Sign in

Darryl Ruggles

@darryl-ruggles.cloud
1.3K followers 411 following 6.6K posts

AWS Hero | Principal Cloud Solutions Architect @ Ciena Serverless, Event-Driven Architecture, AWS, Kubernetes, Rust, Terraform, Security, DevOps, FinOps, MLOps, Maker darryl-ruggles.cloud www.linkedin.com/in/darryl-ruggles

PostsRepliesMedia
Darryl Ruggles @darryl-ruggles.cloud · 4h
lckhd.eu/UKcZSd #EKS #AgentCore #StrandsAgents #Kubernetes #Migration LLMs are being used for many things today, with mixed usefulness in my opinion. Coding agents are a big win, at least for experienced developers. Migrations look promising too, since many teams want Kubernetes but can't
lckhd.eu
AI-powered EKS migration assessment with Amazon Bedrock AgentCore | Amazon Web Services
Learn how to build an AI-powered migration assessment agent using Amazon Bedrock AgentCore and the Strands Agents SDK. The agent reads application source code and container artifacts, scores Amazon EKS migration readiness, identifies blockers by severity, and generates an actionable migration plan with target architecture recommendations.
100
Darryl Ruggles @darryl-ruggles.cloud · 15h
lckhd.eu/yhOJ1v #Kubernetes #scheduling #pdb Kubernetes has many concepts to understand. Many of these make sense alone but get tangled the moment you put them together.
100
Darryl Ruggles @darryl-ruggles.cloud · 15h
lckhd.eu/0YCY7t #Kubernetes #scheduling #pdb Kubernetes has many concepts to understand. Many of these make sense alone but get tangled the moment you put them together.
101
Darryl Ruggles @darryl-ruggles.cloud · 29/09/2026
lckhd.eu/N42LoM #Terraform #ClaudeCode #AWS #GCP #PlatformEngineering As we've all heard by now, LLMs are non-deterministic by nature.
100
Darryl Ruggles @darryl-ruggles.cloud · 29/09/2026
lckhd.eu/BrdcfB #EventBridge #EventDrivenArchitecture #Serverless #AWS #PlatformEngineering Anyone who has worked with EventBridge across multiple AWS accounts knows it can get messy. Setups can expand with every new forwarding rule and you can end up with many custom event buses spread
lckhd.eu
Building event-driven applications at scale with Amazon EventBridge | Amazon Web Services
Amazon EventBridge relaunched the Custom event bus so a platform team can share one governed bus across the organization while application teams publish and subscribe from their own accounts. See how retention, ordering, open formats, transformation, and direct target delivery change what one bus can carry.
220
Darryl Ruggles @darryl-ruggles.cloud · 28/09/2026
lckhd.eu/RNVZ38 #Kubernetes #AmazonEKS #Descheduler #Resilience When a node group is updated or a Spot interruption empties the workers in one AZ, displaced pods land in the remaining AZs. After capacity comes back, every node looks healthy, but the running pods no longer match the spread
lckhd.eu
Fix pod distribution drift in Amazon EKS with the Kubernetes descheduler | Amazon Web Services
A workload spread across three Availability Zones does not necessarily stay spread. This post explains why soft topology spread constraints drift after a node-availability gap, measures the cost, and shows how the Kubernetes descheduler restores even pod distribution on Amazon EKS without downtime and without forcing hard constraints.
