<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on PercussiveRepair.net</title><link>https://percussiverepair.net/posts/</link><description>Recent content in Posts on PercussiveRepair.net</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 13 Oct 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://percussiverepair.net/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Seven Years at Okta, Briefly</title><link>https://percussiverepair.net/posts/2025-10-13-seven-years-at-okta-briefly/</link><pubDate>Mon, 13 Oct 2025 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2025-10-13-seven-years-at-okta-briefly/</guid><description>&lt;p&gt;After a little over seven years, I left Okta last month. Here&amp;rsquo;s a quick look back.&lt;/p&gt;&#10;&lt;p&gt;I joined in July 2018 to run the EMEA Technical Operations SRE team. For most of that time my teams were keeping Okta&amp;rsquo;s identity platform running for hundreds of thousands of organisations and millions of users, with billions of authentications a month going through it.&lt;/p&gt;</description></item><item><title>Building a Platform We Weren't Allowed to Run</title><link>https://percussiverepair.net/posts/2023-11-20-building-a-platform-we-couldnt-run/</link><pubDate>Mon, 20 Nov 2023 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2023-11-20-building-a-platform-we-couldnt-run/</guid><description>&lt;p&gt;Over the last few years a good chunk of my time at Okta has gone on compliance: PCI, GDPR and HIPAA, and then the US government programmes, FedRAMP Moderate, FedRAMP High and DoD IL4.&lt;/p&gt;&#10;&lt;p&gt;The lower levels are mostly about showing you do what you say you do. The higher levels also restrict who is allowed to do it. For the most sensitive environments, anyone operating the platform had to be a US citizen working on US soil.&lt;/p&gt;</description></item><item><title>Wearing Two Hats: SRE and Product</title><link>https://percussiverepair.net/posts/2021-06-14-wearing-two-hats/</link><pubDate>Mon, 14 Jun 2021 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2021-06-14-wearing-two-hats/</guid><description>&lt;p&gt;In mid 2020 I became a Product Owner at Okta, and earlier this year a Product Architect. I&amp;rsquo;ve been doing both while still managing SRE teams, so I decide what we should build and then my teams run it afterwards.&lt;/p&gt;</description></item><item><title>Recording for Posterity</title><link>https://percussiverepair.net/posts/2020-04-27-recording-for-posterity/</link><pubDate>Mon, 27 Apr 2020 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2020-04-27-recording-for-posterity/</guid><description>&lt;p&gt;This is a simple mantra I’ve used in many teams I worked in or led over the years:&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Prefer Services to Software&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Make services that are robust and functional.&lt;br&gt;&#10;Buy services that other folk do better than we could for the time and/or money.&lt;/p&gt;</description></item><item><title>AWS Account Creation Automation &amp; Security</title><link>https://percussiverepair.net/posts/2018-09-14-aws-account-creation/</link><pubDate>Fri, 14 Sep 2018 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2018-09-14-aws-account-creation/</guid><description>&lt;p&gt;It’s been a busy couple of years so, as is usual, my blog was left to languish. That doesn’t mean I’ve not done interesting and challenging things in the interim. Things worth blogging about. So here we are. This is an expansion on one of the topics I briefly covered at my &lt;a href="https://www.youtube.com/watch?v=AceaPKCpjeQ"&gt;AWS London Summit talk&lt;/a&gt; earlier this year.&lt;/p&gt;</description></item><item><title>Traildash on ECS</title><link>https://percussiverepair.net/posts/2016-03-11-traildash-on-ecs/</link><pubDate>Fri, 11 Mar 2016 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2016-03-11-traildash-on-ecs/</guid><description>&lt;p&gt;I’ve recently had some issues where I’ve had to investigate the AWS API usage on one of our accounts. Enabling Cloudtrail is a start but all it does is shove a load of gzipped json files into an S3 bucket which is no use if you actually want to make use of the data.