<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>STP · Insights</title><description>Practical technical writing on IT infrastructure: structured cabling, data centres, private cloud, Kubernetes, disaster recovery and compliance.</description><link>https://stp.am/</link><language>en</language><item><title>Air-gapped Kubernetes: running with no route out</title><link>https://stp.am/engineering/air-gapped-kubernetes/</link><guid isPermaLink="true">https://stp.am/engineering/air-gapped-kubernetes/</guid><description>An air-gapped Kubernetes cluster works when every image, chart, operator and binary it needs is mirrored into an internal registry inside the boundary, when artefacts cross the gap through a signed, reviewed and logged transfer rather than by a person with a USB drive, and when the cluster&apos;s upgrade path has been rehearsed offline, because the usual remedy of pulling a fixed image is unavailable.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>Autoscaling that actually reduces the bill</title><link>https://stp.am/engineering/autoscaling-that-reduces-the-bill/</link><guid isPermaLink="true">https://stp.am/engineering/autoscaling-that-reduces-the-bill/</guid><description>Autoscaling reduces cost only after resource requests are derived from measurement, because a scheduler provisions capacity to satisfy requests rather than usage, so an overstated request reserves machines that nothing runs on and no scaling policy can reclaim them.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Cloud &amp; private cloud</category></item><item><title>Production on AWS: EKS, ECS and Fargate</title><link>https://stp.am/engineering/aws-production-platform/</link><guid isPermaLink="true">https://stp.am/engineering/aws-production-platform/</guid><description>A production AWS platform spreads every tier across at least three Availability Zones, provisions nodes with Karpenter rather than fixed node groups, fronts traffic with CloudFront and an Application Load Balancer, deploys through GitHub Actions using OIDC so no long-lived AWS keys exist anywhere, and is accepted against all six AWS Well-Architected pillars rather than against uptime alone.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Platform engineering</category></item><item><title>Chaos engineering when you cannot break production</title><link>https://stp.am/engineering/chaos-engineering-without-breaking-production/</link><guid isPermaLink="true">https://stp.am/engineering/chaos-engineering-without-breaking-production/</guid><description>Chaos engineering is applicable without a Chaos Monkey in production because its value comes from stating a steady state in business metrics, forming a falsifiable hypothesis about a specific failure, and bounding the blast radius, all of which can be done in an isolated environment or in a scheduled window.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>The golden path, for a team of twelve</title><link>https://stp.am/engineering/golden-path-platform-small-team/</link><guid isPermaLink="true">https://stp.am/engineering/golden-path-platform-small-team/</guid><description>A golden path is the one supported route from commit to production that a platform team paves and keeps working, and a small organisation gets most of its value by writing that route down and automating it rather than by building the self-service portal that large platform teams are known for.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Platform engineering</category></item><item><title>Production on Google Cloud: GKE and ephemeral environments</title><link>https://stp.am/engineering/google-cloud-production-platform/</link><guid isPermaLink="true">https://stp.am/engineering/google-cloud-production-platform/</guid><description>A production Google Cloud platform runs a regional GKE cluster across three zones, authenticates CI and workloads through Workload Identity Federation so no service account keys exist, provisions a complete ephemeral environment per pull request and destroys it on merge, and refreshes lower environments from production on a schedule through an obfuscation job that removes personal data before it ever leaves the production boundary.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Platform engineering</category></item><item><title>Hybrid Exchange: one identity, two mail systems</title><link>https://stp.am/engineering/hybrid-exchange-architecture/</link><guid isPermaLink="true">https://stp.am/engineering/hybrid-exchange-architecture/</guid><description>A hybrid Microsoft Exchange deployment keeps one authoritative identity by synchronising the on-premise directory to the cloud, routes mail through a chosen point rather than both, and retains at least one on-premise Exchange server for as long as the directory is synchronised from on-premise, because recipient attributes remain owned by the local directory and cannot be edited in the cloud.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>The incident review that changes something</title><link>https://stp.am/engineering/incident-review-that-changes-something/</link><guid isPermaLink="true">https://stp.am/engineering/incident-review-that-changes-something/</guid><description>An incident review changes something only when each action has a named owner and a date and is tracked to completion, because a blameless culture removes the fear that hides causes but does nothing on its own to ensure the causes are fixed.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>Multi-datacentre networking and the recovery site</title><link>https://stp.am/engineering/multi-datacentre-networking/</link><guid isPermaLink="true">https://stp.am/engineering/multi-datacentre-networking/</guid><description>A two-datacentre estate with a recovery site works when each site runs its own routing domain joined by a routed interconnect rather than a stretched layer-2 broadcast domain, when the recovery site is built from the same automation as production rather than by hand, and when the failover is exercised on a schedule and timed against the stated recovery objective.