<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://purushotham.me/</id><title>Puru Yanamala</title><subtitle>Puru Yanamala - Cloud DevOps, Architect, Kubernetes</subtitle> <updated>2026-08-14T18:06:01+01:00</updated> <author> <name>Puru Yanamala</name> <uri>https://purushotham.me/</uri> </author><link rel="self" type="application/atom+xml" href="https://purushotham.me/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://purushotham.me/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Puru Yanamala </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Beyond Declarative Allowlists: Escaping Workflow and Git Boundaries in Automated Pipelines</title><link href="https://purushotham.me/posts/beyond-declarative-allowlists-escaping-workflow-and-git-boundaries-in-automated-pipelines/" rel="alternate" type="text/html" title="Beyond Declarative Allowlists: Escaping Workflow and Git Boundaries in Automated Pipelines" /><published>2026-08-14T17:55:39+01:00</published> <updated>2026-08-14T17:55:39+01:00</updated> <id>https://purushotham.me/posts/beyond-declarative-allowlists-escaping-workflow-and-git-boundaries-in-automated-pipelines/</id> <content type="text/html" src="https://purushotham.me/posts/beyond-declarative-allowlists-escaping-workflow-and-git-boundaries-in-automated-pipelines/" /> <author> <name>Puru Yanamala</name> </author> <category term="DevOps" /> <category term="Security" /> <summary>I have spent more than twenty years building and operating production software systems. Currently, I work as a software and platform architect, designing and delivering distributed systems for a large technology company. Over my career, I have observed a…</summary> </entry> <entry><title>Shift-Left Meets Shift-Node: Moving Container Supply Chain Verification to Runtime via NRI</title><link href="https://purushotham.me/posts/shift-left-meets-shift-node-moving-container-supply-chain-verification-to-runtime-via-nri/" rel="alternate" type="text/html" title="Shift-Left Meets Shift-Node: Moving Container Supply Chain Verification to Runtime via NRI" /><published>2026-07-31T05:30:51+01:00</published> <updated>2026-07-31T05:30:51+01:00</updated> <id>https://purushotham.me/posts/shift-left-meets-shift-node-moving-container-supply-chain-verification-to-runtime-via-nri/</id> <content type="text/html" src="https://purushotham.me/posts/shift-left-meets-shift-node-moving-container-supply-chain-verification-to-runtime-via-nri/" /> <author> <name>Puru Yanamala</name> </author> <category term="Security" /> <category term="Kubernetes" /> <summary>We have spent the last half-decade obsessing over "shifting left." We scan our Git repositories, run container image scanners in CI/CD pipelines, sign our artifacts with Cosign, and deploy admission controllers like Kyverno or OPA Gatekeeper to block…</summary> </entry> <entry><title>Beyond Fixed Node Allocation: Composable Infrastructure and Dynamic Resource Allocation for AI Agent Fleets</title><link href="https://purushotham.me/posts/beyond-fixed-node-allocation-composable-infrastructure-and-dynamic-resource-allocation-for-ai-agent-fleets/" rel="alternate" type="text/html" title="Beyond Fixed Node Allocation: Composable Infrastructure and Dynamic Resource Allocation for AI Agent Fleets" /><published>2026-07-30T19:19:04+01:00</published> <updated>2026-07-30T19:19:04+01:00</updated> <id>https://purushotham.me/posts/beyond-fixed-node-allocation-composable-infrastructure-and-dynamic-resource-allocation-for-ai-agent-fleets/</id> <content type="text/html" src="https://purushotham.me/posts/beyond-fixed-node-allocation-composable-infrastructure-and-dynamic-resource-allocation-for-ai-agent-fleets/" /> <author> <name>Puru Yanamala</name> </author> <category term="Kubernetes" /> <category term="AI Infrastructure" /> <summary>When scaling AI agent orchestration pipelines across production Kubernetes clusters, platform engineering teams almost always hit an operational wall. It rarely starts with container runtime panics or scheduler crashes. Instead, it manifests as severe…</summary> </entry> <entry><title>Tightening Kubernetes Workload Boundaries: Balancing Lower PID Caps, PodGroup Preemption, and Batch Density</title><link href="https://purushotham.me/posts/tightening-kubernetes-workload-boundaries-balancing-lower-pid-caps-podgroup-preemption-and-batch-density/" rel="alternate" type="text/html" title="Tightening Kubernetes Workload Boundaries: Balancing Lower PID Caps, PodGroup Preemption, and Batch Density" /><published>2026-07-30T16:43:11+01:00</published> <updated>2026-07-30T16:43:11+01:00</updated> <id>https://purushotham.me/posts/tightening-kubernetes-workload-boundaries-balancing-lower-pid-caps-podgroup-preemption-and-batch-density/</id> <content type="text/html" src="https://purushotham.me/posts/tightening-kubernetes-workload-boundaries-balancing-lower-pid-caps-podgroup-preemption-and-batch-density/" /> <author> <name>Puru Yanamala</name> </author> <category term="Kubernetes" /> <category term="DevOps" /> <summary>I have spent more than twenty years building and operating production software systems. In my current role, I work as a software and platform architect, designing and delivering distributed systems for a large technology company. Having worked with…</summary> </entry> <entry><title>Fixing the Scale-to-Zero Trap: Health Check Polling vs. Multi-Tenant Runtime Isolation</title><link href="https://purushotham.me/posts/fixing-the-scale-to-zero-trap-health-check-polling-vs-multi-tenant-runtime-isolation/" rel="alternate" type="text/html" title="Fixing the Scale-to-Zero Trap: Health Check Polling vs. Multi-Tenant Runtime Isolation" /><published>2026-07-29T20:06:35+01:00</published> <updated>2026-07-29T20:06:35+01:00</updated> <id>https://purushotham.me/posts/fixing-the-scale-to-zero-trap-health-check-polling-vs-multi-tenant-runtime-isolation/</id> <content type="text/html" src="https://purushotham.me/posts/fixing-the-scale-to-zero-trap-health-check-polling-vs-multi-tenant-runtime-isolation/" /> <author> <name>Puru Yanamala</name> </author> <category term="Kubernetes" /> <category term="Platform Engineering" /> <summary>I have spent more than twenty years building and operating production software systems. In my current role as a software and platform architect, I design and deliver distributed systems for a large technology company. Across distributed engineering teams…</summary> </entry> </feed>
