Blog

EKS Learning Plan

EKS Learning Plan — Native Ubuntu 26.04 Host, Single-Host Local Cluster

Revision: targets a native Ubuntu 26.04 LTS (“Resolute Raccoon”) workstation. No WSL, no Git Bash, no second machine. One host runs the control plane and the worker nodes for all local work; AWS runs the control plane only during paid EKS sessions.

Model: the EKS cluster is cattle. It exists only while you are actively typing into it. Idle cost target is $0.00/day.

Read more →

Zscaler Private Access (ZPA) Architecture

Zscaler Private Access (ZPA) Architecture

ZPA is a cloud-delivered Zero Trust Network Access (ZTNA) service that brokers per-application access between users and private applications, without ever placing those applications on the public internet or putting the user on the corporate network.

ZPA Archtitecture

Core components

ComponentWhere it runsRole
Client Connector (Z-App)User’s deviceAuthenticates the user against your IdP and checks device posture before requesting a session
Policy engine (Central Authority)Zscaler cloudEvaluates identity, device posture, group membership, time of day, etc. and authorizes (or denies) each session
Service Edge (Public / Private / Microtenant)Zscaler cloud (or your site, for Private Service Edge)Brokers the connection — stitches the user’s tunnel and the App Connector’s tunnel together
App ConnectorYour data center or cloud VPC, next to the appLightweight VM/container that dials outbound to the Service Edge; never accepts inbound connections

How a connection is brokered

  1. The Client Connector authenticates the user and checks device posture, then dials outbound to the Service Edge.
  2. The App Connector, sitting next to the private application, also dials outbound to the Service Edge.
  3. The Service Edge stitches these two outbound-only streams together into a single brokered session, after the Policy engine has authorized it.
  4. No inbound port is ever opened on either side — the app has no public IP, no public DNS record, and isn’t discoverable by internet scanners.

This “double inside-out tunnel” is what lets ZPA give a user access to exactly one authorized application instead of broad network reach, the way a VPN would.

Read more →