conflicts](https://ethernetdude.com/branching-merging-conflicts/) - Learn Git branching to work safely. Create, switch, merge branches, and resolve conflicts without breaking main—perfect for experimenting confidently. - [Article 01 - Introduction to Cloud Computing](https://ethernetdude.com/introduction-to-cloud-computing/) - In the complex world of traditional data centers, businesses grapple with the intricate task of aligning resource provisioning to unpredictable peak loads, such as the holiday season surge faced by e-commerce giants. The constant commitment to resources that often lie idle during off-peak periods, coupled with the challenges of hardware procurement and staffing, places a - [Article 05 - Introduction to Google Compute Engine](https://ethernetdude.com/introduction-to-google-compute-engine/) - what is a compute Engine? In simple words it is nothing but a virtual machine in google cloud. the service called compute engine in google cloud allows you to create and manage the life cycle of virtual machine instances. You can manage network connectivity and configuration of VM instances. it also allows you to load - [Article 06 - Setting Up an HTTP Server & Static IP Address](https://ethernetdude.com/setup-a-simple-http-server-on-compute-engine/) - ssh to the virtual instance and type the below commands. these below commands will install apache2 web server on the instance & will update the homepage to Hello world followed by hostname & IP address of the virtual instance. sudo su apt update apt -y install apache2 sudo service apache2 start sudo update-rc.d apache2 enable - [Article 07 - Startup Scripts on GCP Virtual Instances](https://ethernetdude.com/startup-script-on-gcp-virtual-instance/) - Let us talk about startup script on Gcp virtual instance. I am creating a new Virtual instance & leaving most of the defaults & allow http traffic on firewall so that I can ssh Expand management & Scroll down a bit you should see the option to enter your startup script. I am going to - [Article 08 - Instance Templates & Custom Images](https://ethernetdude.com/instance-templates-in-gcp-platform/) - In this post we will discuss about instance templates & Custom images in GCP. If you work for a major company, chances are that you will be creating similar type of virtual instance multiple times. It will use the same machine type, has the same start up script, uses the same image family etc... So, - [Article 13 - Billing, Discounts & Keeping Costs Low](https://ethernetdude.com/billing-discounts-keeping-costs-low-on-gcp/) - sustained use discounts: Google will provide you sustained discounts in case if the virtual instance is running more than 25% of the month. Sustained discounts are automatically applied usually the discount is between 20-50% on every incremental minute. The sustained use discounts do not apply for certain machine types like E2 & A2 The sustained - [Article 09 - Compute Engine Live Migration & Best Practices](https://ethernetdude.com/compute-engine-live-migration-best-practices/) - Live Migration: When the host system in needs to be updated live migration of the virtual instance happens. The virtual instance is migrated to a different host system from the same zone. The properties of the instance do not change. However, this is not supported for instances with GPU or for Spot instances. The live - [Article 02 - Command Line Interface of GCP](https://ethernetdude.com/command-line-interface-of-gcp/) - The Command line interface in GCP is called as Gcloud. Most GCP services can be managed from Gcloud. We can create, delete and update virtual machines, you can manage instance groups & databases etc... While there are some more service specific CLI tools in GCP, Gcloud is the most commonly used one. The following is - [Article 03 - Command Structure in Gcloud Simplified](https://ethernetdude.com/command-structure-in-gcloud-simplified/) - The typical Command Structure in Gcloud is "gcloud ". "Group" is usually the service you are working with like, compute, container, config or iam etc... "Subgroup" is the component we are referring to in the group. for example, if we take compute as a group then the instances, images, instance-templates, regions & zones - [Article 04 - Additional Commands in Google Cloud](https://ethernetdude.com/few-additional-commands-in-gcloud/) - Below are few compute instance commands in gcloud. gcloud compute instances start //The instance 1 & 2 are created gcloud compute instances stop < instance 2 > //The instances 1 & are stopped gcloud compute instances delete // The instance 1 is deleted gcloud compute instances - [Article 10 - What Can Instance Groups Do in Google Cloud?](https://ethernetdude.com/what-can-instance-groups-do-in-google-cloud/) - Instance groups are used to manage a group of instances as a single entity. You can manage similar virtual machines having similar life cycles as a single unit. There are 2 types of instance group that you can create namely managed or unmanaged instance group. Managed instance groups unmanaged instance groups Managed instance groups are - [Article 11 - How to Update a Managed Instance Group](https://ethernetdude.com/how-to-update-managed-instance-group/) - You can gradually upgrade an instance in an instance group to a new instance template. This type of upgrade is called as Rolling upgrade. Let us say we have 10 instances running and we want to upgrade only 2 instances at once. this is the default. We can also set a canary template, meaning if - [Article 12 - CLI for Managed Instance Groups](https://ethernetdude.com/how-to-use-cli-for-managed-instance-groups/) - We have been using the cloud console to manage the managed instance groups. Let us now learn how to use the command line interface to manage the instance groups. It is important to note that we need to set the project id before we can execute any of these commands mentioned below. Else, you will - [Article 18 - Load Balancing in Google Cloud](https://ethernetdude.com/load-balancing-in-google-cloud/) - So your application is getting serious traffic. You started with a single VM, and it worked fine for a while. But now it is struggling under the load. Wors... - [Article 14 - Mastering IAM in Google Cloud](https://ethernetdude.com/overview-of-iam/) - Alright, so you have built your infrastructure. You have your VPCs, your VMs, your databases — everything is running. Now comes the part that most people g... - [Article 21 - Mastering Storage in Google Cloud](https://ethernetdude.com/understanding-storage-services-in-google-cloud/) - Your VMs are running, your network is plumbed. But where does your stuff actually live? Your application code, user-uploaded images, database backups, log ... - [Article 17 - Google Cloud Networking](https://ethernetdude.com/google-cloud-networking-the-way-i-think-about-it/) - Alright, let us talk about networking in Google Cloud. This is where everything connects. You can have the best VMs, the best databases, the most optimized... - [Article 15 - Identity-Aware Proxy (IAP)](https://ethernetdude.com/the-smart-bouncer-a-guide-to-identity-aware-proxy-iap/) - Let me paint you a picture. You have built this fantastic internal web application. It is hosted on Compute Engine or GKE, and your employees use it every ... - [Article 16 - Deterministic Encryption in Google Cloud](https://ethernetdude.com/deterministic-encryption/) - Alright, let us talk about something that trips up a lot of people when they encounter it for the first time — Deterministic Encryption. If you have worked... - [Article 20 - Google Cloud Armor & DDoS Protection](https://ethernetdude.com/🛡️-fortifying-your-edge-google-cloud-armor/) - When you deploy applications to the public internet, you are painting a target on your back. Automated bots, script kiddies, nation-state actors — the thre... - [Article 19 - Google Cloud DNS](https://ethernetdude.com/a-deep-dive-into-google-cloud-dns/) - DNS does not get the spotlight. Kubernetes gets the spotlight. GPUs get the spotlight. But DNS is the silent navigator that makes sure your traffic actuall... - [Article 23 - Google App Engine](https://ethernetdude.com/important-things-about-app-engine/) - So you have written a web application. Maybe it is a Flask app in Python, or a Node.js Express server. And your goal is simple: "I just want to run my code... - [Article 24 - GKE in Production](https://ethernetdude.com/a-deep-dive-into-google-kubernetes-engine-gke/) - "But it works on my machine!" — the five words that started it all. Your developer's code runs fine on their laptop but fails in production because of a mi... - [Article 26 - Google Cloud Functions](https://ethernetdude.com/a-technical-deep-dive-into-google-cloud-functions/) - A user uploads a profile picture and you need to resize it into a thumbnail. A new entry gets written to your database and you need to send a notification.... - [Article 22 - Database Services in Google Cloud](https://ethernetdude.com/database-services-in-gcp/) - Your application needs to store, retrieve, and remember things. Without a database, your code is just a brain in a jar — it cannot do anything meaningful. ... - [Article 27 - Cloud Pub/Sub](https://ethernetdude.com/what-pub-sub-is-and-why-its-used/) - Let me paint the problem. You are building an e-commerce app. When a user confirms an order, three things need to happen: inventory gets updated, a shippin... - [Article 28 - Google Cloud Observability](https://ethernetdude.com/cloud-observability/) - Your application is deployed. GKE cluster is humming, databases are ready, functions are awaiting triggers. You have built the ship. Now you have to sail i... - [Article 25 - Google Cloud Run](https://ethernetdude.com/the-magic-box-a-guide-to-google-cloud-run/) - Here is the question that sparked Cloud Run's existence: "Can we have the scale-to-zero simplicity of serverless, but with the freedom to run any Docker co... - [Article 30 - Budget & Billing in Google Cloud](https://ethernetdude.com/budget-billing-in-google-cloud/) - You have architected the infrastructure, deployed the containers, built the event-driven systems. Everything is running beautifully. Then the month-end bil... - [Article 31 - Deployment Manager & Terraform](https://ethernetdude.com/a-guide-to-deployment-manager-terraform/) - Your manager says: "We need a new staging environment. Please create an exact replica of production — the VPC, subnets, firewall rules, GKE cluster, Cloud ... - [Article 40 - The Cloud Engineer's Toolkit](https://ethernetdude.com/the-cloud-engineers-toolkit-advanced-security-productivity-and-ai-services/) - You have mastered the art of cloud infrastructure. You can provision resources, deploy applications, manage networks, and troubleshoot complex systems. But... - [Article 29 - Firebase and Firestore](https://ethernetdude.com/beyond-the-prototype-an-architects-view-of-firebase-and-firestore/) - When you hear "Firebase," you might think of hackathons and startup prototypes. That view is dangerously incomplete. Firebase is not a "lite" tool — it is ... - [Article 32 - Cloud Dataflow](https://ethernetdude.com/the-river-of-data-the-definitive-guide-to-cloud-dataflow/) - In the old days, processing a massive CSV file or a stream of logs meant writing a Python script, throwing it on a Linux box, setting up a CRON job, and pr... - [Article 33 - Google Cloud Dataproc](https://ethernetdude.com/demystifying-google-cloud-dataproc-the-hadoop-spark-powerhouse/) - As an infrastructure engineer, your world is VMs, VPCs, and GKE clusters. But eventually, you will be pulled into a conversation that starts with: "We have... - [Article 34 - DataPrep by Trifacta](https://ethernetdude.com/the-no-code-etl-tool-dataprep/) - As an infrastructure engineer, your world is code, YAML, and gcloud commands. Then, a marketing analyst messages you: "I have a 50GB CSV file in a bucket.... - [Article 35 - Google Cloud Pre-Trained AI APIs](https://ethernetdude.com/google-cloud-ai-pre-trained-ai-api/) - If you tried to build an "intelligent" application ten years ago — something that could look at images, parse text, or transcribe audio — you were basicall... - [Article 36 - Vertex AI: Model Deployment & Endpoints](https://ethernetdude.com/vertex-ai-the-thing-you-deploy-when-youre-done-babysitting-ml/) - Let me start with a scene I have lived through too many times. A data scientist walks into the office with that excited "I trained a new model last night" ... - [Article 37 - Vertex AI: Feature Store, Workbench & Colab Enterprise](https://ethernetdude.com/vertex-ai-feature-store-workbench-colab-enterprise/) - Before we talk about GCP's specific tools, you have to understand the tool every data scientist lives in: the Jupyter Notebook. If you come from traditiona... - [Article 38 - Vertex AI: The Build vs. Buy Decision](https://ethernetdude.com/vertex-ai-the-build-vs-buy-decision-matrix/) - As an Architect, your job is not to build cool models; it is to solve business problems with the least amount of technical debt. When you look at Google Cl... - [Article 39 - Vertex AI: MLOps & Production Pipelines](https://ethernetdude.com/the-it-works-on-my-machine-apocalypse-taming-vertex-ai/) - Let's be honest. Most "AI projects" start as a notebook named Untitled12_final_final_v2.ipynb. It lives on a laptop that hasn't rebooted in three weeks, ru... - [Article 11 - OCI Security and Management: Governance, Observability, and Resource Manager](https://ethernetdude.com/article-11-oci-security-and-management-governance-observability-and-resource-manager-2/) - The Multi-Tool Security Headache In many cloud environments, operational governance and system observability are fragmented across multiple disconnected services. If you want to secure an environment in Google Cloud, you configure Organization Policies at the resource folder level, monitor configurations via Security Command Center, manage encryption keys using Cloud KMS, and store database passwords in - [Article 10 - OCI Load Balancing: Traffic Distribution and DNS steering](https://ethernetdude.com/article-10-oci-load-balancing-traffic-distribution-and-dns-steering-2/) - The Global vs. Regional Proxy Trade-Off In Google Cloud, Cloud Load Balancing is a global, software-defined service. When you deploy a Global External HTTP(S) Load Balancer, it utilizes Google's global Edge network. Traffic from a client enters the closest Edge Point of Presence (PoP) and is immediately terminated, then