Technology stack
What I reach for, what I have run, and what I would not start with today. The radar is the opinionated part; the full index is below it.
See where these were used Adopt
Shipped at real scale, with something you can go and read. Every entry here links to the case study or to this site's own architecture.
- Kubernetes Platform & Infrastructure Production clusters at enterprise scale; the load-test rig drove one to 100GB/s. the receipt →
- Cloudflare Workers Platform & Infrastructure One Worker serves this entire site — SSR, every API route, and the MCP server. the receipt →
- Workers AI Platform & Infrastructure Edge inference behind the Copilot, routed through AI Gateway. the receipt →
- TypeScript Platform & Infrastructure End-to-end typed, astro check clean on every commit. the receipt →
- Terraform Delivery & Automation Multi-cloud IaC; carried the DataDog-to-ELK migration. the receipt →
- Ansible Delivery & Automation Configuration management alongside Terraform on the observability build. the receipt →
- GitHub Actions Delivery & Automation Ran the automated content pipeline end to end. the receipt →
- Prometheus Data & Observability Metrics backbone for the infrastructure-recommendation agent. the receipt →
- ELK Data & Observability Self-hosted, ingesting 5TB of logs a day after leaving usage-priced vendor billing. the receipt →
Trial
Run in production, without a public write-up to point at.
- AWS Platform & Infrastructure Multi-account estates, migrations, and the usual cost-control work.
- Azure Platform & Infrastructure Enterprise workloads, mostly alongside on-prem.
- GCP Platform & Infrastructure Data and ML-adjacent workloads.
- K3s Platform & Infrastructure Lightweight clusters where full Kubernetes is overhead.
- Docker Platform & Infrastructure Still the right answer more often than a cluster is.
- Go Platform & Infrastructure Services and tooling where the runtime matters.
- Python Platform & Infrastructure Automation, data work, and most AI plumbing.
- GitLab CI Delivery & Automation Gates this site: typecheck, lint, tests, dry-run, Lighthouse, secret scan.
- Grafana Data & Observability Dashboards over Prometheus and Loki.
- PostgreSQL Data & Observability Default relational choice; hybrid BM25 + pgvector search without a vector DB.
- Redis Data & Observability Caching and queues where latency is the constraint.
- Vault Security Secret management and dynamic credentials.
Assess
Built something real with it. Not yet a default choice.
- Istio Platform & Infrastructure Service mesh rollout; powerful, and rarely worth its operational cost.
- Pulumi Delivery & Automation Real programming languages for infra; the tradeoff is who can review it.
- LangChain Data & Observability Fine for a prototype; production agents wanted typed tools and explicit control flow.
- Kafka Data & Observability Right at real volume, heavy well before it.
- OPA Security Policy as code — good when policy is genuinely shared across teams.
- Falco Security Runtime detection in clusters.
- Trivy Security Image and dependency scanning in CI.
Hold
Know it, have run it, would not start here today.
// nothing here yet — an invented entry would be worse than an empty ring
Everything else
The full index, unfiltered. A radar is a set of opinions about a few dozen things; this is the rest of what I have worked with, and it is deliberately not a claim about depth.
Languages
Go Python TypeScript JavaScript Rust Java Bash PowerShell HCL
Cloud Providers
AWS Azure GCP Cloudflare DigitalOcean Linode Vultr
Cloudflare Platform
Pages Workers R2 D1 KV Durable Objects Queues Stream Images Vectorize AI Gateway Hyperdrive Workers AI WAF Zero Trust Access Gateway Tunnel DNS Load Balancing Argo Spectrum
HashiCorp Stack
Terraform Terraform Cloud Terraform Enterprise Vault Consul Nomad Packer Waypoint Boundary Vagrant HCP
Kubernetes Ecosystem
kubectl Helm Kustomize ArgoCD FluxCD Istio Linkerd Calico Cilium KEDA Prometheus Operator Cert-Manager External DNS Ingress NGINX Gateway API OPA/Gatekeeper Kyverno Falco Lens k9s
Fastly Platform
Fastly CDN Compute@Edge Image Optimizer Load Balancer WAF DDoS Protection Real-time Stats Log Streaming VCL Edge Dictionary Edge ACL
Orchestration
Kubernetes Docker Swarm Nomad Apache Mesos ECS Rancher
IaC Tools
Terraform Ansible Pulumi CloudFormation CDK Crossplane
CI/CD
GitHub Actions GitLab CI Jenkins CircleCI Travis Drone ArgoCD FluxCD Tekton
Databases
PostgreSQL MySQL MongoDB Cassandra Redis Elasticsearch DynamoDB Consul KV etcd
Message Queues
Kafka RabbitMQ AWS SQS/SNS Azure Service Bus NATS Cloudflare Queues
CDN/Edge Computing
Cloudflare CDN Fastly CDN Akamai AWS CloudFront Azure CDN Compute@Edge Workers
Security & Secrets
HashiCorp Vault Consul SOPS Sealed Secrets OPA Falco Snyk Aqua Twistlock Cloudflare WAF Fastly WAF AWS Secrets Manager Azure Key Vault GCP Secret Manager
DevSecOps
SonarQube Snyk Checkmarx Veracode Trivy Grype Semgrep CodeQL OWASP ZAP Fortify Aqua Security Sysdig Prisma Cloud Clair Anchore
Policy & Compliance
OPA/Gatekeeper Kyverno HashiCorp Sentinel Checkov tfsec Terrascan Chef InSpec OpenSCAP Prowler ScoutSuite Cloud Custodian
Runtime Security
Falco Tracee Tetragon Cilium Calico Enterprise AppArmor SELinux Sysdig Secure
SIEM & Threat Detection
Splunk Enterprise Security ELK Security Wazuh TheHive Cortex XSOAR Security Onion Nuclei
Supply Chain Security
Sigstore Cosign in-toto SLSA Notary TUF SBOM tools Dependency-Track
Service Mesh
Istio Linkerd Consul Connect AWS App Mesh Envoy Traefik
Monitoring & Observability
Prometheus Grafana Elasticsearch Kibana Logstash Beats Elastic APM Grafana Agent Mimir Loki Tempo ELK DataDog New Relic Cloudflare Analytics Fastly Real-time Stats Jaeger Zipkin OpenTelemetry Fluentd Vector Thanos Cortex