<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[BUILD WHAT'S NEXT: Builds]]></title><description><![CDATA[Practical cloud labs, architecture notes, and project case studies from the work of building real systems
One useful skill at a time.]]></description><link>https://www.rateb.cc/s/builds</link><image><url>https://substackcdn.com/image/fetch/$s_!J2zW!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943b7c65-349a-4ece-909f-7616adef45fe_1280x1280.png</url><title>BUILD WHAT&apos;S NEXT: Builds</title><link>https://www.rateb.cc/s/builds</link></image><generator>Substack</generator><lastBuildDate>Sun, 20 Sep 2026 20:28:05 GMT</lastBuildDate><atom:link href="https://www.rateb.cc/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Rateb Lab]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[rateb@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[rateb@substack.com]]></itunes:email><itunes:name><![CDATA[Rateb Slik]]></itunes:name></itunes:owner><itunes:author><![CDATA[Rateb Slik]]></itunes:author><googleplay:owner><![CDATA[rateb@substack.com]]></googleplay:owner><googleplay:email><![CDATA[rateb@substack.com]]></googleplay:email><googleplay:author><![CDATA[Rateb Slik]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[CloudTrail Shows Who Changed AWS, Not Whether Your App Works]]></title><description><![CDATA[Match the question to the evidence layer: CloudTrail for who acted, Config for configuration history, a host check for the app.]]></description><link>https://www.rateb.cc/p/cloudtrail-is-not-application-proof</link><guid isPermaLink="false">https://www.rateb.cc/p/cloudtrail-is-not-application-proof</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Fri, 18 Sep 2026 07:02:57 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dc40b016-7ad8-494f-862d-4c82b751b439_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D6gb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D6gb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!D6gb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!D6gb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!D6gb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D6gb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D6gb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!D6gb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!D6gb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!D6gb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85ffc332-9502-4c48-8ff6-833116769f80_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Better cloud decisions begin when each claim is matched to the evidence layer that can actually support it.</em></p><p>CloudTrail is one of those AWS services that becomes more useful when you stop asking it to answer every question.</p><p>It can record activity in your AWS account. Actions taken in the console, CLI, SDKs, and APIs can appear as events. That makes CloudTrail central to operational auditing, governance, and security investigation.</p><p>But an audit trail is not the same thing as application proof.</p><p>If a CloudTrail event shows an API request to start an EC2 instance, you have meaningful evidence that the recorded AWS API activity occurred. You can inspect the identity, the event name, the time, the source details, and the affected resource context.</p><p>What you do not have is proof that your application became healthy, that Apache served a page, that a database connection succeeded, or that a user completed the outcome you care about.</p><p>That is not a weakness in CloudTrail. It is an evidence boundary.</p><p>The cloud feels confusing when we use one successful screen as a certificate for the entire system. An EC2 instance can be running while SSH still times out. A security-group rule can exist while the subnet is associated with a route table that cannot reach the intended destination. A CloudTrail event can confirm an API action while the guest operating system, application process, or downstream dependency fails somewhere else.</p><p>I now try to state the claim before I choose the service.</p><p>"Who changed this security group?" That is an activity and attribution question. CloudTrail is a sensible place to start.</p><p>"What was the configuration of this resource before it changed?" That is a configuration-history question. AWS Config is closer to the job.</p><p>"Did a network flow pass through this interface?" That is a VPC Flow Logs question, with its own scope and record limitations.</p><p>"Is the web service responding locally?" That belongs on the host, with a local listener or HTTP check.</p><p>"Can an external user reach the application?" That needs an end-to-end request from the relevant external position, interpreted alongside the network path and service evidence.</p><p>This way of thinking prevents a lot of false confidence.</p><p>CloudTrail is especially valuable after you have narrowed the question. If a public SSH rule appeared on a security group, you can investigate the recorded API action and identity. If a role policy changed, you can use activity evidence to understand the request history. If a resource was deleted, an event trail can help reconstruct what happened at the AWS control plane.</p><p>But intent, impact, and application outcome still need their own evidence.</p><p>An API call can be legitimate and still cause an outage. A recorded action can fail. A successful action can create a resource that is misconfigured for the next dependency. A person can be authorized to make a change that should still be reviewed.</p><p>This is why cloud security is not only about turning logging on. It is about connecting an event to a claim, then connecting the claim to the next verification step.</p><p>For a learner, the useful habit is small. When you see a log, event, alert, or dashboard status, finish this sentence:</p><p>"This proves that _______. It does not prove that _______."</p><p>That second blank is where better engineering starts. It keeps the next test honest. It prevents you from announcing a fix before the user-facing system is actually working. And it turns CloudTrail from a passive archive into part of a disciplined investigation.</p><h2>Try this in a sandbox</h2><p>Choose one scenario: a security-group rule changed, an EC2 instance was launched, or a user cannot reach an app. Write the claim, the first evidence source, what it proves, and the separate test needed before you can claim user-facing success.</p><h2>Continue the sequence</h2><p>Start by tracing one request or one security claim end to end. The goal is not to collect more AWS screens. It is to learn what each one can prove before you change the system.</p>]]></content:encoded></item><item><title><![CDATA[In AWS, Classify the Failure Before You Change Anything]]></title><description><![CDATA[An SSH timeout points at the network path, a public-key denial at credentials, a local curl at the host, an alarm at metrics. Classify first.]]></description><link>https://www.rateb.cc/p/classify-the-failure-before-you-change-anything</link><guid isPermaLink="false">https://www.rateb.cc/p/classify-the-failure-before-you-change-anything</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Wed, 16 Sep 2026 07:02:39 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/64cda4a8-bc2e-438f-ae62-793ddfa629af_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lFEm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lFEm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lFEm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lFEm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lFEm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lFEm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lFEm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lFEm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lFEm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lFEm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86323af6-d7dc-4503-83ca-b123cfe504ae_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>A timeout, a public-key denial, a local response, and an alarm are different evidence. Start there.</em></p><p>The fastest way to lose an hour in AWS is to change five things because one thing failed.</p><p>Open the security group. Edit the route table. Restart the instance. Download a new key. Add a broader rule. Refresh the browser. Then wait, hoping one of the changes made the problem disappear.</p><p>I understand the instinct. A timeout feels like the system is refusing to explain itself.</p><p>But the error is already evidence. The first job is not to fix it. The first job is to classify what kind of failure you actually have.</p><p>In a VPC and EC2 lab, two messages can look equally frustrating but send you in opposite directions.</p><p>An SSH timeout means the session did not complete. That points first toward the path: correct public address, Internet Gateway, subnet route-table association, security-group and network ACL rules, host availability, and the possibility that the instance is not reachable from where you are connecting.</p><p><code>Permission denied (publickey)</code> means something different. The SSH service answered enough for authentication to begin. The first branch is now the chosen username, the private-key file, the EC2 key pair, and host authorization. It does not prove every network detail is perfect. It does prove that replacing a route table is a strange first move.</p><p>The same pattern appears when testing a web server.</p><p><code>curl -I local HTTP</code> on an EC2 instance can show that Apache is responding locally. That is useful evidence about the process and local listener. It does not prove that a browser on the public internet can reach it. External reachability still depends on the public address, the route through the Internet Gateway, the subnet association, network controls, and the service being reachable on the right interface and port.</p><p>A CloudWatch alarm is another category. It tells you a metric crossed an evaluation condition. It does not explain root cause. A CPU alarm might be the beginning of an investigation, not the end of one.</p><p>I have started using a small habit before I touch a setting: write the observed symptom as a sentence that does not contain a fix.</p><p>"SSH times out."</p><p>"SSH reaches authentication but rejects the key."</p><p>"The service responds locally but not from the browser."</p><p>"The alarm entered ALARM state."</p><p>That sentence determines the first evidence layer.</p><p>For a timeout, trace the request path in order. Is the address the one you expect? Is the subnet associated with the intended route table? Does the route point to the intended next hop? Does the path have the public or private addressing it needs? Are the relevant policy layers allowing the protocol and return traffic? Is the host up?</p><p>For public-key denial, keep the network configuration still until you have checked the identity path. Confirm the selected key pair, the file permissions on the local key, the AMI-appropriate username, and the matching authorized key on the host if you have another safe access path.</p><p>For a local-only web response, test outward one layer at a time. Local service. Listener. Instance address. Route. Security group. Network ACL. External request. Each test should answer one question.</p><p>This is not only a cloud habit. It is a support habit, a systems habit, and a career habit. Good troubleshooting is visible reasoning under uncertainty. You are not trying to look fast by changing things. You are trying to preserve the signal long enough to learn what failed.</p><p>The smallest proven fix is usually better than the widest possible fix. If port 80 is the question, opening every port does not make you efficient. It makes the system harder to understand and less safe.</p><p>The goal is not to memorize an enormous decision tree. It is to let the failure choose the first branch.</p><p>Before you change an AWS setting, ask one quiet question: what does this exact symptom prove, and what does it leave open?</p><h2>Try this in a sandbox</h2><p>In a sandbox, deliberately compare three outcomes: an unreachable address, a rejected SSH key, and a local-only HTTP response. For each, write the first two checks you would make and one tempting change you would avoid.</p><h2>Continue the sequence</h2><p>Start by tracing one request or one security claim end to end. The goal is not to collect more AWS screens. It is to learn what each one can prove before you change the system.</p>]]></content:encoded></item><item><title><![CDATA[The Work Is Not the Prompt]]></title><description><![CDATA[A useful AI workflow is not a clever prompt. It is a bounded responsibility system: a clear outcome, the right context, a narrow authority lane, and a review loop that earns trust.]]></description><link>https://www.rateb.cc/p/the-work-is-not-the-prompt</link><guid isPermaLink="false">https://www.rateb.cc/p/the-work-is-not-the-prompt</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Sun, 13 Sep 2026 08:57:45 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/66e59fdf-a927-46f3-8656-a659092a1d5d_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HI3O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HI3O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HI3O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HI3O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HI3O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HI3O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HI3O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HI3O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HI3O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HI3O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5038aa9d-d281-4e3d-8c9c-c89c10773931_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I keep noticing the same failure in AI conversations.</p><p>Someone sees a new agent tool, opens a blank workspace, and asks it to "run the business," "manage my inbox," or "find me opportunities."</p><p>Then the result is vague, strange, or quietly wrong.</p><p>The tool gets blamed. The prompt gets rewritten. Another tool is bought.</p><p>But the real problem usually arrived before the model saw a single word.</p><p>There was no job.</p><p>There was only a wish.</p><p>That distinction matters because the most valuable AI skill is not prompt writing. It is delegation design.</p><p>A good prompt can make a model sound useful for one moment. A useful workflow has to do more. It needs to know what it is trying to achieve, what information it can use, what it is allowed to change, what good work looks like, and when it should stop and ask for help.</p><p>That is not magic. It is management.</p><h2>Start with work that deserves automation</h2><p>Not every annoying task needs an agent.</p><p>That is the first thing worth saying, because AI makes every workflow look automatable from a distance.</p><p>A task is a good candidate when three things are true.</p><p>First, it happens often enough to matter. If you do it once a quarter, building and maintaining a system may cost more than simply doing the task well.</p><p>Second, the work has rules. Not perfect rules, but enough structure that you can explain how a good decision is made. An inbox triage process can have sender priorities, urgency signals, labels, examples of good replies, and clear escalation criteria. That is different from asking a tool to "handle my relationships" or "make the best business decisions."</p><p>Third, there is a return on time. The point is not to remove every two-minute task. The point is to remove a repeated piece of work that keeps pulling attention away from something more valuable.</p><p>This is a useful filter because it protects you from building automation as identity theater.</p><p>You do not need an agent because agents are the new thing. You need one when a repeated workflow is already real enough to deserve a better system.</p><p>Before building anything, ask:</p><ol><li><p>Does this happen every week?</p></li><li><p>Can I describe the inputs, choices, and desired output?</p></li><li><p>Will the time saved repay the time required to build, test, and maintain it?</p></li></ol><p>If the answer is no, a simple chat, template, checklist, or manual habit may be the better tool.</p><p>That is not falling behind.</p><p>It is good judgment.</p><h2>A chatbot gives an answer. A workflow carries responsibility.</h2><p>The simplest difference is this.</p><p>A chat helps when you are still thinking.</p><p>A workflow helps when you already know enough about the work to hand off part of it.</p><p>With chat, you ask a question, receive a response, and decide what happens next. That can be incredibly valuable. It can turn confusion into a draft, a plan, an explanation, or a first pass.</p><p>But a reliable agentic workflow has a larger job.</p><p>It receives an outcome, gathers the relevant context, takes a bounded action, checks the result, and reports or escalates what needs human judgment.</p><p>The important word is bounded.</p><p>People often describe an AI agent as an employee. I understand the metaphor, but it can make people careless. An employee has judgment, legal responsibility, a relationship with the company, and a lived understanding of consequences. A software workflow has permissions, instructions, tools, and failure modes.</p><p>Treating those as the same is how people give a system more authority than it has earned.</p><p>A better comparison is a junior operator with a very clear desk.</p><p>The desk contains only what is needed for the current job: the playbook, the approved examples, the necessary tools, the current queue, and a clear rule for when to stop.</p><p>The desk should not contain your entire life.</p><h2>The work is not the prompt</h2><p>A prompt is only one part of the system.</p><p>The real work happens before and after it.</p><p>Before it, you define the outcome.</p><p>Not "manage my inbox."</p><p>Something closer to: "By 9 a.m., every new email is categorized, routine replies are drafted in my voice, and anything urgent or uncertain is flagged for me."</p><p>That is a definition of done. You can see it. You can review it. You can tell when it failed.</p><p>Then you provide the context that makes a good decision possible.</p><p>Who matters most?</p><p>What does urgent mean?</p><p>Which messages should never receive an automatic reply?</p><p>What does your writing actually sound like?</p><p>What examples show the difference between a normal request, a sensitive request, and something that needs escalation?</p><p>This is where many AI workflows become disappointing. People ask for intelligence but provide no operating context.</p><p>Then they are surprised when the system behaves like a stranger.</p><p>Good context is not dumping every document you own into a chat window. That creates noise, stale instructions, and false confidence. Good context is the smallest useful set of rules, examples, current information, and constraints for one job.</p><p>Then comes the part people skip because it is less exciting: authority.</p><p>What can the workflow do without you?</p><p>Can it classify?</p><p>Can it draft?</p><p>Can it archive?</p><p>Can it forward something internally?</p><p>Can it send a message externally?</p><p>Can it touch money, contracts, customer records, or calendar commitments?</p><p>Each answer should be explicit.</p><p>The more consequential the action, the higher the review standard should be.</p><h2>One job. One lane.</h2><p>The temptation is to build one impressive machine that does everything.</p><p>Research the topic. Write the post. Design the visual. Schedule the meeting. Send the invoice. Review the code. Reply to the customer.</p><p>That sounds efficient until something goes wrong and nobody can tell where the error began.</p><p>A better system separates roles.