What’s underneath your app.
I’m Peter Wiggers. I studied civil engineering at TU Delft, where you learn to read the ground before you build on it. Then I spent thirteen years doing the same in IT, building the cloud platforms that banks, logistics companies and regulated SaaS quietly depend on.
So this blog is drawn like a soil survey. Every topic is a layer, from the AI growing at the surface down to the security that everything rests on.
Drill log
Stop rebuilding your CI runner on every push
Stateless CI runners made builds clean, and then made us write caching logic into every workflow. Warm microVM snapshots give you a disposable runner that already remembers everything.
Sovereignty is an exit, not an address
Hosting with a European company doesn't make you sovereign. Being able to leave whenever you want does. Let's turn that into a standard providers can be certified against.
One private network for my clusters, my colleagues and my living room
Why I love Tailscale, and how I use it to reach Kubernetes APIs, Postgres, colleagues' machines and my Home Assistant setup without opening a single port.
Use the cloud, just don't let your code know which one
My one rule against vendor lock-in. Only use managed open source, so your application talks PostgreSQL, RabbitMQ and Kubernetes, and never a cloud SDK.
Warm standby beat multi-cloud, and it wasn't close
A regulated customer asked for multi-cloud resilience. What they actually needed was a second region and a rehearsed failover.
Your requests and limits are where the cloud bill hides
How right-sizing Kubernetes workloads cut public cloud spend by roughly 40% across thirty-odd clusters.
Pick an LLM provider you can walk away from
Notes on designing AI features for a regulated SaaS where auditability matters more than the leaderboard.
What two SOC 2 cycles taught me about security engineering
Compliance frameworks are mostly about proving you do what you say. Here's how to make that cheap.