&lt;/p&gt;</description></item><item><title>How to be a Good Tech Lead</title><link>https://percussiverepair.net/posts/2015-10-24-how-to-be-a-good-tech-lead/</link><pubDate>Sat, 24 Oct 2015 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2015-10-24-how-to-be-a-good-tech-lead/</guid><description>&lt;p&gt;Transitioning from engineering to management/leadership is tough unless you understand the sacrifices you have to make. Rarely can you keep your hands in the guts of the engineering you used to know intimately. And you’ll have to do more paperwork. That said it can be just as rewarding to see your team grow in expertise and experience because of your leadership.&lt;/p&gt;</description></item><item><title>The Operations Documentation Problem</title><link>https://percussiverepair.net/posts/2014-09-11-the-operations-documentation-problem/</link><pubDate>Thu, 11 Sep 2014 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2014-09-11-the-operations-documentation-problem/</guid><description>&lt;p&gt;Documentation tends to be a polarising, all or nothing, topic in the Operations teams I have been a part of. Everyone agrees on its fundamental importance but no one seems to like to spend time or effort producing it. Especially if they see no immediate benefit in it for themselves.&lt;/p&gt;</description></item><item><title>Further Notes on SaltStack Monitoring</title><link>https://percussiverepair.net/posts/2014-05-03-further-notes-on-saltstack-monitoring/</link><pubDate>Sat, 03 May 2014 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2014-05-03-further-notes-on-saltstack-monitoring/</guid><description>&lt;p&gt;A few weeks ago I started looking at SaltStack, my current config management package choice, as the central component of an open source componentised monitoring package.&lt;/p&gt;&#10;&lt;p&gt;This is now up and running in a rudimentary fashion. I have a scheduler state that is applied to several machines in my estate which sends system monitoring data to both a MySQL instance for storage and reuse and to a Graphite endpoint for display.&lt;/p&gt;</description></item><item><title>Elasticsearch on AWS or How I learned to stop worrying and love the lucene index</title><link>https://percussiverepair.net/posts/2014-03-18-elasticsearch-on-aws-or-how-i-learned-to-stop-worrying-and-love-the-lucene-index/</link><pubDate>Tue, 18 Mar 2014 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2014-03-18-elasticsearch-on-aws-or-how-i-learned-to-stop-worrying-and-love-the-lucene-index/</guid><description>&lt;p&gt;Ahh, Elasticsearch, the cause of, and solution to, all of lifes problems.&lt;/p&gt;&#10;&lt;p&gt;I run a Logstash/Elasticsearch/Kibana cluster on EC2 as a application/system log aggregator for the web service I’m supporting. And it’s not been plain sailing. I have a limited AWS budget so I am somewhat restricted in the instances I can fire up. No cc2.8xlarges for me. So I was stuck with two m1.larges. And they struggled.&lt;/p&gt;</description></item><item><title>Saltstack Monitoring</title><link>https://percussiverepair.net/posts/2014-02-15-saltstack-monitoring/</link><pubDate>Sat, 15 Feb 2014 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2014-02-15-saltstack-monitoring/</guid><description>&lt;p&gt;I &lt;a href="https://www.youtube.com/watch?v=IWvZgdLyfaI&amp;amp;noredirect=1"&gt;spoke recently&lt;/a&gt; at the Februrary London DevOps meetup about my adventures with solo DevOps and the &lt;a href="https://github.com/saltstack"&gt;SaltStack&lt;/a&gt; config management system ( &lt;a href="https://docs.google.com/presentation/d/1DPbapT2kxd7UrHvbLr_Eo02Y-F8OSB6vSQq8ArSOI8o/edit?usp=sharing"&gt;Slides&lt;/a&gt; )&lt;/p&gt;&#10;&lt;p&gt;One of the other talks at the meetup, &lt;a href="https://www.youtube.com/watch?v=Q9BagdHGopg"&gt;Stop Using Nagios&lt;/a&gt; by Andy Sykes from Forward3D (&lt;a href="https://twitter.com/supersheep"&gt;@supersheep&lt;/a&gt;) got me thinking about using &lt;a href="https://github.com/saltstack"&gt;Salt&lt;/a&gt; as the core component of a distributed monitoring system. I believe it fits the mould very well:&lt;/p&gt;</description></item><item><title>CloudWatchr for AWS Instances</title><link>https://percussiverepair.net/posts/2014-01-13-cloudwatchr-for-aws-instances/</link><pubDate>Mon, 13 Jan 2014 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2014-01-13-cloudwatchr-for-aws-instances/</guid><description>&lt;p&gt;For some time I’ve been using &lt;a href="https://aws.amazon.com/cloudwatch/"&gt;Cloudwatch&lt;/a&gt; as a supplement to my other graphing and monitoring packages, but I finally got tired of the poor UI and lack of customisation. I had seen and tested some other GitHub releases that seemed like they may do the trick to allow me to run my own CW graphs but none had the features I required. So i wrote my own.&lt;/p&gt;</description></item></channel></rss>