routed over Google's internal network to - [Article 09 - Application Integration: Event-Driven Architectures and Messaging](https://ethernetdude.com/article-09-application-integration-event-driven-architectures-and-messaging-2/) - The Unified Pub/Sub vs. Specialized Service Paradigm In Google Cloud, Cloud Pub/Sub is the default messaging engine. It is a highly scalable, unified service that handles both real-time stream processing (ordered, log-based ingestion) and simple point-to-point application integration (pull-based queue work). Whether you are ingestion-heavy clickstream logging or trying to decouple two microservices, you default - [Article 08 - OCI Database Services: Base DB, Exadata, and Autonomous Databases](https://ethernetdude.com/article-08-oci-database-services-base-db-exadata-and-autonomous-databases-2/) - The Oracle Database Migration Challenge In many cloud environments, running Oracle Database is an operational bottleneck. Because major hyperscalers do not have a native, first-party managed service for Oracle Database, architects are forced to deploy Oracle on standard compute VMs (running on self-managed hypervisors) or utilize co-located, non-integrated physical hardware (like Google Cloud's Bare Metal - [Article 07 - OCI Object Storage: Namespaces, Tiers, and Secure Delegated Access](https://ethernetdude.com/article-07-oci-object-storage-namespaces-tiers-and-secure-delegated-access-2/) - The Global Namespace Challenge In many cloud object storage services (like Google Cloud Storage), bucket names reside in a single, globally shared namespace. If another organization has already registered the bucket name production-logs, you cannot use it. This forces teams to adopt complex naming conventions (e.g., myorg-project-prod-logs) to avoid naming collisions, and complicates multi-environment Terraform - [Article 06 - OCI Storage Services: Elastic Block Volumes and Shared File Systems](https://ethernetdude.com/article-06-oci-storage-services-elastic-block-volumes-and-shared-file-systems-2/) - The Disk Provisioning Trade-Off In many cloud platforms, storage performance is directly bound to storage capacity. If you deploy a database VM in Google Cloud and require 10,000 IOPS, but only need 100 GB of data storage, you cannot simply provision a 100 GB disk. On standard Persistent Disks (PD), performance scales linearly with size. - [Article 05 - Containers and Serverless: Managed Kubernetes, Registry, and Functions](https://ethernetdude.com/article-05-containers-and-serverless-managed-kubernetes-registry-and-functions-2/) - The Container Orchestration Standard In Google Cloud, Google Kubernetes Engine (GKE) is the dominant container runtime platform, offering two operational models: GKE Standard (where you manage the VM node pools) and GKE Autopilot (where Google manages the node provisioning, scaling, and security). Oracle Cloud Infrastructure (OCI) offers an equivalent enterprise-grade Kubernetes service called Container Engine - [Article 04 - OCI Compute Services: Virtualization, Flexible Shapes, and Scale](https://ethernetdude.com/article-04-oci-compute-services-virtualization-flexible-shapes-and-scale-2/) - The Rigidity of Rigid Instance Shapes In many cloud platforms, provisioning a virtual machine requires selecting from a pre-defined matrix of instance types or machine families (e.g., General Purpose n2-standard-4 or Compute-Optimized c2-standard-8 in Google Cloud). Each machine type comes with a fixed, immutable ratio of virtual CPUs (vCPUs) to RAM. If your application is - [Article 03 - VCN Connectivity: Peering, Hybrid Routing, and the DRG Hub](https://ethernetdude.com/article-03-vcn-connectivity-peering-hybrid-routing-and-the-drg-hub-2/) - The Transit Routing Challenge In Google Cloud, connecting multiple VPC networks or bridging cloud environments to on-premises datacenters requires orchestrating multiple distinct components. If you use VPC Network Peering, you face a strict constraint: peering is non-transitive. If VPC A is peered with VPC B, and VPC B is peered with VPC C, workloads in - [Article 02 - Virtual Cloud Network (VCN): Core Networking and Security](https://ethernetdude.com/article-02-virtual-cloud-network-vcn-core-networking-and-security-2/) - The Global vs. Regional VPC Design Shift In Google Cloud, a Virtual Private Cloud (VPC) is inherently a global resource. You create a single VPC network, and you can instantly provision regional subnets across North America, Europe, and Asia, all communicating natively over Google's private global fiber backbone. Routing between these regional subnets is set - [Article 01 - OCI Identity and Access Management (IAM): Governance and Policy Architecture](https://ethernetdude.com/article-01-oci-identity-and-access-management-iam-governance-and-policy-architecture-2/) - The Shared-Account Scaling Trap Imagine you are building out a multi-tier cloud environment. In many cloud models, the default impulse is to spin up separate "accounts" or "projects" for every environment—one for development, one for staging, and one for production. While this creates a hard security and billing boundary, it introduces immediate management overhead. You - [How to Upgrade/Convert ACI Switches.](https://ethernetdude.com/upgrade-aci-switches-when-not-connected-to-fabric/) - Recently, for a Project I was working on. I had to add another POD to the existing ACI setup & one of the general recommendations is that the switches need to be in the same version as the existing switches running in the ACI environment which are already in production. hence, we need to Upgrade - [Article 01 - Kubernetes Architecture: The Big Picture](https://ethernetdude.com/article-01-kubernetes-architecture-the-big-picture/) - The Bare-Metal Container Management Nightmare If you pack your application code into containers, you've solved the "works on my machine" problem. But running those containers at scale in production introduces a new kind of pain. Suppose you spin up a few VMs and run your database, APIs, and frontend web servers as separate containers on - [Article 02 - Container Runtimes: Docker, Containerd, and the CRI](https://ethernetdude.com/article-02-container-runtimes-docker-containerd-and-the-cri/) - The Bloated Translator Problem When Kubernetes was first built, Docker was the only game in town. The early Kubernetes source code was hardcoded to talk directly to Docker. But Docker is an entire developer toolchain, not just a bare container executor. It handles image building, volume storage, developer commands, and network overlays. For an orchestrator - [Article 03 - Etcd: The Single Source of Truth](https://ethernetdude.com/article-03-etcd-the-single-source-of-truth/) - Storing Highly Dynamic Cluster State In a cluster running hundreds of containers across dozens of nodes, tracking the active configuration is a massive challenge. You have to store IP addresses, security keys, pod configurations, and scaling states somewhere. If you use a traditional relational database (like PostgreSQL or MySQL), you face serious issues. Adding a - [Article 04 - Etcd in Action: High Availability and Cluster Topologies](https://ethernetdude.com/article-04-etcd-in-action-high-availability-and-cluster-topologies/) - The Single Point of Database Failure If you run a single instance of etcd in your cluster, you have a single point of failure. The moment the VM hosting that database crashes, your control plane goes offline. You won't be able to deploy new pods, update configurations, or delete resources. However, running etcd on multiple - [Article 05 - Kube API Server: The Cluster's Front Door](https://ethernetdude.com/article-05-kube-api-server-the-clusters-front-door/) - The Central Database Bottleneck If you have multiple developer teams, automated scripts, and various controller agents all running inside a cluster, they need to read and update the cluster state. If all these entities could communicate directly with the etcd database, you would face race conditions and data corruption. One developer might update a pod's - [Article 06 - Kube Controller Manager: The Brains Behind the State](https://ethernetdude.com/article-06-kube-controller-manager-the-brains-behind-the-state/) - The State Drift Problem When running virtual servers and networks, configurations degrade over time. Machines run out of memory, processes crash, and network connections drop. If an orchestrator only updated the system when you manually typed a command, you would spend your time manually replacing dead nodes and containers. If a server hosting three critical - [Article 07 - Kube Scheduler: Smart Placement in a Dynamic World](https://ethernetdude.com/article-07-kube-scheduler-smart-placement-in-a-dynamic-world/) - Placing Workloads Manually When managing multiple machines, resource allocation is a constant challenge. Some servers have specialized hardware like GPUs, some have high storage limits, and others are low-resource virtual machines. If you deploy a heavy analytics workload that requires 4 CPU cores and 16GB of RAM, and you choose a node at random, you - [Article 08 - Kubelet: The On-the-Ground Worker Agent](https://ethernetdude.com/article-08-kubelet-the-on-the-ground-worker-agent/) - Executing the Orchestration Plan The control plane components are great at coordinating and planning. They decide which containers should run and where they should be placed. However, these decisions are just configurations saved in the etcd database. The API Server cannot connect to a host machine directly, configure virtual interfaces, mount storage systems, and execute - [Article 09 - Kube Proxy: The Traffic Director](https://ethernetdude.com/article-09-kube-proxy-the-traffic-director/) - Routing Traffic to Transient Targets In Kubernetes, pods are temporary. They are created, scale up, crash, and get replaced. Each time a pod is recreated, it receives a new IP address. If you configure your application to talk to backend databases by hardcoding pod IP addresses, your connections will break the moment a database pod - [Article 10 - Pods: The Smallest Atom of Compute](https://ethernetdude.com/article-10-pods-the-smallest-atom-of-compute/) - The Isolation Friction of Multi-Container Apps If you are used to working with standalone containers, you treat a single container as your basic unit of deployment. You run a container for your app, and you scale it by spinning up more instances. However, production applications often require helper processes. For instance, your main web application - [Article 11 - Declarative Pods with YAML: Writing Your First Spec](https://ethernetdude.com/article-11-declarative-pods-with-yaml-writing-your-first-spec/) - The Friction of Command-Line Infrastructure When starting out with containers, you often configure everything using CLI flags. You run commands like: docker run -d --name my-app -p 80:80 -v /var/data:/data --restart=always my-image:v2 While this is quick for local testing, it is difficult to manage in production. You cannot easily store CLI histories in a Git - [Article 12 - Replication Controller vs ReplicaSet: Evolution of State](https://ethernetdude.com/article-12-replication-controller-vs-replicaset-evolution-of-state/) - The Outage Risk of Standalone Pods If you run an application on a single pod, you are exposed to downtime. The host VM running that pod could run out of memory or crash. When this happens, your pod goes offline immediately, and your users will see errors until the Kubelet restarts the host. Additionally, if - [Article 13 - Deployments: Declarative Application Lifecycles](https://ethernetdude.com/article-13-deployments-declarative-application-lifecycles/) - The Downtime Risks of Manual Upgrades Suppose you have a running ReplicaSet managing three instances of your application at version 1.0. Your development team releases version 2.0. If you only use a standard ReplicaSet, updating the application is a manual chore. Simply updating the container image tag in the YAML file and applying it will - [Article 14 - Services - NodePort: Exposing Apps to the Outside](https://ethernetdude.com/article-14-services-nodeport-exposing-apps-to-the-outside/) - The Isolated Overlay Network Every pod in your CNI network receives an IP address. However, these IPs are assigned from a private overlay network managed by the Container Network Interface (CNI). While pods can communicate with each other using these internal IPs, they are completely unreachable from outside the cluster. If you attempt to visit - [Article 15 - Services - ClusterIP: Internal Cluster Communication](https://ethernetdude.com/article-15-services-clusterip-internal-cluster-communication/) - Tracking Ephemeral Pod IPs Internally In a multi-tier application architecture, internal service discovery is a primary concern. The frontend web server needs to talk to the backend API, and the API needs to query the database. However, pods are temporary. They crash, scale, and relocate, resulting in frequently changing IP addresses. If you hardcode these - [Article 16 - Services - LoadBalancer: Moving to the Cloud](https://ethernetdude.com/article-16-services-loadbalancer-moving-to-the-cloud/) - The Limitations of Raw NodePorts in Cloud Environments If you deploy your applications in a public cloud environment (such as AWS, GCP, or Azure) and expose them using NodePort services on high-range ports like 30008, you run into production limitations. You cannot easily ask external users to type high-range ports into their browsers. Customers expect - [Article 17 - Namespaces: Logical Multi-Tenancy and Resource Quotas](https://ethernetdude.com/article-17-namespaces-logical-multi-tenancy-and-resource-quotas/) - The Security and Resource Risks of a Flat Cluster If you run different environments (like Development, Testing, and Production) on a single cluster without boundaries, you face operational risks. For instance, developers might choose conflicting resource names, preventing workloads from launching. Additionally, you risk accidental resource deletion. A team member attempting to clean up a - [Article 18 - Imperative vs Declarative: How to Talk to Kubernetes](https://ethernetdude.com/article-18-imperative-vs-declarative-how-to-talk-to-kubernetes/) - The Drift Risk of Step-by-Step Instructions When managing servers, you typically write scripts that dictate the exact steps to install packages, start services, and edit configurations. This is imperative management. While simple, it presents challenges at scale. If a step fails, running the script again might cause errors or overwrite configurations. Additionally, if a user - [Article 19 - Kubectl Mastery: Navigation, Inspection, and Hacks](https://ethernetdude.com/article-19-kubectl-mastery-navigation-inspection-and-hacks/) - The Complexity of a Growing API As your cluster grows, the number of supported API resources increases. You have to manage Ingresses, ServiceAccounts, NetworkPolicies, and custom resources. If you need to write a configuration file for a resource you've never used before, looking up configuration formats online often returns outdated templates that result in syntax - [TFLAB08-Data Sources: Reading Existing Infrastructure](https://ethernetdude.com/tflab08-data-sources-reading-existing-infrastructure/) - Use Terraform data sources to query existing infrastructure — account ID, region, default VPC — without hardcoding values or modifying resources. - [TFLAB09-Resource Dependencies: Implicit, Explicit and the Dependency Graph](https://ethernetdude.com/tflab09-resource-dependencies-implicit-explicit-and-the-dependency-graph/) - Understand how Terraform builds the dependency graph. Learn implicit dependencies via attribute references, explicit depends_on, and terraform graph visualization. - [TFLAB10-count: Creating Multiple Resources from One Block](https://ethernetdude.com/tflab10-count-creating-multiple-resources-from-one-block/) - Use Terraform count to create multiple resource instances. Learn count.index, splat expressions, and conditional resource creation with count = condition ? 