</p><p>One workflow gathers information.</p><p>Another turns approved information into a draft.</p><p>Another checks a draft against a rubric.</p><p>Another prepares a report for a human decision.</p><p>A manager layer can coordinate those pieces, but it should not pretend to be the specialist in every lane.</p><p>This is not only about model quality. It is about keeping context clean.</p><p>When one system tries to remember every policy, every user preference, every tool, every current task, and every exception, it becomes hard to evaluate. It may still produce confident language. That does not mean it is operating with clarity.</p><p>Small lanes make failure visible.</p><p>They also make improvement possible.</p><p>If the research step is weak, improve research. If the draft is off-voice, improve the style guide. If the review misses something, improve the rubric. You do not need to rebuild a giant black box every time one piece behaves badly.</p><h2>Trust is a rollout, not a feeling</h2><p>The hard part is not building the first version.</p><p>The hard part is deciding when to let it act.</p><p>Trust should be earned in stages.</p><p>Start with observation. Let the workflow sort, summarize, or recommend while you compare its output to your own judgment.</p><p>Then let it draft. Correct the drafts and turn recurring corrections into clearer rules or examples.</p><p>Then allow low-risk actions with clear limits. Labeling a routine notification is not the same as sending a client email. Preparing a report is not the same as moving money.</p><p>Only after a workflow has shown reliable behavior should it run on a schedule without direct supervision.</p><p>Even then, the goal is not blind autonomy. The goal is quiet reliability with visible escalation.</p><p>A good system tells you what happened, what it could not decide, and what needs your attention.</p><p>That is how it buys back time without asking you to surrender judgment.</p><h2>The skill that compounds</h2><p>The future of work will contain more AI. That part is obvious.</p><p>The useful question is what kind of person becomes more valuable inside that change.</p><p>I do not think the answer is someone who can produce the longest prompt or collect the most tools.</p><p>It is someone who can look at messy work and make it legible.</p><p>They can identify a real outcome.</p><p>They can separate repeatable work from judgment-heavy work.</p><p>They can write the rules without confusing rules for wisdom.</p><p>They can give a system enough context without drowning it.</p><p>They can build guardrails, review the result, and know when the human should stay in the loop.</p><p>That is not a small skill.</p><p>It is the difference between using AI for occasional help and building a system you can responsibly rely on.</p><p>Before you build your first agent, do not ask what it can do.</p><p>Ask what job you can explain clearly enough to delegate without lying to yourself about the risk.</p><p>That is where the real work begins.</p>]]></content:encoded></item><item><title><![CDATA[The Code Got Smaller. The System Got Bigger.]]></title><description><![CDATA[Why building with agents is becoming less about writing every algorithm and more about designing the primitives, constraints, and judgment around them.]]></description><link>https://www.rateb.cc/p/the-code-got-smaller-the-system-got</link><guid isPermaLink="false">https://www.rateb.cc/p/the-code-got-smaller-the-system-got</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Sat, 12 Sep 2026 08:57:34 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f6c8eabc-6d16-41a4-86c0-0b7d235287ce_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nNQN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nNQN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nNQN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nNQN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nNQN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nNQN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nNQN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nNQN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nNQN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nNQN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7711cea-6691-4b10-8dd4-d178b566f9c6_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I keep thinking about a strange kind of software demo.</p><p>An agent is given a blank voxel world and a few actions. It can place a block. It can place a box, a cylinder, or a sphere. It can inspect the space, choose from a small material list, clear the world, and mirror a shape.</p><p>Then someone asks it for a castle.</p><p>The result is not a single pre-programmed castle. The agent plans towers, walls, arches, windows, and a central keep. Ask again and the shape changes. Ask for a bridge or a pavilion and it starts composing those instead.</p><p>The obvious reaction is that the model is doing something magical.</p><p>The more useful reaction is quieter.</p><p>The application did not contain a castle algorithm. It contained a small world and a small vocabulary for acting inside it.</p><p>That difference matters because it points to a change in what builders need to get good at.</p><h2>The spectacle hides a small interface</h2><p>The visual result looks complicated, but the interface behind it is almost boring.</p><p>A coordinate.</p><p>A material.</p><p>A few higher-level shapes.</p><p>A way to clear the workspace.</p><p>A way to inspect what exists.</p><p>That is the point.</p><p>The agent is not allowed to reach into the renderer and do anything it wants. It is given a set of handles. Those handles are simple enough to understand, but expressive enough to combine.</p><p>A box is more useful than asking an agent to place thousands of blocks one by one. A mirror operation is more useful than making it reinvent symmetry every time. A world-info call is more useful than hoping it guesses the scale of the environment.</p><p>These are not glamorous decisions. They are interface decisions.</p><p>But they determine whether the agent can do useful work or only produce an impressive-looking mess.</p><p>I think this is where a lot of AI coding discussion gets confused. We see the output and talk about prompting. We see the model produce a page, a workflow, or a prototype and assume the skill is learning the right sentence to ask for.</p><p>Prompting matters. But the deeper leverage is often upstream.</p><p>What can the agent observe?</p><p>What actions can it take?</p><p>What does each action mean?</p><p>What is impossible by design?</p><p>What feedback tells it whether it is making progress?</p><p>That is the system.</p><h2>The code did not disappear</h2><p>There is a seductive story about AI coding: soon there will be almost no code, because the model will write everything.</p><p>The voxel demo contains a small truth inside that story. The custom code can get surprisingly small when a capable model supplies planning, pattern recognition, and composition.</p><p>But the engineering does not disappear. It changes location.</p><p>Instead of spending every hour encoding a specific outcome, you spend more time deciding what the environment should make possible.</p><p>You define primitives.</p><p>You choose the level of abstraction.</p><p>You decide which operations are cheap, which are forbidden, and which need confirmation.</p><p>You build a feedback loop so the agent can see the consequences of its actions.</p><p>You decide what a successful result looks like before the system starts improvising.</p><p>This is not less responsibility. In some ways it is more responsibility, because a bad primitive gets reused at scale.</p><p>If the only tool available is a raw database write, the agent will eventually make a raw database mistake. If a tool has broad permissions and a vague description, the model will make the most plausible interpretation it can. If success is never checked, a fluent explanation can hide a broken workflow.</p><p>The shorter codebase can create a larger design surface.</p><h2>Skills are the taste layer</h2><p>The most interesting layer in this kind of system is not the renderer. It is the skill layer.</p><p>A skill can be a plain Markdown file that says how a particular kind of result should feel. A dragon might need a long arcing neck, wings wider than its body, and visible flame. A castle might need slender towers and a clear central keep. A world-building skill might say: inspect the world first, build the big mass first, then add detail, and use higher-level shapes before individual blocks.</p><p>None of this gives the model new intelligence in the abstract sense.</p><p>It gives the model a clearer standard inside a particular environment.</p><p>That is why I think of skills as a taste layer.</p><p>Tools answer: what can I do?</p><p>Skills answer: what does good look like here?</p><p>The distinction matters outside of demos too.</p><p>A content workflow can have tools for reading a source, drafting an essay, creating an image, and preparing a post. Without a skill layer, the system may still produce plenty. It may not know what should be cut, what must be verified, what belongs in private notes, or what would embarrass you in public.</p><p>An infrastructure workflow can have tools for creating resources and reading logs. Without a skill layer, it may not know the order of operations, the rollback rule, or the evidence required before calling a deployment safe.</p><p>Capability is not judgment.</p><p>More tools do not automatically produce better work.</p><h2>The new bottleneck is legibility</h2><p>When people say that code is getting cheap, I do not hear that software is getting easy.</p><p>I hear that legibility is becoming more valuable.</p><p>A good agent environment should be easy for a human to reason about as well as easy for a model to use.</p><p>A person looking at the tool list should understand what each action changes. They should understand the scope of the permissions. They should be able to predict the cost of a loop. They should know where the result will appear and how it will be checked.</p><p>That is not bureaucracy. It is how you keep speed from becoming hidden risk.</p><p>The more capable the model is, the more important this becomes. A weak tool can only do limited damage. A powerful tool with a vague contract can create a large, confident failure very quickly.</p><p>So the goal is not to give an agent every possible action.</p><p>The goal is to give it the smallest set of actions that let it do the job well, then make the consequences visible.</p><p>That is a much more demanding design problem than adding another integration.</p><h2>Five questions before you add another agent tool</h2><p>When I look at an agent workflow now, these are the questions I want to ask before I add more capability.</p><ol><li><p><strong>What is the smallest useful primitive?</strong></p><p>Do not begin with the most powerful endpoint. Begin with the smallest action that is safe, understandable, and composable. A narrow tool is often easier to evaluate and harder to misuse.</p></li><li><p><strong>What does the agent need to observe first?</strong></p><p>Good action depends on state. Give the agent a way to inspect the relevant world before asking it to change that world.</p></li><li><p><strong>What should be a higher-level operation?</strong></p><p>If the same sequence appears again and again, turn it into a stable primitive. Do not make the agent rediscover basic batching, symmetry, validation, or rollback in every run.</p></li><li><p><strong>Where does taste live?</strong></p><p>Write down the preferences, order of operations, quality thresholds, and exclusions that define a good outcome. Keep them close to the tools so they guide work instead of becoming a forgotten document.</p></li><li><p><strong>How will failure become visible?</strong></p><p>A tool call succeeding is not the same as the task succeeding. Decide what evidence the system needs before it reports completion.</p></li></ol><p>These questions sound less exciting than asking an agent to build a castle.</p><p>They are also the questions that survive after the demo ends.</p><h2>What I want to learn next</h2><p>I do not think the lesson is that builders should stop learning how software works.</p><p>I think it is the opposite.</p><p>When an agent can write the local implementation, the surrounding system becomes easier to ignore and more important to understand. Permissions, state, interfaces, costs, observability, and evaluation stop being background details. They become the work that makes an agent useful in the real world.</p><p>The builder of the next few years may write fewer lines of application logic by hand.</p><p>But they will need a sharper eye for the world they are creating around the model.</p><p>The best agent systems will not be the ones with the longest tool lists.</p><p>They will be the ones where a human can point to every primitive, every boundary, and every quality rule and say: this exists for a reason.</p>]]></content:encoded></item><item><title><![CDATA[The AWS Traffic Map That Finally Made VPC Networking Click]]></title><description><![CDATA[A practical map for tracing one browser request through AWS, understanding the controls around it, and finding the layer that actually failed.]]></description><link>https://www.rateb.cc/p/aws-traffic-map-vpc-networking</link><guid isPermaLink="false">https://www.rateb.cc/p/aws-traffic-map-vpc-networking</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Wed, 09 Sep 2026 07:01:51 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/da7a5bc2-925b-47af-b427-1311f4068a0a_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xbZ3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xbZ3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xbZ3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xbZ3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xbZ3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xbZ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xbZ3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xbZ3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xbZ3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xbZ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d24276a-a0e1-41cd-82d8-c9e4d3ccd96e_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>A practical map for tracing one browser request through AWS, understanding the controls around it, and finding the layer that actually failed.</em></p><p>A web server can be running perfectly and still be unreachable.</p><p>That is the first lesson hidden inside many AWS labs. You can install <code>httpd</code>, start the service, open port 80 in a security group, paste a public IP address into a browser, and see nothing. The natural reaction is to keep changing settings until the page appears.</p><p>That is how beginners lose hours.</p><p>The more useful habit is to stop seeing AWS networking as a pile of settings. Treat it as a path. A browser request has to make it through a series of decisions before an Amazon Linux web server can answer it. Each decision has a different job. Each can fail for a different reason. And each leaves a different clue.</p><p>This guide is the map I wish every early cloud learner had before touching an EC2 networking lab.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uPlj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uPlj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uPlj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uPlj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uPlj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uPlj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg" width="728" height="406.3255813953488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:1536,&quot;width&quot;:2752,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;AWS cloud request-flow reference diagram&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AWS cloud request-flow reference diagram" title="AWS cloud request-flow reference diagram" srcset="https://substackcdn.com/image/fetch/$s_!uPlj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uPlj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uPlj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uPlj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d18e464-f7bf-479c-9fc3-cde0bf4ddb26_2752x1536.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The diagram: an orientation layer, not a literal packet trace</h2><p><em>The supplied AWS map is the visual anchor for this guide. Read the centre from left to right, then use the side panels as a troubleshooting index. The written guide expands the parts that must not be learned as icons alone.</em></p><p>The diagram is valuable because it puts the major questions in one frame: where traffic is trying to go, which layer can reject it, and whether the operating system is actually ready to answer. It is deliberately simplified, though. Treat the orange elements as <strong>decision layers</strong>, not as a set of physical boxes every packet literally visits in that screen order.</p><p>Four caveats keep the picture technically useful:</p><ul><li><p>A public production endpoint often includes DNS, a CDN, AWS WAF, and an Application or Network Load Balancer before traffic reaches a workload. The diagram uses direct public EC2 access because it is the smallest useful learning topology.</p></li><li><p>A route table is not a firewall gate. It selects the next hop for a destination; it does not allow TCP port 80.</p></li><li><p>A subnet is public because its route table has a path to an Internet Gateway. A public IPv4 address on the instance is also required for direct IPv4 internet communication, but an address alone does not make the subnet public.</p></li><li><p>The return journey matters. Security Groups are stateful, so a response to an allowed flow is permitted automatically. Custom Network ACLs are stateless, so their outbound rules must independently allow the response.</p></li></ul><p>The small text inside the image should not carry the lesson by itself, especially on a phone. Use it as the map. Use the sections below as the explanation and the verification method.</p><div><hr></div><h2>First, picture the request as a journey</h2><p>Imagine a browser requesting <code>http://&lt;public-ip&gt;</code>. The request does not jump from your laptop straight into <code>httpd</code>. For a public IPv4 EC2 workload, the useful mental model is:</p><pre><code>Browser
  &#8594; Internet
  &#8594; Internet Gateway
  &#8594; Route table and public subnet
  &#8594; Network ACL
  &#8594; Security group
  &#8594; EC2 network interface
  &#8594; Amazon Linux
