<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Agrohi — Engineering Insights</title><description>Real cost breakdowns, migration war stories, and technical decisions on resilient, low-cost cloud infrastructure.</description><link>https://www.agrohi.com/</link><language>en-us</language><item><title>Canary Deployment With Istio</title><link>https://www.agrohi.com/blog/canary-deployment-with-istio/</link><guid isPermaLink="true">https://www.agrohi.com/blog/canary-deployment-with-istio/</guid><description>Istio service mesh is great for many things ie. Security, Multicluster and hybrid deployment, Circuit breaking, rate limiting, retries, service-to-service authentication/authorization, cluster-wide mTLS, and many more. But this demo will focus on the Canary deployment with Kubernetes Gateway API and Istio.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>DevOps</category><category>Istio</category><category>kuberntes</category><category>Zero Downtime</category></item><item><title>Real Client IP Behind Istio Ambient Gateway: Secure X-Forwarded-For in Go</title><link>https://www.agrohi.com/blog/real-client-ip-behind-istio-ambient-gateway-secure-x-forwarded-for-in-go/</link><guid isPermaLink="true">https://www.agrohi.com/blog/real-client-ip-behind-istio-ambient-gateway-secure-x-forwarded-for-in-go/</guid><description>Istio ambient mesh is great for many things ie. sidecar-free mTLS, L4 authorization with ztunnel, a clean Gateway API entry point, and a much smaller per-pod footprint than the old sidecar model. But the moment you put a service behind an ambient ingress gateway, one thing quietly breaks: access logs stop showing who is actually calling the service. And the way it breaks is nastier than the usual “read X-Forwarded-For” story, because it breaks intermittently.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>Backend</category><category>Kubernetes</category><category>Go(Golang)</category><category>Security</category></item><item><title>Managed DevOps vs. Hiring In-House: The Real 2026 Cost Comparison</title><link>https://www.agrohi.com/blog/managed-devops-vs-hiring-in-house-the-real-2026-cost-comparison/</link><guid isPermaLink="true">https://www.agrohi.com/blog/managed-devops-vs-hiring-in-house-the-real-2026-cost-comparison/</guid><description>Short answer: Hiring one in-house DevOps engineer costs roughly $150,000–$200,000/year fully loaded — and a single person cannot provide 24/7 coverage, take vacation, or cover every domain (Kubernetes, networking, security, cost, databases). Managed DevOps typically runs $500–$2,500/month for equivalent or broader coverage, with no recruiting cycle and no key-person risk. The right choice depends on how much ongoing, original infrastructure engineering you actually have — not on day-to-day operations.</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate><category>DevOps</category><category>Managed DevOps</category><category>Hiring</category><category>Cost Optimization</category><category>Team</category></item><item><title>Heroku, Render &amp; Vercel Alternatives for Scaling Startups (2026 Cost Guide)</title><link>https://www.agrohi.com/blog/heroku-render-vercel-alternatives-for-scaling-startups-2026-cost-guide/</link><guid isPermaLink="true">https://www.agrohi.com/blog/heroku-render-vercel-alternatives-for-scaling-startups-2026-cost-guide/</guid><description>Managed PaaS (Heroku, Render, Vercel) is the cheapest option when your bill is small and your team is tiny. It becomes the most expensive option once you cross roughly $2,000/month in platform spend, because you&apos;re paying a 3–10x markup on raw compute for convenience you eventually outgrow. The best alternatives in 2026 are AWS ECS/Fargate or Cloud Run (the moderate step) and managed Kubernetes — EKS, GKE, AKS (the full step), ideally run for you so you don&apos;t trade a platform bill for a hiring problem.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>Cost</category><category>PaaS</category><category>Cost Optimization</category><category>Migration</category><category>Heroku</category><category>AWS</category></item><item><title>Harden WordPress with Cloudflare Free Plan Using Terraform</title><link>https://www.agrohi.com/blog/harden-wordpress-with-cloudflare-free-plan-using-terraform/</link><guid isPermaLink="true">https://www.agrohi.com/blog/harden-wordpress-with-cloudflare-free-plan-using-terraform/</guid><description>Maximize Cloudflare’s Free tier for WordPress using OpenTofu/Terraform. Learn how to provision 77+ resources, including WAF rules, Cache Rules, and security headers, via Infrastructure as Code - without spending a dime.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>DevOps, IaC</category><category>WordPress</category><category>Cloudflare</category><category>InfrastructureAsCode</category><category>OpenTofu</category><category>Terraform</category><category>WebSecurity</category><category>FreeTier</category><category>DevOps</category><category>WAF</category><category>CDN</category><category>Agrohi</category></item><item><title>CI/CD Guardrails: Preventing Friday Deployments</title><link>https://www.agrohi.com/blog/cicd-guardrails-preventing-friday-deployments/</link><guid isPermaLink="true">https://www.agrohi.com/blog/cicd-guardrails-preventing-friday-deployments/</guid><description>Ship fast without breaking prod. Our 5 guardrails: change windows, policy-as-code, canary releases, SLO-based gating, and automated rollback.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>CI/CD</category><category>CI/CD</category><category>DevOps</category><category>Reliability</category><category>Kubernetes</category></item><item><title>Infrastructure as Code: 5 Best Practices for Scale</title><link>https://www.agrohi.com/blog/infrastructure-as-code-5-best-practices-for-scale/</link><guid isPermaLink="true">https://www.agrohi.com/blog/infrastructure-as-code-5-best-practices-for-scale/</guid><description>Stop clicking in the console. Learn the 5 non-negotiable best practices for scaling your Infrastructure as Code using Terraform.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>IaC</category><category>Terraform</category><category>IaC</category><category>DevOps</category><category>Automation</category></item><item><title>Run Ansible Playbook From Terraform: Provision and Configure EC2 in AWS</title><link>https://www.agrohi.com/blog/run-ansible-playbook-from-terraform-provision-and-configure-ec2-in-aws/</link><guid isPermaLink="true">https://www.agrohi.com/blog/run-ansible-playbook-from-terraform-provision-and-configure-ec2-in-aws/</guid><description>Combine Terraform and Ansible to fully automate AWS Bastion Host deployment. This project provisions EC2 infrastructure and configures it with Docker/Compose v2 in one single, repeatable IaC workflow.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>DevOps, IaC</category><category>Terraform</category><category>Ansible</category><category>AWS</category><category>bastion host</category><category>EC2</category><category>automation</category><category>infrastructure as code</category><category>Docker</category><category>Docker Compose</category><category>provisioning</category><category>configuration management</category><category>DevOps</category><category>IaC</category><category>AWS networking</category><category>remote exec</category></item><item><title>Terraform State Management: Kill Local State</title><link>https://www.agrohi.com/blog/terraform-state-management/</link><guid isPermaLink="true">https://www.agrohi.com/blog/terraform-state-management/</guid><description>Why committing .tfstate to Git is a security disaster. A guide to setting up robust S3+DynamoDB remote backends with encryption and locking.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>DevOps</category><category>Terraform</category><category>Security</category><category>DevOps</category></item><item><title>GitOps Best Practices: ArgoCD vs Flux in Production</title><link>https://www.agrohi.com/blog/gitops-best-practices-argocd-flux/</link><guid isPermaLink="true">https://www.agrohi.com/blog/gitops-best-practices-argocd-flux/</guid><description>From the three-repository pattern to progressive delivery with Argo Rollouts. Real-world GitOps architecture that eliminates drift and provides audit trails.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>GitOps</category><category>GitOps</category><category>ArgoCD</category><category>Kubernetes</category></item></channel></rss>