1 : 0. - [TFLAB11-for_each: Creating Resources from Maps and Sets](https://ethernetdude.com/tflab11-for_each-creating-resources-from-maps-and-sets/) - Use Terraform for_each with maps and sets for stable, key-based resource creation. Learn each.key, each.value, toset(), and when to choose for_each over count. - [TFLAB27-terraform state Commands: Inspecting and Manipulating State](https://ethernetdude.com/tflab27-terraform-state-commands-inspecting-and-manipulating-state/) - Master terraform state commands — list, show, mv, rm, and pull. Rename resources, remove from management, and inspect state details. - [TFLAB28-Importing Existing Resources into Terraform](https://ethernetdude.com/tflab28-importing-existing-resources-into-terraform/) - Import pre-existing cloud resources into Terraform management using the import block and terraform import CLI. Auto-generate HCL with -generate-config-out. - [Article 03: IGMP Snooping Lab — Stopping the Multicast Flood at Layer 2](https://ethernetdude.com/article-03-igmp-snooping-lab-stopping-the-multicast-flood-at-layer-2/) - If I had a dollar for every time someone told me "multicast is working, so what is the problem?" while their access switch was flooding multicast traffic o... - [Article 05: PIM Sparse Mode Lab — Building the Multicast Tree from Scratch](https://ethernetdude.com/article-05-pim-sparse-mode-lab-building-the-multicast-tree-from-scratch/) - If there is one protocol you absolutely must understand inside-out to call yourself a multicast engineer, it is PIM Sparse Mode. This is the protocol runni... - [Article 08: Multicast in the Data Center Lab — VXLAN Underlay with PIM](https://ethernetdude.com/article-08-multicast-in-the-data-center-lab-vxlan-underlay-with-pim/) - If you have been following this series, you now understand multicast deeply at a campus & enterprise level. Now let us talk about where multicast takes... - [Article 09: Multicast Troubleshooting Lab — 5 Broken Scenarios, You Fix Them](https://ethernetdude.com/article-09-multicast-troubleshooting-lab-5-broken-scenarios-you-fix-them/) - This article is different from the others. I am not going to teach you a protocol from scratch. Instead, I am going to hand you a broken network & ask ... - [Article 04: PIM Dense Mode Lab — Flood, Prune & Why Nobody Uses It](https://ethernetdude.com/article-04-pim-dense-mode-lab-flood-prune-why-nobody-uses-it/) - I remember the first time I configured PIM Dense Mode in a lab. I thought it would be the simple, straightforward option — no RP to deal with, no rendezvou... - [Article 06: Rendezvous Point Lab — Static RP, Auto-RP & BSR Side-by-Side](https://ethernetdude.com/article-06-rendezvous-point-lab-static-rp-auto-rp-bsr-side-by-side/) - If PIM Sparse Mode is the engine of multicast, the RP is the steering wheel. Get the RP wrong & your entire multicast domain collapses — new receivers ... - [Article 07: RPF Lab — Breaking & Fixing Multicast's Most Common Failure](https://ethernetdude.com/article-07-rpf-lab-breaking-fixing-multicasts-most-common-failure/) - Let me tell you about the single most frustrating multicast troubleshooting session I ever had. It was a campus network running IPTV for a hotel — about 20... - [TFLAB15-String Functions: Manipulating Text in HCL](https://ethernetdude.com/tflab15-string-functions-manipulating-text-in-hcl/) - Master Terraform string functions — join, split, format, replace, upper, lower, trimspace, and substr. Build safe resource names from messy inputs. - [TFLAB29-moved Blocks: Refactoring Without Destroy or Recreate](https://ethernetdude.com/tflab29-moved-blocks-refactoring-without-destroy-or-recreate/) - Rename Terraform resources safely using moved blocks — declarative refactoring that updates state without destroying and recreating resources. - [TFLAB30-Workspaces: Managing Multiple Environments](https://ethernetdude.com/tflab30-workspaces-managing-multiple-environments/) - Use Terraform workspaces for multi-environment management. Create isolated state per environment with terraform.workspace-based configuration lookups. - [TFLAB31-Debugging: TF_LOG, Console, Validate and Format](https://ethernetdude.com/tflab31-debugging-tf_log-console-validate-and-format/) - Debug Terraform with TF_LOG levels, TF_LOG_PATH, terraform console for interactive expression testing, terraform validate, and terraform fmt. - [TFLAB32-Sensitive Variables: Protecting Secrets in Terraform](https://ethernetdude.com/tflab32-sensitive-variables-protecting-secrets-in-terraform/) - Protect secrets with Terraform sensitive variables. Learn sensitive = true, TF_VAR_ environment variables, sensitive outputs, and state file security. - [TFLAB33-Taint, Replace and Drift Detection](https://ethernetdude.com/tflab33-taint-replace-and-drift-detection/) - Force-replace resources with -replace flag, understand deprecated taint/untaint, and detect infrastructure drift with terraform plan -refresh-only. - [TFLAB34-HCP Terraform: Cloud Block, Login and Remote Runs](https://ethernetdude.com/tflab34-hcp-terraform-cloud-block-login-and-remote-runs/) - Connect to HCP Terraform with the cloud block and terraform login. Understand CLI-driven runs, VCS-driven workflows, and variable sets. - [TFLAB35-HCP Terraform: Teams, Policies, Health Checks and Dynamic Credentials](https://ethernetdude.com/tflab35-hcp-terraform-teams-policies-health-checks-and-dynamic-credentials/) - Configure HCP Terraform teams, Sentinel/OPA policy enforcement, workspace health assessments for drift detection, and OIDC dynamic credentials. - [Terraform Associate 004 — Practice Exam Set 1](https://ethernetdude.com/terraform-associate-004-practice-exam-set-1/) - Ace your HashiCorp certification with our comprehensive Terraform 004 Practice Exam Set 1. Explore 50 rigorous questions covering state management, modules, and provider configurations. Includes detailed answer key. - [Terraform Associate 004 — Practice Exam Set 2](https://ethernetdude.com/terraform-associate-004-practice-exam-set-2/) - Ace your HashiCorp certification with our comprehensive Terraform 004 Practice Exam Set 2. Explore 50 rigorous questions covering state management, modules, and provider configurations. Includes detailed answer key. - [Terraform Associate 004 — Practice Exam Set 3](https://ethernetdude.com/terraform-associate-004-practice-exam-set-3/) - Ace your HashiCorp certification with our comprehensive Terraform 004 Practice Exam Set 3. Explore 50 rigorous questions covering state management, modules, and provider configurations. Includes detailed answer key. - [Terraform Associate 004 — Practice Exam Set 4](https://ethernetdude.com/terraform-associate-004-practice-exam-set-4/) - Ace your HashiCorp certification with our comprehensive Terraform 004 Practice Exam Set 4. Explore 50 rigorous questions covering state management, modules, and provider configurations. Includes detailed answer key. - [Article 10: Multicast Network Design Lab — Building a Scalable Architecture](https://ethernetdude.com/article-10-multicast-network-design-lab-building-a-scalable-architecture/) - This is the capstone. If you have worked through Articles 01 through 09, you now know how every multicast protocol operates at the packet level. You can co... - [Article 02: IGMP Hands-On Lab — Watching Receivers Talk to the Network](https://ethernetdude.com/article-02-igmp-hands-on-lab-watching-receivers-talk-to-the-network/) - Here is something that catches a lot of engineers off-guard. They configure PIM, set up the RP, multicast "works," & they move on. Then six months late... - [Article 01: Multicast Fundamentals Lab Why Unicast Fails at Scale](https://ethernetdude.com/article-01-multicast-fundamentals-lab-why-unicast-fails-at-scale/) - Let me tell you something that took me an embarrassing amount of time to truly appreciate early in my career. I understood multicast conceptually — "send o... - [Terraform init — What Actually Happens Under the Hood](https://ethernetdude.com/terraform-init-what-actually-happens-under-the-hood/) - terraform init — What Actually Happens Under the Hood You Type terraform init. What Actually Happens? Most people treat terraform init as "the thing you ru... - [Terraform State: What It Is and Why You Should Fear Losing It](https://ethernetdude.com/terraform-state-what-it-is-and-why-you-should-fear-losing-it/) - Terraform State: What It Is and Why You Should Fear Losing It The Uncomfortable Truth About State Terraform doesn't query your cloud every time to figure o... - [Providers: The Plugin Bridge Between Terraform and the World](https://ethernetdude.com/providers-the-plugin-bridge-between-terraform-and-the-world/) - Providers: The Plugin Bridge Between Terraform and the World Terraform Core Doesn't Know Your Cloud This is a point that confuses people early on. Terrafor... - [Why Terraform Specifically? The Multi-Cloud Angle](https://ethernetdude.com/why-terraform-specifically-the-multi-cloud-angle/) - Why Terraform Specifically? The Multi-Cloud Angle There Are Other Tools. Why Terraform? Every major cloud has its own IaC tool. AWS has CloudFormation. Azu... - [TFLAB26-State Locking: Preventing Concurrent State Corruption](https://ethernetdude.com/tflab26-state-locking-preventing-concurrent-state-corruption/) - Prevent concurrent state corruption with DynamoDB state locking. Learn lock acquisition, release, and terraform force-unlock for stuck locks. - [TFLAB25-Local vs Remote State: Where Does Terraform Store State](https://ethernetdude.com/tflab25-local-vs-remote-state-where-does-terraform-store-state/) - Understand Terraform state — local terraform.tfstate vs S3 remote backend. Migrate state between backends and enable encryption at rest. - [TFLAB24-Module Composition: Passing Data Between Modules](https://ethernetdude.com/tflab24-module-composition-passing-data-between-modules/) - Wire Terraform modules together by passing outputs from one module as inputs to another. Understand cross-module dependencies and composition patterns. - [TFLAB23-Module Sources and Versioning](https://ethernetdude.com/tflab23-module-sources-and-versioning/) - Reference Terraform modules from local paths, the Terraform Registry, Git URLs, and GitHub. Pin module versions with pessimistic constraints. - [TFLAB22-Writing Your First Terraform Module](https://ethernetdude.com/tflab22-writing-your-first-terraform-module/) - Create a reusable Terraform module from scratch — define inputs, outputs, and resources in a module directory. Call it multiple times with different parameters. - [TFLAB21-precondition, postcondition and check Blocks](https://ethernetdude.com/tflab21-precondition-postcondition-and-check-blocks/) - Validate assumptions before and after resource creation with Terraform precondition and postcondition. Use check blocks for ongoing health monitoring. - [TFLAB20-null_resource and terraform_data: Actions Without Cloud Resources](https://ethernetdude.com/tflab20-null_resource-and-terraform_data-actions-without-cloud-resources/) - Use null_resource and terraform_data to attach provisioners and triggers to non-cloud actions. Learn triggers, triggers_replace, and legacy vs modern approaches. - [TFLAB19-Provisioners: local-exec, remote-exec and Why They Are a Last Resort](https://ethernetdude.com/tflab19-provisioners-local-exec-remote-exec-and-why-they-are-a-last-resort/) - Learn Terraform provisioners — local-exec, remote-exec, file, on_failure, destroy-time. Understand why HashiCorp considers them a last resort. - [TFLAB18-Lifecycle Rules: Controlling Resource Behavior](https://ethernetdude.com/tflab18-lifecycle-rules-controlling-resource-behavior/) - Control Terraform resource behavior with lifecycle rules — create_before_destroy, prevent_destroy, ignore_changes, and replace_triggered_by. - [TFLAB17-templatefile() and file(): External Content in Terraform](https://ethernetdude.com/tflab17-templatefile-and-file-external-content-in-terraform/) - Use templatefile() to render external templates with Terraform variables. Learn file() for static content, heredoc syntax, and template loop/conditional directives. - [TFLAB16-Collection Functions: Maps, Lists and Transformations](https://ethernetdude.com/tflab16-collection-functions-maps-lists-and-transformations/) - Master Terraform collection functions — merge, flatten, lookup, keys, values, coalesce, contains, element, zipmap, and length. - [TFLAB14-for Expressions: Transforming Lists and Maps](https://ethernetdude.com/tflab14-for-expressions-transforming-lists-and-maps/) - Transform, filter, and reshape data with Terraform for expressions. Learn list-to-list, list-to-map, map-to-list, and filtering with if clauses. - [TFLAB13-Conditional Expressions: If-Then-Else in HCL](https://ethernetdude.com/tflab13-conditional-expressions-if-then-else-in-hcl/) - Master HCL ternary operator for conditional attributes, tags, and