  &#8594; Web server listening on port 80</code></pre><p>The reply has to make the return journey too.</p><p>That last sentence matters. A successful inbound request is not the same as a successful connection. The server must be able to send a response, and the network controls on the return path must permit it.</p><p>The five pillars below turn that one line into a working AWS model.</p><div><hr></div><h2>Pillar 1: The request journey is a sequence of jobs</h2><h3>Step zero: distinguish name resolution from the network path</h3><p>The diagram begins at &#8220;Browser Request.&#8221; In a real web visit, the browser normally resolves a DNS name before it can open a TCP connection. If DNS returns the wrong record, has not propagated, or points at an old load balancer, the later VPC layers may be perfectly healthy and the browser will still fail to reach the intended workload.</p><p>That is why a useful first split is:</p><p>| Symptom | First question | | --- | --- | | The hostname does not resolve | Is DNS returning the intended record? | | The hostname resolves but the connection times out | Does a network path and policy permit the connection? | | The TCP connection opens but HTTP returns an error | Is the listener, reverse proxy, or application healthy? |</p><p>Using <code>http://&lt;public-ip&gt;</code> in an early lab intentionally removes DNS from the first exercise. That does not make DNS unimportant; it lets you learn the VPC path without mixing two different problem classes.</p><h3>1. The Internet Gateway is the VPC&#8217;s internet edge</h3><p>An Internet Gateway, or IGW, attaches to a VPC. It is not a firewall rule and it is not an IP address. It is the VPC component that makes a route to the public internet possible.</p><p>For IPv4, an EC2 instance also needs a public IPv4 address or an Elastic IP, plus a route from its subnet to the IGW. AWS documents that the instance itself is aware of its private address inside the VPC; the IGW performs the logical one-to-one network address translation between the instance&#8217;s private IPv4 address and its public address.</p><p>That gives us a practical definition of a <strong>public subnet</strong>:</p><blockquote><p>A subnet is public when its associated route table has a direct route to an Internet Gateway.</p></blockquote><p>A private subnet is not &#8220;a subnet with no public IP by definition.&#8221; Its important property is that it does <strong>not</strong> have a direct route to an IGW. A private workload may need outbound internet access for updates or package downloads, but it should use a NAT device for that outbound path rather than accept unsolicited inbound connections from the internet.</p><h3>2. The route table is a map, not a gate</h3><p>A route table answers a direction question:</p><blockquote><p>&#8220;Where should traffic for this destination go next?&#8221;</p></blockquote><p>For a basic public IPv4 subnet, the familiar default route is:</p><pre><code>Destination: 0.0.0.0/0
Target:      igw-...</code></pre><p>This does <strong>not</strong> mean &#8220;allow all traffic.&#8221; It means traffic with a destination not covered by a more specific route should be sent toward the Internet Gateway. The firewall-like decisions come later.</p><p>This distinction removes one of the most common AWS confusions. A route table can make a destination reachable in principle. It cannot open TCP port 80. It cannot decide whether a user may call <code>DescribeInstances</code>. It cannot prove that <code>httpd</code> is alive.</p><h3>Which route table actually applies?</h3><p>A VPC has a main route table, but a subnet can be explicitly associated with another route table. When a connection fails, looking at a route table that exists somewhere in the VPC is not enough. Verify the association for <strong>the subnet that contains the workload&#8217;s network interface</strong>.</p><p>Then verify route selection. AWS uses the most specific matching route, often called the <strong>longest prefix match</strong>. A route for <code>10.0.0.0/16</code> is more specific than <code>0.0.0.0/0</code>, so traffic for an internal <code>10.0.x.x</code> address follows the internal route rather than the internet default route. That is normal and desirable.</p><p>For a browser reaching a public IPv4 address, the simplified public-subnet requirement is still familiar:</p><pre><code>Destination: 0.0.0.0/0
Target:      Internet Gateway</code></pre><p>But the real troubleshooting question is more precise: <strong>does the workload&#8217;s subnet have the intended associated route table, and does that table choose the intended next hop for this destination?</strong></p><h3>Do not confuse public addressing with public architecture</h3><p>A direct public IPv4 EC2 instance is a good learning lab because every layer is visible. It is rarely the final shape of a production web tier. A more typical public path is browser, DNS, optional CDN/WAF, load balancer, then private application targets. The important mental model survives the topology change: every hop still needs a route, a policy decision, and a healthy receiver. What changes is the number of hops and the security-group relationships between them.</p><h3>3. The subnet is the local network boundary</h3><p>A VPC contains subnets. Every subnet lives entirely inside exactly one Availability Zone. It cannot span Availability Zones.</p><p>The useful hierarchy to remember is:</p><pre><code>Region
  VPC
    Availability Zone
      Subnet
        Network interface / EC2 instance</code></pre><p>That is a location model, not a security stack. It tells you where the workload&#8217;s network interface lives. The route table, NACL, and security group decide how that interface may communicate.</p><h3>4. The final application must be ready</h3><p>Even a correct VPC configuration cannot make a stopped service respond.</p><p>For an Amazon Linux Apache lab, the host-level checks are simple:</p><pre><code>sudo systemctl status httpd
sudo ss -tlnp | grep ':80'
curl -I http://localhost</code></pre><p>These commands answer different questions:</p><ul><li><p>Is the service process healthy?</p></li><li><p>Is anything listening on TCP port 80?</p></li><li><p>Can the local machine receive an HTTP response without involving the network path?</p></li></ul><p>If <code>curl -I http://localhost</code> fails, do not start by rewriting a security group. The problem is on the host.</p><div><hr></div><h2>Pillar 2: AWS uses layered network security on purpose</h2><p>The two controls beginners most often merge into one imaginary &#8220;AWS firewall&#8221; are Network ACLs and Security Groups. They overlap in the sense that both can affect traffic. They do not do the same job.</p><h3>Network ACLs: the subnet-level policy</h3><p>A Network ACL, or NACL, is associated with a subnet. It applies to traffic entering and leaving that subnet.</p><p>NACLs have several traits worth memorising:</p><p>| NACL property | Why it matters | | --- | --- | | <strong>Subnet-level</strong> | It can affect every workload in its associated subnet. | | <strong>Stateless</strong> | Inbound permission does not automatically create return-path permission. | | <strong>Allow and deny rules</strong> | You can explicitly block matching traffic. | | <strong>Ordered evaluation</strong> | AWS checks the lowest rule number first and stops at the first matching rule. |</p><p>A subnet must be associated with one NACL. If you do not explicitly associate a custom NACL, AWS associates the subnet with the default NACL.</p><h3>Security Groups: the workload-level policy</h3><p>A Security Group is associated with network interfaces used by an EC2 instance or other resource. For early learning, &#8220;instance-level firewall&#8221; is a useful simplification, but the precise mental model is interface-level policy.</p><p>Security Groups are:</p><p>| Security Group property | Why it matters | | --- | --- | | <strong>Stateful</strong> | Replies to allowed traffic are automatically allowed back. | | <strong>Allow-only</strong> | There are no deny rules. You allow the traffic you need and leave the rest unapproved. | | <strong>All rules evaluated</strong> | AWS evaluates the applicable rules rather than stopping at a first matching rule number. | | <strong>Composable</strong> | Multiple security groups can be associated with one resource. |</p><p>A simple web-server rule might allow inbound TCP port 80 from <code>0.0.0.0/0</code> for a deliberately public demonstration. That can be valid for a public web endpoint. It is not a good default for SSH. AWS explicitly recommends restricting SSH access on port 22 to the specific IP ranges that need it.</p><h3>The NACL return-traffic trap</h3><p>This is the detail that turns a diagram into operational knowledge.</p><p>A Security Group is stateful. If it allows an inbound HTTP request to your instance, it allows the matching response to leave even if you did not write a separate outbound reply rule.</p><p>A NACL is stateless. If its inbound rules allow a client&#8217;s HTTP request, its outbound rules still need to allow the response. A NACL does not remember that the inbound packet was permitted.</p><p>That means a broken connection can look like this:</p><ol><li><p>The browser sends an HTTP request.</p></li><li><p>The route table directs traffic correctly.</p></li><li><p>The NACL inbound rule allows TCP port 80.</p></li><li><p>The Security Group allows TCP port 80.</p></li><li><p><code>httpd</code> receives the request and prepares a response.</p></li><li><p>The outbound NACL rejects the return traffic because no matching outbound rule permits it.</p></li><li><p>The browser hangs or times out.</p></li></ol><p>The lesson is not &#8220;always use a wide ephemeral-port range.&#8221; Exact ranges depend on the client and design. The lesson is: <strong>when you use a custom NACL, reason about both directions.</strong></p><p>For many basic EC2 environments, Security Groups are the primary workload control. NACLs add a broader subnet boundary when that extra layer is actually useful. They are not automatically &#8220;more secure&#8221; just because they are another service to configure.</p><h3>Why return traffic involves more than port 80</h3><p>HTTP is an application protocol carried over TCP. A browser normally opens a connection from a temporary client-side source port to destination port 80 or 443. The server replies from port 80 or 443 back to that temporary client port.</p><p>That is why a custom NACL needs to be designed in both directions. An inbound rule that permits destination port 80 does not by itself describe the outbound response, whose destination is the client&#8217;s ephemeral source port. The exact ephemeral range depends on the client operating system and your architecture, so copying a random range from a tutorial is not a substitute for understanding the flow.</p><p>The practical sequence is:</p><ol><li><p>Identify the initiator and the service port.</p></li><li><p>Identify the reply direction and the initiator&#8217;s temporary source port range.</p></li><li><p>Write and review NACL rules for both legs.</p></li><li><p>Test the full connection, not merely whether the inbound rule exists.</p></li></ol><p>Security Group statefulness makes the normal response flow less manual, but it does not mean &#8220;all outbound traffic is automatically safe.&#8221; Outbound Security Group rules still control <strong>new flows initiated by the workload</strong>. A package manager downloading updates, an application calling a third-party API, and a server replying to an allowed browser connection are different cases.</p><h3>Prefer intent-based Security Group relationships in multi-tier designs</h3><p>CIDR rules are sometimes correct. A public load balancer may need to allow traffic from the internet. But inside a VPC, a Security Group can often reference another Security Group. For example, an application-tier Security Group can allow TCP 8080 <strong>from the load-balancer Security Group</strong>, rather than from a broad IP range.</p><p>That rule expresses architecture rather than a fragile address list: only interfaces carrying the load-balancer role may initiate that application flow. It is one reason production designs can be safer and easier to reason about than a single public EC2 instance, even though they contain more components.</p><div><hr></div><h2>Pillar 3: Identity, infrastructure, and responsibility are different layers</h2><p>Cloud security becomes much clearer when you ask two separate questions.</p><ol><li><p><strong>Who is allowed to perform an AWS action?</strong></p></li><li><p><strong>What network traffic is allowed to reach a workload?</strong></p></li></ol><p>IAM answers the first question. Network controls answer the second.</p><h3>IAM is about authority</h3><p>AWS Identity and Access Management controls permissions to AWS APIs and resources. It can decide whether a principal may start an instance, view a bucket, create a security group, or read an object.</p><p>IAM does not listen on TCP port 22. It does not decide whether an incoming browser request can reach an EC2 network interface.</p><h3>Network controls are about reachability</h3><p>Route tables, NACLs, Security Groups, public IP configuration, and host firewalls decide whether traffic can take a path to the workload and whether it may cross the relevant policy boundaries.</p><p>A useful distinction:</p><p>| Question | Primary control family | | --- | --- | | Can this user create or stop an EC2 instance? | IAM | | Can this IP address connect to TCP 22? | Security Group, possibly NACL, then host firewall | | Can internet-bound traffic leave this subnet? | Route table and IGW or NAT design | | Is Apache actively answering on port 80? | Operating system and application |</p><h3>Shared responsibility is a working boundary, not a slogan</h3><p>AWS describes its model as <strong>security of the cloud</strong> and <strong>security in the cloud</strong>.</p><p>AWS is responsible for the physical infrastructure and the services it provides. The customer&#8217;s responsibility depends on the service and its configuration. With an EC2 workload, you still own important decisions: IAM permissions, network configuration, operating-system patching, application configuration, data handling, and who can reach the server.</p><p>The useful mindset is not &#8220;AWS will secure it&#8221; or &#8220;I must secure everything.&#8221; It is:</p><blockquote><p>AWS secures the underlying cloud. I must understand and operate the parts I configure inside it.</p></blockquote><p>That mindset naturally leads to verification. A rule exists. Is it attached to the right interface? A route exists. Is the subnet actually associated with that route table? The service is installed. Is it running and listening?</p><div><hr></div><h2>Pillar 4: The anti-confusion map</h2><p>A fast way to learn AWS is to stop asking what a service is called and start asking what job it performs.</p><h3>Route table vs firewall</h3><ul><li><p><strong>Route table:</strong> chooses a next hop for a destination.</p></li><li><p><strong>Firewall-like policy:</strong> permits or rejects traffic.</p></li></ul><p>A route can be correct while the Security Group blocks the connection. A Security Group can allow port 80 while no route leads from the internet to the subnet.</p><h3>Internet Gateway vs NAT Gateway</h3><ul><li><p><strong>Internet Gateway:</strong> enables direct internet connectivity for workloads in a public subnet when routing and public addressing are configured.</p></li><li><p><strong>NAT Gateway:</strong> gives workloads in a private subnet a way to initiate outbound IPv4 connections without making them directly reachable for unsolicited inbound internet connections.</p></li></ul><p>A NAT Gateway is not an inbound door for a private web server.</p><h3>CloudWatch vs CloudTrail</h3><ul><li><p><strong>Amazon CloudWatch:</strong> operational visibility. Think metrics, logs, alarms, and the question &#8220;is the system healthy or behaving as expected?&#8221;</p></li><li><p><strong>AWS CloudTrail:</strong> API activity and audit history. Think &#8220;who called what API, when, and from where?&#8221;</p></li></ul><p>They can work together, but they answer different questions. Monitoring an unhealthy server is not the same as auditing a configuration change.</p><h3>S3 vs EBS</h3><ul><li><p><strong>Amazon S3:</strong> object storage. You work with objects in buckets through APIs and URLs.</p></li><li><p><strong>Amazon EBS:</strong> durable block storage attached to EC2, used like a disk device after attachment and filesystem setup.</p></li></ul><p>EBS is appropriate for an EC2 system disk, databases, and frequently updated block storage. EBS volumes persist independently of the running life of the instance and must be in the same Availability Zone as the EC2 instance they attach to.</p><p>S3 is not &#8220;an EBS drive in the cloud.&#8221; It is a different storage model with different access patterns, durability design, and operational responsibilities.</p><h3>Linux permissions vs IAM permissions</h3><p>IAM can grant permission to call AWS APIs. Linux file permissions determine whether a local process or user on the instance can read, write, or execute a file.</p><p>They are separate systems. Giving an IAM role S3 permissions does not make a local file readable by every Linux user. Changing <code>chmod</code> does not grant an IAM principal access to a bucket.</p><div><hr></div><h2>Pillar 5: Infrastructure literacy is the ability to debug a path</h2><p>The point of memorising AWS terms is not to pass a vocabulary test. It is to make the next failure smaller.</p><p>When a public EC2 web server is unreachable, use this order.</p><h3>Step 1: Test the network path</h3><p>Ask whether a path exists at all.</p><ul><li><p>Is the IGW attached to the VPC?</p></li><li><p>Is the instance subnet associated with a route table that points the intended internet-bound traffic to the IGW?</p></li><li><p>Does the instance have a public IPv4 address or Elastic IP for IPv4 internet communication?</p></li><li><p>Is the instance in the intended subnet and VPC?</p></li></ul><p>Do not change a Security Group until the path itself is plausible.</p><h3>Step 2: Test the traffic policy</h3><p>Now ask which policy may be rejecting the packet.</p><ul><li><p>Does the subnet&#8217;s NACL allow the inbound traffic?</p></li><li><p>Does its outbound NACL allow the response?</p></li><li><p>Does the Security Group allow the inbound protocol, port, and source?</p></li><li><p>Is there an operating-system firewall rule that blocks the service locally?</p></li></ul><p>For an HTTP demo, be precise: protocol TCP, destination port 80, and the right source range.</p><h3>Step 3: Test the host state</h3><p>Only after network path and policy make sense should you troubleshoot the machine.</p><pre><code>sudo systemctl status httpd
sudo systemctl enable httpd
sudo ss -tlnp | grep ':80'
