Blog
Practical architecture notes — Azure, security, and the occasional AI detour.
-
Azure DDoS Protection: One Plan, Many Subscriptions
28 June 2026One DDoS Protection Plan covers VNets across every subscription in a tenant. Creating one per subscription burns roughly US$35K a year, per extra plan.
-
Azure Application Gateway: Common Mistakes and the Right WAF Rollout
28 June 2026The ten mistakes I see most often, a disciplined detection-to-prevention rollout, and what changes when the traffic is healthcare.
-
An Architect's Guide to Azure Storage
4 June 2026Blob, Files, Queues, Tables, and Disks — redundancy, lifecycle, multi-region DR, and cost, with Terraform and Bicep baselines.
-
Claude for Developers: Using AI Agents Across the Development Lifecycle
17 May 2026Where AI agents genuinely help across planning, coding, review, and deployment — and the security controls worth putting around them.
-
Microsoft Fabric and Azure AI Foundry for Healthcare Analytics
16 May 2026Unifying claims, FHIR, and streaming data in OneLake, then layering AI for denial prediction and document summarisation — HIPAA intact.
-
DevOps is Dead? How AI Agents Are Rewriting the Pipeline Playbook
10 May 2026Incident response, Kubernetes triage, Terraform drift, and security auto-fix — what agents actually do well in a pipeline, and what they don't.
-
AI Agents in Every IDE
28 April 2026Setup for VS Code, JetBrains, Visual Studio, Eclipse, and Neovim, with real troubleshooting and deployment scenarios.
-
Building Agentic AI Systems: MCP, Orchestration, and Architecture
18 March 2026The Model Context Protocol, multi-agent patterns, memory architecture, and the enterprise security controls that make them viable.
-
Generative AI in the Enterprise: Patterns for Production LLM Deployments
12 February 2026RAG pipeline design, private model deployment, responsible AI controls, and evaluation-driven development.
-
Cloud Trends Enterprise Architects Must Act On Now
22 January 2026AI-native infrastructure, platform engineering, confidential computing, and sovereign cloud — what to prioritise, and why.
-
Zero Trust Architecture on Azure: A Practitioner's Blueprint
14 November 2025End-to-end Zero Trust — identity and Conditional Access through network micro-segmentation, encryption, and SIEM-driven detection.
-
Healthcare Cloud: Designing for HIPAA and HITRUST
8 October 2025How a large-scale claims platform reached HITRUST in under six months — reference architecture, risk register, and control mapping.
-
Azure Landing Zone Design
5 September 2025Getting the foundation right before you build — management group hierarchy, hub-spoke networking, and policy as code.