Writing
In random intervals I write things and publish them on the internet. Some of the things can be helpful, others are just rants. I try to collect these writings here and keep an archive.
You can also subscribe to the RSS feed to be notified when new posts are published.
2026
- Self-hosted Umami analytics on Azure Container AppsFor the last 2-3 years I have been using Umami.is to track the tiny bit of website analytics I am interested in. It has served me well, it's nice and easy, and I do like that it only collects anonymous information (as in: doesn't track client IPs), but after I moved all the images in the Photography section to its own website the limitations of the free tier was a bit frustrating. I don't need many of its features, but I want to track more than 1 website. I could of course just create multiple accounts, but that would be cheating, and I would need to swap between logins to view the different sites.
- Renewed (and relieved)Once a year, a little less than 4000 Microsoft MVP's have minor breakdowns, on what some just call "F5 day" (because they are obsessively refreshing their inbox), while others barely notice something is going on until all kinds of group chats wake up from hibernation in the middle of a lazy summer. This year, this day was July 15, and I'm happy (and judging from the myriad of LinkedIn posts the lingo is "humbled and honored") to be renewed for another year. Same category, same technology area, and honestly I was a little bit surprised I got the congratulatory email and not the sad goodbye.
- All vibes, no QA!The week before easter I visited Microsoft's HQ in Redmond for the annual MVP Summit. Naturally, as you probably expect, the topic of everything AI was almost impossible to avoid (I tried) and when I woke up on Saturday morning, with hours to spare before we had to drag our weary butts and heavy luggage to the airport I was having some shower thoughts: There must be something in this whole AI thing right? "Everyone" who's raving about the amazing opportunities and possibilities can't all be wrong, can they?
- Replacing Terraform (for fun and profit?)The client I’m currently spending most (all) of my working time with have a lot of Terraform code. And I mean a lot. Like, you will spend a solid amount of time getting an overview of where everything is before you start being productive, a lot.
- A new colophon for 2026You might be unfamiliar with the word “colophon”, and I admit it’s pretty niche. Merriam Webster’s definition is: “an inscription at the end of a book or manuscript usually with facts about its production”. And because it’s a new year, and I spent the weekend cooking up a big batch of changes to this website it’s only fair to include a post on how it’s built, and my reasoning behind the choices I made.
- Great technology should be invisible and nice to useI was thinking about that Steve Jobs keynote from 2007 where Apple launched the iPhone this week. If you have been living in a cave, or for various other reason haven’t seen it you can watch it on YouTube: Steve Jobs MacWorld Keynote in 2007. I wasn’t thinking about it in some kind of romantic nostalgic way though. I just remembered the (small) group of telecom analysts that got out of their beds on the wrong side and started to spew out words on how shit Apple’s new device was. The specs were bad! it didn’t have 3G! It didn’t support MMS (archaic service to send grainy dick pics)! Pro-users wanted a keyboard with buttons! $400 was soooo expensive! ad nauseam…
- homelab automation with pyinfraDuring the Christmas break I crawled into the storage / datacenter / Harry Potter-esque bedroom under my stairs and retrieved an Intel Nuc that had been powered off for a year++, added an additional SSD, and installed Arch Linux to setup a small lab for learning new things and brushing up forgotten skills.
- DNSSEC and DNS child zones in AzureBefore christmas holidays set in we had a feature request in my work life where owners of a landing zone in Azure wanted access to manage records in public dns. After a bit of thinking, discussions with the team posting the request, and understanding their use case better we discovered that what they really wanted was to not deal with the existing process of manually ordering/renewing a publicly trusted certificate, store it in a key vault, and then forget about it until it expired one year later. Instead they wanted to automate the process with Let's Encrypt. In the end we settled on a design where the subscription vending has a feature flag for enabling a DNS child zone in the new subscription and create the necessary delegations in the parent zone. This essentially gives a team a subdomain with its own DNS zone they have full control over, while also not creating any complicated role assignments to avoid granting too wide credentials and allow someone to modify records outside of their own scope.
2025
- Configure settings for EntraID roles in Privileged Identity Management with TerraformWhen I last wrote about the new msgraph provider for Terraform my conclusion was that the preview release was not yet really usable, partly due to missing features. Well, one month later, and version 0.2.0 was shipped this week with one major update to change a lot of that and help us solve some (imho) pretty big problems with the old azuread provider
- A new terraform provider for Entra IDLast month, in the middle of everyone's summer holidays, Microsoft released a new Terraform provider for the Graph API. I have been waiting for this for quite some time after first hearing about the development in one of the "Terraform on Azure" community calls. (which you can sign up for at https://aka.ms/aztfcommunity), as I have been a bit annoyed and frustrated with the existing provider maintained by Hashicorp.
