<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Ricardo Saad</title><description>Platform engineering, infrastructure decisions, and the lessons between them.</description><link>https://ricardosaad.com/</link><item><title>Access is a product, not a firewall rule</title><link>https://ricardosaad.com/blog/access-is-a-product-not-a-firewall-rule/</link><guid isPermaLink="true">https://ricardosaad.com/blog/access-is-a-product-not-a-firewall-rule/</guid><description>Why the right private-access decision can be to stop maintaining the mechanism and start designing the experience.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Platform engineering</category><category>Networking</category><category>Product design</category><category>Operations</category></item><item><title>A stopping condition is part of the design</title><link>https://ricardosaad.com/blog/a-stopping-condition-is-part-of-the-design/</link><guid isPermaLink="true">https://ricardosaad.com/blog/a-stopping-condition-is-part-of-the-design/</guid><description>A credible delivery plan says what blocks promotion, what evidence would unblock it, and where more effort stops changing the decision.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Engineering leadership</category><category>Delivery</category><category>Risk</category><category>Evidence</category></item><item><title>AI should explain the evidence, not become the evidence</title><link>https://ricardosaad.com/blog/ai-should-explain-the-evidence-not-become-the-evidence/</link><guid isPermaLink="true">https://ricardosaad.com/blog/ai-should-explain-the-evidence-not-become-the-evidence/</guid><description>In a cloud audit, deterministic collectors and rules should establish findings while AI helps people understand what those records mean.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Artificial intelligence</category><category>Product engineering</category><category>Cloud security</category><category>Evidence</category></item><item><title>Recovery is part of the system</title><link>https://ricardosaad.com/blog/recovery-is-part-of-the-system/</link><guid isPermaLink="true">https://ricardosaad.com/blog/recovery-is-part-of-the-system/</guid><description>A production rebuild exposed why teardown, dependency ordering, bootstrap safety, and content restoration belong in the design—not in an emergency notebook.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Incident response</category><category>AWS</category><category>Infrastructure as code</category><category>Operations</category></item><item><title>The plan you reviewed should be the plan you apply</title><link>https://ricardosaad.com/blog/the-plan-you-reviewed-should-be-the-plan-you-apply/</link><guid isPermaLink="true">https://ricardosaad.com/blog/the-plan-you-reviewed-should-be-the-plan-you-apply/</guid><description>Infrastructure approval is meaningful only when reviewable configuration, source, and the applied plan remain cryptographically bound.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Infrastructure as code</category><category>Governance</category><category>Delivery</category></item><item><title>Two schedulers are not high availability</title><link>https://ricardosaad.com/blog/two-schedulers-are-not-high-availability/</link><guid isPermaLink="true">https://ricardosaad.com/blog/two-schedulers-are-not-high-availability/</guid><description>When a cloud control plane places work onto Proxmox capacity, allowing both layers to schedule the same guest creates conflicting authority—not resilience.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Platform engineering</category><category>Edge</category><category>Scheduling</category><category>Reliability</category></item><item><title>Your CRM should know the customer, not run the product</title><link>https://ricardosaad.com/blog/your-crm-should-know-the-customer-not-run-the-product/</link><guid isPermaLink="true">https://ricardosaad.com/blog/your-crm-should-know-the-customer-not-run-the-product/</guid><description>Commercial context belongs in the CRM. Questionnaire state, report generation, delivery, and recovery belong with the product that promises them.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Product architecture</category><category>CRM</category><category>Reliability</category><category>Data governance</category></item><item><title>The gateway needed its own boundary</title><link>https://ricardosaad.com/blog/the-gateway-needed-its-own-boundary/</link><guid isPermaLink="true">https://ricardosaad.com/blog/the-gateway-needed-its-own-boundary/</guid><description>A private release repository separates the gateway appliance from the public infrastructure that surrounds it.</description><pubDate>Sat, 01 Aug 2026 16:50:00 GMT</pubDate><category>Infrastructure</category><category>Networking</category><category>Security</category><category>Release engineering</category></item><item><title>The pipeline was the product</title><link>https://ricardosaad.com/blog/the-pipeline-was-the-product/</link><guid isPermaLink="true">https://ricardosaad.com/blog/the-pipeline-was-the-product/</guid><description>What an impossible forecasting problem taught me about evidence, operational boundaries, and knowing when to stop.</description><pubDate>Sat, 01 Aug 2026 08:30:00 GMT</pubDate><category>MLOps</category><category>Machine learning</category><category>AWS</category><category>Infrastructure as code</category><category>Operations</category></item><item><title>An architecture should be allowed to change</title><link>https://ricardosaad.com/blog/an-architecture-should-be-allowed-to-change/</link><guid isPermaLink="true">https://ricardosaad.com/blog/an-architecture-should-be-allowed-to-change/</guid><description>Superseded decisions are evidence of learning, not defects to hide behind a tidy final diagram.