computed values. Adapt configuration behavior per environment without separate configs. - [TFLAB12-dynamic Blocks: Generating Repeated Nested Blocks](https://ethernetdude.com/tflab12-dynamic-blocks-generating-repeated-nested-blocks/) - Use Terraform dynamic blocks to generate repeated nested blocks from variables. Learn content, iterator, and data-driven security group rules. - [TFLAB07-Locals: DRY Configuration with Computed Values](https://ethernetdude.com/tflab07-locals-dry-configuration-with-computed-values/) - Use Terraform locals to eliminate repetition. Create naming prefixes, common tag maps, and computed values referenced across multiple resources. - [TFLAB06-Outputs: Basic, Sensitive and Complex Types](https://ethernetdude.com/tflab06-outputs-basic-sensitive-and-complex-types/) - Create Terraform outputs of all types — basic strings, sensitive values, lists, and maps. Learn terraform output, -raw, and -json CLI commands. - [TFLAB05-Variable Validation: Catching Bad Input at Plan Time](https://ethernetdude.com/tflab05-variable-validation-catching-bad-input-at-plan-time/) - Add validation rules to Terraform variables using can(), regex(), and contains(). Catch invalid input immediately at plan time with clear error messages. - [TFLAB04-Variable Precedence: Six Ways to Set a Variable](https://ethernetdude.com/tflab04-variable-precedence-six-ways-to-set-a-variable/) - Discover all six ways to set Terraform variables and their precedence order — from defaults to -var flag. Test which value wins when set in multiple places. - [TFLAB03-Complex Variable Types: Objects, Tuples and Optional Attributes](https://ethernetdude.com/tflab03-complex-variable-types-objects-tuples-and-optional-attributes/) - Learn Terraform complex types — object, tuple, optional() attributes, and nullable variables. Group related settings into structured inputs. - [TFLAB02-Variables: The Five Core Types](https://ethernetdude.com/tflab02-variables-the-five-core-types/) - Master all five Terraform variable types — string, number, bool, list, and map. Learn type, default, and description attributes with practical S3 bucket examples. - [TFLAB01-Your First Terraform Configuration from Scratch](https://ethernetdude.com/tflab01-your-first-terraform-configuration-from-scratch/) - Build your very first Terraform config from scratch — learn the terraform block, required_version, required_providers, and the init/plan/apply/destroy workflow using a simple S3 bucket. - [Repository Structure & Team Ownership: Organizing Terraform at Scale](https://ethernetdude.com/repository-structure-team-ownership-organizing-terraform-at-scale/) - You don't build a company's infrastructure in a single Terraform directory. Not because Terraform can't handle it because people can't. Networking engineers shouldn't be reviewing compute changes. - [LAB01_AWS_Launching Your First EC2 Instance with a Security Group](https://ethernetdude.com/lab01_aws_launching-your-first-ec2-instance-with-a-security-group/) - You have just joined a small startup as their first cloud engineer. The team needs a simple web server running on AWS to host an internal tool. Your manag... - [Secrets in Terraform: Never Hardcode, Never Regret](https://ethernetdude.com/secrets-in-terraform-never-hardcode-never-regret/) - Secrets in Terraform: Never Hardcode, Never Regret The Fastest Way to Get Paged at 2am # DO NOT DO THIS resource "aws_db_instance" "main&quo... - [Validation & Checks: Failing Fast Before You Break Prod](https://ethernetdude.com/validation-checks-failing-fast-before-you-break-prod/) - Validation & Checks: Failing Fast Before You Break Prod The Cost of Discovering Errors Late You run terraform apply. It successfully provisions 15 reso... - [Provisioners & null_resource: The Last Resort](https://ethernetdude.com/provisioners-null_resource-the-last-resort/) - Provisioners & null_resource: The Last Resort HashiCorp's Own Warning — And Why You Should Listen HashiCorp explicitly documents provisioners as a "las... - [Built-in Functions & Dynamic Expressions](https://ethernetdude.com/built-in-functions-dynamic-expressions/) - Built-in Functions & Dynamic Expressions HCL Is Not a Programming Language — But It's Surprisingly Capable You can't write arbitrary loops, define cust... - [count & for_each: Dynamic Resource Creation Done Right](https://ethernetdude.com/count-for_each-dynamic-resource-creation-done-right/) - count & for_each: Dynamic Resource Creation Done Right The Problem: Copy-Pasting Resource Blocks resource "aws_instance" "web_1" { ... - [lifecycle Meta-Arguments: Guard Your Infrastructure](https://ethernetdude.com/lifecycle-meta-arguments-guard-your-infrastructure/) - lifecycle Meta-Arguments: Guard Your Infrastructure The Default Behavior Will Surprise You When Terraform needs to replace a resource — because a changed a... - [References, Dependencies & the Resource Graph](https://ethernetdude.com/references-dependencies-the-resource-graph/) - References, Dependencies & the Resource Graph Terraform Knows the Order — That's the Point One of Terraform's most powerful properties is that you don'... - [HCL Type System: Complex Types Deep Dive](https://ethernetdude.com/hcl-type-system-complex-types-deep-dive/) - HCL Type System: Complex Types Deep Dive Why Types Matter in Infrastructure Code A lot of Terraform configs run fine for months — until someone passes a li... - [Variable Precedence & .tfvars](https://ethernetdude.com/variable-precedence-tfvars/) - Variable Precedence & .tfvars: Who Wins the Override War? When Multiple Sources Compete for the Same Variable Terraform lets you set variable values fr... - [locals: Stop Repeating Yourself](https://ethernetdude.com/locals-stop-repeating-yourself/) - locals: Stop Repeating Yourself The Problem Locals Solve You have a project name, an environment tag, and a naming convention. They appear in resource name... - [Variables & Outputs: Making Configuration Reusable](https://ethernetdude.com/variables-outputs-making-configuration-reusable/) - Variables & Outputs: Making Configuration Reusable Hardcoded Configs Are Dead on Arrival A Terraform config with hardcoded values — a specific AMI ID, ... - [Terraform fmt, validate & destroy — The Cleanup Crew](https://ethernetdude.com/terraform-fmt-validate-destroy-the-cleanup-crew/) - terraform fmt, validate & destroy — The Cleanup Crew terraform fmt — Why Formatting Matters More Than You Think HCL has an official canonical format. t... - [Resources & Data Sources: The Building Blocks](https://ethernetdude.com/resources-data-sources-the-building-blocks/) - Resources & Data Sources: The Building Blocks Two Fundamental Block Types — And They Solve Different Problems Everything you do in Terraform comes down... - [terraform plan & terraform apply — Reading the Diff Like a Pro](https://ethernetdude.com/terraform-plan-terraform-apply-reading-the-diff-like-a-pro/) - terraform plan & terraform apply — Reading the Diff Like a Pro terraform plan — The Safety Net You Should Never Skip Never run terraform apply without ... - [Managing Terraform & Provider Versions](https://ethernetdude.com/managing-terraform-provider-versions/) - Managing Terraform & Provider Versions Why Version Pinning Exists You build infrastructure with Terraform 1.5 today. Six months later a teammate clones... - [101: The Problem With Clicking](https://ethernetdude.com/101-the-problem-with-clicking/) - Why IaC? The Case Against Clicking in the Console The Problem With Clicking You spin up a VM. You click through the console, pick the right region, set the... - [Modules 101: Structure, Inputs, Outputs & Local Modules](https://ethernetdude.com/modules-101-structure-inputs-outputs-local-modules-2/) - module is just a reusable, self-contained package of Terraform configuration. Write it once, call it from anywhere, feed it different inputs per environment. - [The Terraform Registry & Module Versioning](https://ethernetdude.com/the-terraform-registry-module-versioning/) - I've watched engineers spend two weeks writing a custom VPC module. Handcrafting subnet logic, NAT gateway failover, route table associations. Beautiful code. Then I showed them terraform-aws-modules/vpc/aws - [Backends: Where State Lives & How It Stays Locked](https://ethernetdude.com/backends-where-state-lives-how-it-stays-locked/) - By default, Terraform stores state locally in ./terraform.tfstate. For learning and solo projects? Fine. In any environment where more than one person touches the infrastructure? It's a disaster waiting to happen. - [State Operations: Import, Move, Refactor & Drift](https://ethernetdude.com/state-operations-import-move-refactor-drift/) - Most engineers treat the state file like it's radioactive. And look, healthy respect is good — it IS the single source of truth for what Terraform manages. But it's not untouchable. Terraform gives you safe, auditable commands for manipulating state when the situation demands it. - [terraform_remote_state: Reading State Across Workspaces](https://ethernetdude.com/terraform_remote_state-reading-state-across-workspaces/) - A Terraform workspace is an isolated execution context with its own state file. Think of it as a boundary: everything declared in this directory of .tf files, backed by this state file, is one unit of infrastructure. - [Debugging Terraform: Logs, Errors & the TF_LOG Nuclear Option](https://ethernetdude.com/debugging-terraform-logs-errors-the-tf_log-nuclear-option/) - Terraform errors: they look scary but they're almost always specific. Wrong argument name, missing required field, provider API rejection with a reason attached. Before you reach for verbose logging, just read the error message. - [Operational Commands: terraform show, state list & the Inspection Toolkit](https://ethernetdude.com/operational-commands-terraform-show-state-list-the-inspection-toolkit/) - there's a whole set of commands that are purely for reading understanding what Terraform thinks is deployed, what state looks like, what outputs are available. - [Workspaces Are Isolated State Environments](https://ethernetdude.com/workspaces-are-isolated-state-environments/) - You've got one Terraform config. You want to deploy it to dev, staging, and prod without copy-pasting into three separate directories. CLI workspaces let you do exactly this - [HCP Terraform: Workspaces, Variable Sets, Remote Runs & Migration](https://ethernetdude.com/hcp-terraform-workspaces-variable-sets-remote-runs-migration/) - Terraform OSS is a CLI tool. Works great for one person. The moment you have a team, the cracks show: - [HCP Terraform: Teams, Policies, Health, Explorer & Dynamic Credentials](https://ethernetdude.com/hcp-terraform-teams-policies-health-explorer-dynamic-credentials/) - But running Terraform at scale isn't just about execution. It's about governance: who can do what, what policies are enforced before changes land, how do you know if infrastructure has drifted - [CI/CD Pipelines: From Pull Request to Production](https://ethernetdude.com/ci-cd-pipelines-from-pull-request-to-production/) - If someone on your team is running terraform apply against production from their laptop, your process has a hole in it. Fix it before you fix anything else. - [The End-to-End Production Scenario: How It All Fits Together](https://ethernetdude.com/the-end-to-end-production-scenario-how-it-all-fits-together/) - You've learned the pieces: modules, state files, backends, remote state, workspaces, policies, CI/CD. This article puts them all together. We're walking through a complete production scenario - [LAB41_AWS_Step Functions: Saga Pattern for Distributed Order Transactions](https://ethernetdude.com/lab41_aws_step-functions-saga-pattern-for-distributed-order-transactions/) - Your e-commerce order workflow involves three microservices: Inventory (reserves stock), Payment (charges the customer), and Fulfilment (ships the order).... - [LAB42_AWS_Amazon EKS: Managed Node Group, IRSA, and ALB Ingress Controller](https://ethernetdude.com/lab42_aws_amazon-eks-managed-node-group-irsa-and-alb-ingress-controller/) - Your platform team is migrating workloads to Kubernetes on EKS. You need a production-ready cluster with managed node groups (so AWS handles node upgrades... - [LAB43_AWS_AWS Organizations: Service Control Policies as Account Guardrails](https://ethernetdude.com/lab43_aws_aws-organizations-service-control-policies-as-account-guardrails/) - Your organisation uses AWS Organizations with three OUs: Production, Development, and Sandbox. Your security team needs preventative guardrails that no i... - [LAB44_AWS_Terraform Workspaces + Remote State Data Sources: Env Pipeline](https://ethernetdude.com/lab44_aws_terraform-workspaces-remote-state-data-sources-env-pipeline/) - Your infrastructure is split into two layers: a networking layer (VPCs, subnets, route tables) managed by the networking team, and an application layer (... - [LAB45_AWS_User Authentication: Cognito User Pool + API Gateway JWT Authorizer](https://ethernetdude.com/lab45_aws_user-authentication-cognito-user-pool-api-gateway-jwt-authorizer/) - Your React SPA calls a REST API. Currently the API has no authentication — anyone who finds the URL can call it. You need to add user authentication using... - [LAB46_AWS_Threat Detection: GuardDuty + Security Hub + Automated Response](https://ethernetdude.com/lab46_aws_threat-detection-guardduty-security-hub-automated-response/) - Your security team is alerted to threats via email but by the time a human investigates, attackers have already exfiltrated data. You need an automated th... - [LAB47_AWS_In-Memory Caching: ElastiCache Redis Cluster with Subnet Group and Auth](https://ethernetdude.com/lab47_aws_in-memory-caching-elasticache-redis-cluster-with-subnet-group-and-auth/) - Your application's database is under heavy read load because every API response requires multiple queries for session data, product catalog lookups, and u... - [LAB48_AWS_Hybrid Connectivity: Site-to-Site VPN with BGP Routing](https://ethernetdude.com/lab48_aws_hybrid-connectivity-site-to-site-vpn-with-bgp-routing/) - Your organisation has an on-premises data center in London with a Cisco ASA firewall. Internal teams need access to cloud resources in AWS using private I... - [LAB49_AWS_Advanced HCL: Dynamic Blocks, Complex Expressions, and Custom Conditions](https://ethernetdude.com/lab49_aws_advanced-hcl-dynamic-blocks-complex-expressions-and-custom-conditions/) - You manage security groups