curl -I http://localhost</code></pre><p>If the local test works but the public request fails, move back outward one layer. If the local test fails, fix the service before touching the VPC.</p><h3>Step 4: Gather evidence instead of reopening every rule</h3><p>A good troubleshooting loop replaces guesses with evidence. AWS gives you different evidence sources because the layers are different:</p><p>| Question | Evidence source | What it can tell you | | --- | --- | --- | | Did a control-plane change happen? | CloudTrail | Which identity called an AWS API, such as an EC2, VPC, or IAM API, and when. | | Is the workload healthy over time? | CloudWatch metrics, logs, and alarms | CPU, instance/application logs, health signals, and operational trends. | | Did IP traffic reach an ENI, subnet, or VPC boundary and get accepted or rejected? | VPC Flow Logs | Source/destination addresses, ports, protocol, action, and the relevant network interface context. | | Is the local listener or application failing? | System logs and host commands | Whether the service is running, listening, and returning a local response. |</p><p>VPC Flow Logs are especially useful once the topology contains more than one tier. They record IP traffic metadata for a network interface, subnet, or VPC. They do <strong>not</strong> replace application logs and they do not automatically explain every possible application failure, but an <code>ACCEPT</code> or <code>REJECT</code> record can narrow the network question dramatically.</p><p>For example, a rejected flow involving the expected ENI, source address, destination port, and protocol suggests the request is being stopped before the application can answer. An accepted flow does not prove the website is healthy; it tells you the flow was not rejected at the logged network layer. Continue inward to the listener and application response.</p><h3>The request-trace worksheet</h3><p>For any failed connection, write down a compact trace rather than mentally juggling settings:</p><p>| Layer | What you record | Healthy signal | Typical failure | | --- | --- | --- | --- | | Name | DNS name and returned address | Correct target resolves | Stale, absent, or wrong record | | Addressing | Public IP/EIP or private target | Address matches intended topology | No public address for direct IPv4 path | | Route | Subnet, associated route table, matching next hop | Intended route selected | Wrong association or no viable next hop | | Subnet policy | NACL inbound and outbound rules | Both legs permitted | Return flow blocked by stateless policy | | Interface policy | Attached Security Groups and exact rule | Correct source, protocol, and port allowed | Missing/too-narrow inbound rule | | Host | Listener, local firewall, service logs | Local curl succeeds | Service stopped, wrong bind address, app error | | Application | HTTP status and access/error logs | Expected response code | Reverse proxy, virtual host, or application failure |</p><p>This is the operational version of the diagram. Instead of saying &#8220;networking is broken,&#8221; you can say which layer has evidence, which layer has not been verified, and which test should happen next.</p><h3>A small addressing fact that prevents subnet mistakes</h3><p>AWS reserves five IPv4 addresses in every subnet: the first four and the last address. In <code>10.0.0.0/24</code>, that includes the network address, the VPC router address, the DNS-related reserved address, one address reserved for future use, and the final address.</p><p>That is why a <code>/24</code> does not give you 256 assignable EC2 addresses.</p><div><hr></div><h2>The practice that turns this into skill</h2><p>Take one disposable EC2 web-server lab and trace the request on paper before changing anything.</p><ol><li><p>Write the instance&#8217;s subnet and Availability Zone.</p></li><li><p>Find the route table associated with that subnet.</p></li><li><p>Identify the route that makes it public or private.</p></li><li><p>Record the NACL associated with the subnet and inspect inbound <strong>and</strong> outbound rules.</p></li><li><p>Record the Security Group attached to the instance network interface.</p></li><li><p>Verify the listener locally with <code>curl -I http://localhost</code>.</p></li><li><p>Make one safe change at a time, then test again.</p></li></ol><p>The outcome you want is not simply a working browser page. It is the ability to explain why it works.</p><p>Once that explanation is clear, AWS stops being a console full of magical checkboxes. It becomes an environment where each layer has a job, each failure has a location, and each fix can be verified.</p><div><hr></div><h2>Official AWS references</h2><ul><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Internet_Gateway.html">Internet gateway basics</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/infrastructure-security.html#VPC_Security_Comparison">Compare security groups and network ACLs</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html">Network ACL basics</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/vpc-security-groups.html">Security group basics</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/security-group-rules.html">Security group referencing</a></p></li><li><p><a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-connection-tracking.html">Security group connection tracking</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/route-tables-priority.html">Route priority and longest prefix match</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/configure-subnets.html">Subnet basics</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/subnet-sizing.html">Subnet sizing for IPv4</a></p></li><li><p><a href="https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-records-examples.html">VPC Flow Log records</a></p></li><li><p><a href="https://docs.aws.amazon.com/cdk/v2/guide/security.html">AWS Shared Responsibility Model</a></p></li><li><p><a href="https://docs.aws.amazon.com/ebs/latest/userguide/ebs-volumes.html">Amazon EBS volumes</a></p></li><li><p><a href="https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html">What is AWS CloudTrail?</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Learn the Layer Beneath the AI Hype]]></title><description><![CDATA[When AI headlines get loud, the layer worth learning is how systems run, where they fail, and how to take responsibility for them.]]></description><link>https://www.rateb.cc/p/the-ground-beneath-the-ai-boom</link><guid isPermaLink="false">https://www.rateb.cc/p/the-ground-beneath-the-ai-boom</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Wed, 02 Sep 2026 08:41:36 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a8303609-98be-4e6d-b1bc-ff35177ead58_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QMjI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QMjI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QMjI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QMjI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QMjI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QMjI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QMjI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QMjI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QMjI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QMjI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb05306-a83d-455b-9436-0d8c79d1b4b2_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The easiest way to lose a year is to let a headline make your decisions for you.</p><p>One week you read that AI will erase entry-level work. The next week you read that every company is rebuilding around AI. Then someone tells you cloud is crowded, someone else says cloud is the foundation of everything, and after a while the only honest feeling left is paralysis.</p><p>I know that feeling because I am learning AWS while the loudest conversation in technology is whether people like me will be needed at all.</p><p>It would be comforting to find one clean answer. Cloud is safe. AI will replace everyone. Certifications are enough. There are no jobs. There are unlimited jobs.</p><p>None of those sentences is a useful map.</p><p>The job market is real, but it is not a prophecy machine. Companies cut people for many reasons. They also hire for many reasons. A headline can tell you that something happened. It cannot tell you what you should become.</p><p>The question I keep coming back to is simpler:</p><blockquote><p>What can I learn now that will still make me useful if the tools get much better?</p></blockquote><p>For me, the answer is not a narrow job title. It is the infrastructure layer.</p><p>Not because infrastructure is glamorous. It usually is not.</p><p>Because every exciting product eventually becomes a system someone has to run.</p><h2>AI is impressive. Production is still unforgiving.</h2><p>An AI assistant can write Terraform, draft an IAM policy, explain a VPC, generate a Dockerfile, or suggest a CI/CD pipeline in seconds. That is real leverage. It has already changed how people learn and build.</p><p>But a plausible answer is not the same as a safe system.</p><p>If an AI-generated policy gives a role more access than it needs, the problem is not that the policy was written quickly. The problem is that somebody trusted it without understanding its blast radius.</p><p>If a generated deployment exposes a service to the internet, leaks a secret, sends data to the wrong place, or quietly creates costs that grow every week, the business does not care that the first draft was fast.</p><p>The business cares who can explain what happened, fix it, and prevent it from happening again.</p><p>That is the part of technical work I do not think becomes less important when AI gets better.</p><p>Code may become cheaper to produce. Configuration may become easier to draft. But the work around the output becomes more serious:</p><ul><li><p>What are we actually trying to build?</p></li><li><p>Which data is sensitive?</p></li><li><p>Who should have access?</p></li><li><p>What fails first?</p></li><li><p>What will this cost at ten times the current usage?</p></li><li><p>How will we know whether the system is healthy?</p></li><li><p>Who is accountable when the answer is wrong?</p></li></ul><p>Those are not typing questions. They are judgment questions.</p><p>And judgment is difficult to fake because it sits on top of understanding.</p><h2>The cloud is the ground beneath the product</h2><p>AI can feel like the product because it is the part people touch. You ask a question. You get an answer. You see a demo. It feels immediate.</p><p>But the useful question is what has to be true before that answer reaches you.</p><p>There has to be compute. Storage. Networking. Identity and access. Observability. Security boundaries. Data movement. Cost controls. Recovery plans.</p><p>That is the cloud and infrastructure layer.</p><p>It is not only relevant to AI. It is relevant whenever an organization depends on software that has to be available, secure, fast enough, and affordable enough to keep using.</p><p>This does not mean every cloud learner needs to become an expert in every AWS service. That is another trap. AWS has too many services for a beginner to hold in their head as a list.</p><p>What matters first is a map.</p><p>A virtual machine is compute you can configure. Object storage is data you can store and control access to. A virtual network is the boundary and path through which systems communicate. Identity decides who can do what. Monitoring helps you notice when reality differs from your expectation.</p><p>When those ideas become clear, service names start to have a job. Until then, they are just vocabulary.</p><p>This is why I do not see cloud learning as a bet on one vendor or one trend. I see it as learning the language of modern systems.</p><h2>The real divide is ownership</h2><p>The conversation about AI often gets framed as people versus machines.</p><p>I think that frame hides the more useful divide.</p><p>The divide is between people who can use a generated answer and people who can own it.</p><p>Using it is easy. You can paste a prompt into a chat window, get a script, run it, and hope the green check mark means you are done.</p><p>Owning it is different.</p><p>Owning it means you can explain what the script changes. You can identify the permissions it requests. You can test it in a small environment. You can read the logs when it breaks. You can tell a teammate why a tradeoff was made. You can say, "I do not know yet," before something unsafe reaches production.</p><p>That last sentence matters more than it sounds.</p><p>A person who knows their boundary is safer than a person who copies confidently.</p><p>My support and operations background makes this feel familiar. Users rarely experience a system as a collection of elegant diagrams. They experience it when access fails, a workflow stops, a request disappears, or nobody can explain why something changed.</p><p>The person who can move calmly from symptom to system is useful.</p><p>AI can make that person faster. It cannot make responsibility disappear.</p><h2>Do not confuse a certificate with proof</h2><p>I still think certifications can help. They give beginners a curriculum, language, and a reason to learn the basics properly.</p><p>But a certificate is not a substitute for evidence that you can think through a real system.</p><p>The stronger proof is smaller and more demanding:</p><p>Build something.</p><p>For example, deploy a simple application with a clear boundary around it. Keep the data private by default. Use least-privilege access. Add monitoring. Write down the cost assumption. Break one thing deliberately. Recover it. Explain the decisions in plain English.</p><p>That one project teaches more than a polished architecture diagram with no scars on it.</p><p>It also gives you something better than a claim in an interview. It gives you a story:</p><p>"Here is what I built. Here is what surprised me. Here is the risk I found. Here is what I changed. Here is what I would do differently next time."</p><p>That is the language of someone learning to own systems, not someone collecting badges.</p><h2>A five-part standard for learning with AI</h2><p>I am trying to hold myself to a simple standard as I learn cloud and use AI alongside it.</p><h3>1. Understand the layer</h3><p>Before I ask AI to speed something up, I need a plain-English model of the problem. What does a VPC do? What does this policy permit? What is an availability zone protecting me from?</p><h3>2. Build a small version</h3><p>A small lab is where vague knowledge becomes visible. Keep the scope narrow enough that you can observe the parts.</p><h3>3. Explain the tradeoff</h3><p>Every system has a cost. More availability can mean more complexity. More convenience can mean more access. More speed can mean less control. If I cannot explain the tradeoff, I probably do not understand the decision yet.</p><h3>4. Verify the output</h3><p>Read the generated configuration. Check permissions. Check logs. Check the billing screen. Check the documentation. A green check mark is not a security review.</p><h3>5. Document the proof</h3><p>Write what you built, why you chose it, what failed, and what changed. Documentation turns private learning into a visible record of judgment.</p><p>This is not the fastest path to feeling advanced.</p><p>It is the path that makes AI more useful to you instead of making you dependent on it.</p><h2>I am not betting on a forecast</h2><p>I do not know exactly what the cloud job market will look like in two years. Nobody does.</p><p>Maybe AI investment keeps accelerating. Then companies will need people who can build, secure, connect, observe, and operate the systems underneath it.</p><p>Maybe the hype cools down. Companies will still have existing infrastructure, data, costs, permissions, and systems that need care.</p><p>Maybe the titles change. Cloud engineer becomes platform engineer, cloud security engineer, automation engineer, infrastructure engineer, or something we have not named yet.</p><p>The labels can move.</p><p>The underlying work remains recognizable: make systems reliable enough to trust and understandable enough to improve.</p><p>That is the ground beneath the AI boom.</p><p>And it is the ground I am still willing to learn.</p><div><hr></div><h2>Closing reflection</h2><p>The future will not reward people for predicting every tool correctly.</p><p>It will reward people who can stay close enough to reality to tell the difference between a fluent answer and a working system.</p>]]></content:encoded></item><item><title><![CDATA[What an AWS Incident Response Plan Looks Like Before the Incident]]></title><description><![CDATA[A response plan turns a noisy alert into a safer sequence of verification, containment, recovery, and learning.]]></description><link>https://www.rateb.cc/p/an-aws-incident-response-plan-before-the-incident</link><guid isPermaLink="false">https://www.rateb.cc/p/an-aws-incident-response-plan-before-the-incident</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Mon, 31 Aug 2026 07:01:59 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dc9bd1ae-8724-476f-b835-9d4c050cc982_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vdbn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vdbn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vdbn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vdbn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vdbn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vdbn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vdbn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vdbn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vdbn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vdbn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef75396a-9ef1-4738-9c71-3df3c975cab9_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>A response plan turns a noisy alert into a safer sequence of verification, containment, recovery, and learning.</em></p><p>Most incident response explanations begin at the moment something is already broken.</p><p>An alert fires. A dashboard turns red. A customer cannot reach a service. Someone starts changing settings under pressure.</p><p>The better time to think about incident response is before any of that happens.</p><p>An AWS incident response plan is not a long document that predicts every failure. It is a decision sequence that stops a team from treating every alert as confirmed compromise, every containment action as harmless, and every restored service as proof that the system is healthy again.</p><p>The first step is verification.</p><p>An alarm state means a metric crossed the condition you configured. A GuardDuty finding means a detection system identified a pattern worth triage. An AWS Config rule can say a resource is noncompliant. None of those signals should be ignored. But none of them automatically proves the full story.</p><p>Before acting, identify the smallest claim that can be verified. Which account, Region, resource, identity, and time window are involved? What is the exact alert? What customer or workload impact is observed? Which evidence layer owns the answer?</p><p>Then scope the incident.</p><p>This is the moment to resist broad changes. If one role, one instance, one security group, or one access key is in question, begin there. The point is not to do nothing. The point is to contain the relevant risk without destroying useful evidence or creating a wider outage through panic.</p><p>Containment might mean restricting a security-group rule, isolating a resource, rotating a credential, limiting a route, or pausing an automated action. The right action depends on the observed evidence and the safety of the workload. It should not become a habit of opening every port, deleting every log, or disabling a control just to make a graph look better.</p><p>Recovery is a different job.</p><p>Containment limits spread. Recovery restores an acceptable service state. That distinction becomes important when you bring business continuity and disaster recovery into the conversation.</p><p>A business continuity plan describes how the business continues operating, even in a reduced mode, during disruption. A disaster recovery plan focuses on restoring systems and services after an outage or loss.</p><p>RTO and RPO make those promises concrete.</p><p>Recovery Time Objective is the maximum tolerable downtime. Recovery Point Objective is the maximum acceptable data-loss window. They are not AWS settings you choose inside a console. They are business targets that drive architecture, backup frequency, replication, operational practice, and cost.</p><p>A team that says it can tolerate one hour of data loss is making a different design decision from a team that can tolerate one day. A system that must return in minutes costs more to build and operate than a system that can recover over a longer window. The point is not to choose the smallest number. The point is to choose a number the business understands and the engineering system can actually support.</p><p>After containment and recovery comes the step that makes the plan compound: analysis.</p><p>What changed? Which control worked? Which alert was too noisy? What evidence was missing? Which action was harder than it should have been? What needs to be practiced before the next incident?</p><p>That is where incident response stops being a dramatic moment and becomes an engineering feedback loop.</p><p>For someone learning AWS, you do not need a large enterprise environment to practice the mindset. Take a sandbox architecture and write a one-page response plan. Define one alert, one verification source, one owner, one safe containment action, one recovery target, and one re-check. Then add the sentence that many plans leave out: what does this evidence not prove?</p><p>A calm response is rarely the result of calm personalities. It is the result of decisions made before urgency arrives.