200
Darryl Ruggles @darryl-ruggles.cloud · 28/09/2026
lckhd.eu/UYBeFf #Kubernetes #K9s #kubectl I have spent years looking at Kubernetes clusters with kubectl, and I know the common resource types and flags by heart. This works really good for me, but it can take a long time to get there, and for many a higher level view of what is running
100
Darryl Ruggles @darryl-ruggles.cloud · 27/09/2026
lckhd.eu/p9Xyh5 #Serverless #FinOps #Containers #PlatformEngineering I really like reading engineering blogs from big orgs like Netflix. Real-world stories from large systems are always interesting. Many function resource configs start as a copy of some other function, with extra padding
200
Darryl Ruggles @darryl-ruggles.cloud · 27/09/2026
lckhd.eu/J9AbQL #Istio #ServiceMesh #Terraform #EKS Managing observability, security, and service-to-service communication gets complex as microservices scale. Traffic routing, mTLS, and circuit breaking are important. Implementing these typically means modifying application code. Istio
100
Darryl Ruggles @darryl-ruggles.cloud · 26/09/2026
lckhd.eu/AtQoY3 #EKS #Auth #AccessEntries For anyone still managing EKS access through the aws-auth ConfigMap, you really should move on. A single YAML indentation slip can lock out your admins and CI/CD pipelines at the worst possible moment. There's been a better path for a long time
100
Darryl Ruggles @darryl-ruggles.cloud · 26/09/2026
lckhd.eu/j3b5Ha #Kubernetes #VPA #Autoscaling #PlatformEngineering #FinOps Getting resource requests right for a pod in Kubernetes is difficult a lot of the time.
200
Darryl Ruggles @darryl-ruggles.cloud · 26/09/2026
lckhd.eu/XvfP5v #Kubernetes #StatefulSet #Deployment Kubernetes can seem complicated with so many options available. Choosing between StatefulSets and Deployments is one confusing example. If your app needs persistent storage or unique pod identities, go with StatefulSet. Otherwise,
lckhd.eu
Kubernetes StatefulSet vs. Deployment: Differences & Examples
Learn the differences between Kubernetes StatefulSets and Deployments, with examples and best practices for managing stateful and stateless applications.
100
Darryl Ruggles @darryl-ruggles.cloud · 25/09/2026
lckhd.eu/m0a5CU #SRE #DevOps #CICD Jev is everywhere! Everyone is trying to figure out how to take advantage of it, given the performance and cost numbers it promises.
100
Darryl Ruggles @darryl-ruggles.cloud · 25/09/2026
lckhd.eu/2CQeJC #EKS #Kubernetes #AWSConfig #SNS #EventBridge Using the Elastic Kubernetes Service (EKS) on AWS makes using Kubernetes easier than setting up from scratch. One complication that many teams don't handle well is regularly updating Kubernetes versions as they get released
100
Darryl Ruggles @darryl-ruggles.cloud · 24/09/2026
lckhd.eu/hargOj #AmazonEventBridge #Serverless #EventDrivenArchitecture #AWS New custom event buses in Amazon EventBridge just launched!!
lckhd.eu
Introducing enhanced custom event buses in Amazon EventBridge for enterprise-scale event-driven applications | Amazon Web Services
Amazon EventBridge announces an enhanced custom event bus for organizations scaling event-driven applications across teams and accounts. Deploy a single event bus shared across all AWS accounts in your organization, with ordering guarantees, a simplified Subscriber resource, and improved economics at scale.
100
Darryl Ruggles @darryl-ruggles.cloud · 24/09/2026
lckhd.eu/NKTtZ3 #AmazonBedrock #AgentCore #MCP #MultiAccount #Agents Using multiple AWS accounts to isolate resources is a good approach in many cases, but it can be a problem when you deploy agents that need to work with data from many accounts. Copying data or dealing with cross-account
lckhd.eu
Build a multi-account AI agent with AgentCore Gateway and MCP | Amazon Web Services
Build a multi-account architecture that keeps each team
210
Darryl Ruggles @darryl-ruggles.cloud · 24/09/2026
lckhd.eu/7mPsl4 #ArgoCD #GitOps #Kubernetes #ContinuousDelivery With PR automation set up, a merged code change builds a new container image, and then the rollout waits. Argo CD Image Updater polls the registry on an interval, while Argo CD polls Git on its own delay. Whoever merged the
200
Darryl Ruggles @darryl-ruggles.cloud · 23/09/2026
lckhd.eu/yf872N #Kubernetes #containerd #Docker #CRI #PlatformEngineering One topic that confuses many people is Docker and its support in Kubernetes.
