Sign in

Michael Levan 👨🏻‍💻☕️

@mikelevan.bsky.social
364 followers 86 following 234 posts

Building High-Performing Agentic and Kubernetes Environments | AI Architect @Solo.io | CNCF Ambassador | Microsoft MVP (Azure) | AWS Community Builder | Published Author & International Public Speaker

PostsRepliesMedia
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 20/12/2025
🤨 All AI traffic is context-aware. It's stateful. Context-aware networking is the new norm in AI workloads, which means we need to implement workflows for long-term and short-term memory.
110
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 22/11/2025
Fine-tuning a Model could take A LOT of resources Example: Llama has 7 billion parameters and 2-7B weight matrices. That's where LoRA/PEFT come into play. Instead of having to update/train every part of the Model, it adds the new training layer on top of what already exists.
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 16/11/2025
Inference in AI breakdown (and a need-to-know) 👇 ✅ Inference == Make a prediction on unseen/new data. ✅ Inference Routing == the infrastructure layer. #kubernetes #agenticai #LLMs
011
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 11/05/2025
Consolidating 15 years of software engineering, cyber security, DevOps, and cloud into bite-sized bits 👇 Posting daily as I'm working. Sharing tips and tricks as I go michaellevan.substack.com
michaellevan.substack.com
Michael Levan | Substack
Consolidating 15 years of software engineering, cyber security, DevOps, and cloud into bitesized bits. Click to read Michael Levan, a Substack publication. Launched a day ago.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 06/05/2025
Security is actually pretty simple: 1. Ensure that the data is secure 2. Ensure that any third-party libraries/packages you're using in your code are secure Well... since that's 100% of security, I guess security isn't all that simple lol
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 06/05/2025
Ohhh, I have to hear more. I have a finished basement that I haven't done anything with since I bought my house and I've been thinking of doing this exact same thing.
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 06/05/2025
1. Continuous monitoring of networks. 2. Tie specific malicious behavior to an IP address to see where it originated. Both of these really fall under the vulnerability assessment category.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 06/05/2025
One of the biggest pieces to remember with CDR is how data is being traversed and who has access to what. Network Detection and Response (NDR) provides two primary capabilities:
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 06/05/2025
This could be larger cloud-based environments like Azure, Google Cloud Platform (GCP), and Amazon Web Services (AWS), or smaller clouds like Vultr and Digital Ocean (DO). The primary goal of a CDR is to have a deep understanding of the environment. (cont)
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 06/05/2025
Cloud Detection Response (CDR) and Network Detection Response (NDR) 👇 Cloud Detection and Response (CDR) focuses purely on cloud environments. (cont) #kubernetes #devops #platformengineering
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 01/05/2025
That means the apps/tools you're running locally to reach the k8s Service won't be able to reach it either.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 01/05/2025
That means if you're trying to access the resource locally (for example, connecting to the DB running in k8s), you have to do it from your local terminal. If you try it from a cloud shell or something that isn't local, you won't be able to hit it via localhost. (cont)
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 01/05/2025
An important reminder when using `port-forward` with Kubernetes. If you run something like `kubectl port-forward svc/service_name portnumber:port:number` You're bringing the traffic from the Kubernetes to your local computer. (cont) #kubernetes #devops #platformengineering
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 27/04/2025
I updated KoaPerf to include: 1. AWS Support! You can get recommendations for containerized apps running in AWS now. 2. A better UI (more visually appealing) Check it out at the link below 👇 koaperf-apeseqd2cehnhjgh.z03.azurefd.net #kubernetes #devops #platformengineering
011
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 21/04/2025
Here are a few tips when thinking about what platforms to use, how to use them, and what to think about when managing them.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 21/04/2025
For any organization, big or small. Enterprise or startup. Figuring out the workflow of how environments should be deployed, managed, and most importantly, what should be deployed and managed is the make or break. (cont) #kubernetes #devops #platformengineering
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 20/04/2025
And the goal is to add AWS EKS and AWS ECS. KoaPerf is a scanner that tells you based on performance, cost, and resource needs where you should deploy a containerized workload.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 20/04/2025
The current recommendations it gives you are between: ✅ Azure Kubernetes Service (AKS) ✅ Azure Container Apps (ACA) ✅ Azure Container Instance (ACI)
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 20/04/2025
Instead of scanning a Kubernetes Manifest to tell you the best place to deploy, it'll read a description that you add in or an architecture doc you upload.