</p><h2>Try this in a sandbox</h2><p>Write a one-page response card for a sandbox event: high CPU, an unexpected public security-group rule, or a failed web endpoint. Include the alert, scope fields, first evidence, a reversible containment action, an RTO/RPO conversation point, and a final verification test.</p><h2>Continue the sequence</h2><p>Start by tracing one request or one security claim end to end. The goal is not to collect more AWS screens. It is to learn what each one can prove before you change the system.</p>]]></content:encoded></item><item><title><![CDATA[AWS Security Is an Evidence Loop, Not a List of Services]]></title><description><![CDATA[Match each security claim to the service that can prove it: Config for configuration state, CloudTrail for who acted, GuardDuty for signals.]]></description><link>https://www.rateb.cc/p/aws-security-is-an-evidence-loop-not-a-list-of-services</link><guid isPermaLink="false">https://www.rateb.cc/p/aws-security-is-an-evidence-loop-not-a-list-of-services</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Thu, 20 Aug 2026 07:01:14 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7f42f355-6485-4b93-98e3-c6db1d24aa13_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y29_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y29_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y29_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y29_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y29_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y29_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y29_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y29_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y29_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y29_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82d49123-79cf-4e72-9178-b7314ba32e47_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>A practical way to connect intended state, audit evidence, detection, response, and verification in AWS.</em></p><p>The first time I started seeing AWS security services together, I made the usual beginner mistake. I treated each service like a separate item to memorize.</p><p>CloudTrail records activity. GuardDuty detects threats. AWS Config checks configuration. Patch Manager checks patch state.</p><p>That is true, but it is not yet useful.</p><p>A list of services does not tell you what to do when a security screen turns red. It does not tell you which claim the screen can support. And it does not stop you from making the most expensive beginner error in cloud security: treating one signal as proof that the whole system is safe, unsafe, fixed, or compromised.</p><p>The model that finally made these services click for me was an evidence loop.</p><p>You start with an intended state. A private instance should not have a public IP. A public security group should not allow SSH from everywhere. An EBS volume should be encrypted. A managed node should meet the patch baseline assigned to it.</p><p>AWS Config can help record the configuration of supported resources, retain history, and evaluate rules. If a rule flags a resource as noncompliant, that tells you something narrow and valuable: the configuration did not meet the condition of that rule at the time it was evaluated.</p><p>It does not tell you who made the change. It does not tell you why they made it. It does not prove malicious intent.</p><p>That is where CloudTrail belongs. CloudTrail records AWS account activity such as actions taken in the console, CLI, SDKs, and APIs. When you need to understand an API action, it can help you ask a different question: which identity or service took which recorded action, when, and against which resource?</p><p>The distinction matters. Config answers a configuration question. CloudTrail answers an activity and attribution question. They reinforce each other, but neither should be promoted into a story it cannot prove.</p><p>GuardDuty adds another layer. A finding is not a verdict. It is a signal that deserves triage. The job is to scope the finding, check the affected resource and time window, look for corroborating evidence, and decide whether containment is needed. A detection system is useful because it narrows attention. It does not remove the need for judgment.</p><p>Then comes the part that is easy to skip when learning services in isolation: response and re-check.</p><p>A safe sequence is simple enough to remember:</p><ol><li><p>Name the intended state.</p></li><li><p>Verify the signal before treating it as an incident.</p></li><li><p>Inspect the evidence layer that owns the claim.</p></li><li><p>Scope the smallest affected identity, resource, Region, and time window.</p></li><li><p>Contain only the relevant path or permission where possible.</p></li><li><p>Recover without quietly weakening the control that was supposed to protect the system.</p></li><li><p>Re-check the resulting state against the original baseline.</p></li></ol><p>This is also why a patch dashboard should not be read like a general health certificate. Patch compliance is evidence relative to a baseline. A CloudTrail event is evidence of a recorded AWS action. A GuardDuty finding is evidence of a signal. A Config evaluation is evidence of configuration against a rule.</p><p>Each is useful precisely because it is narrower than the whole story.</p><p>For someone learning cloud engineering, that is the habit worth building early. Do not ask which security service is best. Ask what question you are trying to answer, what evidence can answer only that question, and what you still need to verify before changing the system.</p><p>The durable skill is not collecting service names. It is learning how to move from an intended state to evidence, from evidence to a scoped decision, and from a change back to proof.</p><h2>Try this in a sandbox</h2><p>Pick one resource in a sandbox. Write one expected state, one piece of configuration evidence, one activity record you would inspect, one signal that would need triage, and one re-check that would prove a scoped fix.</p><h2>Continue the sequence</h2><p>Start by tracing one request or one security claim end to end. The goal is not to collect more AWS screens. It is to learn what each one can prove before you change the system.</p>]]></content:encoded></item><item><title><![CDATA[In Your First AWS Week, Learn Responsibility Before Service Names]]></title><description><![CDATA[My first week learning AWS reminded me that cloud is not only about services. It is about infrastructure, responsibility, verification, and learning how to touch powerful systems carefully.]]></description><link>https://www.rateb.cc/p/cloud-is-not-magic-it-is-responsibility</link><guid isPermaLink="false">https://www.rateb.cc/p/cloud-is-not-magic-it-is-responsibility</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Wed, 19 Aug 2026 05:44:36 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2c280eaf-21a9-46b5-bab4-924724fac4dc_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gxHz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gxHz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gxHz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gxHz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gxHz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gxHz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gxHz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gxHz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gxHz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gxHz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F138ae88b-0524-4315-820f-4b423c336ad1_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I started my first week in AWS Cloud Computing expecting to learn services.</p><p>I thought the week would be about names like EC2, S3, IAM, VPC, Lambda, and CloudFront. I expected buttons, commands, maybe a few labs, and a growing list of terms to memorize.</p><p>That did happen, but it was not the real lesson.</p><p>The real lesson was more basic and more important:</p><blockquote><p>Cloud is not magic. It is responsibility arranged in layers.</p></blockquote><p>The more I studied the first week, the more I noticed that AWS becomes overwhelming when you look at it as a huge menu of services. But it becomes understandable when you look at it as a map of responsibility.</p><p>Physical machines still exist. Networks still exist. Storage still exists. Security still exists. Cost still exists. Location still matters. Verification still matters.</p><p>AWS does not remove those things.</p><p>AWS gives you a new way to use them.</p><p>And that is why the first beginner cloud lesson is not only technical. It is a mindset shift.</p><p>You are not just learning where to click.</p><p>You are learning how to become safe around infrastructure.</p><div><hr></div><h2>The first mistake is trying to memorize services too early</h2><p>When you are new to AWS, the service names can make you feel behind before you even begin.</p><p>There are compute services, storage services, networking services, security services, monitoring services, database services, migration services, AI services, and pricing models. Every page can open five more pages. Every acronym can lead to another acronym.</p><p>A beginner can easily think the solution is to memorize faster.</p><p>More flashcards. More videos. More AI summaries. More diagrams. More tabs.</p><p>But after the first week, I think that is the wrong starting point.</p><p>The weak map says: memorize more names first and understanding will arrive later.</p><p>The better map starts with responsibility first, then service names.</p><p>Before memorizing services, a beginner needs a better question:</p><p><strong>What responsibility does this part of the cloud handle?</strong></p><p>That better question changes the shape of learning.</p><p>EC2 is not just a service name. It is a way to rent virtual server capacity.</p><p>S3 is not just storage. It is object storage with access, encryption, durability, naming, and cost decisions.</p><p>A Region is not just a label in the Console. It is a geographic boundary that affects latency, availability, compliance, and where resources live.</p><p>A subnet is not just a networking word. It is part of the placement map for resources inside an Availability Zone.</p><p>A security group is not just a configuration screen. It is a firewall decision around what traffic reaches an instance.</p><p>Once you start asking what each layer is responsible for, AWS becomes less like a giant menu and more like a system.</p><div><hr></div><h2>Cloud is still physical</h2><p>The first useful map is this:</p><pre><code><code>physical hardware
virtualization layer
cloud resources
customer applications
</code></code></pre><p>That one map already removes a lot of confusion.</p><p>Cloud does not mean there are no computers.</p><p>It means you are using computers, storage, networking, and security through a different operating model.</p><p>There are still CPUs executing instructions. There is still RAM holding temporary working data. There is still persistent storage. There are still operating systems. There are still servers. There are still data centers with power, cooling, racks, cables, redundancy, and physical security.</p><p>AWS abstracts much of this away, but abstraction is not disappearance.</p><p>This matters because beginners sometimes talk about the cloud as if it is floating above reality.</p><p>But cloud engineering is closer to reality than that.</p><p>A cloud engineer still needs to understand what compute means, what storage means, what a network does, what an operating system controls, and why physical location can affect performance, cost, and reliability.</p><p>The cloud gives you access to those resources without asking you to own the whole physical stack.</p><p>That is the power.</p><p>But it also means the responsibility does not vanish. It moves.</p><div><hr></div><h2>Virtualization is the bridge</h2><p>The second useful idea from Week 1 was virtualization.</p><p>Virtualization is one of those words that sounds abstract until you make it simple.</p><p>A physical machine can be split into isolated virtual environments. Each environment behaves like its own computer, even though it shares underlying physical resources.</p><p>That is the bridge between a physical server and a cloud service like EC2.</p><p>A local VirtualBox machine and an AWS EC2 instance are not the same product, but they share a core idea: a real physical host can support isolated virtual machines.</p><p>This helps explain why EC2 is not &#8220;the cloud.&#8221;</p><p>EC2 is one building block. It gives you a virtual server. You still choose the machine image, instance size, network placement, security group, storage, key pair, and access method.</p><p>The beginner-friendly version is:</p><blockquote><p>EC2 gives you a server-like environment. AWS manages the physical side. You still have decisions to make inside the environment you control.</p></blockquote><p>That small sentence already prepares you for the shared responsibility model.</p><div><hr></div><h2>Location is part of the architecture</h2><p>The third useful map is location.</p><p>Before this week, I could have repeated words like Region and Availability Zone. But repeating a word is not the same as understanding where responsibility lives.</p><p>The simple map is:</p><pre><code><code>Region
VPC
Availability Zone
subnet
EC2 instance
</code></code></pre><p>A Region is a geographic area.</p><p>An Availability Zone is an isolated location inside a Region.</p><p>A VPC is regional.</p><p>A subnet belongs to one Availability Zone.</p><p>An EC2 instance is placed inside this network and location structure.</p><p>This is the kind of beginner map that looks small, but it changes how you read the AWS Console.</p><p>If you switch Regions and a resource disappears, maybe it did not disappear. Maybe you are looking in a different geographic scope.</p><p>If a subnet belongs to one Availability Zone, you cannot treat it like a global container.</p><p>If you design across multiple Availability Zones, you may improve availability, but you may also increase cost or complexity.</p><p>Cloud is not just &#8220;online.&#8221;</p><p>Cloud resources live somewhere.</p><p>And where they live affects how they behave.</p><div><hr></div><h2>More control means more responsibility</h2><p>The shared responsibility model was one of the most important ideas of the week.</p><p>The simple version is:</p><blockquote><p>AWS is responsible for security of the cloud. The customer is responsible for security in the cloud.</p></blockquote><p>That sounds clean, but it becomes more useful when you connect it to control.</p><p>The more control a service gives you, the more responsibility you carry.</p><p>With EC2, you control a lot. You choose the operating system image, instance type, storage, network, security group, access method, and what runs on the server. That means you also carry more responsibility for configuration, patching, access, data, and traffic rules.</p><p>With more managed services, AWS takes on more of the operational burden, but you still do not become responsibility-free. You still decide permissions, data exposure, identity, configuration, and cost behavior.</p><p>This is where cloud learning becomes more serious.</p><p>It is not enough to know which button launches a resource.</p><p>You need to ask:</p><ul><li><p>Who is responsible for this layer?</p></li><li><p>What can I accidentally expose?</p></li><li><p>What will this cost?</p></li><li><p>What permissions does this need?</p></li><li><p>What should be private by default?</p></li><li><p>What must I verify before I trust the result?</p></li></ul><p>That is also why AI can be helpful and dangerous at the same time.</p><p>AI can explain a command, write a policy, summarize a service, or help debug an error. But if you paste secrets into it, copy commands without understanding them, or accept security advice without checking official documentation, you are not learning responsibly.</p><p>In cloud work, verification is not a bonus skill.</p><p>Verification is part of the job.</p><div><hr></div><h2>S3 taught me that access is a decision</h2><p>S3 looks simple at first.</p><p>A bucket. An object. A link.</p><p>But the first hands-on AWS day made the security lesson very concrete: a URL does not automatically mean public access.</p><p>S3 is private by default. That is a feature, not an obstacle.</p><p>A bucket stores objects. Each object has a key. Permissions decide who can read or write. Block Public Access exists because accidental exposure is a real problem. Encryption is now a default baseline for new uploads, but encryption does not replace access control.</p><p>This is a good beginner lesson because it is small enough to understand and serious enough to matter.</p><p>You can copy an object URL and still get <code>AccessDenied</code>.</p><p>That is not AWS being confusing for no reason.</p><p>It is AWS reminding you that access is separate from existence.</p><p>The object can exist.</p><p>The URL can exist.</p><p>The permission can still be denied.</p><p>That is cloud responsibility in one small example.</p><div><hr></div><h2>Cloud is flexible, not automatically cheap</h2><p>Another important Week 1 lesson was cost.</p><p>Cloud is often described as flexible, scalable, and pay-as-you-go. That is true. But beginners can easily translate that into a weaker sentence:</p><p>&#8220;Cloud is cheap.&#8221;</p><p>That is not always true.</p><p>Cloud is flexible. It is not automatically cheap.</p><p>The basic cost drivers are compute, storage, and data transfer.</p><p>The design choices that make a system more available, faster, or more scalable can also change its cost.</p><p>Multi-AZ design can improve availability. CloudFront can reduce latency by serving content from edge locations closer to users. Auto Scaling can add or remove capacity based on demand. Load balancing can spread traffic across instances. CloudWatch can watch metrics and alarms.</p><p>A simple operational loop looks like this:</p><pre><code><code>users
load balancer
EC2 instances
CloudWatch metrics
Auto Scaling decisions
</code></code></pre><p>That loop helped me understand why companies move workloads to AWS.</p><p>It is not only because they want to stop buying servers.</p><p>They want systems that can respond to demand, recover from failure, reach users in different places, and make infrastructure decisions faster.</p><p>But every decision still has a tradeoff.</p><p>That is why pricing and architecture belong together.</p><div><hr></div><h2>A simple Week 1 cloud plan readers can copy</h2><p>If I had to turn this first week into a training plan for another beginner, I would not start with &#8220;learn 20 AWS services.&#8221;</p><p>I would start with this.</p><h3>Day 1: Build your learning environment</h3><p>Set up your tools and one place for your notes.</p><p>Install or verify AWS CLI. Install or verify VS Code. Know why Terraform matters, even if you do not need to master it yet. Create one folder where you keep commands, screenshots, questions, and explanations.</p><p>Your output for the day:</p><ul><li><p>one AWS learning folder;</p></li><li><p>one tool checklist;</p></li><li><p>one rule: do not run cloud commands you cannot explain.</p></li></ul><h3>Day 2: Write your AI-use policy</h3><p>Use AI, but do not let it replace your understanding.</p><p>Use it for hints, explanations, quizzes, and alternative examples. Do not paste secrets, credentials, private links, or sensitive files. Verify commands, security behavior, pricing, and service limits against official documentation or safe tests.</p><p>Your output for the day:</p><pre><code><code>I use AI for support.
I verify technical claims myself.
I do not submit or run work I cannot explain.
