Blog

Notes from the keyboard.

Short, specific posts on real problems we hit -- and how we solved them.

FortiGate

FortiOS 7.4 silently breaks LDAPS against self-signed CAs

Setting ca-cert now auto-enables server-identity-check. Two-line fix; thirty-minute root cause.

2026-05-18
Cisco IOS-XE

Nine gotchas after upgrading a Cat9K fleet in install-mode

The 6-hour auto-abort, the install_commit invoke_shell, U vs C state, and six more lessons we wrote up after the project closed.

2026-05-21
Terraform

Importing AWS Secrets Manager without clobbering live creds

If you use ignore_secret_changes=true, you must import both the secret and its version resource -- or the first apply silently overwrites the running password.

2026-04-30
Talk to an engineer →