Making AI reviews useful in pull requests
AI code review becomes noisy quickly on busy pull requests. These are the patterns I would use for managed comments, finding identity, severity, evidence and merge gates.
Building better platforms with Azure, GitHub, Terraform and AI
AI code review becomes noisy quickly on busy pull requests. These are the patterns I would use for managed comments, finding identity, severity, evidence and merge gates.
Part 1 covered the consumption side of an AI gateway: rate limits, token quotas, usage attribution and the telemetry needed to understand them. The next runtime decision is whether a request should be allowed through at all, followed by whether that consumer is entitled to use the model it asked for. Those are separate controls, … Read more
How I would use Azure API Management to control AI request rates and token consumption, attribute usage, emit useful telemetry and handle backend throttling.
Azure Policy and API Management solve different parts of AI governance in Azure. This post goes into the actual policies and APIM XML behind that two-layer model, covering network controls, approved models, token quotas, content safety and observability.
An Azure AI Landing Zone should make the governed route the easiest route for delivery teams. This post covers how Azure API Management, Azure Policy, identity, networking, quotas, telemetry and clear ownership boundaries work together to control AI consumption without turning the platform team into an approval bottleneck.
Agent skills are only useful if the agent knows when to use them. A clear description acts as selection metadata, helping the agent load the right guidance, avoid noisy context, and produce more consistent results across repeated engineering tasks.
A quick HolmesGPT demo using Azure AI Foundry, Azure OpenAI and a local kind cluster. Deploy a deliberately broken Kubernetes pod, ask HolmesGPT to investigate it, and see how it identifies the root cause from the pod spec, scheduler events and cluster state.
Agent skills, custom instructions, and MCP configuration are becoming part of the engineering trust boundary. This post walks through using NVIDIA SkillSpector in GitHub Actions to scan AI skill repositories, surface findings in SARIF or PR comments, and make risky agent behaviour visible during normal review.
AI-assisted engineering is moving beyond “can the agent do the task?” and into the same practical concerns platform teams already deal with: cost visibility, ownership, observability, governance, repeatable workflows, and sensible defaults.
This post looks at why AI engineering needs boring platform controls, from APIM policies and token visibility through to Agent Skills, MCP, Terraform modules, OpenTelemetry, and evaluation loops.
AI-assisted engineering is moving beyond proving that agents can complete tasks. The harder question is whether those workflows can be repeated, reviewed safely, kept within sensible cost, and improved over time.
This post looks at why platform teams need to treat AI usage as more than activity metrics, with a focus on token visibility, repeatable agent skills, controlled context, practical guardrails, and measurement that connects AI-assisted work to real engineering outcomes.