Cloud
Building a Private Cloud

Cloud Architecture
- How We Built an IaaS Platform Running 50,000 Virtual Machines
- Inside a Cloud Zone Controller Architecture
- Why We Replaced etcd with PostgreSQL
- Migrating a State Store Without Downtime
- From NATS to gRPC: Lessons from a Large-Scale Migration
- API Versioning Without Breaking Clients
- What Fails First in a Cloud Platform?
- Building a Private Cloud from Scratch
- Operating Multiple Availability Zones at Scale
- Designing a Control Plane for Cloud Infrastructure
Virtualization
- What Really Happens When a Virtual Machine Starts
- Managing the VM Lifecycle with QEMU and libvirt
- Online CPU and Memory Resizing: Challenges and Pitfalls
- How Disk Hotplug Works Under the Hood
- Live Migration of Virtual Machines Explained
- Building Encrypted and Compressed S3 Backups
- Creating and Managing VM Images
- Cloud-Init Internals: Bootstrapping Infrastructure
- VNC and Serial Consoles for Cloud VMs
- Why We Decided to Move Away from libvirt
QEMU
- Moving from libvirt to Direct QEMU Management
- Talking to QEMU Through QMP
- Building a Hypervisor Agent Around QEMU
- Understanding QEMU Device Hotplug
- Lessons Learned from Running QEMU at Scale
- Replacing libvirt: What You Gain and What You Lose
SDN and Networking
- Building a Software Defined Network for a Private Cloud
- Designing a VPC Implementation from Scratch
- IP Address Management at Cloud Scale
- Hardware Address Management in Distributed Systems
- Interconnect: Connecting VPCs Across Availability Zones
- Providing Public IP Addresses to Virtual Machines
- Building a VM Firewall with OVN ACLs
- Integrating Katran as an External Load Balancer
- Writing an OpenFlow Controller in Go
- Delivering Cloud-Init Through OpenFlow
- SSH Access Without SDN: A WebSocket-Based Approach
- Building a Layer 4 Load Balancer Prototype
- Eliminating Interconnect Dependencies Between Zones
Databases and Distributed Systems
- Why PostgreSQL Can Be a Better Control Plane Database Than etcd
- Modeling Cloud Infrastructure State in PostgreSQL
- Consistency Challenges in Infrastructure Platforms
- Distributed Transactions in Cloud Control Planes
- Scaling a Database Backing 50,000 Virtual Machines
Observability
- End-to-End Tracing with OpenTelemetry
- Building Dynamic Prometheus Service Discovery
- Monitoring Virtual Machines at Scale
- Collecting SDN Metrics
- Monitoring Netfilter with eBPF
- Building an Observability Stack with Grafana, Loki, Tempo, and Prometheus
- What Infrastructure Metrics Actually Matter
Security
- Host-Based Firewalls for Hypervisors Using Netfilter
- Encrypting Backups in a Cloud Environment
- Managing Secrets with Vault
- Designing Multi-Tenant Network Isolation
- Security Lessons from Running a Private Cloud
Go Engineering
- Building a Cloud Platform in Go
- Writing an End-to-End Testing Framework in Go
- Implementing the OVSDB Protocol in Go
- gRPC Patterns for Infrastructure Software
- Managing Long-Running Infrastructure Operations
- Building Reliable CLI and TUI Tools in Go
Scaling Stories
- Running 50,000 Virtual Machines: What We Learned
- The Most Difficult Bugs in a Cloud Platform
- Technical Debt in Infrastructure Software
- Scaling a Small Team Against Enterprise Problems
- Features That Look Easy but Aren’t
- Mistakes We Made Building a Private Cloud
- Things I Would Do Differently If I Started Again
Suggested First Article Series
- How We Built an IaaS Platform Running 50,000 Virtual Machines
- Inside a Cloud Zone Controller Architecture
- Why We Replaced etcd with PostgreSQL
- From NATS to gRPC: Lessons from a Large-Scale Migration
- Building a Software Defined Network for a Private Cloud
- What Really Happens When a Virtual Machine Starts
- Moving from libvirt to Direct QEMU Management
- Running 50,000 Virtual Machines: What We Learned
etc…