2024
- Add an overview of Terraform changes to GitHub ActionsI have had a small itch for a while when using GitHub Actions to run Terraform deployments where I had no easy way to get a very quick overview of which resources that will be created, changed, or deleted if I approve and merge a pull request. So I spent a little time scratching that itch and figuring out a small solution using Python to parse the output of terraform plan and direct the output to GitHub's job summary.
- Azure subscription vending machine with Github and TerraformThis week we kicked off the first of six events in our Atea Community tour and I am lucky enough to be asked to host a session again this year. With more time, and a more technical fun stuff!
- Don’t try to sell me a Ferrari when I’m looking for a FiatWith irregular intervals I notice streaming providers, especially the ones that have paid wild amounts of money for broadcasting rights to the most valuable sports events, turn on their lobbying machine and produce variations of the same story: Don’t use IPTV, you’re supporting organized crime. And every single time I get slightly annoyed.
- Writing better and more re-usable code in TerraformOver the years I have, on numerous occasions, received questions from colleagues or customers if I could help them out with a bit of QA or tips on some Terraform code they have written. Typically these questions comes from people who have recently started using infrastructure as code, gone through the tutorials, deployed their first workloads, and are now hitting their first problems where their code starts to become harder to maintain and they feel like automation isn't giving them the increased productivity and quality of life the marketing promised.
- I reinvented the wheel, againIt is somewhat of a trend of mine. As time goes by, my urge to reinvent the wheel and "fix" my website by completely rewriting the whole things is asymptotic to one. So this is a summary of how, and why, I did it this time around.
.old
- Use archetype_config_overrides to set role assignments in Azure landing zones Terraform moduleUsing terraform-azurerm-caf-enterprise-scale and custom landing zone archetypes makes it easy to modify role assignments by using the access_control block under parameters. To set role assignments for the built-in management groups is a bit different, and not very clearly documented in the repository wiki.
- Assign policy definitions from Azure landing zones Terraform moduleA little while back I spent an hour or so writing an Azure policy, only to discover that the Azure landing zones Terraform module already has a policy definition that does exactly what I wanted to accomplish, but no assignments linked to it. It took me another hour of confusion and frustration to figure out how to actually assign the policy, as there is a step I completely overlooked. So here is a quick summary of how to use these policies so you can save yourself the trouble.
- Own your own contentFor some time I have reflected over the evolution of social media and their efforts to present me with content I am not interested in. Maybe I am somewhat special kind of grumpy, but the amount of “Suggested posts”, reels, recommended posts, etc. that is presented to me when I open an app instead of giving me a chronological feed of content from the people I actively choose to follow only makes me disengaged and less likely to publish anything at all.
- Use the AzAPI provider to deploy Virtual Network Manager with TerraformI believe most of us who works with Azure have felt the frustration of managing virtual networks as they grow in complexity. It’s easy to make mistakes when configuring peering and route tables and end up spending too much time running queries in Network Watcher to figure out what’s going on. Azure Virtual Network Manager aims to make this a lot easier and let us configure both Hub-Spoke and Mesh networks, as well as central management of security rules for all virtual networks.
- Azure Static Web Apps, gohugo.io and TailwindCSSRecently I spent a few (too many) hours to rebuild my personal website. It still use Hugo and Tailwind CSS, but I have changed hosting from using a storage account in Azure to using Azure Static Web Apps. The change has brought along some limitations, but it has also made the build pipeline a lot easier.
- Pi-hole and Docker on MacOS to get rid of pesky advertisingWhen I'm at home I have setup a Raspberry Pi to run [Pi-hole](https://pi-hole.net/) and block pesky advertising. But. I am not always at home. I also bring my Macbook to work, customers, airports & hotels. I didn't want to clutter up my system and install Pi-hole natively, so instead I used [Docker](https://docs.docker.com/docker-for-mac/) To make starting/stopping Pi-hole easier I created a small shell script:
- Static Website Hosting With Azure and HugoEarlier this summer Microsoft announced Static Website Hosting for Azure Storage in public preview. An affordable way of hosting websites where you don’t need any server side logic. Instead of paying for, securing and updating my own Virtual Machine I decided to check it out. This of course led me deep down a rabbit hole thinking about resurrection my personal website in some way.
- Certificates with Ansible, Letsencrypt and CloudflareThe example use Cloudflare for DNS, but any provider with an ansible module works.