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 20/04/2025
I built a free tool to tell you the best place to deploy containerized workloads. koaperf-apeseqd2cehnhjgh.z03.azurefd.net (cont) #kubernetes #devops #platformengineering
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 17/04/2025
After planning and deploying a Kubernetes environment, you're left with: ✅ Performance optimization ✅ Monitoring and observability ✅ Upgrades and a few other specifics that are necessary to ensure k8s is running as expected. #kubernetes #devops #platformengineering
020
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 16/04/2025
However, before using ArgoCD, it has to be deployed to the cluster. CICD pipelines are still the best way to get workloads and infrastructure initially deployed in an automated fashion. I break down my thoughts about it in the link below. buff.ly/3GWl2wy
buff.ly
Keeping The Lights On: Pipeline Differentiations for CICD
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 16/04/2025
The tool needs to be deployed before it can be used. ArgoCD is a great example of this. Argo is implemented for workloads in k8s to be deployed automatically based on an interval instead of having to run a bunch of `kubectl apply -f` commands locally or in a pipeline. (cont)
buff.ly
Keeping The Lights On: Pipeline Differentiations for CICD
110
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 15/04/2025
and a few other aspects that are super crucial to implementing EKS (and Kubernetes in general) within any environment. In this blog post, I break it all down. buff.ly/WYBXgqU
buff.ly
Optimizing AWS Elastic Kubernetes Service (EKS)
As you develop environments, infrastructure, and orchestration platforms (like k8s), you'll begin to notice that there are several directions to go in. There's a joke that goes something like "line up...
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 15/04/2025
I was recently on a consulting project and the goal was to optimize AWS EKS. It came down to a few key aspects including: 1. Workload isolation 2. Multi-az 3. Cluster security around multi-tenancy 4. Performance optimization (cont)
buff.ly
Optimizing AWS Elastic Kubernetes Service (EKS)
As you develop environments, infrastructure, and orchestration platforms (like k8s), you'll begin to notice that there are several directions to go in. There's a joke that goes something like "line up...
110
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 14/04/2025
Therefore, security really just ensures that there are people on the team who know the system/platform/application exceptionally well. If they do, they can secure it.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 14/04/2025
More importantly - security, and I mean proper cyber security, can only occur when you know a system/platform/application VERY well. You must know the ins and outs in every capacity. (cont)
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 14/04/2025
I never thought about security as a specialty. i.e - DevOps Security, Cloud Security, Network Security, etc. The reason is that security should be embedded in all of our jobs. (cont)
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 12/04/2025
I just updated DevOps-The-Hard-Way-AWS for the first time in 4 years. ✅ Removed the creation of a VPC for EKS with CloudFormation ✅ Terraform Modules for EKS and VPC creation ✅ Simplified the steps for the labs and A LOT more. Link below 👇 github.com/AdminTurnedD...
github.com
GitHub - AdminTurnedDevOps/DevOps-The-Hard-Way-AWS: This repository contains free labs for setting up an entire workflow and DevOps environment from a real-world perspective in AWS
This repository contains free labs for setting up an entire workflow and DevOps environment from a real-world perspective in AWS - AdminTurnedDevOps/DevOps-The-Hard-Way-AWS
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 12/04/2025
You're not late to learning Cloud/DevOps/Platform Engineering, you're right on time. Open up that new DevOps course. Learn Kubernetes and why orchestration is important. Understand networks, systems, and design. You'll never reach a point where you "know it all".
030
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 11/04/2025
It'll turn into: 1. Tech debt 2. No one will know how to troubleshoot 3. No one will know how to add specific functionality for your edge cases And worse, everyone that finds a bug will have ZERO knowledge on how to actually fix it.
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 11/04/2025
In the world of AI programming with things like Cursor... If you don't spend the time now getting really good at programming, you're going to fail drastically. If you let "the AI thing" do it all for you without you understanding what's happening underneath the hood... (cont)
110
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 10/04/2025
All Kubernetes implementations start with: ✅ Proper planning and architecture ✅ Security ✅ Teamwork Ensure you know exactly what's being deployed, managed, and by whom. #kubernetes #devops #platformengineering
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 09/04/2025
In the last week or so, I started trying Cursor out to build some cloud-native tooling. The result? Pretty good actually! I created a tool in Python to do a `diff` on a bunch of cloud security policies across Azure CIS and MCSB. buff.ly/R7zDF8j #kubernetes #devops #platformengineering
buff.ly
Keeping The Lights On: Planning Cloud Security With Prompt Engineering
In this episode, Michael Levan dives into a few key tips on creating programs for "diffs". The idea is that you have two things and you need to ensure that you aren't re-doing work that already exists...