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Networking</category></item><item><title>Observability without lock-in: OpenTelemetry first</title><link>https://stp.am/engineering/observability-stack/</link><guid isPermaLink="true">https://stp.am/engineering/observability-stack/</guid><description>An observability stack avoids lock-in by instrumenting applications once with OpenTelemetry and sending data through a collector, because the collector is the point at which a backend can be changed, duplicated or split by signal without touching application code or redeploying a single service.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>On-call that does not burn the team</title><link>https://stp.am/engineering/on-call-that-does-not-burn-the-team/</link><guid isPermaLink="true">https://stp.am/engineering/on-call-that-does-not-burn-the-team/</guid><description>An on-call rotation becomes sustainable when every page is a symptom a user would notice and requires a human decision, because an alert that fires on a cause, or that nobody acts on, trains the responder to ignore the channel the real page will arrive on.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>On-premise clusters: VMware, Hyper-V and shared storage</title><link>https://stp.am/engineering/on-premise-virtualisation-clusters/</link><guid isPermaLink="true">https://stp.am/engineering/on-premise-virtualisation-clusters/</guid><description>An on-premise virtualisation cluster survives a host loss only if it is sized N+1 against the largest host rather than against the average, has a witness placed outside both failure domains so quorum cannot be lost by a single event, and is patched by rolling hosts through maintenance mode with live migration, which requires that no single virtual machine is larger than the spare capacity of one host.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Data centre</category></item><item><title>Secrets, and the places they leak</title><link>https://stp.am/engineering/secrets-and-where-they-leak/</link><guid isPermaLink="true">https://stp.am/engineering/secrets-and-where-they-leak/</guid><description>A secret management programme reduces risk only when it removes long-lived credentials rather than relocating them, because a vault still issues a value that reaches a process, and the leak paths that matter are CI logs, container images, Git history and the process environment rather than the store.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>When active-active is the right answer</title><link>https://stp.am/engineering/when-active-active-is-the-right-answer/</link><guid isPermaLink="true">https://stp.am/engineering/when-active-active-is-the-right-answer/</guid><description>Multi-region active-active is the right architecture when the business is genuinely fault-intolerant, meaning it cannot accept the outage that any failover implies, and it is one of several ways to meet that requirement rather than a maturity level every estate should reach.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Cloud &amp; private cloud</category></item><item><title>When event-driven is the wrong shape</title><link>https://stp.am/engineering/when-event-driven-is-the-wrong-shape/</link><guid isPermaLink="true">https://stp.am/engineering/when-event-driven-is-the-wrong-shape/</guid><description>Event-driven architecture is the wrong shape when a caller needs an answer before it can continue, because turning a synchronous question into an asynchronous flow does not remove the wait, it only removes the caller&apos;s ability to see where the wait is happening.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Platform engineering</category></item><item><title>Schema migrations that do not take the site down</title><link>https://stp.am/engineering/zero-downtime-schema-migrations/</link><guid isPermaLink="true">https://stp.am/engineering/zero-downtime-schema-migrations/</guid><description>A schema migration avoids downtime by expanding the schema first so old and new code both work, deploying the code, backfilling in batches, and only then contracting, because every step in that sequence is independently reversible and none requires the application to stop.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Platform engineering</category></item><item><title>Zero trust without rebuilding the network</title><link>https://stp.am/engineering/zero-trust-without-rebuilding/</link><guid isPermaLink="true">https://stp.am/engineering/zero-trust-without-rebuilding/</guid><description>Zero trust can be adopted incrementally by moving authorisation decisions from network location to verified identity and device state one application at a time, starting with the applications a compromised laptop would reach first, rather than by replacing the network.</description><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>AI մշակման կյանքի ցիկլի անվտանգությունը</title><link>https://stp.am/engineering/hy/secure-ai-development-lifecycle/</link><guid isPermaLink="true">https://stp.am/engineering/hy/secure-ai-development-lifecycle/</guid><description>Secure AI-DLC-ը կիրառում է անվտանգ մշակման կյանքի ցիկլի կարգապահությունը AI մոդելների վրա կառուցված համակարգերի նկատմամբ՝ վերահսկելով մոդելի մատակարարման շղթան, հուշումներն ու ստացված բովանդակությունը դիտարկելով որպես ոչ վստահելի մուտք, կառավարելով inference սահմանը հատող տվյալները, սահմանափակելով մուտքը մոդելի վերջնակետեր և թեստավորելով prompt injection-ի ու տվյալների արտահոսքի դեմ։</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>Ինչպիսին է վերականգնման իրական փորձարկումը</title><link>https://stp.am/engineering/hy/what-a-real-disaster-recovery-test-looks-like/</link><guid isPermaLink="true">https://stp.am/engineering/hy/what-a-real-disaster-recovery-test-looks-like/</guid><description>Վերականգնման իրական