</code></code></pre><h3>Day 3: Learn the physical cloud map</h3><p>Before you memorize AWS services, understand what sits underneath them.</p><p>Explain CPU, RAM, storage, operating systems, servers, and data centers in simple words. Then explain virtualization as the bridge between physical hardware and virtual resources.</p><p>Your output for the day:</p><pre><code><code>hardware
virtualization
virtual server
application
</code></code></pre><p>If you can explain that chain, EC2 becomes less mysterious.</p><h3>Day 4: Learn location, scaling, and cost</h3><p>Learn Region, Availability Zone, VPC, subnet, and EC2 placement.</p><p>Then learn the basic scaling story: a load balancer distributes traffic, EC2 instances run the application, CloudWatch watches metrics, and Auto Scaling changes capacity.</p><p>Finally, remember the cost baseline: compute, storage, and data transfer.</p><p>Your output for the day:</p><ul><li><p>one Region to subnet diagram;</p></li><li><p>one scaling loop diagram;</p></li><li><p>one sentence: cloud is flexible, not automatically cheap.</p></li></ul><h3>Day 5: Touch AWS carefully</h3><p>Open the AWS Console and connect the map to real services.</p><p>Notice which Region you are in. Notice where resources live. Learn why S3 is private by default. Learn the decisions behind launching EC2: AMI, instance type, network, security group, storage, key pair, and access method.</p><p>Your output for the day:</p><ul><li><p>one S3 safety checklist;</p></li><li><p>one EC2 launch checklist;</p></li><li><p>one screenshot or short runbook that proves what you did and how you verified it.</p></li></ul><div><hr></div><h2>Closing reflection: the cloud beginner I want to become</h2><p>After Week 1, I do not think the goal is to look like someone who knows every AWS service.</p><p>That would be fake confidence.</p><p>The better goal is smaller and stronger:</p><p>I want to become the kind of beginner who can explain the map, verify the command, respect the cost, protect the data, and understand which layer I am responsible for.</p><p>That is not as flashy as saying &#8220;I know AWS.&#8221;</p><p>But it is more honest.</p><p>And maybe that is the real start of cloud engineering.</p><p>Not memorizing the cloud.</p><p>Learning how to become responsible inside it.</p>]]></content:encoded></item><item><title><![CDATA[A VPC Is Not “Public” Because You Named It Public]]></title><description><![CDATA[Public and private are traffic outcomes created by paths, addresses, policy, and services.]]></description><link>https://www.rateb.cc/p/a-vpc-is-not-public-because-you-named-it-public</link><guid isPermaLink="false">https://www.rateb.cc/p/a-vpc-is-not-public-because-you-named-it-public</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Tue, 18 Aug 2026 07:00:49 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/74d86004-a72a-4922-8596-7d8a574d8b6f_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BfpJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BfpJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BfpJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BfpJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BfpJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BfpJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BfpJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BfpJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BfpJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BfpJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6e35d2c-c0ed-40ad-ac49-51bdf11a4079_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Public and private are traffic outcomes created by paths, addresses, policy, and services.</em></p><p>I used to read VPC diagrams as if the labels did the work.</p><p>Public subnet. Private subnet. Public route table. Private route table.</p><p>The labels are helpful for people. AWS does not route traffic because a box has a reassuring name.</p><p>A subnet becomes public in the useful sense when its associated route table provides a path to an Internet Gateway. But that is only one condition in a longer chain. An EC2 instance that should be reached from the internet also needs a public IPv4 address or Elastic IP, policy that allows the requested traffic, and a service that is actually listening.</p><p>This became much clearer when I built a VPC manually instead of relying only on the wizard.</p><p>The VPC itself is the network boundary. Subnets divide its address range into smaller sections. Route tables tell traffic where to go next. The Internet Gateway provides a path between the VPC and the internet. Security groups and network ACLs filter traffic at different layers. The workload still has to answer the request when traffic reaches it.</p><p>None of those parts can be skipped by calling a subnet public.</p><p>A common failure is the route-table association. A new subnet uses the VPC main route table until you explicitly associate it with another table. You can create a beautiful route table with a default route to an Internet Gateway and still have an unreachable instance if the subnet is using a different table.</p><p>That detail changed how I read every VPC screen. I stopped asking, "Does this route table look right?" I started asking, "Which route table does this subnet actually use?"</p><p>Private does not mean disconnected. It means the workload does not accept direct internet-initiated traffic through a public address. A private EC2 instance can still initiate package downloads or outbound API calls through a NAT Gateway.</p><p>The NAT boundary is where many diagrams become misleading.</p><p>A public NAT Gateway sits in a public subnet and has a route through the Internet Gateway. The private subnet sends its default internet-bound traffic to that NAT Gateway. The NAT handles return traffic for connections initiated from inside.</p><p>That gives you a path like this:</p><p>Private EC2. Private route table. NAT Gateway in a public subnet. Public route table. Internet Gateway. Internet.</p><p>The private EC2 instance does not become public because it can download updates. NAT is not a public front door. It is not a bastion host. It does not give the private instance a public identity that accepts unsolicited inbound SSH.</p><p>This is why I think "public versus private" is a poor place to stop learning. The stronger mental model is reachability.</p><p>For every request, name the source, destination, protocol, next hop, address type, policy layer, and listener. A browser reaching an Apache instance is a different flow from a private instance reaching a package repository. One is inbound and depends on public addressing, route, policy, and a listener. The other is outbound and can travel through NAT without creating direct inbound exposure.</p><p>That distinction matters beyond certification questions. It is how you avoid building a network that is accidentally reachable, or assuming a private workload is broken because it cannot be reached the way a public test server can.</p><p>The next time a VPC diagram looks simple, trace one packet. Do not read the labels. Follow the path.</p><h2>Try this in a sandbox</h2><p>Draw a two-subnet VPC on paper. For one browser-to-web-server request and one private-instance-to-package-repository request, write the route table, next hop, address requirement, policy rule, and final service evidence each flow needs.</p><h2>Continue the sequence</h2><p>Start by tracing one request or one security claim end to end. The goal is not to collect more AWS screens. It is to learn what each one can prove before you change the system.</p>]]></content:encoded></item><item><title><![CDATA[Stop Treating Hermes Like a Smarter Chat Tab]]></title><description><![CDATA[The useful shift is not from bad model to good model. It is from chat window to operating layer.]]></description><link>https://www.rateb.cc/p/hermes-bible</link><guid isPermaLink="false">https://www.rateb.cc/p/hermes-bible</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Sun, 09 Aug 2026 09:47:58 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4da8672e-c23b-4a0d-bf24-261326e93342_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aqwe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aqwe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aqwe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aqwe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aqwe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aqwe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aqwe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aqwe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aqwe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aqwe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a474d36-f704-498b-9758-2c6537de30ac_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The trap is thinking the model is the whole system</h2><p>I went through the Hermes Bible and kept noticing the same pattern.</p><p>The interesting part is not only Hermes as a tool.</p><p>The interesting part is what it reveals about AI work.</p><p>Most people still treat an AI agent like a smarter chat tab. They ask a question, get an answer, maybe copy something out, then start over the next day with a slightly better prompt.</p><p>That is useful.</p><p>But it is not the real shift.</p><p>The real shift begins when the agent has a place to stand.</p><p>A terminal.</p><p>A file system.</p><p>A memory layer.</p><p>A set of skills.</p><p>A way to talk to you on Telegram, WhatsApp, Slack, email, or the desktop.</p><p>A schedule.</p><p>A way to call tools.</p><p>A way to delegate work.</p><p>A way to leave receipts.</p><p>That is when AI stops being a conversation and starts becoming an operating layer around your work.</p><h2>Better prompts are not enough</h2><p>For a long time, the obvious move was to write better prompts.</p><p>Be more specific.</p><p>Give more context.</p><p>Ask for a table.</p><p>Ask for a plan.</p><p>Ask for examples.</p><p>That still matters. But it is a thin layer.</p><p>A prompt only describes the work.</p><p>A system can hold the work.</p><p>That distinction matters because most real work does not fit inside one clean message. It stretches across notes, files, tasks, tools, deadlines, open loops, errors, preferences, and half-finished decisions.</p><p>A chat tab forgets that shape unless you keep reloading it by hand.</p><p>A useful agent system starts carrying that shape with you.</p><h2>Hermes is a map of the missing layers</h2><p>The Hermes Bible is useful because it makes the missing layers visible.</p><p>Installation is only the door.</p><p>The deeper map is everything around the model:</p><ul><li><p>tools and toolsets for touching the real environment</p></li><li><p>skills for saving procedures that worked</p></li><li><p>memory for stable preferences and facts</p></li><li><p>context files for project-specific behavior</p></li><li><p>profiles for separate agent identities</p></li><li><p>cron for scheduled work</p></li><li><p>webhooks for event-driven work</p></li><li><p>delegation for parallel work</p></li><li><p>Kanban for durable multi-agent coordination</p></li><li><p>messaging gateways for always-available access</p></li><li><p>security layers for credentials and approvals</p></li><li><p>developer internals for people who want to extend the system</p></li></ul><p>That is not a feature checklist.</p><p>It is a picture of what a working AI assistant actually needs.</p><p>Not just intelligence.</p><p>Surface area.</p><p>Continuity.</p><p>Boundaries.</p><p>Review.</p><h2>The missing skill is designing the workbench</h2><p>This is the part that feels practical to me.</p><p>The model gets most of the attention because it is the visible brain. But the workbench decides what the brain can actually do.</p><p>A strong model with no tools can only advise.</p><p>A strong model with tools, memory, files, schedules, and review gates can start turning advice into verified work.</p><p>That does not mean giving an agent unlimited freedom.</p><p>It means building a small, trustworthy environment around repeated work.</p><p>For content, that might mean the agent knows the writing style, reads the material, drafts in the right folder, checks for public-reader safety, creates a publish handoff, and records the status.</p><p>For learning, that might mean the agent turns a study session into notes, flashcards, labs, questions, and a follow-up task.</p><p>For operations, it might mean a scheduled check, a webhook trigger, a saved skill, and a receipt that proves what happened.</p><p>The important point is this:</p><p>The agent becomes more useful when the work becomes more structured.</p><h2>The useful unit is not one agent</h2><p>One agent can help you.</p><p>A system of loops can compound.</p><p>That is the part I keep coming back to.</p><p>Hermes is not only trying to answer one request. It can sit inside repeated loops: a daily report, a weekly review, a content workflow, a project board, a webhooks flow, a memory and skill improvement cycle, a research pipeline, or a messaging inbox.</p><p>The result is not magic autonomy.</p><p>It is controlled repetition.</p><p>The agent does not become useful because it is free to do anything. It becomes useful because the work has rails.</p><p>A good Hermes setup tells the agent:</p><ul><li><p>where to look</p></li><li><p>what tools it can use</p></li><li><p>what quality bar matters</p></li><li><p>when to stop and ask</p></li><li><p>what needs a receipt</p></li><li><p>what must never be published without approval</p></li><li><p>what should be saved for next time</p></li></ul><p>That is how agency becomes safe enough to use.</p><h2>This changes how I think about my own work</h2><p>For me, this connects directly to the way I am rebuilding my own technical path.</p><p>I do not only need another AI tool.</p><p>I need a workbench.</p><p>A place where cloud notes, local files, content drafts, visual systems, job-search material, browser checks, scheduling records, and reminders can connect without becoming a mess.</p><p>That is why the Hermes model is interesting.</p><p>It says the hard part is not asking AI to think.</p><p>The hard part is building the environment where thinking can turn into verified action.</p><p>A model can draft.</p><p>A system can draft, save, check, revise, prepare, schedule, and remember the lesson.</p><p>A model can answer a question.</p><p>A system can keep track of what the answer changed.</p><p>A model can suggest a workflow.</p><p>A system can run the workflow again next week with fewer mistakes.</p><h2>The real skill is operating the layer</h2><p>This is where I think many people will get confused.</p><p>They will look for the best model, the best prompt, the best agent framework, or the best automation hack.</p><p>Those matter.</p><p>But the durable skill is learning how to operate the layer around the model.</p><p>Can you define the work clearly?</p><p>Can you give the agent the right tools without giving it too much freedom?</p><p>Can you separate private working notes from public output?</p><p>Can you make it verify instead of assume?</p><p>Can you turn repeated corrections into reusable procedures?</p><p>Can you create review gates before anything touches the outside world?</p><p>Can you keep the system small enough to trust?</p><p>That is not prompt engineering.</p><p>That is technical judgment.</p><h2>The danger is agent sprawl</h2><p>There is also a trap here.</p><p>Once you see agents as operating layers, it becomes tempting to connect everything to everything. Every app gets a workflow. Every idea gets an automation. Every repeated task gets a scheduled agent. Every project gets a board, a memory, a profile, a skill, and a new system around it.</p><p>That can become another kind of clutter.</p><p>The point is not to automate your life into a machine you no longer understand.</p><p>The point is to build a few loops that are clear enough to trust.</p><p>This is why receipts matter so much. Without receipts, automation becomes rumor. The agent says something happened, but you cannot easily prove it. A file path, URL, task ID, test result, screenshot, or read-back changes that. It lets the human stay in control without personally repeating every small check.</p><p>This is also why review gates matter.</p><p>A useful AI system should know the difference between drafting and publishing, between suggesting and executing, between local preparation and external distribution, between memory worth keeping and temporary task state.</p><p>Those boundaries are not obstacles.</p><p>They are what make delegation possible.</p><p>A person does not trust an agent because it sounds confident. A person trusts an agent because the workflow creates evidence, the boundaries are clear, and mistakes can be turned into better procedures.</p><h2>What this means for technical self-rebuilders</h2><p>For someone learning cloud, Linux, AI, automation, or systems, this is the real lesson.</p><p>Do not only learn tools as separate tricks. Learn how work moves through a system.</p><p>Inputs arrive. Context is gathered. A decision is made. A tool runs. Output is checked. State is saved. The next action is triggered. A human reviews the risky step. Evidence is recorded. The lesson becomes reusable.</p><p>That pattern is everywhere.</p><p>It is in incident response.</p><p>It is in cloud operations.</p><p>It is in content production.</p><p>It is in job hunting.</p><p>It is in personal knowledge systems.</p><p>The agent makes the pattern visible because a weak workflow breaks quickly when you ask another intelligence to run it. Missing context becomes obvious. Vague standards become expensive. No verification becomes dangerous. No memory means the same correction returns again and again.</p><p>That is why Hermes is interesting beyond Hermes.</p><p>It teaches the shape of useful delegation.</p><p>Not just &#8220;ask AI.&#8221;</p><p>Design the loop.</p><p>Give the loop tools.</p><p>Define the review gate.</p><p>Save the lesson.</p><p>Demand the receipt.</p><h2>The human stays responsible</h2><p>This is the part that should not be romanticized.</p><p>An operating layer does not remove responsibility from the human. It makes responsibility more explicit.</p><p>If the workflow is vague, the agent will amplify the vagueness.</p><p>If the quality bar is weak, the agent will produce more weak work faster.</p><p>If the approval boundary is unclear, the system becomes risky.</p><p>If the memory layer stores the wrong things, future sessions inherit noise.</p><p>So the human job changes. It does not disappear.</p><p>The human becomes the designer of the environment, the setter of constraints, the reviewer of risky actions, and the person who decides which lessons deserve to become reusable procedure.</p><p>That is a more serious skill than prompting. It is closer to operations. It asks for judgment, taste, patience, and the ability to turn repeated mistakes into better rails.</p><p>The best agent systems will not be the ones that sound most autonomous. They will be the ones where the human can see the loop clearly, trust the evidence, and improve the rails after each mistake. That is how AI work becomes less like magic and more like craft.</p><p>And that is the quiet advantage: not replacing responsibility, but making responsibility easier to practice with better tools, better memory, and better proof.</p><p>A serious agent setup is not measured by how much it can do alone. It is measured by how reliably it helps the human carry better work forward.</p><p>In real work.</p><h2>A simple map for agent leverage</h2><p>The practical map I took from this is simple.</p><p>If you want an AI agent to become more useful, do not start by asking for more autonomy.