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 09/04/2025
Do I know anyone who works at AWS?
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 08/04/2025
Terraform is always funny. I need an S3 bucket to store my state! Ah, that S3 bucket needs to be created before I create my other resources that need to store state. I'll put it in my module! Wait, the module needs to access the S3 bucket and it's not created yet...
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 08/04/2025
It’s CLI-based and you can pull down the binary at the link below.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 08/04/2025
➡️ Scans k8s clusters to tell you the best way to optimize it ➡️ Scans a doc or an architecture diagram to tell you the best way to deploy your environment ➡️ Allows you to ask a cloud-native and/or Kubernetes based question to help you deploy and manage your workflow
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 08/04/2025
I built a new open-source cloud and Kubernetes based tool that: buff.ly/ZT8IyHs #kubernetes #devops #platformengineering
buff.ly
GitHub - AdminTurnedDevOps/cloudigest
Contribute to AdminTurnedDevOps/cloudigest development by creating an account on GitHub.
220
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 05/04/2025
Ah, this looks awesome. I have to pick up a copy.
010
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 04/04/2025
Scaling k8s workloads in an event-driven fashion == ensure proper performance, cost, and resource optimization for various situations that occur. In this video, I break down one method of scaling Kubernetes workloads with KEDA. buff.ly/5WgJidU #kubernetes #devops #platformengineering
buff.ly
(2025) Using KEDA On AKS To Trigger Based Off Of Resource Optimization
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 04/04/2025
Does anyone have the key takeaways for KubeCon EU? So far I'm seeing: 1. VMs on Kubernetes. 2. Kubernetes could be a solid place to run Agents and ML workloads Anything else? #kubernetes #kubecon
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 03/04/2025
Managed k8s services were meant to be... well, managed. EKS Auto Mode and AKS Automatic got us there. In this blog post, I break down how to get started from a hands-on perspective with both. buff.ly/fhJweo8 #kubernetes #devops #platformengineering
buff.ly
AKS Automatic and AWS EKS Auto Mode: Setup and Deployment
Discover the benefits of AKS Automatic and EKS Auto Mode in Kubernetes management. Learn how these features streamline container orchestration, enhance scalability, and optimize cloud performance. Div...
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 29/03/2025
It can scale anywhere and live anywhere. This is the technology engineers should be putting time into understanding. It’s a true Distributed System.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 29/03/2025
That same binary can be scaled out in those three places for high availability and scalability. It effectively ensures that it literally doesn’t matter where you’re running your app.
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 29/03/2025
With a Component, you can run anywhere AND have the binary scaled out, running wherever, communicating back and forth. For example - let’s say you have the same binary running on Kubernetes, on a bare-metal Linux box, and on your laptop.
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 29/03/2025
Wasm gives DevOps and Platform Engineers true Distributed Systems. You have the ability to not care where your app is running. 1. Build your application 2. Build a Component (made up of a WIT) 3. Compile it down to Wasm A thread 🧵 #kubernetes #devops #wasm
163
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 19/01/2025
- It's use `gpt-4` - The temperature is set very low to ensure as close to no-nonsense answers as possible Now, here's the interesting thing... It's defaulting to carving out answers from 2023, which 2 years time in tech is like a decade.
000
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 19/01/2025
Alright, so this is rather interesting and why fine-tuning or creating a RAG is necessary. This agent has a clear, defined job: Tell me the best region to deploy k8s workloads to based on cost and performance. A few things: (in the next comment) #kubernetes #devops #platformengineering
100
Michael Levan 👨🏻‍💻☕️ @mikelevan.bsky.social · 19/01/2025
Just a reminder that those AI Agents that everyone thinks will "take jobs" have to run somewhere. That "somewhere" is most likely going to be: 1. k8s 2. Containers 3. Event-driven services This stuff isn't magic. It needs to run somewhere. #kubernetes #devops #platformengineering
020