for 12 different microservices. Each service has a different set of ingress rules defined in a YAML-like variable structure. Wr... - [LAB50_AWS_Capstone: Production Deployment — State Management, Drift Detection, and Lifecycle Control](https://ethernetdude.com/lab50_aws_capstone-production-deployment-state-management-drift-detection-and-lifecycle-control/) - You've been handed ownership of a production AWS account. Somebody manually created an RDS instance and an S3 bucket directly in the console — they are no... - [LAB38_AWS_Real-Time Data Pipeline: Kinesis Streams + Firehose + Lambda + S3](https://ethernetdude.com/lab38_aws_real-time-data-pipeline-kinesis-streams-firehose-lambda-s3/) - Your IoT devices emit sensor readings at 50,000 events/minute. You need a pipeline that captures these events in real time, enriches each record with a ti... - [LAB39_AWS_IAM Identity Center: Multi-Account SSO with Permission Sets](https://ethernetdude.com/lab39_aws_iam-identity-center-multi-account-sso-with-permission-sets/) - Your organisation has grown to 5 AWS accounts managed under AWS Organizations. Engineers currently have individual IAM users with long-term credentials in... - [LAB40_AWS_Resilient Queue Processing: SQS + Lambda with Concurrency Controls and DLQ](https://ethernetdude.com/lab40_aws_resilient-queue-processing-sqs-lambda-with-concurrency-controls-and-dlq/) - Your payment processing service writes messages to an SQS queue. A Lambda function processes each payment. Last Black Friday, the queue backed up to 200,0... - [LAB21_AWS_SSM Parameter Store: Standard and SecureString Parameters](https://ethernetdude.com/lab21_aws_ssm-parameter-store-standard-and-securestring-parameters/) - Your application across multiple services needs to share configuration values — database hostnames, feature flags, and API keys. You want a centralised, v... - [LAB22_AWS_Terraform count: Creating Multiple Resources from One Block](https://ethernetdude.com/lab22_aws_terraform-count-creating-multiple-resources-from-one-block/) - Your company runs three environments: dev, staging, and prod. Each environment needs an identically-configured S3 bucket for application logs. Rather tha... - [LAB23_AWS_Terraform for_each: Map-Driven Resource Creation](https://ethernetdude.com/lab23_aws_terraform-for_each-map-driven-resource-creation/) - Your organisation needs to create multiple IAM users for a new development team, each with different access levels. You also need to create multiple S3 bu... - [LAB24_AWS_Input Variables: Validation Rules, Types, and Sensitive Values](https://ethernetdude.com/lab24_aws_input-variables-validation-rules-types-and-sensitive-values/) - Your Terraform modules are being used by multiple teams who occasionally pass invalid values — wrong environment names, invalid CIDR blocks, non-positive ... - [LAB25_AWS_S3 Remote State with DynamoDB Locking and Workspaces](https://ethernetdude.com/lab25_aws_s3-remote-state-with-dynamodb-locking-and-workspaces/) - Your team has been running Terraform on individual laptops with local state files. Two engineers ran terraform apply simultaneously last week and corrupte... - [LAB26_AWS_Three-Tier VPC: Public, Private App, and Private Data Subnets with Flow Logs](https://ethernetdude.com/lab26_aws_three-tier-vpc-public-private-app-and-private-data-subnets-with-flow-logs/) - Your security team has audited your AWS environment and identified the following gaps: the VPC has no flow logging (no audit trail of network connections)... - [LAB27_AWS_Serverless CRUD API: API Gateway + Lambda + DynamoDB with IAM Auth](https://ethernetdude.com/lab27_aws_serverless-crud-api-api-gateway-lambda-dynamodb-with-iam-auth/) - You are building a serverless items catalog API. The API must support full CRUD operations — create, read, update, and delete items — each handled by a de... - [LAB28_AWS_Production ECS Fargate Service: ALB, Auto Scaling, and Secrets Manager](https://ethernetdude.com/lab28_aws_production-ecs-fargate-service-alb-auto-scaling-and-secrets-manager/) - Your containerised web API needs to run in a production-grade configuration: traffic must enter through an Application Load Balancer, the ECS service must... - [LAB29_AWS_Production RDS: Multi-AZ, Read Replica, Enhanced Monitoring, and Secrets Manager](https://ethernetdude.com/lab29_aws_production-rds-multi-az-read-replica-enhanced-monitoring-and-secrets-manager/) - Your MySQL database is a single-AZ instance with no read scaling and the master password stored in Terraform state. Your DBA has raised three concerns: if... - [LAB30_AWS_Global SPA Hosting: S3 + CloudFront + ACM Certificate + WAF](https://ethernetdude.com/lab30_aws_global-spa-hosting-s3-cloudfront-acm-certificate-waf/) - Your React SPA needs to be served globally on a custom domain with a valid TLS certificate, protection against common web exploits (SQL injection, XSS), a... - [LAB31_AWS_Reusable Terraform Module: VPC with Subnets and Route Tables](https://ethernetdude.com/lab31_aws_reusable-terraform-module-vpc-with-subnets-and-route-tables/) - Your Terraform configurations for dev, staging, and prod all contain nearly identical VPC code — 80 lines of subnets, route tables, and IGW that differ o... - [LAB32_AWS_CI/CD Pipeline: CodePipeline + CodeBuild + CodeDeploy to ECS](https://ethernetdude.com/lab32_aws_ci-cd-pipeline-codepipeline-codebuild-codedeploy-to-ecs/) - Your team currently deploys the containerised API by running docker build and terraform apply manually from a developer's laptop. This is slow, error-pro... - [LAB33_AWS_Event-Driven Processing: EventBridge Rules + Lambda + SQS DLQ](https://ethernetdude.com/lab33_aws_event-driven-processing-eventbridge-rules-lambda-sqs-dlq/) - Your order management system publishes events to EventBridge whenever an order is placed, updated, or cancelled. Three different downstream services need ... - [LAB34_AWS_Cross-Account S3 Replication with KMS Encryption](https://ethernetdude.com/lab34_aws_cross-account-s3-replication-with-kms-encryption/) - Your compliance team requires that all objects uploaded to the production S3 bucket in Account A are automatically replicated to a disaster recovery vault... - [LAB35_AWS_VPC Peering: Connecting Application and Data VPCs Privately](https://ethernetdude.com/lab35_aws_vpc-peering-connecting-application-and-data-vpcs-privately/) - Your organisation uses two VPCs: an application VPC (10.0.0.0/16) running ECS workloads, and a data VPC (10.1.0.0/16) running RDS databases. Currently, a... - [LAB36_AWS_Compliance Automation: AWS Config Rules + Lambda Auto-Remediation](https://ethernetdude.com/lab36_aws_compliance-automation-aws-config-rules-lambda-auto-remediation/) - Your security team's compliance scan revealed that S3 buckets with public access enabled and EC2 instances without required tags slip through undetected u... - [LAB37_AWS_Transit Gateway: Hub-and-Spoke Multi-VPC Connectivity](https://ethernetdude.com/lab37_aws_transit-gateway-hub-and-spoke-multi-vpc-connectivity/) - Your organisation has three VPCs: App, Shared Services (DNS, Active Directory), and Egress (with a NAT Gateway for shared internet access). VPC Peering d... - [LAB04_AWS_IAM Role, Policy Document, and Instance Profile](https://ethernetdude.com/lab04_aws_iam-role-policy-document-and-instance-profile/) - Your EC2 instances need to read objects from a specific S3 bucket and send messages to an SQS queue, but you do not want to store AWS access keys on the s... - [LAB05_AWS_RDS MySQL Instance with Parameter Group and Random Password](https://ethernetdude.com/lab05_aws_rds-mysql-instance-with-parameter-group-and-random-password/) - The development team needs a MySQL database for their application. It should be placed in a private subnet, use a securely-generated random password (neve... - [LAB06_AWS_Lambda Function with IAM Execution Role](https://ethernetdude.com/lab06_aws_lambda-function-with-iam-execution-role/) - Your team wants to run a small Python function that logs a greeting message whenever it is invoked. Rather than uploading a zip file manually, you want Te... - [LAB07_AWS_SQS Queue with Dead Letter Queue and Access Policy](https://ethernetdude.com/lab07_aws_sqs-queue-with-dead-letter-queue-and-access-policy/) - Your application publishes job requests to an SQS queue and a worker process consumes them. Sometimes a message cannot be processed (corrupted data, tempo... - [LAB08_AWS_SNS Topic with Email and SQS Subscriptions](https://ethernetdude.com/lab08_aws_sns-topic-with-email-and-sqs-subscriptions/) - Your application needs to send notifications when a critical event occurs — for example, when a deployment succeeds or fails. You want two things to happe... - [LAB09_AWS_CloudWatch Alarm on EC2 CPU with SNS Alert](https://ethernetdude.com/lab09_aws_cloudwatch-alarm-on-ec2-cpu-with-sns-alert/) - Your EC2-based web server has been running in production and sometime last week it hit 100% CPU for several minutes, causing request timeouts. Nobody noti... - [LAB10_AWS_DynamoDB Table with GSI, TTL, and Point-in-Time Recovery](https://ethernetdude.com/lab10_aws_dynamodb-table-with-gsi-ttl-and-point-in-time-recovery/) - Your application stores user session data in DynamoDB. Sessions need to automatically expire after a set time (TTL), and you need to be able to query sess... - [LAB11_AWS_Auto Scaling Group with Launch Template](https://ethernetdude.com/lab11_aws_auto-scaling-group-with-launch-template/) - Traffic to your web application spikes every weekday morning. A single EC2 instance can't handle peak load, and you can't afford to run large instances 24... - [LAB12_AWS_Application Load Balancer with Target Group and HTTPS Listener](https://ethernetdude.com/lab12_aws_application-load-balancer-with-target-group-and-https-listener/) - Your Auto Scaling Group runs multiple EC2 instances, but there is no single DNS name for the application and no way to distribute traffic evenly across in... - [LAB13_AWS_Route53 Hosted Zone, Alias Record, and Health Check](https://ethernetdude.com/lab13_aws_route53-hosted-zone-alias-record-and-health-check/) - Your application is now running behind an Application Load Balancer with a long, autogenerated DNS name. You need to create a user-friendly domain name li... - [LAB14_AWS_Secrets Manager Secret with KMS Encryption](https://ethernetdude.com/lab14_aws_secrets-manager-secret-with-kms-encryption/) - A common beginner pattern is to generate an RDS password with random_password and store it directly in Terraform state. While the state is encrypted at r... - [LAB15_AWS_KMS Customer Managed Key with Grants and Aliases](https://ethernetdude.com/lab15_aws_kms-customer-managed-key-with-grants-and-aliases/) - Your organisation's security policy requires that all S3 buckets, EBS volumes, and RDS instances use customer-managed KMS keys (CMKs) — not AWS-managed ke... - [LAB16_AWS_ECR Private Repository with Lifecycle Policy and Image Scanning](https://ethernetdude.com/lab16_aws_ecr-private-repository-with-lifecycle-policy-and-image-scanning/) - Your team is containerising the web application and needs a private Docker image repository in AWS. You also need to automatically clean up old images to ... - [LAB17_AWS_ECS Fargate Cluster with Task Definition and Service](https://ethernetdude.com/lab17_aws_ecs-fargate-cluster-with-task-definition-and-service/) - You have containerised the web application, built a Docker image, and pushed it to a private ECR repository. Now you want to run it on AWS Fargate without... - [LAB18_AWS_REST API Gateway with Lambda Integration and Stage Deployment](https://ethernetdude.com/lab18_aws_rest-api-gateway-with-lambda-integration-and-stage-deployment/) - You have a Python Lambda function that returns a JSON greeting response and you want to expose it as a public HTTP endpoint. API Gateway REST API is the m... - [LAB19_AWS_CloudFront Distribution with S3 Origin and Origin Access Control](https://ethernetdude.com/lab19_aws_cloudfront-distribution-with-s3-origin-and-origin-access-control/) - Your team has built a React single-page application and wants to host it as a static site served globally via CDN. The S3 bucket must not be publicly acce... - [LAB20_AWS_NAT Gateway and Elastic IP for Private Subnet Egress](https://ethernetdude.com/lab20_aws_nat-gateway-and-elastic-ip-for-private-subnet-egress/) - Your private subnet has no internet access. EC2 instances and ECS tasks in private subnets need to make outbound calls — to download package updates, call... - [LAB02_AWS_S3 Bucket with Versioning, Encryption and Lifecycle Rules](https://ethernetdude.com/lab02_aws_s3-bucket-with-versioning-encryption-and-lifecycle-rules/) - Your company stores customer-uploaded documents in S3. The security team requires that all objects be encrypted at rest and that older versions of documen... - [LAB03_AWS_Custom VPC with Public and Private Subnets](https://ethernetdude.com/lab03_aws_custom-vpc-with-public-and-private-subnets/) - Your team is moving away from the default AWS VPC, which exposes all subnets to the internet by default. You need to build a proper network foundation wit... - [LAB27_GCP_Serverless: API Gateway to Cloud Functions to Firestore](https://ethernetdude.com/lab27_gcp_serverless-api-gateway-to-cloud-functions-to-firestore/) - You are building a microservice to track user high scores. Exposing individual Cloud Functions directly to clients is difficult for routing and versioning... - [LAB29_GCP_Database Architecture: Cloud SQL HA and Read Replicas](https://ethernetdude.com/lab29_gcp_database-architecture-cloud-sql-ha-and-read-replicas/) - Your e-commerce database is mission-critical. If an availability zone goes down, your system must failover instantaneously. Furthermore, your analytics t... - [LAB28_GCP_Secure Connections: Cloud Run Direct VPC Egress to Cloud SQL](https://ethernetdude.com/lab28_gcp_secure-connections-cloud-run-direct-vpc-egress-to-cloud-sql/) - You are deploying a Node.js container to Cloud Run. The container must securely connect to a Cloud SQL PostgreSQL database. The database does not have a ... - [LAB26_GCP_Architecture: Production VPC Topology](https://ethernetdude.com/lab26_gcp_architecture-production-vpc-topology/) - In a production environment, you never use the `default` VPC network. You need a custom VPC with strict boundaries. You will build a foundational network... - [LAB07_GCP_Asynchronous Messaging: Pub/Sub Topics and