<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DevOps on Thalamus</title><link>https://blog.thalamus.am/tag/devops/</link><description>Recent content in DevOps on Thalamus</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Thalamus TM</copyright><lastBuildDate>Sat, 18 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.thalamus.am/tag/devops/index.xml" rel="self" type="application/rss+xml"/><item><title>The apply is still mine</title><link>https://blog.thalamus.am/posts/the-apply-is-still-mine/</link><pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate><guid>https://blog.thalamus.am/posts/the-apply-is-still-mine/</guid><description>&lt;img src="https://blog.thalamus.am/posts/the-apply-is-still-mine/editorial-cover.png" alt="Featured image of post The apply is still mine" /&gt;&lt;p&gt;Claude Code writes a useful share of my Terraform now. It drafts Helm values, reviews GitOps configuration and helps me write runbooks. I still decide which changes reach production.&lt;/p&gt;
&lt;p&gt;The useful output is a diff I can review. Getting that diff faster doesn&amp;rsquo;t remove the need to understand it.&lt;/p&gt;
&lt;p&gt;My workflow keeps commits, pushes and deployment commands with me. Claude Code&amp;rsquo;s permissions help enforce that split. But a list of blocked commands is only part of the control: a tool that has production credentials may have more than one way to use them.&lt;/p&gt;</description></item></channel></rss>