</description><pubDate>Thu, 30 Jul 2026 13:00:00 GMT</pubDate><category>Architecture</category><category>Cost</category></item><item><title>Build the gateway to be replaced</title><link>https://ricardosaad.com/blog/build-the-gateway-to-be-replaced/</link><guid isPermaLink="true">https://ricardosaad.com/blog/build-the-gateway-to-be-replaced/</guid><description>A small network gateway becomes safer when recovery means reconciliation, not careful repair.</description><pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate><category>Networking</category><category>Reliability</category></item><item><title>Secrets should live with their failure domain</title><link>https://ricardosaad.com/blog/secrets-should-live-with-their-failure-domain/</link><guid isPermaLink="true">https://ricardosaad.com/blog/secrets-should-live-with-their-failure-domain/</guid><description>Centralizing every secret can simplify the diagram while making recovery, authority, and outages harder to reason about.</description><pubDate>Thu, 30 Jul 2026 11:00:00 GMT</pubDate><category>Security</category><category>Operations</category></item><item><title>Private is not a login state</title><link>https://ricardosaad.com/blog/private-is-not-a-login-state/</link><guid isPermaLink="true">https://ricardosaad.com/blog/private-is-not-a-login-state/</guid><description>Authentication answers who a caller is. Network structure should still decide which doors exist.</description><pubDate>Thu, 30 Jul 2026 10:00:00 GMT</pubDate><category>Networking</category><category>Security</category></item><item><title>An approval email should not approve anything</title><link>https://ricardosaad.com/blog/an-approval-email-should-not-approve-anything/</link><guid isPermaLink="true">https://ricardosaad.com/blog/an-approval-email-should-not-approve-anything/</guid><description>Notifications can carry context. Authority should remain behind the boundary where the decision belongs.</description><pubDate>Thu, 30 Jul 2026 09:00:00 GMT</pubDate><category>Identity</category><category>Security</category></item><item><title>Public code, private inventory</title><link>https://ricardosaad.com/blog/public-code-private-inventory/</link><guid isPermaLink="true">https://ricardosaad.com/blog/public-code-private-inventory/</guid><description>Open infrastructure is most useful when reusable mechanisms are separated from the identities and facts of one real deployment.</description><pubDate>Thu, 30 Jul 2026 08:00:00 GMT</pubDate><category>Open source</category><category>Architecture</category></item><item><title>Scale to zero without giving up control</title><link>https://ricardosaad.com/blog/scale-to-zero-without-giving-up-control/</link><guid isPermaLink="true">https://ricardosaad.com/blog/scale-to-zero-without-giving-up-control/</guid><description>An on-demand server still needs durable identity, narrow access, and one authority for its lifecycle.</description><pubDate>Thu, 30 Jul 2026 07:00:00 GMT</pubDate><category>Cloud</category><category>Operations</category></item><item><title>Terraform builds the stage, not the play</title><link>https://ricardosaad.com/blog/terraform-builds-the-stage-not-the-play/</link><guid isPermaLink="true">https://ricardosaad.com/blog/terraform-builds-the-stage-not-the-play/</guid><description>Infrastructure code should define durable boundaries without becoming the runtime operator for every changing thing.</description><pubDate>Thu, 30 Jul 2026 06:00:00 GMT</pubDate><category>Infrastructure as code</category><category>Control planes</category></item><item><title>The safest form can be no form yet</title><link>https://ricardosaad.com/blog/the-safest-form-can-be-no-form-yet/</link><guid isPermaLink="true">https://ricardosaad.com/blog/the-safest-form-can-be-no-form-yet/</guid><description>Deferring a small public feature is an architecture decision when its abuse, privacy, and authority costs are not small.</description><pubDate>Thu, 30 Jul 2026 05:00:00 GMT</pubDate><category>Product engineering</category><category>Security</category></item><item><title>One interface, three trust levels</title><link>https://ricardosaad.com/blog/one-interface-three-trust-levels/</link><guid isPermaLink="true">https://ricardosaad.com/blog/one-interface-three-trust-levels/</guid><description>A shared frontend does not require a shared trust boundary. The useful separation happens in projections, paths, and server-side capability checks.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Architecture</category><category>Authorization</category></item><item><title>The cloud decides; the edge executes</title><link>https://ricardosaad.com/blog/the-cloud-decides-the-edge-executes/</link><guid isPermaLink="true">https://ricardosaad.com/blog/the-cloud-decides-the-edge-executes/</guid><description>How to keep storage-adjacent services at home without quietly creating a second control plane.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate><category>Platform engineering</category><category>Edge</category></item><item><title>Failure should be visible, not invasive</title><link>https://ricardosaad.com/blog/failure-should-be-visible-not-invasive/</link><guid isPermaLink="true">https://ricardosaad.com/blog/failure-should-be-visible-not-invasive/</guid><description>A public status view should prove the system is alive without turning operational detail into an attack surface.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>Observability</category><category>Security</category></item></channel></rss>