Subscriptions](https://ethernetdude.com/lab07_gcp_asynchronous-messaging-pub-sub-topics-and-subscriptions/) - In event-driven architectures, services communicate indirectly. When a user creates an order, the "Orders Service" publishes an event, and the "Invoicing ... - [LAB08_GCP_Cron Jobs: Cloud Scheduler Triggering Pub/Sub](https://ethernetdude.com/lab08_gcp_cron-jobs-cloud-scheduler-triggering-pub-sub/) - You have a batch process that needs to run every night at 2:00 AM to aggregate analytics. Instead of keeping a VM running just to execute a cron tab, you... - [LAB10_GCP_NoSQL Database: Provisioning a Firestore Database](https://ethernetdude.com/lab10_gcp_nosql-database-provisioning-a-firestore-database/) - Your serverless app requires a flexible, fast, heavily scalable NoSQL document database to store application profiles. Instead of provisioning a heavy Ca... - [LAB30_GCP_Edge Security: HTTPS Load Balancing, Cloud CDN, and Cloud Armor](https://ethernetdude.com/lab30_gcp_edge-security-https-load-balancing-cloud-cdn-and-cloud-armor/) - An HTTP load balancer isn't enough for production. You require encrypted HTTPS connections and protection from DDoS attacks or SQL injection. You will orc... - [LAB31_GCP_Multi-Project Networking: Shared VPC](https://ethernetdude.com/lab31_gcp_multi-project-networking-shared-vpc/) - In enterprise environments, networking resources (VPCs, VPNs, Interconnects) are centralized in a single "Host Project" managed by the Network Administrat... - [LAB32_GCP_DevOps: CI/CD Pipeline with Cloud Build](https://ethernetdude.com/lab32_gcp_devops-ci-cd-pipeline-with-cloud-build/) - You want code pushes to automatically build a Docker container and deploy it to serverless infrastructure. Instead of using GitHub Actions or Jenkins, you... - [LAB33_GCP_Event-Driven: Eventarc, Cloud Storage, and Cloud Run](https://ethernetdude.com/lab33_gcp_event-driven-eventarc-cloud-storage-and-cloud-run/) - When a user uploads an image to a Cloud Storage Bucket, you want an asynchronous background process to immediately resize the image. Instead of polling th... - [LAB50_GCP_State Capstone: Import blocks, moved blocks, and prevent_destroy](https://ethernetdude.com/lab50_gcp_state-capstone-import-blocks-moved-blocks-and-prevent_destroy/) - An administrator "ClickOps'd" a critical Cloud Storage bucket directly in the GCP console. You need to bring it under Terraform management using the moder... - [LAB09_GCP_Observability: Cloud Monitoring Alert Policies](https://ethernetdude.com/lab09_gcp_observability-cloud-monitoring-alert-policies/) - You want to be notified if the average CPU utilisation of your Compute Engine instances goes above 80% for more than 5 minutes. You will use a Cloud Monit... - [Basics of Python Part -1](https://ethernetdude.com/basics-of-python-part-1/) - Expressions: In python, 2+2 is called an expression, which is the most basic kind of programming instruction in the language. Expressions consists of values such as 2 & the + symbol is called operator. Below is the list of Math Operators in python. The order of operations {Also called precedence} of python math operators is - [LAB15_GCP_Encryption: Customer Managed Encryption Keys (CMEK)](https://ethernetdude.com/lab15_gcp_encryption-customer-managed-encryption-keys-cmek/) - By default, all Google Cloud Storage data is encrypted using Google Managed Encryption Keys. For regulatory compliance, your client requires Customer Mana... - [LAB16_GCP_Container Images: Artifact Registry Repository](https://ethernetdude.com/lab16_gcp_container-images-artifact-registry-repository/) - Before you can deploy containers to Cloud Run or GKE, you must store their images in a secure registry. Google Cloud replaced the legacy "Container Regist... - [LAB17_GCP_Kubernetes: Deploying a GKE Autopilot Cluster](https://ethernetdude.com/lab17_gcp_kubernetes-deploying-a-gke-autopilot-cluster/) - Your team wants to deploy workloads to Kubernetes, but they don't want the operational burden of managing Node Groups, VM scaling, or Kubernetes version ... - [LAB18_GCP_Serverless Containers: Deploying to Cloud Run](https://ethernetdude.com/lab18_gcp_serverless-containers-deploying-to-cloud-run/) - You have a stateless web application packaged as a Docker container. You don't want to deal with Kubernetes. Cloud Run is Google's Knative-based serverles... - [LAB19_GCP_Static Delivery: Cloud CDN caching a Cloud Storage Bucket](https://ethernetdude.com/lab19_gcp_static-delivery-cloud-cdn-caching-a-cloud-storage-bucket/) - You have a folder of static frontend assets (images, CSS, JS) that need to be delivered to global users with extremely low latency. Instead of serving the... - [LAB20_GCP_Egress Networks: Cloud NAT and Cloud Router](https://ethernetdude.com/lab20_gcp_egress-networks-cloud-nat-and-cloud-router/) - You have provisioned a Virtual Machine sitting on a custom VPC subnet. For security, you explicitly did not give the VM a public IP address. Now, the VM n... - [LAB21_GCP_Data Protection: Compute Engine Disk Snapshots](https://ethernetdude.com/lab21_gcp_data-protection-compute-engine-disk-snapshots/) - You have a standalone Compute Engine instance running legacy software that stores data directly on its boot disk. You need to create a point-in-time backu... - [LAB22_GCP_Terraform State: Creating Multiple Resources with Count](https://ethernetdude.com/lab22_gcp_terraform-state-creating-multiple-resources-with-count/) - Your data engineering team is running an experiment and needs 3 identical Cloud Storage buckets, one for each phase of their pipeline (ingest, process, se... - [LAB23_GCP_Terraform State: Creating Managed Resources with For_Each](https://ethernetdude.com/lab23_gcp_terraform-state-creating-managed-resources-with-for_each/) - Your microservices architecture defines 3 Pub/Sub topics: orders, payments, and shipping. Instead of writing three resource blocks, or using count (which... - [LAB48_GCP_Terraform Engineering: Advanced Reusable GCP Modules](https://ethernetdude.com/lab48_gcp_terraform-engineering-advanced-reusable-gcp-modules/) - Your organization creates dozens of Cloud Storage buckets a week. You want to enforce a standard where all buckets must have uniform bucket level access e... - [LAB49_GCP_Advanced HCL: Dynamic Blocks and Lifecycle Preconditions](https://ethernetdude.com/lab49_gcp_advanced-hcl-dynamic-blocks-and-lifecycle-preconditions/) - You are writing a complex `.tf` file to rapidly spin up testing Compute Instances with specific open firewall ports. Instead of hardcoding 10 different `a... - [LAB25_GCP_Terraform State: Cloud Storage Remote Backend and Workspaces](https://ethernetdude.com/lab25_gcp_terraform-state-cloud-storage-remote-backend-and-workspaces/) - So far, your `terraform.tfstate` file has lived locally on your laptop. If your hard drive crashes, you lose track of the infrastructure. For teams, you m... - [LAB03_GCP_VPC Networks: Custom Mode and Subnets](https://ethernetdude.com/lab03_gcp_vpc-networks-custom-mode-and-subnets/) - GCP default networks automatically create subnets in every single region across the globe. For greater control and security, you should use custom mode VP... - [LAB04_GCP_Identity and Access Management: Service Accounts & Bindings](https://ethernetdude.com/lab04_gcp_identity-and-access-management-service-accounts-bindings/) - In Google Cloud, applications and resources authenticate using Service Accounts rather than human user credentials. You need to create a service account d... - [LAB05_GCP_Cloud SQL: Provisioning a PostgreSQL Managed Database](https://ethernetdude.com/lab05_gcp_cloud-sql-provisioning-a-postgresql-managed-database/) - Your application needs a relational database. Instead of managing VMs and database software manually, you will use Cloud SQL, Google's fully managed relat... - [LAB06_GCP_Serverless: Deploying Cloud Functions (2nd Gen)](https://ethernetdude.com/lab06_gcp_serverless-deploying-cloud-functions-2nd-gen/) - You want to deploy a simple serverless "Hello World" API endpoint without managing any infrastructure. In Google Cloud, Cloud Functions (2nd Gen) is the r... - [LAB35_GCP_Network Topology: VPC Network Peering](https://ethernetdude.com/lab35_gcp_network-topology-vpc-network-peering/) - Your decentralized organization has two separate VPC networks ("Frontend" and "Backend") living in completely independent administrative planes. They mus... - [LAB36_GCP_DevSecOps: Security Command Center Auto-Remediation](https://ethernetdude.com/lab36_gcp_devsecops-security-command-center-auto-remediation/) - Your organization uses Security Command Center (SCC) to detect misconfigurations. You want to implement Auto-Remediation. When a developer accidentally ma... - [LAB02_GCP_Cloud Storage: Versioned Buckets and Lifecycle Rules](https://ethernetdude.com/lab02_gcp_cloud-storage-versioned-buckets-and-lifecycle-rules/) - Your data science team needs a place to store training datasets. They require a bucket that prevents accidental deletion of files (by keeping previous ver... - [LAB38_GCP_Data Engineering: Pub/Sub to BigQuery Streaming Pipeline](https://ethernetdude.com/lab38_gcp_data-engineering-pub-sub-to-bigquery-streaming-pipeline/) - Your IoT devices publish thousands of telemetry events to a Pub/Sub topic per second. You need to stream these events directly into a BigQuery table for a... - [LAB12_GCP_Traffic Routing: Global External Application Load Balancer](https://ethernetdude.com/lab12_gcp_traffic-routing-global-external-application-load-balancer/) - You have an unmanaged group of instances (or an empty backend for right now) and you need to deploy Google's globally distributed External Application Lo... - [LAB13_GCP_DNS: Cloud DNS Managed Zones and Record Sets](https://ethernetdude.com/lab13_gcp_dns-cloud-dns-managed-zones-and-record-sets/) - Your project owns the domain example.com and you want Google Cloud DNS to act as the authoritative name server. You need to create a public Managed Zone ... - [LAB44_GCP_State Architecture: Multi-Environment Workspaces and GCS](https://ethernetdude.com/lab44_gcp_state-architecture-multi-environment-workspaces-and-gcs/) - You are building infrastructure that supports "dev", "staging", and "prod" environments. Instead of using completely separate Git directories with duplica... - [LAB45_GCP_API Security: Validating Identity Platform JWTs at the Gateway](https://ethernetdude.com/lab45_gcp_api-security-validating-identity-platform-jwts-at-the-gateway/) - Your mobile app allows users to log in (using email or Google OAuth). This process leverages GCP Identity Platform (formerly Firebase Auth), which issues ... - [LAB11_GCP_Autoscaling: Managed Instance Groups and Instance Templates](https://ethernetdude.com/lab11_gcp_autoscaling-managed-instance-groups-and-instance-templates/) - A single Compute Engine VM is a single point of failure and cannot handle varying amounts of traffic. To solve this, you use a Managed Instance Group (MIG... - [LAB42_GCP_Kubernetes Security: GKE with Workload Identity](https://ethernetdude.com/lab42_gcp_kubernetes-security-gke-with-workload-identity/) - In a GKE cluster, the worker nodes (Compute Engine VMs) have a Service Account. Historically, all pods running on those nodes inherited the node's Service... - [LAB43_GCP_Guardrails: Enforcing Organization Policies](https://ethernetdude.com/lab43_gcp_guardrails-enforcing-organization-policies/) - Your legal department mandates that all data must reside in the United States or the European Union. Developers should not be able to accidentally deploy... - [LAB24_GCP_Terraform Core: Advanced Input Variables and Custom Validation](https://ethernetdude.com/lab24_gcp_terraform-core-advanced-input-variables-and-custom-validation/) - You are writing a Terraform configuration that will be used by other developers. They need to supply an environment name and an instance size. If they sup... - [LAB34_GCP_Multi-Project Security: Cross-Project IAM and Storage](https://ethernetdude.com/lab34_gcp_multi-project-security-cross-project-iam-and-storage/) - An application running in your "App Project" needs to securely read analytics data stored in a Cloud Storage bucket located in your completely separate "D... - [LAB37_GCP_Hybrid Connectivity: High Availability (HA) VPN with BGP](https://ethernetdude.com/lab37_gcp_hybrid-connectivity-high-availability-ha-vpn-with-bgp/) - Your GCP VPC needs to establish an encrypted, highly resilient Site-to-Site tunnel to an On-Premises data center (or another cloud like AWS). You must pr... - [LAB01_GCP_Compute Engine: Deploying a VM with Firewall Rules](https://ethernetdude.com/lab01_gcp_compute-engine-deploying-a-vm-with-firewall-rules/) - You are deploying a simple Nginx web server on Google Cloud Platform. You need to provision a Compute Engine virtual machine (VM) and ensure it's accessib... - [LAB14_GCP_Secrets: Google Secret Manager](https://ethernetdude.com/lab14_gcp_secrets-google-secret-manager/) - Your application needs to securely connect to a 3rd-party API using a token. Hardcoding credentials in code or storing them raw in Terraform state isn't s... - [LAB39_GCP_Secure Auth: Workload Identity Federation (Keyless APIs)](https://ethernetdude.com/lab39_gcp_secure-auth-workload-identity-federation-keyless-apis/) - Your GitHub Actions CI/CD pipeline needs to deploy files to Google Cloud Storage. Previously, you would generate a JSON Service Account Key and store it i... - [LAB40_GCP_Asynchronous Execution: Cloud Tasks and Cloud Run](https://ethernetdude.com/lab40_gcp_asynchronous-execution-cloud-tasks-and-cloud-run/) - Your serverless API application lets users generate reports. Report generation takes 3 minutes. If you run this synchronously, the user's HTTP request wil... - [LAB41_GCP_Advanced IAM: Custom Roles and IAM Conditions](https://ethernetdude.com/lab41_gcp_advanced-iam-custom-roles-and-iam-conditions/) - The predefined `roles/storage.admin` role grants too much power. You want a "Bucket Manager" role that can create and delete buckets, but cannot read or m... - [LAB46_GCP_Data Exfiltration Prevention: VPC Service Controls](https://ethernetdude.com/lab46_gcp_data-exfiltration-prevention-vpc-service-controls/) - Your organization handles highly sensitive PII data in Cloud Storage and BigQuery. You are worried that a malicious insider with `roles/storage.admin` cou... - [LAB47_GCP_Caching: Memorystore (Redis) and Legacy Serverless Connectors](https://ethernetdude.com/lab47_gcp_caching-memorystore-redis-and-legacy-serverless-connectors/) - Your