</p><p>Start with six layers.</p><h3>1. Tools</h3><p>What can the agent actually touch?</p><p>Files, shell commands, browser pages, APIs, notes, calendars, messages, images, and documents all change the kind of work it can do.</p><h3>2. Memory</h3><p>What should survive the session?</p><p>Preferences, environment facts, stable constraints, and reusable lessons matter more than raw chat history.</p><h3>3. Skills</h3><p>What should the agent do better next time?</p><p>A good procedure is a small upgrade to the future version of the agent.</p><h3>4. Surfaces</h3><p>Where can the agent meet you?</p><p>A terminal is powerful, but many workflows become real only when the agent can reach you through the channels you already use.</p><h3>5. Loops</h3><p>What should happen repeatedly?</p><p>Daily scans, weekly reviews, scheduled checks, webhook triggers, project boards, and content pipelines are where small improvements compound.</p><h3>6. Receipts</h3><p>How do you know it worked?</p><p>A file path, a URL, a task ID, a read-back, a screenshot, a test result, or a log matters because it turns AI output into evidence.</p><h2>Final reflection</h2><p>The Hermes Bible is called a bible, but the lesson I took from it is not religious.</p><p>It is operational.</p><p>The future of useful AI work is not one perfect prompt.</p><p>It is a controlled environment where an agent can act, remember, verify, improve, and still stay accountable to the person using it.</p><p>That is the part worth learning.</p><p>Not because every person needs Hermes specifically.</p><p>Because every serious AI workflow eventually has to answer the same question:</p><p>What system surrounds the model?</p>]]></content:encoded></item><item><title><![CDATA[Turn Hermes Into a Practical Superagent]]></title><description><![CDATA[The integrations and workflows that make Hermes useful beyond chat.]]></description><link>https://www.rateb.cc/p/turn-hermes-into-a-practical-superagent</link><guid isPermaLink="false">https://www.rateb.cc/p/turn-hermes-into-a-practical-superagent</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Fri, 31 Jul 2026 07:07:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8OGn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8OGn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8OGn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8OGn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8OGn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8OGn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8OGn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg" width="728" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:1040,&quot;width&quot;:1456,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8OGn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8OGn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8OGn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8OGn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd270c114-eed4-4b60-9885-db176c2b411f_1456x1040.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hermes can feel underwhelming the first time you open it.</p><p>You send a message.</p><p>It replies.</p><p>You ask a question.</p><p>It answers.</p><p>And after a few minutes you can easily think:</p><blockquote><p>Is this just ChatGPT or Claude inside Telegram?</p></blockquote><p>That reaction makes sense if Hermes has nothing connected to it.</p><p>An agent without integrations is just a smart brain with no eyes, hands, workspace, or memory.</p><p>The useful version starts when Hermes can:</p><ul><li><p>look things up</p></li><li><p>read your workspace</p></li><li><p>remember your notes</p></li><li><p>draft actions</p></li><li><p>route tasks to the right mode</p></li><li><p>run small scheduled workflows</p></li></ul><p>The source I studied showed this through Hermes, Claude Code/Codex, Telegram, Obsidian, GitHub, Apollo, Gmail, Calendar, personas, and scheduled reflection.</p><p>The pattern is simple:</p><blockquote><p>Hermes becomes useful when it moves from chat to workflow.</p></blockquote><p>There are 4 jobs every serious setup needs.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JZwc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JZwc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 424w, https://substackcdn.com/image/fetch/$s_!JZwc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 848w, https://substackcdn.com/image/fetch/$s_!JZwc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!JZwc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JZwc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png" width="1456" height="1040" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1040,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1242209,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ratebsl.substack.com/i/198251992?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JZwc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 424w, https://substackcdn.com/image/fetch/$s_!JZwc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 848w, https://substackcdn.com/image/fetch/$s_!JZwc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!JZwc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8152a0bd-897c-456c-90f5-b0eee572653d_1456x1040.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Job 1: Capture</h2><p>Capture is how Hermes gets ideas from your real life into the system.</p><p>In the source, this starts with Telegram.</p><p>Telegram gives Hermes a mobile interface, so you can message the agent when an idea shows up instead of waiting until you are back at your desk.</p><p>Example:</p><blockquote><p>I just thought of a lead workflow for roofing companies. Save this idea, connect it to my Obsidian notes, and remind me to turn it into a test.</p></blockquote><p>Why it matters:</p><p>Most useful ideas are not born inside your IDE.</p><p>They happen while walking, reading, talking, or working on something else.</p><p>If Hermes only lives on your computer, those ideas die before they become workflows.</p><p>Minimum setup:</p><ul><li><p>create the Telegram bot</p></li><li><p>restrict it to your allowed user ID</p></li><li><p>treat the bot token like a secret</p></li><li><p>test with one simple message</p></li></ul><p>Good test:</p><blockquote><p>Hey Hermes, reply only if this message came from an allowed user.</p></blockquote><p>What can go wrong:</p><p>If the bot is open to the wrong users, your &#8220;personal assistant&#8221; becomes a public endpoint.</p><h2>Job 2: Research</h2><p>Research is how Hermes gets context without you spoon-feeding it every detail.</p><p>From the source and the reference article, the research bucket includes tools like:</p><ul><li><p>web search or Firecrawl-style page extraction</p></li><li><p>Reddit or community scanning</p></li><li><p>YouTube transcript extraction</p></li><li><p>Apollo for company and lead research</p></li></ul><p>The exact tools can change.</p><p>The job stays the same:</p><blockquote><p>Give Hermes eyes and ears on the outside world.</p></blockquote><p>Example workflow:</p><blockquote><p>Research Austin roofing companies. Find 20 businesses, summarize what each does, identify likely pain points, and rank which ones might be worth contacting. Do not collect personal contact details or draft outreach yet.</p></blockquote><p>That one prompt is practical because it gives Hermes a bounded research task.</p><p>It does not say:</p><blockquote><p>Go find leads and start emailing them.</p></blockquote><p>That matters.</p><p>Research should come before action.</p><p>Useful research integrations:</p><ul><li><p><strong>Web extraction:</strong> cleaner context from websites</p></li><li><p><strong>Reddit/community search:</strong> what people complain about or want</p></li><li><p><strong>YouTube transcripts:</strong> searchable notes from long videos</p></li><li><p><strong>Apollo/lead database:</strong> company discovery and prospecting context</p></li></ul><p>Good test:</p><blockquote><p>Use the connected research tool to summarize one company website and list 3 possible customer pain points.</p></blockquote><p>If Hermes gives a generic answer, the integration is not doing real work yet.</p><h2>Job 3: Workspace</h2><p>Workspace is where Hermes touches the places you actually work.</p><p>This is the bucket that makes the agent feel less like a chatbot and more like an assistant.</p><p>From the source, this includes:</p><ul><li><p>Claude Code or Codex for coding work</p></li><li><p>GitHub for repos, issues, PRs, and config backup</p></li><li><p>Gmail for email search and drafts</p></li><li><p>Calendar for meetings and availability</p></li><li><p>Google Workspace-style docs/sheets if connected through your stack</p></li><li><p>Discord or Slack-style channels if your business runs there</p></li></ul><p>The key is permission design.</p><p>Hermes should not get the same power everywhere.</p><p>Gmail:</p><ul><li><p>search: yes, when scoped</p></li><li><p>read relevant threads: yes, when needed</p></li><li><p>draft email: yes</p></li><li><p>send email: not by default</p></li><li><p>delete email: no</p></li></ul><p>Calendar:</p><ul><li><p>read events: yes</p></li><li><p>find availability: yes</p></li><li><p>propose events: yes</p></li><li><p>delete events: confirmation required</p></li></ul><p>GitHub:</p><ul><li><p>inspect repos: yes</p></li><li><p>create backup repo: after confirmation</p></li><li><p>open PRs: only if that is part of your workflow</p></li><li><p>store secrets: never</p></li></ul><p>Example workflow:</p><blockquote><p>Check my Gmail for support emails from the last 24 hours. Group them by issue type. Draft replies for the urgent ones, but do not send anything. Save a summary in Obsidian.</p></blockquote><p>This is where the workflow becomes useful.</p><p>Gmail gives the source.</p><p>Hermes classifies.</p><p>Obsidian stores the pattern.</p><p>Human approval protects the external action.</p><p>Good test:</p><blockquote><p>What is on my calendar today?</p></blockquote><p>Then:</p><blockquote><p>Draft a short prep note for the next meeting using only the calendar title and any related notes you can find.</p></blockquote><p>If Hermes can answer both, the workspace layer is starting to work.</p><h2>Job 4: Memory</h2><p>Memory is what stops Hermes from being useful once and forgetful forever.</p><p>In the source, Obsidian is the main memory layer.</p><p>That is the right instinct.</p><p>Obsidian gives Hermes an inspectable knowledge base:</p><ul><li><p>raw sources</p></li><li><p>compiled notes</p></li><li><p>project context</p></li><li><p>writing drafts</p></li><li><p>user profile</p></li><li><p>recurring decisions</p></li><li><p>agent rules</p></li></ul><p>The important detail:</p><p>Do not treat raw chat logs as memory.</p><p>Raw logs are noisy.</p><p>Memory should be compiled.</p><p>Example:</p><p>Raw input:</p><blockquote><p>I want this newsletter to be less philosophical and more practical, with examples and technical use cases.</p></blockquote><p>Compiled memory:</p><pre><code><code>- User prefers practical technical writing over abstract AI philosophy.
- When rewriting content, include concrete tools, workflows, examples, and failure modes.
- Mark source gaps instead of inventing missing implementation details.</code></code></pre><p>That is useful memory.</p><p>It changes the next output.</p><p>Obsidian workflow:</p><ul><li><p><strong>Full transcript:</strong> Sources</p></li><li><p><strong>Durable concept:</strong> Learning</p></li><li><p><strong>Active build plan:</strong> Projects</p></li><li><p><strong>Newsletter draft:</strong> Writing</p></li><li><p><strong>Visuals and exports:</strong> Files</p></li></ul><p>Good test:</p><blockquote><p>Find the study note about the Hermes agent bridge and summarize the three safest connector rules.</p></blockquote><p>If Hermes can do that, it is reading your memory layer instead of only answering from the current chat.</p><h2>The 12 Practical Integrations To Think About</h2><p>Use this as a practical menu, not a claim that every tool is required.</p><p>Start with the tools that match your workflow.</p><ul><li><p><strong>Capture - Telegram:</strong> Talk to Hermes from your phone</p></li><li><p><strong>Research - Web extraction / Firecrawl-style tool:</strong> Read websites cleanly</p></li><li><p><strong>Research - Reddit/community search:</strong> Find real user complaints and demand</p></li><li><p><strong>Research - YouTube transcripts:</strong> Turn videos into searchable notes</p></li><li><p><strong>Research - Apollo:</strong> Find companies and prospecting context</p></li><li><p><strong>Workspace - Claude Code / Codex:</strong> Work with repos and implementation context</p></li><li><p><strong>Workspace - GitHub:</strong> Issues, PRs, repo backup, config versioning</p></li><li><p><strong>Workspace - Gmail:</strong> Search emails and create drafts</p></li><li><p><strong>Workspace - Calendar:</strong> Read schedule and prepare meetings</p></li><li><p><strong>Workspace - Google Drive / Docs / Sheets:</strong> Work inside documents and structured files</p></li><li><p><strong>Workspace - Discord / Slack:</strong> Push summaries into team channels</p></li><li><p><strong>Memory - Obsidian:</strong> Long-term inspectable memory</p></li></ul><p>The point is not &#8220;connect all 12 today.&#8221;</p><p>The point is to cover all 4 jobs:</p><ul><li><p>capture</p></li><li><p>research</p></li><li><p>workspace</p></li><li><p>memory</p></li></ul><p>Miss one bucket and Hermes goes blind in that direction.</p><h2>Where It Gets Powerful: Chaining</h2><p>One integration is useful.</p><p>The real jump happens when Hermes chains three or four together.</p><h3>Workflow 1: Support Triage</h3><p>Prompt:</p><blockquote><p>Every morning, scan support emails from Gmail. Group them by issue type and priority. Draft replies for the urgent ones. Save the top recurring issues in Obsidian. Do not send replies.</p></blockquote><p>Tools:</p><ul><li><p>Gmail</p></li><li><p>Obsidian</p></li><li><p>scheduled job</p></li></ul><p>Output:</p><ul><li><p>urgent issues</p></li><li><p>draft replies</p></li><li><p>recurring problem list</p></li><li><p>root-cause note</p></li></ul><h3>Workflow 2: Prospecting Brief</h3><p>Prompt:</p><blockquote><p>Use Apollo and web research to find 20 Austin roofing companies. Summarize what each company does, likely pain points, and why they may be a fit. Rank the top 5. Do not collect personal contact data or draft outreach yet.</p></blockquote><p>Tools:</p><ul><li><p>Apollo</p></li><li><p>web extraction</p></li><li><p>Obsidian memory</p></li></ul><p>Output:</p><ul><li><p>company list</p></li><li><p>pain points</p></li><li><p>top picks</p></li><li><p>next-step recommendation</p></li></ul><h3>Workflow 3: Weekly Business Review</h3><p>Prompt:</p><blockquote><p>Every Monday, pull the key numbers from connected business tools, summarize what changed from last week, and post a short review note. Do not make changes to billing, customers, posts, or campaigns.</p></blockquote><p>Tools:</p><ul><li><p>payment/business dashboard connector if available</p></li><li><p>social/workspace connector if available</p></li><li><p>Obsidian or Discord/Slack</p></li><li><p>scheduled job</p></li></ul><p>Output:</p><ul><li><p>week-over-week summary</p></li><li><p>anomalies</p></li><li><p>follow-up questions</p></li><li><p>one suggested action</p></li></ul><h3>Workflow 4: Coding Handoff</h3><p>Prompt:</p><blockquote><p>I captured this feature idea on Telegram. Turn it into a project note, connect it to the relevant repo context, and prepare a Claude/Codex implementation brief. Do not edit files yet.</p></blockquote><p>Tools:</p><ul><li><p>Telegram</p></li><li><p>Obsidian</p></li><li><p>GitHub</p></li><li><p>Claude Code/Codex</p></li></ul><p>Output:</p><ul><li><p>project note</p></li><li><p>repo context</p></li><li><p>implementation brief</p></li><li><p>open questions</p></li></ul><p>That is the practical bridge.</p><p>Not one agent doing everything.</p><p>Several tools passing the right context through Hermes with approval boundaries.</p><h2>How To Plug One In</h2><p>Use the simple loop.</p><h3>Step 1: Ask Hermes what it needs</h3><p>Prompt:</p><blockquote><p>Hey Hermes, I want to connect Gmail. What do you need from me?</p></blockquote><p>Depending on the tool, the answer might be:</p><ul><li><p>OAuth</p></li><li><p>API key</p></li><li><p>MCP connector</p></li><li><p>local path</p></li><li><p>environment variable</p></li><li><p>CLI authentication</p></li></ul><p>Do not guess.</p><p>Let the agent tell you the required path, then verify sensitive steps yourself.</p><h3>Step 2: Store secrets outside chat</h3><p>API keys and bot tokens should not go into:</p><ul><li><p>chat logs</p></li><li><p>Obsidian notes</p></li><li><p>GitHub repos</p></li><li><p>screenshots</p></li><li><p>public content packages</p></li></ul><p>Use environment variables or a secret manager.</p><h3>Step 3: Test the tool directly</h3><p>Ask a question that only the tool can answer.</p><p>Examples:</p><blockquote><p>What is on my calendar today?</p><p>Find the last email from this client.</p><p>Pull the last 5 companies matching this search.</p><p>Read this Obsidian note and summarize the action items.</p></blockquote><p>If it gives a generic answer, the integration is not live.</p><h3>Step 4: Chain one more tool</h3><p>Once one tool works, add a second.</p><p>Example:</p><blockquote><p>Find support emails in Gmail and save the recurring issues into Obsidian.</p></blockquote><p>Now Hermes is not just answering.</p><p>It is moving context between systems.</p><h3>Step 5: Add approval rules</h3><p>Before you automate, write the boundaries.</p><p>Example:</p><pre><code><code>Allowed:
- read email
- draft replies
- summarize notes
- create internal notes

Requires approval:
- send email
- publish content
- delete files
- create external events
