Skip to main content
NewThe No-Backend Backend: Neon Data API, RLS and 27 Attacks

Learn DevOps by doing,
not just reading.

733+ articles, guides, and hands-on learning tools for engineers who prefer a terminal over a slide deck.

Join 5,000+ DevOps engineers learning every week

kubectl --watch
$
devops-daily --stats

// featured

Interactive Simulators

Browse all simulators

// categories

Popular Categories

Explore our content by topic

// exercises

Hands-On Exercises

Practice real-world DevOps scenarios with step-by-step guidance

View all exercises

// quizzes

Test Your Knowledge

Short interactive quizzes across Docker, Kubernetes, Terraform, networking, and more

// posts

Latest Posts

Stay up to date with the latest DevOps content

DevOps

The No-Backend Backend: Neon Data API, RLS and 27 Attacks

A team task board with no server code: static React, Neon Auth, and the Neon Data API with row-level security as the only guard. A signed-in attacker tried 27 ways in. What held, the four mistakes that would have let her through, and the 15-minute gap.

|14 min read
CI/CD

CI Passed 6 of 6 Migrations. A Neon Branch of Production Passed 1

How to test Postgres migrations before production: branch production on Neon in seconds, run each migration while an app keeps reading and writing, and gate on errors, failed queries, lock stalls and lost rows. The six migrations that passed on our fixture database failed five times on the branch.

|17 min read
DevOps

Your Semantic Cache Answers the Question Next Door

We put a semantic cache in front of an ops assistant on DigitalOcean Serverless Inference and replayed 288 hand-labelled questions through six embedding models. At the threshold that cut the bill by about 30 percent, about one hit in three was the answer to a different question. Someone asking how to undo a pushed commit got the instructions for an unpushed one.

|14 min read
Networking

Cloudflare Freed 100 TB of RAM From Its Hash Rings. Your Proxy May Have the Opposite Problem

Cloudflare got back 100 TB of RAM partly by cutting 90% of the points on its consistent hash rings. We measured the other end of the same curve: a million keys through nginx and HAProxy to 100 backends, and Envoy rebuilt from its source. The busiest server ranged from 1.05x to 2x its fair share, and the points per server explained most of it.

|16 min read
DevOps

We Hid 96 Instructions in the Logs an Ops Agent Reads. Here Is What Stopped Them.

An on-call agent reads logs and tickets that other people write. We planted 96 prompt injections in that text and measured six defences on DigitalOcean Serverless Inference. One paragraph in the system prompt cut the attack rate from 35 percent to 4. Delimiters on their own did nothing we could measure. A check outside the model stopped every forbidden action, and still missed the secrets the agent wrote into its own reports.

|16 min read
Networking

We Put Localhost on the Internet and Watched Who Turned Up

A Cloudflare quick tunnel gives you a public URL for a port on your laptop in one command and no account. We ran one in front of a server that logs everything and answers nothing, to find out how long it takes the internet to find you, and what the thing actually costs.

|10 min read

// guides

Latest Guides

Step-by-step tutorials to boost your DevOps skills

// tools

DevOps Tools and Calculators

Free, browser-only utilities. CIDR, JWT, base64, UUID, cron, K8s sizing, YAML. No sign-up, no server.

// about

DevOps Daily is a free, independent education platform for engineers who want to learn by running things, not by reading pitch decks. Kubernetes, Docker, Terraform, CI/CD, observability, and security, through hands-on simulators, quizzes, exercises, and a weekly newsletter.

Free
$0
forever
Tools
59
interactive
Subscribers
5,000+
engineers
Cadence
Weekly
no spam
devops-daily --subscribe
$ echo "Weekly DevOps digest. No spam. Unsubscribe anytime."
Weekly DevOps digest. No spam. Unsubscribe anytime.
$ subscribe --email
$

5,000+ engineers subscribed