The architectures, drawn the way they run.
Reference blueprints from real engagements — full data flows, not marketing clouds. Every diagram here is the same style we hand clients in an assessment deliverable.
Engagement workflow — from assessment to operations.
Fixed-price assessment first, so both sides start with certainty. The same engineer carries the work through every stage.
EKS GPU platform — full data flow.
External traffic enters through zero-trust edge, the control plane schedules onto GPU and CPU pools, Karpenter buys capacity only when the queue demands it.
Agentic AI platform — orchestrator and delegates.
Not a chatbot with a system prompt: an orchestrator with memory, planning, and MCP tool access, delegating to specialized agents and looping every result through feedback before output.
Four layers of a production cloud platform — explained.
Every engagement lands somewhere in this stack. Fix capability at the right layer, and the ones above it get simpler.
Landing Zone
the foundationMulti-account AWS with guardrails as code. Accounts are cattle: vended by a factory, never hand-built.
Global Network
the fabricCloud WAN core with policy as code. Segments, not spaghetti — every region and edge attaches to one intent-driven fabric.
Runtime
the workloadEKS with GPU-aware scheduling. Karpenter buys capacity when the queue demands it, and gives it back when it doesn't.
Control Plane
the governanceNothing touches production except through a repo. Merge is the deployment; drift is detected, not discovered.
The toolbox — the right tool for the right layer.
Every tool in the reference stack earns its place at exactly one layer. When a control lives at the wrong layer, you feel it as toil everywhere above it.
| tool | layer | used for | key capabilities |
|---|---|---|---|
| entra-ididentity provider | foundation | Workforce identity and conditional access — the root of every trust decision downstream. |
|
| aws-cloud-wanglobal transit | network | One segmented, policy-driven fabric for every region and edge attachment. |
|
| zscaler-zpazero-trust access | network | User-to-app access without network access — the VPN retirement plan. |
|
| eks + karpenterorchestration | runtime | GPU-aware scheduling with capacity that follows the queue, not the forecast. |
|
| vllmmodel serving | runtime | High-throughput LLM inference that makes the GPUs earn their invoice. |
|
| terraform + spaceliftiac · gitops | control-plane | Everything above becomes a pull request — planned, gated, applied, audited. |
|
Agent orchestration patterns — pick by shape, not by framework.
Frameworks change quarterly; these five shapes don't. Choose the pattern that matches the problem, then the framework is an implementation detail.
Chain
sequentialOne step feeds the next. Right when the path is known and every request looks the same.
Orchestrator
hub · delegatesA planner delegates to specialists and owns the final answer. Right when tasks vary and quality gates matter.
Crew
role-basedNamed roles pass work through a shared queue. Right for repeatable multi-step production lines.
RAG
retrieval-augmentedGround the model in your documents before it answers. Right when correctness beats creativity.
Loop
observe · act · verifyAct, check the result against an external signal, repeat until it truly passes. The unit of real agency.
Production agent guardrails — six layers a prompt can't replace.
A safe agent isn't a better system prompt. It's a request passing through six independent control layers, each of which can stop it, before any tool touches the real world.
Input Screening
before the llmCatch the request that shouldn't reach the model at all.
Context Verification
trust the right contextOnly feed the model data this user is allowed to see.
Response Generation
ground the llmConstrain what the model can reach while it reasons.
Output Validation
check before it leavesNothing ships without passing an external check.
Tool & Action Guardrails
critical for agentsThe layer a prompt can never enforce: what the agent may actually do.
Operational Guardrails
protect the platformKeep one bad run from taking the platform — or the invoice — with it.
Agentic AI containment — the threat model.
An autonomous agent that can reach the internet and run code is a supply-chain actor. Here is how a containment breach propagates — and the control at each hop that ends it.