Guardrails That Hold: RAI Filters & a Governed MCP Gateway
Part 2 of the governed AI platform: a custom RAI content filter with harm thresholds, plus an MCP gateway that tiers tool access.
Read articleInfrastructure as Code • Security & Compliance • DevOps Automation
My experiences building with Microsoft Azure,
IaC and DevOps automation.
Day-to-day learnings, Azure updates, and practical solutions from the field.
timo@azure ~ % whoami Cloud & DevOps Engineer · Netcloud, CH timo@azure ~ % cat stack.txt Azure · IaC · Security · DevOps · AI agents timo@azure ~ %
Part 2 of the governed AI platform: a custom RAI content filter with harm thresholds, plus an MCP gateway that tiers tool access.
Read articleAzure CW33 2026: the Firewall Premium deny-mode throughput numbers, Markdown for Agents in App Service, and MAI-Thinking-1 in Microsoft Foundry.
How I built an internal AI platform on Microsoft Foundry with governance first: data residency, secret-less identity, and central audit.
Azure CW32 2026: Trusted Launch on by default for new Gen2 VMs, the cc_v5 confidential VM retirement on September 1st, and Firewall explicit proxy GA.
Six areas I write about most, straight from client work
Platform services, features, and field notes.
Reusable modules, patterns, and automation.
Zero Trust, identity, and hardening.
Policy-as-code, compliance, landing zones.
CI/CD pipelines and delivery automation.
Foundry, agents, and governed AI platforms.
Production Azure insights from someone who ships cloud solutions daily
I design and deploy Azure landing zones, governance frameworks, and security architectures for real businesses. Learn from implementations, not tutorials.
Deep dives into Microsoft Defender, Sentinel, zero-trust design, and compliance automation. See how enterprise security actually gets built.
Terraform modules, Bicep templates, and CI/CD pipelines I actually use. Battle-tested code from production environments.
Cloud engineer building secure, scalable Azure infrastructure
Architecting multi-tenant Azure environments, implementing security controls, and automating everything with IaC. I turn complex requirements into reliable cloud solutions.
Writing technical guides, creating open-source stuff, and sharing lessons learned. Helping cloud engineers solve real problems faster.
Weekly blog posts breaking down Azure updates, troubleshooting production issues, and documenting implementations. Building a community that learns together.
Whether you're looking for cloud architecture expertise, need guidance on Azure best practices, or want to explore technical insights on my blog, I'm here to help.