100
Darryl Ruggles @darryl-ruggles.cloud · 23/09/2026
lckhd.eu/3tdjhF #AmazonEKS #AmazonECR #Kubernetes #MultiTenancy #CloudSecurity In many cases there are multiple teams or projects running in the same EKS cluster.
lckhd.eu
Implement per-pod image pull permissions with ECR repository policies on Amazon EKS | Amazon Web Services
Learn how to scope Amazon ECR image pull permissions to individual Kubernetes pods on a multi-tenant Amazon EKS cluster using KEP 4412 credential providers and ECR repository deny policies, so teams sharing the same nodes can pull only their own container images.
120
Darryl Ruggles @darryl-ruggles.cloud · 22/09/2026
lckhd.eu/1awgYk #LLM #Opus #Anthropic #AWS #Bedrock Opus 5.5 is now available! Yet another new model to play with! I just moved to Opus 5.0 recently and now 5.5 is available. Opus 5.5 is also already available on Bedrock.
lckhd.eu
Claude Opus 5.5 is now available on AWS - AWS
Discover more about what
000
Darryl Ruggles @darryl-ruggles.cloud · 22/09/2026
lckhd.eu/eDmRZa #Jev #TypeSafeAI #StructuredOutputs #AIEngineering #MLOps I guess it's possible you have not heard about Jev yet but it has taken over the internet in the last week.
100
Darryl Ruggles @darryl-ruggles.cloud · 22/09/2026
lckhd.eu/MmaRlV #StrandsAgents #AIAgents #ContextEngineering #AmazonBedrock There are a number of AI harnesses out there now. You have likely used coding harnesses like Claude Code or Codex.
lckhd.eu
Introducing Strands harness: frontier performance with 28% lower token cost
Strands harness is a fully assembled, customizable, state-of-the-art agent you run locally or deploy anywhere.
100
Darryl Ruggles @darryl-ruggles.cloud · 22/09/2026
lckhd.eu/q6s9DQ #Kubernetes #Storage #FinOps #PlatformEngineering Kubernetes does not delete Persistent Volume Claims (PVCs) when their pods go away. This helps to protect the data but can leave orphaned volumes.
lckhd.eu
Kubernetes v1.37: Tracking When a PersistentVolumeClaim Was Last Used (Beta)
Kubernetes v1.37 promotes the PersistentVolumeClaimUnusedSinceTime feature gate to Beta (enabled by default). With this feature, the PersistentVolumeClaim (PVC) protection controller adds an Unused condition to each PVC, telling you whether any running pod currently references it — no custom tooling or cross-referencing required. For the API definition of PVC conditions, see the PersistentVolumeClaim API reference. Read on to learn how the Unused condition works and how to use it. Why track PVC usage?In large-scale Kubernetes clusters, it is common for users to create PVCs and then delete the associated pods without cleaning up the storage, because Kubernetes does not automatically delete PVCs when their pods are removed (to protect against accidental data loss). Over time, these orphaned PVCs may accumulate, silently consuming storage capacity and driving up cloud costs.
320
Darryl Ruggles @darryl-ruggles.cloud · 21/09/2026
lckhd.eu/3gD4y3 #AWS #Terraform #CloudWatch #CloudTrail #Observability There are many different tools you need to use to debug issues on AWS, including app logs, Lambda logs, CloudTrail logs to see who changed what, and VPC flow logs to see if traffic was blocked or not. In many cases
110
Darryl Ruggles @darryl-ruggles.cloud · 21/09/2026
lckhd.eu/yAURM1 #Kubernetes #RBAC #MCP #PlatformEngineering Most people are experimenting with agents and gradually warming up to giving them more access to help debug issues and perform mundane tasks for them. Some examples with Kubernetes include reading logs and describing pods. We
110
Darryl Ruggles @darryl-ruggles.cloud · 20/09/2026
lckhd.eu/h1eR0x #GitHubActions #Docker #DockerCompose #CICD #DevOps I like to setup automation whenever possible and use tools like GitHub Actions to help.