serverless API is experiencing high latency querying BigQuery. You want to introduce a caching layer. You will deploy GCP's managed Redis offering: M... - [The Security Specialist: Cloud NGFW Enterprise & Secure Web Proxy](https://ethernetdude.com/the-security-specialist-cloud-ngfw-enterprise-secure-web-proxy/) - Standard VPC Firewall rules operate at Layer 3 and Layer 4—they allow or deny traffic based on IP addresses, ports, and protocols. This is sufficient for most use cases, but it cannot distinguish between a legitimate HTTPS request and an SQL injection payload hiding inside the same TCP 443 stream. For organizations that need deep packet - [Advanced BGP, SSL Policies & Network Benchmarking](https://ethernetdude.com/advanced-bgp-ssl-policies-network-benchmarking/) - This article addresses the advanced specifics that experienced network engineers expect to see in a comprehensive study guide. These are the topics that bridge the gap between "I know what BGP is" and "I can configure BGP route advertisements with custom filtering on Cloud Router." If you come from a traditional networking background with Cisco - [Private Access & Service Connectivity](https://ethernetdude.com/private-access-service-connectivity/) - One of the most counterintuitive things about Google Cloud is that your VMs, by default, cannot reach Google APIs like Cloud Storage or BigQuery over a private path. If your VM calls storage.googleapis.com, the request leaves Google's network, traverses the public internet, and comes back in through Google's front door. The data stays within Google's infrastructure - [The Final Granularity: reCAPTCHA, Cache Invalidation & IPv6 Load Balancing](https://ethernetdude.com/the-final-granularity-recaptcha-cache-invalidation-ipv6-load-balancing/) - Every exam has a handful of questions that test extremely specific, granular features. These are not the "big concept" questions—they are the ones that separate a score of 75% from 90%. This article covers the niche details that are easy to overlook but appear with surprising regularity on the PCNE exam. reCAPTCHA Enterprise with Cloud - [Compliance, Encryption & Migration Patterns](https://ethernetdude.com/compliance-encryption-migration-patterns/) - Cloud migration is not just a technical exercise—it is a compliance exercise. Every byte of data that moves from on-premises to Google Cloud must satisfy regulatory requirements for encryption, data residency, and access control. The PCNE exam tests your understanding of how Google Cloud's networking features support these compliance mandates, and how you design migration - [Edge Security & Performance: Advanced Cloud Armor & CDN](https://ethernetdude.com/edge-security-performance-advanced-cloud-armor-cdn/) - The edge of your network is where the internet meets your infrastructure. It is the first line of defense against DDoS attacks, bot swarms, and exploit attempts—and the last opportunity to cache content before it begins its journey to the user. Google Cloud's edge is unique because it is the same edge that protects Google - [Serverless Networking: Cloud Run, Functions & App Engine](https://ethernetdude.com/serverless-networking-cloud-run-functions-app-engine/) - Serverless computing promises that you never think about servers. You write code, deploy it, and it scales automatically. But the network does not disappear just because the compute is abstracted—it becomes harder to see and easier to misconfigure. How does a Cloud Run service connect to a Cloud SQL instance on a private IP? How - [The Ultimate Cheat Sheet: Limits, Quotas & Decision Trees](https://ethernetdude.com/the-ultimate-cheat-sheet-limits-quotas-decision-trees/) - The night before the exam, you do not need another 2,000-word article. You need the numbers, the limits, and the decision shortcuts that the exam tests repeatedly. This article is designed to be your "last look"—the quick reference that cements the critical facts in your memory. VPC Limits Load Balancer Limits Cloud NAT Limits Decision - [Architecture Patterns: The Grand Design](https://ethernetdude.com/architecture-patterns-the-grand-design/) - You know the building blocks—VPCs, VPNs, load balancers, firewalls. Now it is time to assemble them into production architectures. The PCNE exam does not just ask you to configure a single resource; it presents a business scenario and expects you to choose the correct architecture from a set of options. The patterns you choose determine - [Network Cost Optimization: FinOps for Networking](https://ethernetdude.com/network-cost-optimization-finops-for-networking/) - Networking costs in Google Cloud are the silent budget killer. Compute costs are obvious—you see the VM, you see the price. But network egress charges, Cloud NAT processing fees, and Interconnect port costs hide in the margins of your invoice, growing quietly until someone in finance asks, "Why is our cloud bill 40% higher than - [The Troubleshooting Handbook: Real-World Scenarios](https://ethernetdude.com/the-troubleshooting-handbook-real-world-scenarios/) - Theory is comfortable. Troubleshooting is not. The PCNE exam does not just test whether you know what a firewall rule is—it tests whether you can diagnose why a specific connection is failing when five different components are involved. This article presents the most common real-world troubleshooting scenarios you will encounter, both on the exam and - [Network Automation with Terraform](https://ethernetdude.com/network-automation-with-terraform/) - In a world where a single VPC can span the globe and a single firewall misconfiguration can expose an entire organization, manual configuration through the Cloud Console is not just inefficient—it is dangerous. Clicking through the UI to create subnets, firewall rules, and VPN tunnels works for a lab environment, but in production, you need - [PBR, BFD & Direct VPC Egress](https://ethernetdude.com/pbr-bfd-direct-vpc-egress/) - There is a level of Google Cloud networking that most documentation glosses over. These are the features that only matter when your architecture is complex enough to need them—when standard routing is not flexible enough, when BGP convergence is too slow, and when your serverless workloads need to break out of their sandboxed environment. Policy-Based - [The Missing Links: Network Tiers, Shared VPC IAM & Cloud IDS](https://ethernetdude.com/the-missing-links-network-tiers-shared-vpc-iam-cloud-ids/) - Every certification exam has topics that feel "minor" until you encounter three questions about them in a row. These are the concepts that sit between the major pillars—not important enough for their own dedicated section in the study guide, but tested frequently enough that ignoring them is a gamble. Network Service Tiers, Shared VPC IAM - [Advanced Network Services: NCC, CDN, IPv6 & BYOIP](https://ethernetdude.com/advanced-network-services-ncc-cdn-ipv6-byoip/) - Once you have mastered the core VPC, the VPN, the load balancers, and the firewalls, there is a layer of advanced services that the PCNE exam tests at the edges. These are the services that most engineers never touch in their day-to-day work, but they appear in exam scenarios designed to separate the "Professional" from - [Network Operations, Observability & Troubleshooting](https://ethernetdude.com/network-operations-observability-troubleshooting/) - Building a network is one thing. Keeping it running is another. In production, the most dangerous state is not "broken"—it is "silently degraded." A misconfigured firewall rule that blocks 5% of traffic. A route that sends packets on a suboptimal path. A health check that reports healthy when the application is returning 500 errors. These - [VPC Service Controls: The Data Exfiltration Shield](https://ethernetdude.com/vpc-service-controls-the-data-exfiltration-shield/) - Firewalls protect your network from unauthorized access. IAM protects your resources from unauthorized users. But neither of them protects you from the most dangerous threat of all: a legitimate, authorized user copying your data to an unauthorized project. Imagine a developer with read access to your BigQuery dataset. They run bq cp my-dataset.my-table attacker-project:stolen-data.my-table. The firewall sees nothing - [Cloud NAT & Network Reliability Patterns](https://ethernetdude.com/cloud-nat-network-reliability-patterns/) - In the cloud, "no public IP" is a security best practice. Your VMs should be private. Your GKE nodes should be private. Your Cloud Run services should be private. But private VMs still need to reach the internet—to pull package updates, download container images, call third-party APIs, or push telemetry data. How does a VM - [Private Access: The Backdoor Keys](https://ethernetdude.com/private-access-the-backdoor-keys/) - In a modern cloud architecture, you constantly consume services: Cloud SQL, MongoDB Atlas, Snowflake, or even Google's own APIs. The naive way to connect is over the public internet. The professional way is to keep it private. The Trio of Private Connectivity Google Cloud offers three distinct ways to do this, and mixing them up - [Network Security: Firewalls, Identity, and Organizational Control](https://ethernetdude.com/network-security-firewalls-identity-and-organizational-control/) - Security in cloud networking is not just about blocking bad actors. It is about managing complexity at scale. In a small project with five VMs, you write a few firewall rules and move on. But when you have a hundred VPCs across fifty projects, managed by twenty teams, with compliance auditors asking for evidence—the simple - [GKE Networking: A Deep Dive](https://ethernetdude.com/gke-networking-a-deep-dive/) - Kubernetes is a container orchestration platform, but under the hood, it is fundamentally a networking problem. Every Pod needs an IP address. Every Service needs a stable endpoint. Every Ingress needs to connect the outside world to the inside world. And in Google Kubernetes Engine (GKE), the way these networking primitives are implemented is tightly - [Load Balancing Part 2: The Layer 4 Workhorse](https://ethernetdude.com/load-balancing-part-2-the-layer-4-workhorse/) - Layer 7 load balancers are smart—they can read HTTP headers, inspect cookies, and route traffic based on URL paths. But that intelligence comes at a cost: latency. The load balancer must terminate the connection, parse the request, and then open a new connection to the backend. For many workloads—databases, gaming servers, IoT protocols, or raw - [Load Balancing Part 1: The Layer 7 Traffic Cop](https://ethernetdude.com/load-balancing-part-1-the-layer-7-traffic-cop/) - In the old days of on-premises data centers, a load balancer was a big metal appliance sitting in a rack—an F5 BIG-IP or a Citrix NetScaler. You plugged cables into it, configured VIPs, and prayed for firmware updates. In Google Cloud, there is no box. The load balancer is a distributed software capability that lives - [A Deep Dive into Cloud DNS & Traffic Management](https://ethernetdude.com/a-deep-dive-into-cloud-dns-traffic-management/) - In the world of cloud networking—especially when you are deep in the weeds of VPCs, Interconnects, and hybrid architectures—Cloud DNS is often the "unsung hero." While Kubernetes clusters and load balancers get the spotlight, DNS is the silent navigator making sure your traffic actually finds its way home. Before any packet moves, a name must - [Hybrid Connectivity Part 2: Cloud VPN & Cloud Router](https://ethernetdude.com/hybrid-connectivity-part-2-cloud-vpn-cloud-router/) - Not every organization can justify the cost and complexity of a physical Interconnect. Maybe your branch office is in a strip mall with no colocation facility within 200 miles. Maybe you need connectivity in five minutes, not five months. Or perhaps you are connecting to AWS or Azure, and there is no physical cable between - [Hybrid Connectivity Part 1: Cloud Interconnect](https://ethernetdude.com/hybrid-connectivity-part-1-cloud-interconnect/) - There comes a point in every enterprise cloud journey where the VPN tunnel stops being enough. Maybe you are migrating petabytes of genomic data, or your trading platform demands sub-millisecond jitter between your on-premises data center and Google Cloud. The public internet, no matter how fast, is unpredictable. It is a shared resource—your packets ride - [Understanding Core VPC Architecture & Routing in Google Cloud](https://ethernetdude.com/understanding-core-vpc-architecture-routing-in-google-cloud/) - In the world of traditional networking, a network is a physical thing. You buy cables, plug them into switches, and pray that spanning-tree doesn't ruin your Monday. In Google Cloud, there are no cables. There are no switches you can SSH into. The entire network is a software-defined abstraction running on top of one of - [Understanding VPC in Google Cloud](https://ethernetdude.com/understanding-vpc-in-google-cloud/) - fundamentals of Google Cloud VPCs, including why they are global resources, how regional subnets work, and the key differences between default and custom vpc - [How to configure devices using NAPALM](https://ethernetdude.com/how-to-configure-devices-using-napalm/) - NAPALM or Network automation and programmability abstraction layer with multivendor support. is an open source python library that implements a set of functions to interact with network devices of different vendors using a unified API. This Software also helps in installing configurations, Merging configurations, Rolling back configurations etc… The library also have some very useful - [Enable SSH using Net Miko](https://ethernetdude.com/enable-ssh-using-net-miko/) - Telnet to switches in the Lab is fine, However, in a production environment for security reasons we should use SSH. For SSH connections to the network devices, we use Netmiko. Netmiko is a multi vendor library that simplifies paramiko ssh connections to network devices. if we want we can use Paramiko as well but its - [How to configure Vlans using loops easily](https://ethernetdude.com/using-loops-in-python/) - In python, we can use loops if we want to repeat a task specified number of times. The below code will print number from 2 to 9. So, here we are introducing the range keyword & it is important to note that the colon is important after the input in parentheses. The print (n) section - [First steps in Automation