- modify repos</code></code></pre><p>This is what keeps the superagent useful instead of dangerous.</p><h2>The Main Rule</h2><p>Do not judge Hermes after opening a blank agent.</p><p>Judge it after you connect:</p><ul><li><p>one capture surface</p></li><li><p>one research tool</p></li><li><p>one workspace tool</p></li><li><p>one memory system</p></li><li><p>one approval rule</p></li></ul><p>That is when the chatbot starts turning into a workflow engine.</p><p>Start small.</p><p>Connect one tool.</p><p>Test it.</p><p>Then chain it with memory.</p><p>That is the point where Hermes stops being &#8220;AI in Telegram&#8221; and starts becoming a practical operating layer for your work.</p>]]></content:encoded></item><item><title><![CDATA[When Code Gets Cheap, Judgment Gets Expensive ]]></title><description><![CDATA[AI makes it easier to produce code. That does not make technical judgment less valuable. It makes judgment, specs, tests, review, and clear thinking the part that matters more.]]></description><link>https://www.rateb.cc/p/when-code-gets-cheap-judgment-gets</link><guid isPermaLink="false">https://www.rateb.cc/p/when-code-gets-cheap-judgment-gets</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Thu, 30 Jul 2026 13:19:36 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bcf37000-452f-482b-949b-460cb4347151_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TZOh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TZOh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TZOh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TZOh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TZOh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TZOh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TZOh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TZOh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TZOh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TZOh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b475e9-6126-402e-8cfd-9a7e39633503_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a strange feeling that comes with using AI for technical work.</p><p>At first, it feels like relief.</p><p>The blank page is less scary. The terminal feels less lonely. The error message becomes less humiliating. The tool can explain, suggest, rewrite, scaffold, debug, and turn a vague idea into something that looks real.</p><p>For someone rebuilding technical skill, that is powerful.</p><p>It means you can move faster than your confidence. You can build small things before you fully feel like the kind of person who builds. You can ask questions you would have been embarrassed to ask in a room full of senior engineers. You can turn a note into a script, a script into a workflow, and a workflow into proof.</p><p>But there is another feeling underneath the relief.</p><p>It shows up after the first excitement fades.</p><p>The tool gave you an answer.</p><p>Now you have to know whether the answer deserves trust.</p><p>That is the part people do not talk about enough.</p><p>AI makes output cheaper. It does not make judgment automatic.</p><p>In fact, the cheaper output becomes, the more expensive judgment becomes.</p><h2>The wrong map is speed</h2><p>The tempting belief is simple:</p><p>If AI can help me write code faster, then the main advantage is speed.</p><p>Ship faster. Build faster. Learn faster. Automate faster. Produce more. Keep up with everyone else.</p><p>There is truth in that.</p><p>Speed matters. A learner who can test ideas quickly has an advantage over someone waiting for perfect confidence. A builder who can use AI to explore a codebase, draft a script, or generate a first version has more surface area for learning.</p><p>But speed is a dangerous god.</p><p>If speed becomes the whole map, the work starts to look better than it is.</p><p>A generated script can run and still be brittle. A pull request can pass a simple test and still miss the real behavior. A cloud command can work in a tutorial and still fail in a real environment. A clean explanation can sound correct and still hide the detail that matters.</p><p>The beginner version of this mistake is obvious.</p><p>You copy the answer before you understand the answer.</p><p>The advanced version is more subtle.</p><p>You produce so much that you lose the ability to inspect what you produced.</p><p>That is where AI changes the shape of technical learning.</p><p>The scarce skill is no longer only typing the thing. It is knowing what good looks like before the thing exists.</p><h2>The better map is verification</h2><p>I am starting to think of AI-assisted technical work as a trust problem.</p><p>Not because the tools are bad.</p><p>Because the tools are productive.</p><p>The more they produce, the more you need a way to check the work.</p><p>That means the new stack is not only prompts and models. It is specs, tests, logs, review habits, monitoring, clear naming, good notes, and the ability to explain your decision in plain English.</p><p>A prompt asks for output.</p><p>A spec defines what the output must satisfy.</p><p>A test checks whether the behavior matches the claim.</p><p>A log tells you what happened when the system moved.</p><p>A note preserves what you learned so you do not repeat the same confusion tomorrow.</p><p>Writing explains the decision well enough that another person, or your future self, can challenge it.</p><p>This is why writing matters more in the AI age, not less.</p><p>Writing is not decoration around technical work.</p><p>Writing is a verification layer.</p><p>If I cannot explain what I asked the system to do, what changed, why it changed, how I checked it, and what risk remains, then I probably do not understand the work yet.</p><p>That does not mean I should avoid AI.</p><p>It means I should use AI in a way that forces me to become clearer.</p><h2>AI can hide the part you most need to learn</h2><p>This is the danger for technical self-rebuilders.</p><p>AI can help you climb.</p><p>It can also quietly remove the friction that would have trained your eye.</p><p>When you type everything yourself, you hit small walls. You misspell commands. You forget flags. You misunderstand directory structure. You break things. You read errors. You search docs. You slowly build a map of how the system behaves.</p><p>That process is annoying.</p><p>It is also how judgment is formed.</p><p>If AI removes every small wall before you have learned what the wall was teaching you, you may become faster without becoming stronger.</p><p>You can end up with a strange gap.</p><p>You can create more advanced-looking outputs than your understanding can support.</p><p>This is not a reason to reject AI. That would be the opposite mistake.</p><p>The point is to keep apprenticeship inside the workflow.</p><p>Use AI to generate, but do not let it replace the part where you inspect.</p><p>Use AI to explain, but do not let it replace the part where you restate the idea in your own words.</p><p>Use AI to debug, but do not let it replace the part where you ask what broke and why.</p><p>Use AI to draft a script, but do not let it replace the part where you read the commands, run small tests, and understand the failure mode.</p><p>The goal is not to prove that you can work without AI.</p><p>The goal is to prove that AI has not taken your judgment away from you.</p><h2>The new builder has two jobs</h2><p>The first job is to create leverage.</p><p>Use the tools. Build small workflows. Ask better questions. Let the model help you move through friction. Do not romanticize slow work just because old work was slow.</p><p>The second job is to protect trust.</p><p>This is the part that separates useful builders from fast operators.</p><p>A fast operator can generate an answer.</p><p>A useful builder can say:</p><ul><li><p>This is what good means here.</p></li><li><p>This is how I checked it.</p></li><li><p>This is where the output is weak.</p></li><li><p>This is what I still do not trust.</p></li><li><p>This is the next test I would run.</p></li></ul><p>That kind of person becomes more valuable as tools get better.</p><p>Because better tools increase the amount of work moving through the system. More work means more decisions. More decisions mean more places where vague judgment becomes expensive.</p><p>This is true in code.</p><p>It is true in cloud learning.</p><p>It is true in automation.</p><p>It is true in writing.</p><p>It is true in any environment where AI can create something plausible faster than a human can review it.</p><p>Plausible is not the same as correct.</p><p>Fast is not the same as useful.</p><p>A working demo is not the same as a trusted system.</p><h2>My practical loop now</h2><p>The loop I want to build into my own learning is simple.</p><p>Before I use AI, I ask: what does good look like?</p><p>Not perfectly. Just clearly enough to avoid asking for magic.</p><p>Then I write the smallest version of the spec.</p><p>What should this script do?<br>What should this note explain?<br>What should this workflow change?<br>What should this command prove?<br>What would make the result unsafe, misleading, or useless?</p><p>Then I let AI help.</p><p>Generate the draft. Suggest the command. Explain the error. Sketch the workflow. Create the first version.</p><p>Then comes the important part.</p><p>I test the output against the definition of good.</p><p>I read it. I run it. I break it. I ask it to explain its assumptions. I compare it against docs when the detail matters. I write down what I learned. I keep the failure in the learning record instead of hiding it.</p><p>That turns AI from a shortcut into a training partner.</p><p>The tool gives me more attempts.</p><p>The verification gives me more judgment.</p><p>Without the second part, I am only outsourcing the work.</p><p>With the second part, I am increasing the number of reps I can learn from.</p><h2>The future is not no-code. It is more judgment per hour</h2><p>I do not think the useful question is whether coding is over.</p><p>That question is too dramatic to help a beginner.</p><p>The better question is:</p><p>What skill becomes more important when code is easier to produce?</p><p>My answer right now is judgment.</p><p>Technical judgment.<br>Product judgment.<br>Writing judgment.<br>Learning judgment.</p><p>The ability to define good work, create useful constraints, verify outputs, notice weak signals, and explain what changed.</p><p>That is a better career bet than chasing every tool as if the tool itself is the moat.</p><p>Tools will keep changing.</p><p>The person who can inspect, explain, test, and improve what the tools create has a better chance of changing with them.</p><p>For me, that is the real promise of learning with AI.</p><p>Not becoming someone who never struggles.</p><p>Becoming someone who can struggle at a higher level, with better feedback, clearer notes, and more useful proof.</p><h2>Final reflection</h2><p>The work is not just to generate more.</p><p>The work is to become harder to fool by what you generate.</p><p>That is the standard I want to keep in front of me. If AI gives me more speed, I want to answer with more clarity. If it gives me more drafts, I want to answer with sharper review. If it gives me more confidence, I want to answer with better tests.</p><p>Because the real danger is not that the tool becomes useful.</p><p>The real danger is that I become impressed by output before I have earned trust in it.</p>]]></content:encoded></item><item><title><![CDATA[Cloud Judgment Architecture ]]></title><description><![CDATA[AI can generate infrastructure suggestions, templates, and commands. But someone still has to decide what should be reliable, secure, observable, affordable, and worth building in the first place.]]></description><link>https://www.rateb.cc/p/cloud-judgment-architecture</link><guid isPermaLink="false">https://www.rateb.cc/p/cloud-judgment-architecture</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Fri, 24 Jul 2026 07:53:01 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b308276e-2c5b-45b4-ba4d-c7da238d5c05_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xcNc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xcNc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xcNc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xcNc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xcNc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xcNc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg" width="728" height="382.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xcNc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xcNc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xcNc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xcNc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e648c02-86b0-41bb-9426-46535c6ce866_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It is easy to look at AI-generated code, templates, and architecture suggestions and think cloud work is becoming smaller.</p><p>The model can explain a service. It can draft a Terraform file. It can compare options. It can create a checklist. It can turn a vague idea into something that looks like a deployment plan.</p><p>That is useful.</p><p>But I think it also creates a misunderstanding.</p><p>If AI makes the first version easier, the real cloud skill does not disappear. It moves.</p><p>It moves toward judgment.</p><p>Someone still has to decide what should be reliable. What should be secure. What should be observable. What should be cheap enough. What should be simple enough. What risk is acceptable. What failure would hurt the user.</p><p>That is the human architecture layer.</p><h2>The wrong map: if AI writes the config, cloud skill matters less</h2><p>This is the tempting story.</p><p>If AI can generate the command, the template, the diagram, or the explanation, then the beginner does not need to understand as much.</p><p>Just ask better. Copy the answer. Deploy faster. Let the tool handle the boring parts.</p><p>That can work in a lab for a while.</p><p>It can even make you feel like you are learning faster.</p><p>But production does not care how fluent the answer sounded.</p><p>A cloud system is not good because the configuration exists. It is good because the configuration fits the constraints.</p><p>A deployment can be technically valid and still be wrong for the business, too expensive, too fragile, too exposed, too hard to monitor, or too complicated for the team that has to maintain it.</p><p>AI can help generate options. It cannot remove the need to choose responsibly.</p><h2>The better map: architecture is organized judgment</h2><p>Architecture sounds like a senior word, but the beginner version is simple.</p><p>Architecture is organized judgment.</p><p>It is the practice of connecting a goal to constraints and deciding what tradeoffs are acceptable.</p><p>What matters most here? Speed, cost, reliability, security, simplicity, learning, compliance, user experience, recovery time, team skill, or future flexibility?</p><p>You cannot optimize all of them equally.</p><p>That is why cloud work becomes judgment work.</p><p>AI can offer a menu. It can draft a path. It can explain the service. It can even warn you about common mistakes.</p><p>But someone has to decide which tradeoff is right for this situation.</p><h2>The mechanism: generated infrastructure increases review responsibility</h2><p>When production gets easier, review becomes more important.</p><p>This is the same pattern as writing with AI. The first draft appears quickly. The value moves to seeing what is missing, what is unsafe, what is unclear, and what should be changed.</p><p>Cloud has an even stronger version of this problem because cloud mistakes can have real cost.</p><p>A misconfigured permission can expose data.</p><p>An unmonitored service can fail silently.</p><p>A poor cost decision can burn money.</p><p>A fragile architecture can break when traffic changes.</p><p>A copied command can work without the learner understanding why.</p><p>The more AI helps create infrastructure, the more the human has to understand failure modes.</p><p>Not every beginner needs to become a senior architect overnight. But every serious learner should start practicing judgment early.</p><h2>The field note: this is how I want to position my cloud learning</h2><p>For me, this changes how I want to study cloud.</p><p>I do not want to only collect commands.</p><p>Commands matter. Labs matter. Syntax matters. Knowing the services matters. But if I stop there, I am training myself to become a copy-paste operator with better tools.</p><p>The stronger path is to turn each lab into a judgment note.</p><p>Why this design? Why not another? What can fail? What would I monitor? What would make this too expensive? What permission is risky? What assumption did I make? What would I explain to a non-technical person?</p><p>That is where the learning becomes more portable.</p><p>Not because I know everything, but because I am practicing the thing AI does not automatically give me: a reasoned decision.</p><h2>The beginner version of architecture</h2><p>I do not think beginners should wait until they feel senior before practicing architecture thinking.</p><p>The beginner version is not pretending to design enterprise systems. It is asking better questions around small labs.</p><p>What is the goal? What is the simplest version that solves it? What did I expose? What did I forget to monitor? What would cost money if I left it running? What would fail if one assumption changed?</p><p>These questions are not advanced decoration. They are how you stop treating cloud as a list of services.</p><p>A service is a tool. An architecture is a decision about how tools fit a goal.</p><p>AI can help with the list of tools. It can even suggest a reasonable design.</p><p>But if I cannot explain why the design fits, I have not really learned the architecture. I have only borrowed the shape of one.</p><h2>A cloud judgment note for every lab</h2><ol><li><p><strong>Write the business goal in one sentence before touching the tool.</strong> If you cannot explain the goal, the architecture will drift.</p></li><li><p><strong>Name the constraints.</strong> Cost, reliability, security, observability, simplicity, time, and your current skill level.</p></li><li><p><strong>Use AI to draft options, but ask it to compare tradeoffs instead of only giving you steps.</strong></p></li><li><p><strong>After the lab works, write what could fail.</strong> Permissions, networking, scaling, cost, monitoring, backups, human error, or unclear ownership.</p></li><li><p><strong>End with a decision note.</strong> Why this setup, what you would change in production, and what you still do not understand.</p></li></ol><h2>Final reflection</h2><p>AI will make many parts of cloud work faster.</p><p>That does not make cloud learning pointless.</p><p>It makes shallow cloud learning easier to expose.</p><p>If all you have is commands, AI can probably outrun you.</p><p>If you are building judgment, documentation, tradeoff thinking, and the ability to explain systems clearly, AI becomes a tool inside your architecture instead of a replacement for your thinking.</p><p>The cloud learner who can explain tradeoffs will age better than the learner who only collects commands.</p>]]></content:encoded></item><item><title><![CDATA[The Simple Map Behind Every Useful Automation]]></title><description><![CDATA[The archive reminded me that useful automation starts before the tool. It starts with naming the job, the trigger, the input, the output, and the review loop.]]></description><link>https://www.rateb.cc/p/the-simple-map-behind-every-useful</link><guid isPermaLink="false">https://www.rateb.cc/p/the-simple-map-behind-every-useful</guid><dc:creator><![CDATA[Rateb Slik]]></dc:creator><pubDate>Mon, 15 Jun 2026 07:01:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lkMX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lkMX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lkMX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 424w, https://substackcdn.com/image/fetch/$s_!lkMX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 848w, https://substackcdn.com/image/fetch/$s_!lkMX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!lkMX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lkMX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png" width="1456" height="1040" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1040,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:655392,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ratebsl.substack.com/i/198396910?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lkMX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 424w, https://substackcdn.com/image/fetch/$s_!lkMX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 848w, https://substackcdn.com/image/fetch/$s_!lkMX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!lkMX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77fa6e75-8be5-4f0a-adc2-d56a28e54967_1456x1040.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I used to think the hard part of automation was choosing the right tool.</p><p>Make or n8n. ChatGPT or Claude. A voice agent or a chatbot. A scraper, a dashboard, a workflow, an API.</p><p>After turning a large automation-learning archive into a structured learning system, I see the problem differently.</p><p>The tool is not the system.</p><p>The system is the workflow you can exp&#8230;</p>
      <p>
          <a href="https://www.rateb.cc/p/the-simple-map-behind-every-useful">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>