100
Darryl Ruggles @darryl-ruggles.cloud · 19/09/2026
dev.to/aws-builders/argo-cd-app-of-apps-on-eks-bcc #aws #EKS #ArgoCD #GitOps Managing multiple apps across Kubernetes clusters can get complicated. Using a Gitops approach with ArgoCD and using The "App of Apps" pattern offers a clean way to bootstrap everything.
100
Darryl Ruggles @darryl-ruggles.cloud · 19/09/2026
lckhd.eu/lFvmP3 #aws #AmazonS3 #VPC #FinOps #Terraform Using a VPC on AWS to isolate your traffic is the right answer in many cases and using private subnets is the right default most of the time.
100
Darryl Ruggles @darryl-ruggles.cloud · 18/09/2026
lckhd.eu/hQr7km #AWSLambda #Serverless #AIAgents #Firecracker Being able to run agents in an isolated environment and give them only what access and credentials they need is important.
lckhd.eu
Running self-hosted AI agent sandboxes with AWS Lambda MicroVMs | Amazon Web Services
Learn how to run AI agent tool calls in secure, isolated sandboxes using AWS Lambda MicroVMs. This post shows how to architect a self-hosted control plane that launches a fresh, VM-isolated MicroVM for each agent session, keeping credentials, networking, and governance entirely within your own AWS account.
100
Darryl Ruggles @darryl-ruggles.cloud · 18/09/2026
lckhd.eu/kEo1g3 #Bedrock #AgentCore #Serverless #Agents I like building projects with AgentCore so it's interesting to see a new AgentCore runtime.
lckhd.eu
The new AgentCore runtime: Elastic, optimized, and consistently fast starts | Amazon Web Services
Today we are announcing the new AgentCore runtime, a capability of Amazon Bedrock AgentCore built for the speed, flexibility, and cost efficiency that production agents demand. It reclaims memory as sessions release it and delivers consistent cold starts regardless of image size or concurrency.
110
Darryl Ruggles @darryl-ruggles.cloud · 18/09/2026
lckhd.eu/UkWjJ1 #Kubernetes #Kueue #GangScheduling #BatchWorkloads #MLOps Being able to schedule jobs and manage quotas on Kubernetes is something you may need to setup and using Kueue is one good approach for this. Kueue isn't a scheduler but a controller that decides when a job is
lckhd.eu
Inside Kueue: How Kubernetes Decides What Runs Next
See how Kueue brings order to overloaded Kubernetes clusters by intelligently managing batch workloads with a hands on demo.
100
Darryl Ruggles @darryl-ruggles.cloud · 17/09/2026
lckhd.eu/2hq5jL #StepFunctions #AWSLambda #Serverless #AgenticAI Many apps work well as part of a workflow and the managed approach for this on AWS typically involves Step Functions.
lckhd.eu
AWS Step Functions adds new AWS service integrations automatically, starting with AWS Lambda MicroVMs - AWS
Discover more about what
110
Darryl Ruggles @darryl-ruggles.cloud · 17/09/2026
lckhd.eu/X4qFnS #ArgoCD #GitOps #Kubernetes #PlatformEngineering Using a GitOps approach for managing apps in Kubernetes helps with organization and maintainability.
