Insights & Thinking

The NovaRock Blog

Practical writing on enterprise software architecture, cloud infrastructure, AI/ML engineering, DevOps, and cybersecurity — from the people building it every day.

Browse by topic Cloud AI / ML DevOps Software Cybersecurity All Posts

Kubernetes Cost Optimisation: 8 Changes That Cut Our Client's AWS Bill by 41%

Most Kubernetes clusters in production are significantly over-provisioned. Here are the specific configuration changes — from VPA to spot instance node pools — that consistently deliver the largest savings without risking availability.

8 min read

Implementing Zero Trust Architecture in a Legacy Enterprise Network: A Step-by-Step Approach

Zero Trust is not a product you buy — it is an architectural philosophy you implement incrementally. This guide covers the practical phasing strategy we use when helping enterprises transition away from perimeter-based security models.

11 min read

Platform Engineering vs. DevOps: Why the Distinction Matters for Engineering Organisations at Scale

As organisations grow past 30-40 engineers, raw DevOps practices start to create invisible bottlenecks. Platform engineering — the discipline of building internal developer platforms — is how leading teams reclaim deployment velocity without sacrificing reliability.

9 min read

Event-Driven Architecture: When to Use It and When It Will Make Your Life Worse

Event-driven systems are powerful when applied to the right problems and catastrophically over-engineered when applied to the wrong ones. Here is a decision framework based on real production systems — not whiteboard architecture diagrams.

10 min read

Building RAG Pipelines That Actually Work in Production: Lessons From Five Enterprise Deployments

Retrieval-Augmented Generation is powerful on paper and finicky in practice. Chunking strategies, embedding model choice, retrieval scoring, and re-ranking all compound into either accurate, trustworthy answers — or confident hallucinations. Here is what we learned the hard way.

14 min read

Multi-Cloud Strategy in 2026: What Works, What Does Not, and What the Vendors Won't Tell You

Multi-cloud promises resilience and negotiating leverage, but the operational overhead is real and often underestimated. This is an honest look at the scenarios where multi-cloud genuinely pays off versus where a well-managed single-cloud strategy is the more defensible choice.

10 min read

GitOps in Practice: Why We Switched from ArgoCD to Flux for Our Largest Client — and What We Learned

Both ArgoCD and Flux are excellent. The decision between them is not about features — it is about your team's mental model of infrastructure management, your cluster topology, and how you think about drift detection. Here is how we made the call.

7 min read

Software Supply Chain Security: Building an SBOM Programme From Zero in a Mid-Size Engineering Team

The XZ Utils backdoor was a wake-up call for the industry. A Software Bill of Materials programme is no longer optional for any organisation shipping software to enterprise clients. Here is a practical implementation guide that does not require a dedicated security team to execute.

9 min read

How to Quantify Technical Debt So That Non-Technical Stakeholders Actually Act on It

Technical debt is real, but "the codebase is messy" does not persuade a CFO to fund a refactoring sprint. Here are the metrics, framing strategies, and business-language translations that consistently move technical debt from an engineering complaint to a funded initiative.

8 min read

No articles found

Try a different search term or clear your filters to browse all posts.

Get New Articles in Your Inbox

We publish one or two deeply considered articles per month — no filler, no newsletters padded with curated links. Just original writing on the problems our team is solving in the field.

Have a Project in Mind?

Reading about the work is one thing. Let's talk about what we can build together. Tell us about your challenge and we will respond within one business day.

Start a Conversation View Our Portfolio