
The Infrastructure Decisions That Are Hardest to Undo
Learn which infrastructure decisions are hardest to undo, from storage and networking to identity, integrations, data location, and APIs.
Read field noteField notes / Latest
Engineering notes from operating open infrastructure: the failures, design decisions, and upstream work that make open infrastructure better.
Browse all field notes
Learn which infrastructure decisions are hardest to undo, from storage and networking to identity, integrations, data location, and APIs.
Read field note
Learn how to safely upgrade production GPU infrastructure across NVIDIA drivers, CUDA, Kubernetes, firmware, containers, and AI workloads.
Read field note
Your cloud bill is only part of the cost. Learn how operations, licensing, data movement, utilization, and migration affect cloud TCO.
Read field noteEliminate static API keys and credential sprawl with our open-source Vault and OpenBao plugin that generates short-lived OpenStack application credentials on demand—now with multi-project support.
Today we're releasing major updates to our OpenStack Secrets Engine. The plugin now works with both HashiCorp Vault and OpenBao.
Static API keys are a liability. They end up scattered across config files, CI/CD pipelines, and environment variables. When credentials don't expire, neither does your exposure window.
Our secrets engine flips this model. Applications request credentials when they need them, use them immediately, and watch them expire minutes later.
No rotation schedules. No keys to track. No emergency revocations after incidents.
user_domain_id and project_domain_name match standard tooling.Dynamic credentials change the audit conversation. Instead of explaining rotation policies and access reviews, you demonstrate that credentials physically cannot be long-lived.
Every request is authenticated, authorized, and logged. This aligns with zero-trust principles that SOC 2, ISO 27001, and PCI DSS frameworks increasingly expect.
The plugin is Apache 2.0 licensed. We built it because we needed it—we run it in production on VEXXHOST infrastructure.
Installation takes minutes. See the README for details.
Choose from Atmosphere Cloud, Hosted, or On-Premise.
Simplify your cloud operations with our intuitive dashboard.
Run it yourself, tap our expert support, or opt for full remote operations.
Leverage Terraform, Ansible or APIs directly powered by OpenStack & Kubernetes