փորձարկումը վերականգնում է իրական համակարգեր իրական պահուստավորումներից մեկուսացված միջավայրում, չափում է իրականում ծախսված ժամանակը հայտարարված RTO-ի համեմատ, ստուգում է վերականգնված տվյալները հայտարարված RPO-ի համեմատ և գրանցում, թե ինչ է ձախողվել՝ դրանից պակաս ամեն ինչ պլանի վերանայում է, ոչ թե փորձարկում։</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>Securing the AI development lifecycle</title><link>https://stp.am/engineering/secure-ai-development-lifecycle/</link><guid isPermaLink="true">https://stp.am/engineering/secure-ai-development-lifecycle/</guid><description>Secure AI-DLC applies secure development lifecycle discipline to systems built on AI models: controlling the model supply chain, treating prompts and retrieved content as untrusted input, governing what data crosses the inference boundary, restricting access to model endpoints, and testing for prompt injection and data leakage.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>What a real disaster recovery test looks like</title><link>https://stp.am/engineering/what-a-real-disaster-recovery-test-looks-like/</link><guid isPermaLink="true">https://stp.am/engineering/what-a-real-disaster-recovery-test-looks-like/</guid><description>A real disaster recovery test restores actual systems from actual backups into an isolated environment, measures how long it truly took against the stated RTO, verifies the restored data against the stated RPO, and records what failed: anything short of that is a plan review, not a test.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Operations</category></item><item><title>How to choose a structured cabling contractor</title><link>https://stp.am/engineering/choosing-a-structured-cabling-contractor/</link><guid isPermaLink="true">https://stp.am/engineering/choosing-a-structured-cabling-contractor/</guid><description>Choose a structured cabling contractor on three verifiable things: the certified test results they will hand over per port, the as-built documentation they produce, and the warranty covering installation workmanship as well as materials, because everything else they tell you is unverifiable before the walls close.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>Structured cabling</category></item><item><title>Ինչպես ընտրել մալուխացման կապալառու</title><link>https://stp.am/engineering/hy/choosing-a-structured-cabling-contractor/</link><guid isPermaLink="true">https://stp.am/engineering/hy/choosing-a-structured-cabling-contractor/</guid><description>Մալուխացման կապալառուն ընտրեք երեք ստուգելի բանով՝ յուրաքանչյուր պորտի համար հանձնվող սերտիֆիկացված թեստի արդյունքները, կատարողական փաստաթղթերը և երաշխիքը, որը ծածկում է ոչ միայն նյութերը, այլև տեղադրման աշխատանքը, քանի որ մնացած ամեն ինչը, որ նրանք ասում են, անստուգելի է, քանի դեռ պատերը չեն փակվել։</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>Structured cabling</category></item><item><title>ISO 27001․ ի՞նչ ապացույց է պահանջում աուդիտորը</title><link>https://stp.am/engineering/hy/iso-27001-infrastructure-evidence/</link><guid isPermaLink="true">https://stp.am/engineering/hy/iso-27001-infrastructure-evidence/</guid><description>ISO 27001 աուդիտորները հիմնականում չեն ստուգում՝ գոյություն ունեն արդյոք Ձեր վերահսկողությունները, այլ ընտրանքով ստուգում են ապացույցը, որ դրանք գործել են ժամանակի ընթացքում, ինչը նշանակում է իրականությանը համապատասխանող ակտիվների ցանկ, ընդունման-տեղափոխման-հեռացման գրառումներ, պարբերական մուտքի վերանայումներ, արտադրական փոփոխությունների գրառումներ, խոցելիությունների սկանավորման և վերացման պատմություն, վերականգնման թեստերի արդյունքներ և լոգերի պահպանման ապացույց։</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>Մասնավո՞ր, թե՞ հանրային ամպ բանկերի համար</title><link>https://stp.am/engineering/hy/private-cloud-vs-public-cloud-armenian-financial-institutions/</link><guid isPermaLink="true">https://stp.am/engineering/hy/private-cloud-vs-public-cloud-armenian-financial-institutions/</guid><description>Հայկական ֆինանսական կազմակերպությունները սովորաբար ընտրում են մասնավոր ամպը հանրայինի փոխարեն երեք պատճառով՝ հաճախորդների տվյալների տեղակայման պահանջներ, սեփական հարթակի ավելի պարզ ստուգելիություն կարգավորող վերահսկողության պայմաններում, և ավելի ցածր կայուն ծախս կանխատեսելի, մշտապես աշխատող համակարգերի համար՝ փոխարենը ստանձնելով հզորության պլանավորումը և սարքավորումների նորացման ցիկլը։</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>Cloud &amp; private cloud</category></item><item><title>What ISO 27001 auditors ask for from infrastructure</title><link>https://stp.am/engineering/iso-27001-infrastructure-evidence/</link><guid isPermaLink="true">https://stp.am/engineering/iso-27001-infrastructure-evidence/</guid><description>ISO 27001 auditors do not primarily test whether your controls exist. They sample evidence that the controls operated over time, which means an asset inventory matching reality, joiner-mover-leaver access records, periodic access reviews, production change records, vulnerability scan and remediation history, restore test results, and log retention proof.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>Security &amp; compliance</category></item><item><title>Private or public cloud for Armenian financial institutions</title><link>https://stp.am/engineering/private-cloud-vs-public-cloud-armenian-financial-institutions/</link><guid isPermaLink="true">https://stp.am/engineering/private-cloud-vs-public-cloud-armenian-financial-institutions/</guid><description>Armenian financial institutions generally choose private cloud over public cloud for three reasons: data residency requirements over customer data, simpler auditability of an owned platform under regulatory scrutiny, and lower steady-state cost for predictable always-on workloads, while accepting that they carry the capacity planning and hardware refresh burden in return.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>Cloud &amp; private cloud</category></item></channel></rss>