120
Darryl Ruggles @darryl-ruggles.cloud · 16/09/2026
lckhd.eu/qqFfTT #AWS #Serverless #AWSFreeTier #IAM I encourage people to try out AWS all the time but it has always been a challenge directing them on how to get started.
lckhd.eu
New AWS experience helps builders get started and ship faster - AWS
Discover more about what
100
Darryl Ruggles @darryl-ruggles.cloud · 16/09/2026
lckhd.eu/Sbn2WA #Kubernetes #DynamicResourceAllocation #MIG #GPUSharing #MLOps GPUs are in high demand these days and the costs can really add up. With the large GPUs available today, it doesn't make sense to dedicate a whole one to many tasks. Using fractional GPUs in Kubernetes is
110
Darryl Ruggles @darryl-ruggles.cloud · 15/09/2026
lckhd.eu/7tiS3v #Bedrock #PromptCaching #GenerativeAI #FinOps #MultiTenancy Almost everyone is watching their AI spend more closely these days. As the price of LLM tokens moves closer to their real cost, teams have to start to optimize spend as much as they can. Prompt caching is one of
lckhd.eu
Optimizing cost and latency with Amazon Bedrock prompt caching | Amazon Web Services
Prompt caching in Amazon Bedrock can cut input token costs by up to 90% when you repeatedly send the same context to foundation models. This post walks through six practical prompt caching scenarios using the Converse API: message content, system prompt, tool definition, mixed TTL, tenant isolation, and LangChain integration.
110
Darryl Ruggles @darryl-ruggles.cloud · 15/09/2026
lckhd.eu/xRBpoU #Kubernetes #Longhorn #K3s #DisasterRecovery I have used Longhorn with Kubernetes for a long time. It is a really nice way to deal with storage and backups. The example here shows setting up Longhorn on a Raspberry Pi 5 K3s cluster. The example includes two replicas
100
Darryl Ruggles @darryl-ruggles.cloud · 15/09/2026
lckhd.eu/6ksJLI #Bedrock #AgentCore #OAuth #MCP Teams are building agents that call GitHub, Slack, or other apps that need OAuth grants bound to the right identity. AgentCore now hosts that flow for you, including the callback endpoint, browser sessions, and the final
lckhd.eu
Manage end-user OAuth consent for AI agents with Amazon Bedrock AgentCore | Amazon Web Services
Amazon Bedrock AgentCore Identity now offers a Consent portal, a managed web experience and session binding endpoint for AgentCore Gateway. This post walks through provisioning a portal, configuring GitHub and Slack 3LO targets, and the end-user consent flow, and shows how to review activity in AWS CloudTrail.
110
Darryl Ruggles @darryl-ruggles.cloud · 14/09/2026
lckhd.eu/ZkTpEy #Observability #Fargate #ECS #Prometheus Using the Elastic Container Service (ECS) is a great way to get started on with containers on AWS and using Fargate compute is a good starting point. ECS/Fargate handles your infrastructure, but that convenience has a tradeoff where
100
Darryl Ruggles @darryl-ruggles.cloud · 13/09/2026
lckhd.eu/PnG7TS #DynamoDB #DuckDB #ApacheIceberg #Serverless There are many different options for databases on AWS and it's great to be able to pick the one that best matches your use case. DynamoDB (DDB) is an example of a highly performant non-relational database which can provide
lckhd.eu
Run DuckDB analytics on your Amazon DynamoDB data with zero-ETL | Amazon Web Services
Run ad hoc SQL analytics on your Amazon DynamoDB data with DuckDB. A zero-ETL integration replicates your table into Apache Iceberg tables on Amazon S3 Tables, and an AWS Lambda function running DuckDB serves SQL queries through an IAM-authorized function URL.
210
Darryl Ruggles @darryl-ruggles.cloud · 13/09/2026
lckhd.eu/YPX255 #vLLM #Kubernetes #NVIDIA #Minikube #LocalAI With LLM token prices climbing all the time, more teams are looking at running smaller models locally, and a lot of local GPUs handle that size of workload fine. For people stuck using Windows, getting one of them visible to a
111
Darryl Ruggles @darryl-ruggles.cloud · 13/09/2026
lckhd.eu/l9zV5m #EDA #Route53 #Eventbridge #DNS Managing DNS records manually across multiple AWS accounts is one of those operational tasks that quietly drains time and attention.
