~/blueprints

The architectures, drawn the way they run.

Reference blueprints from real engagements — full data flows, not marketing clouds. Every diagram here is the same style we hand clients in an assessment deliverable.

blueprint/01

Engagement workflow — from assessment to operations.

Fixed-price assessment first, so both sides start with certainty. The same engineer carries the work through every stage.

$ flow --engagement
01 02 03 04 assess/ fixed-price · 2-3 wks roadmap/ prioritized · costed build/ terraform · gitops operate/ runbooks · sre
blueprint/02

EKS GPU platform — full data flow.

External traffic enters through zero-trust edge, the control plane schedules onto GPU and CPU pools, Karpenter buys capacity only when the queue demands it.

$ flow --eks-gpu-platform
client anywhere zero-trust-edge zpa · entra-id ingress alb · waf EKS CONTROL PLANE api-server eks · 1.31 etcd state scheduler gpu-aware GPU NODE POOL · p4d/g6e vllm-pod tensor-parallel training-pod mig · slices CPU NODE POOL · m7i agents-pod mcp · tools api-pod gateway otel-collector traces · gpu-util grafana slo · cost karpenter spot · od mix
external traffic control plane data plane
blueprint/03

Agentic AI platform — orchestrator and delegates.

Not a chatbot with a system prompt: an orchestrator with memory, planning, and MCP tool access, delegating to specialized agents and looping every result through feedback before output.

$ flow --agentic-platform
orchestrator-llm vllm · eks-gpu client query memory/ tools · mcp/ planning/ feedback/ coding-agent retrieval-agent infra-agent output/
blueprint/04

Four layers of a production cloud platform — explained.

Every engagement lands somewhere in this stack. Fix capability at the right layer, and the ones above it get simpler.

1

Landing Zone

the foundation

Multi-account AWS with guardrails as code. Accounts are cattle: vended by a factory, never hand-built.

control-toweraccount-factoryscpidentity-center
org-management control-tower account: prod account: staging account: sandbox guardrails/ scp · config · iam
2

Global Network

the fabric

Cloud WAN core with policy as code. Segments, not spaghetti — every region and edge attaches to one intent-driven fabric.

cloud-wansegmentspolicy-as-codeinspection
us-east-1 segment: prod cloud-wan core-network us-west-2 segment: dr
3

Runtime

the workload

EKS with GPU-aware scheduling. Karpenter buys capacity when the queue demands it, and gives it back when it doesn't.

ekskarpentergpu-operatorvllm
ingress alb · waf eks-cluster gpu-scheduler vllm-pods p4d · spot
4

Control Plane

the governance

Nothing touches production except through a repo. Merge is the deployment; drift is detected, not discovered.

gitopsplan-gatesdrift-detectionaudit-trail
git-merge reviewed plan-gate policy · cost apply automated drift-detection loop
$ takeaway — a platform is not one control. It is four layers, each governed as code, each simplifying the one above it.
blueprint/05

The toolbox — the right tool for the right layer.

Every tool in the reference stack earns its place at exactly one layer. When a control lives at the wrong layer, you feel it as toil everywhere above it.

$ matrix --toolbox
toollayerused forkey capabilities
entra-ididentity provider foundation Workforce identity and conditional access — the root of every trust decision downstream.
  • sso · mfa
  • conditional-access
  • workload-identity
aws-cloud-wanglobal transit network One segmented, policy-driven fabric for every region and edge attachment.
  • core-network-policy
  • segments · routing
  • multi-region
zscaler-zpazero-trust access network User-to-app access without network access — the VPN retirement plan.
  • app-connectors
  • policy-per-app
  • inspection · dlp
eks + karpenterorchestration runtime GPU-aware scheduling with capacity that follows the queue, not the forecast.
  • gpu-operator · mig
  • spot · consolidation
  • node-pools
vllmmodel serving runtime High-throughput LLM inference that makes the GPUs earn their invoice.
  • paged-attention
  • tensor-parallel
  • openai-compatible
terraform + spaceliftiac · gitops control-plane Everything above becomes a pull request — planned, gated, applied, audited.
  • plan-gates · policy
  • drift-detection
  • audit-trail
identify entra-id connect cloud-wan · zpa run eks · vllm govern terraform · spacelift everything returns to the control plane
blueprint/06

Agent orchestration patterns — pick by shape, not by framework.

Frameworks change quarterly; these five shapes don't. Choose the pattern that matches the problem, then the framework is an implementation detail.

1

Chain

sequential

One step feeds the next. Right when the path is known and every request looks the same.

deterministiccheapeasy-to-test
prompt agent tools out
2

Orchestrator

hub · delegates

A planner delegates to specialists and owns the final answer. Right when tasks vary and quality gates matter.

planningdelegationquality-gate
orchestrator plans · verifies research-agent coding-agent review-agent
3

Crew

role-based

Named roles pass work through a shared queue. Right for repeatable multi-step production lines.

roleshandoffsshared-state
writer editor task-queue shared state deliverable
4

RAG

retrieval-augmented

Ground the model in your documents before it answers. Right when correctness beats creativity.

embeddingsvector-storegrounding
docs load · parse index vectors retrieve top-k llm
5

Loop

observe · act · verify

Act, check the result against an external signal, repeat until it truly passes. The unit of real agency.

external-verifystop-ruleself-correcting
observe act verify tests · ci repeat until the check passes
$ takeaway — most production systems are two of these composed: an orchestrator whose delegates each run a loop.
blueprint/07

Production agent guardrails — six layers a prompt can't replace.

A safe agent isn't a better system prompt. It's a request passing through six independent control layers, each of which can stop it, before any tool touches the real world.

$ pipeline --request-lifecycle
request 1 · screen 2 · verify 3 · generate 4 · validate 5 · act
1

Input Screening

before the llm

Catch the request that shouldn't reach the model at all.

prompt-injectionjailbreakpii-detectionrate-limitssafe-fallback
2

Context Verification

trust the right context

Only feed the model data this user is allowed to see.

doc-authorizationrag-source-validationpii/phi-filteringtenant-isolation
3

Response Generation

ground the llm

Constrain what the model can reach while it reasons.

grounded-ragtool-access-policytoken/context-limitsmodel-routing
4

Output Validation

check before it leaves

Nothing ships without passing an external check.

groundednesshallucination-detectionpii-leakageschema-validationretry-fallback
5

Tool & Action Guardrails

critical for agents

The layer a prompt can never enforce: what the agent may actually do.

tool-allowlistleast-privilegeread-vs-writetransaction-limitshuman-approval
6

Operational Guardrails

protect the platform

Keep one bad run from taking the platform — or the invoice — with it.

concurrency-limitscircuit-breakerstoken-budgetscost-limitsaudit-logging
$ takeaway — the prompt shapes intent; the harness decides capability. Fix safety in layers 5 and 6, never in the prompt.
blueprint/08

Agentic AI containment — the threat model.

An autonomous agent that can reach the internet and run code is a supply-chain actor. Here is how a containment breach propagates — and the control at each hop that ends it.

$ threat-model --agent-containment
ai-agent sandboxed package-proxy allowed egress path open-internet public services model-registry poisoned dataset cluster-credentials internal-clusters lateral movement protected-data-store objective reached escape exfil route supply-chain inject harvest pivot egress-deny no default-out allowlist-only named hosts signed-artifacts verify provenance short-lived-creds nothing to harvest segmentation no lateral path
attack path mitigating control
$ takeaway — the model is never the vulnerability; the harness is. Deny egress by default, verify every artifact, keep credentials short-lived, and segment the blast radius — break any one hop and the chain dies.