with Python](https://ethernetdude.com/first-steps-in-automation-with-python/) - The below is my current topology. I have the Network Automation controller connected to the Ethernet Switch in GNS3 which is connected to Cisco Switch & Cisco IOS router. I also have a Cloud which actually bridges the GNS Network devices to my Physical router at my home which has internet access. It is a - [How to setup GNS3 for Network automation using Python](https://ethernetdude.com/how-to-setup-gns3-for-network-automation-using-python/) - There is no need for me to explain the importance of learning a programming language. However, often network engineers find it difficult to understand the concepts of programming and apply then knowledge to their respective field. I am not going to talk about python in general, although we will talk about all the basic constructs - [What is docker compose and how to create docker compose files](https://ethernetdude.com/docker-compose/) - If we want to run a complex application using multiple services, a better way to do it is to use docker compose. Docker compose is a file written in YAML format. We can put together multiple services running in this file & then use the docker compose up command to bring up the entire application stack. It - [Deploying our First application with Docker](https://ethernetdude.com/deploying-our-first-application-with-docker/) - We are going to deploy the Voting app using Docker. It has to be noted, that this application is not written by me & I am simply using an app that is available in GitHub. The application is available on this URL : Click Here I am going to download this application to my ubuntu machine. - [How to easily create your own docker image](https://ethernetdude.com/create-your-own-docker-image/) - in case, if you are developing an application & decide to run it as container or if you want to install something as a container that is not available on docker hub, then you would have to create your own docker image. How to create your image ? First, create a file named "dockerfile" & - [All you need to know about docker storage & networking](https://ethernetdude.com/docker-storage-networking/) - Docker Storage: When you install docker on a machine it creates a folder structure under /var/lib/docker. This will have multiple sub folder. all the files related to containers are stored under /var/lib/docker/containers & all the files related to images are stored under /var/lib/docker/images folder. If you remember from the notes about Creating your own docker images we learnt - [Understand basics of Docker Engine](https://ethernetdude.com/docker-engine/) - Docker Engine as we discussed before is simply referred to a host with docker installed on it. When we install docker on a machine, three different components are installed. The docker Deamon is a background process that manages such as images, volumes, containers & networks. The docker rest api is that programs can use to - [Simple Explanation of docker Registry](https://ethernetdude.com/docker-registry/) - Docker images are stored in the docker registry. When we run a docker command line docker run ngnix the image is being pulled from the docker.io library By default, the library prefix is used indicating an official docker Hub image. However, there is an option for us to create our custom images & store them. Where we - [Docker Basic Concepts & Commands](https://ethernetdude.com/docker-basic-concepts-commands/) - docker run : The docker run command is used to create a container from an image. for example, docker run ngnix command will create an instance from the image. if the image is not present on the host, it will try to get a copy of image from docker hub if it is available there. - [Why use Docker ?](https://ethernetdude.com/why-docker/) - Docker lets us run each component in a separate container with its own dependencies & libraries. This let's us run the application irrespective of the operating system we are using. What are Containers ? Containers are isolated environments, which can have their own processes, network & mounts just like virtual machines except that they all ## Pages - [About Kapil Kanth - Cloud & Infrastructure Architect](https://ethernetdude.com/) - Master multi-cloud architecture and Infrastructure as Code. Practical labs, exam prep, and production workflows for Terraform, AWS, and GCP. No hype. Just practice. - [Google Cloud Network Engineer Practice Tests](https://ethernetdude.com/google-cloud-network-engineer-practice-tests/) - Master the Google Professional Cloud Network Engineer exam. Practice with realistic questions, in-depth solutions, and track your progress to certification. ## Categories - [Blog](https://ethernetdude.com/category/blog/) - Your blog category - [Google Cloud Platform](https://ethernetdude.com/category/google-cloud-platform-gcp/) - [ACI](https://ethernetdude.com/category/blog/aci/) - [Docker](https://ethernetdude.com/category/docker/) - [Kubernetes](https://ethernetdude.com/category/kubernetes/) - [Network Automation](https://ethernetdude.com/category/network-automation/) - [Cloud Network Engineer](https://ethernetdude.com/category/google-cloud-platform-gcp/gcp-network-professional/) - [Professional Cloud Architect](https://ethernetdude.com/category/google-cloud-platform-gcp/google-cloud-professional-architect/) - [Terraform](https://ethernetdude.com/category/terraform/) - [Terraform-GCP-Labs](https://ethernetdude.com/category/terraform/terraform-gcp-labs/) - [Terraform-AWS-Labs](https://ethernetdude.com/category/terraform/terraform-aws-labs/) - [Terraform Notes](https://ethernetdude.com/category/terraform-notes/) - [Terraform Practice Lab](https://ethernetdude.com/category/terraform/terraform-practice-lab/) - [terraform-practice-tests](https://ethernetdude.com/category/terraform/terraform-practice-tests/) - [GIT](https://ethernetdude.com/category/git/) - [Multicast](https://ethernetdude.com/category/multicast/) - [OCI for GCP Architects](https://ethernetdude.com/category/oci-for-gcp-architects/) - [Cloud Platforms](https://ethernetdude.com/category/cloud-platforms/) - [OCI](https://ethernetdude.com/category/cloud-platforms/oci/) - [IAM](https://ethernetdude.com/category/cloud-platforms/oci/oci-iam/) - [OCI Networking](https://ethernetdude.com/category/cloud-platforms/oci/oci-networking/) ## Tags - [billing](https://ethernetdude.com/tag/billing/) - [gcp](https://ethernetdude.com/tag/gcp/) - [discounts](https://ethernetdude.com/tag/discounts/) - [spot instances](https://ethernetdude.com/tag/spot-instances/) - [sustained use discount](https://ethernetdude.com/tag/sustained-use-discount/) - [commited](https://ethernetdude.com/tag/commited/) - [introduction to cloud](https://ethernetdude.com/tag/introduction-to-cloud/) - [compute engine](https://ethernetdude.com/tag/compute-engine/) - [google cloud](https://ethernetdude.com/tag/google-cloud/) - [traditional datacenter](https://ethernetdude.com/tag/traditional-datacenter/) - [first virtual instance](https://ethernetdude.com/tag/first-virtual-instance/) - [http server](https://ethernetdude.com/tag/http-server/) - [apache](https://ethernetdude.com/tag/apache/) - [static ip](https://ethernetdude.com/tag/static-ip/) - [vpc network](https://ethernetdude.com/tag/vpc-network/) - [startup script](https://ethernetdude.com/tag/startup-script/) - [virtual instance](https://ethernetdude.com/tag/virtual-instance/) - [instance template](https://ethernetdude.com/tag/instance-template/) - [custom image](https://ethernetdude.com/tag/custom-image/) - [live migration](https://ethernetdude.com/tag/live-migration/) - [best practices](https://ethernetdude.com/tag/best-practices/) - [gpu](https://ethernetdude.com/tag/gpu/) - [spot instance](https://ethernetdude.com/tag/spot-instance/) - [terminate vm](https://ethernetdude.com/tag/terminate-vm/) - [CLI in Gcloud](https://ethernetdude.com/tag/cli-in-gcloud/) - [Command structure in Gloud](https://ethernetdude.com/tag/command-structure-in-gloud/) - [filtering](https://ethernetdude.com/tag/filtering/) - [compute instance.](https://ethernetdude.com/tag/compute-instance/) - [gcloud commands](https://ethernetdude.com/tag/gcloud-commands/) - [instance group](https://ethernetdude.com/tag/instance-group/) - [auto scaling](https://ethernetdude.com/tag/auto-scaling/) - [auto healing](https://ethernetdude.com/tag/auto-healing/) - [managed instance group](https://ethernetdude.com/tag/managed-instance-group/) - [unmanaged instance group](https://ethernetdude.com/tag/unmanaged-instance-group/) - [stateful managed instance](https://ethernetdude.com/tag/stateful-managed-instance/) - [stateless managed instance](https://ethernetdude.com/tag/stateless-managed-instance/) - [Instance groups](https://ethernetdude.com/tag/instance-groups/) - [update managed instance groups in gcp](https://ethernetdude.com/tag/update-managed-instance-groups-in-gcp/) - [ACI](https://ethernetdude.com/tag/aci/) - [ACI Firmware upgrade](https://ethernetdude.com/tag/aci-firmware-upgrade/) - [NXOS TO ACI MODE](https://ethernetdude.com/tag/nxos-to-aci-mode/) - [not connected to fabric](https://ethernetdude.com/tag/not-connected-to-fabric/) - [manual aci upgrade](https://ethernetdude.com/tag/manual-aci-upgrade/) - [Docker](https://ethernetdude.com/tag/docker/) - [Kubernetes](https://ethernetdude.com/tag/kubernetes/) - [Network Automation using Python](https://ethernetdude.com/tag/network-automation-using-python/) - [GCP App Engine](https://ethernetdude.com/tag/gcp-app-engine/) - [dataflow](https://ethernetdude.com/tag/dataflow/) - [Terraform](https://ethernetdude.com/tag/terraform/) - [Infrastructure as code](https://ethernetdude.com/tag/infrastructure-as-code/) - [GCP-Terraform Labs](https://ethernetdude.com/tag/gcp-terraform-labs/) - [terraform-practice-exam](https://ethernetdude.com/tag/terraform-practice-exam/) - [GIT](https://ethernetdude.com/tag/git/) - [Version Control](https://ethernetdude.com/tag/version-control/) - [Multicast](https://ethernetdude.com/tag/multicast/) - [DevOps](https://ethernetdude.com/tag/devops/) - [Containers](https://ethernetdude.com/tag/containers/) - [Cloud Infrastructure](https://ethernetdude.com/tag/cloud-infrastructure/) - [containerd](https://ethernetdude.com/tag/containerd/) - [Container Runtime](https://ethernetdude.com/tag/container-runtime/) - [CRI](https://ethernetdude.com/tag/cri/) - [Consensus](https://ethernetdude.com/tag/consensus/) - [etcd](https://ethernetdude.com/tag/etcd/) - [Raft](https://ethernetdude.com/tag/raft/) - [Tolerations](https://ethernetdude.com/tag/tolerations/) - [Scheduler](https://ethernetdude.com/tag/scheduler/) - [Taints](https://ethernetdude.com/tag/taints/) - [Scheduling](https://ethernetdude.com/tag/scheduling/) - [PLEG](https://ethernetdude.com/tag/pleg/) - [Probes](https://ethernetdude.com/tag/probes/) - [Kubelet](https://ethernetdude.com/tag/kubelet/) - [Kube-proxy](https://ethernetdude.com/tag/kube-proxy/) - [iptables](https://ethernetdude.com/tag/iptables/) - [IPVS](https://ethernetdude.com/tag/ipvs/) - [Networking](https://ethernetdude.com/tag/networking/) - [Pods](https://ethernetdude.com/tag/pods/) - [Namespaces](https://ethernetdude.com/tag/namespaces/) - [Sidecar](https://ethernetdude.com/tag/sidecar/) - [ReplicaSet](https://ethernetdude.com/tag/replicaset/) - [Rolling Update](https://ethernetdude.com/tag/rolling-update/) - [Deployments](https://ethernetdude.com/tag/deployments/) - [Load Balancing](https://ethernetdude.com/tag/load-balancing/) - [ClusterIP](https://ethernetdude.com/tag/clusterip/) - [LoadBalancer](https://ethernetdude.com/tag/loadbalancer/) - [Services](https://ethernetdude.com/tag/services/) - [NodePort](https://ethernetdude.com/tag/nodeport/) - [LimitRange](https://ethernetdude.com/tag/limitrange/) - [ResourceQuota](https://ethernetdude.com/tag/resourcequota/) - [kubectl](https://ethernetdude.com/tag/kubectl/) - [CLI](https://ethernetdude.com/tag/cli/) - [JSONPath](https://ethernetdude.com/tag/jsonpath/) - [OCI](https://ethernetdude.com/tag/oci/) - [IAM](https://ethernetdude.com/tag/iam/) - [Compartments](https://ethernetdude.com/tag/compartments/) - [Cloud Security](https://ethernetdude.com/tag/cloud-security/) - [Identity Domain](https://ethernetdude.com/tag/identity-domain/) - [VCN](https://ethernetdude.com/tag/vcn/) - [Subnets](https://ethernetdude.com/tag/subnets/) - [Network Path Analyzer](https://ethernetdude.com/tag/network-path-analyzer/) - [DRG](https://ethernetdude.com/tag/drg/) - [VCN Peering](https://ethernetdude.com/tag/vcn-peering/) - [FastConnect](https://ethernetdude.com/tag/fastconnect/) - [Site-to-Site VPN](https://ethernetdude.com/tag/site-to-site-vpn/) - [Compute](https://ethernetdude.com/tag/compute/) - [Bare Metal](https://ethernetdude.com/tag/bare-metal/) - [Flexible Shapes](https://ethernetdude.com/tag/flexible-shapes/) - [OSMS](https://ethernetdude.com/tag/osms/) - [OKE](https://ethernetdude.com/tag/oke/) - [OCIR](https://ethernetdude.com/tag/ocir/) - [OCI Functions](https://ethernetdude.com/tag/oci-functions/) - [Block Volume](https://ethernetdude.com/tag/block-volume/) - [File Storage](https://ethernetdude.com/tag/file-storage/) - [Storage Tiers](https://ethernetdude.com/tag/storage-tiers/) - [NFS](https://ethernetdude.com/tag/nfs/) - [Object Storage](https://ethernetdude.com/tag/object-storage/) - [PAR](https://ethernetdude.com/tag/par/) - [Data Archival](https://ethernetdude.com/tag/data-archival/) - [Lifecycle Policy](https://ethernetdude.com/tag/lifecycle-policy/) - [Database](https://ethernetdude.com/tag/database/) - [Autonomous Database](https://ethernetdude.com/tag/autonomous-database/) - [Exadata](https://ethernetdude.com/tag/exadata/) - [Data Guard](https://ethernetdude.com/tag/data-guard/) - [Streaming](https://ethernetdude.com/tag/streaming/) - [Queue](https://ethernetdude.com/tag/queue/) - [Notifications](https://ethernetdude.com/tag/notifications/) - [Events](https://ethernetdude.com/tag/events/) - [Load Balancer](https://ethernetdude.com/tag/load-balancer/) - [NLB](https://ethernetdude.com/tag/nlb/) - [Traffic Management](https://ethernetdude.com/tag/traffic-management/) - [DNS](https://ethernetdude.com/tag/dns/) - [Cloud Guard](https://ethernetdude.com/tag/cloud-guard/) - [Security Zones](https://ethernetdude.com/tag/security-zones/) - [Vault](https://ethernetdude.com/tag/vault/) - [Resource Manager](https://ethernetdude.com/tag/resource-manager/) - [OCI Networking](https://ethernetdude.com/tag/oci-networking/)