100
Darryl Ruggles @darryl-ruggles.cloud · 12/09/2026
lckhd.eu/oIYXOM #AWSLambda #Terraform #Serverless #FinOps #AWS I recently wrote about Lambda Managed Instances. Traditional Lambda allows a single request per execution environment, so a 150 MB catalog loaded into memory by a 100 concurrent requests loads a 100 times, with a potential
lckhd.eu
Lambda Managed Instances: Multi-Concurrency & High Memory
Discover Lambda Managed Instances with Terraform: handle high concurrency, memory-intensive tasks, and explore AWS compute options.
100
Darryl Ruggles @darryl-ruggles.cloud · 12/09/2026
lckhd.eu/fO5f5e #crossplane #iac #kubernetes One really interesting approach to Infrastructure as Code is using Crossplane alongside CI/CD as an alternative to Terraform inside pipelines. The premise is simple but easy to ignore: pipelines are deployment tools, not infrastructure
lckhd.eu
Crossplane + CI/CD: How I Stopped Fighting Kubernetes Config Drift and Actually Shipped Faster - techdigestor
Learn how to stop fighting Kubernetes config drift and ship faster with Crossplane + CI/CD. Simplify your deployment pipeline and reduce provisioning time.
100
Darryl Ruggles @darryl-ruggles.cloud · 11/09/2026
lckhd.eu/y7M7JS #EKS #Auth #AccessEntries For anyone still managing EKS access through the aws-auth ConfigMap, you really should move on. A single YAML indentation slip can lock out your admins and CI/CD pipelines at the worst possible moment. There's been a better path for a long time
100
Darryl Ruggles @darryl-ruggles.cloud · 11/09/2026
lckhd.eu/No0PVf #DuckDB #AWSLambda #ApacheIceberg #S3Tables #DataEngineering DuckDB has been in the news lately with AWS acquiring DuckLabs. Many people have been using DuckDB for a long time and really appreciate its performance. I like reading examples of tools like this, and there is
lckhd.eu
AWS Builder Center
Connect with builders who understand your journey. Share solutions, influence AWS product development, and access useful content that accelerates your growth. Your community starts here.
101
Darryl Ruggles @darryl-ruggles.cloud · 11/09/2026
lckhd.eu/UiJgsn #ArgoCD #GitOps #Kubernetes Using a GitOps approach with ArgoCD for your apps running in Kubernetes works well. Seeing examples of setting things up helps me understand them more. The example below installs ArgoCD with Helm and then deploys two apps. One app comes from a
lckhd.eu
Setting Up Argo CD on Kubernetes
Argo CD is a Kubernetes-native, declarative GitOps tool for deploying applications at scale. It pulls...
101
Darryl Ruggles @darryl-ruggles.cloud · 10/09/2026
lckhd.eu/5lFS8Y #Kubernetes #KIND #Docker Getting started with Kubernetes can sound challenging, and reading about it only goes so far. Hands-on is usually a better way to learn.
100
Darryl Ruggles @darryl-ruggles.cloud · 10/09/2026
lckhd.eu/b4b1We #AWS #ECS #Fargate #Containers #Terraform I like using serverless services for many cases but you always need to use the right tool for any given use case.
lckhd.eu
Master AWS ECS: Run & Manage Containers with Ease
Amazon Elastic Container Service (ECS) is the go-to solution for running containers on AWS. Learn about its cost-effective orchestration, deep AWS integrations.
110
Darryl Ruggles @darryl-ruggles.cloud · 10/09/2026
lckhd.eu/2inBFB #AWSLambda #Serverless #LambdaManagedInstances #Async #ESM AWS Lambda now supports a 90 minute function timeout on Lambda Managed Instances for async and Event Source Mapping invocations.
lckhd.eu
AWS Lambda now supports 90-minute function timeout on Lambda Managed Instances - AWS
Discover more about what
200