At Cloudflare, we are heavy users of ClickHouse, an open-source analytical database management system. We redesigned one of our largest ClickHouse tables to add a column to the partitioning key. The change enabled per-tenant retention on a table that serves hundreds of internal teams. The design went through several rounds of revision and review with engineers across multiple teams before we landed on the final approach. But a few weeks after rollout, the jobs that produce most of Cloudflare's bills were running up against their hard daily deadline.
All the usual suspects looked clean: I/O, memory, rows scanned, parts read. Everything we would normally check when a ClickHouse query is slow appeared to be normal. The problem turned out to be lock contention in query planning, something we'd never had reason to look for before.
This is the story of how this migration exposed a hidden bottleneck in ClickHouse's internals, and the patches we wrote to fix it.
We use ClickHouse to store over a hundred petabytes of data across a few dozen clusters. To simplify onboarding for our many internal teams, we built a system called "Ready-Analytics" in early 2022.
The premise is Continue reading
In a previous blog post, I described the ARP issues you’ll encounter when using centralized routing (on a spine switch) between two EVPN MAC-VRF instances (a fancy name for a VLAN encapsulated in VXLAN or MPLS).
That blog post established a baseline that will help us unravel the ARP behavior in a more realistic scenario: asymmetric Integrated Routing and Bridging (IRB). That’s a mouthful, but it’s really quite a simple concept; the following diagram explains the asymmetric forwarding behavior:

Packet forwarding in an EVPN asymmetric IRB design
We’re excited to announce the release of Calico Open Source v3.32! 
This release corresponds with Kubernetes v1.36 (Codename Haru) and it goes beyond just sharing a cat as the mascot of the release, it actually extends capabilities and features of Kubernetes to keep you up to date with the latest innovations of the cloud.

This release brings some of the most significant architectural changes in Calico, from live-migrating KubeVirt VMs to eBPF based Maglev load balancer.
Here’s a quick look at everything that’s new:
Breaking Changes & DeprecationsAdminNetworkPolicy and BaselineAdminNetworkPolicy have been removed. You must migrate to ClusterNetworkPolicy before upgrading to v3.32, as Calico will no longer enforce the old resources.calico-apiserver Deprecated: The aggregated API server is deprecated and will be removed in a future release. It is being replaced by Native v3 CRDs. (Requires MutatingAdmissionPolicy feature gate, Kubernetes 1.30+).
Key Feature UpdateskubeVirtVMAddressPersistence: Enabled Continue reading
The biggest AI story of 2026 isn’t the growing need for electrical power or the ridiculous way the market sold out for RAM based on a letter of intent to acquire. No, the biggest AI story of the year so far is how a scrappy little project completely upset the AI apple cart. OpenClaw (nee ClaudeBot, nee OpenMolt) set the world on fire. And it destroyed how people were trying to direct AI. I’m sitting over here giggling about it.
The basics of OpenClaw are simple enough. You have a system of agents that do things. It can read your texts or email and triage the flow of information. It can send you a text summary of the news or the weather every morning. But it can also be configured to monitor things as they arrive to deal with them on the fly. That’s where the real narrative shift has happened.
When you open a browser window to talk to an LLM you are creating a session that has a finite time limit. You are saying that you are going to work on a project for a specific period of time and that’s that. Once you complete Continue reading
We’ve enabled higher usage limits, faster performance, and better reliability for Browser Run by rebuilding on top of Cloudflare’s Containers.
You can now spin up 60 browsers per minute via the Workers binding and run up to 120 concurrently — 4x the previous limit. Also, Quick Action response times dropped more than 50%. You don't need to change anything: these improvements are live today. On top of that, we’re shipping fixes and new features faster than before. Read on to learn how we did it and see the data.
Browser Run enables developers to programmatically control and interact with headless browser instances running on Cloudflare’s global network. That’s useful for end-to-end testing of web applications, securely investigating suspicious URLs, and leveraging how browsers can easily render PDF documents, amongst other quick actions like capturing screenshots and extracting content. More recently, it’s become a critical enabler of AI agents to interact with the web. We’re building Browser Run to be the go-to platform to responsibly utilize automated browsers securely at massive scale.
Before adopting Cloudflare Containers, we shared infrastructure with Browser Isolation (BISO). While technically similar, BISO’s larger container images slowed Continue reading
The second demo1 I did during the Segment Routing workshop @ ITNOG10 illustrated how easy it is to set up and explore a small SR-MPLS network with netlab. The lab topology described a small three-router network (you need three routers to see “true” labels besides the penultimate-hop popping ones):
Berkendara di jalan menanjak dan turunan memerlukan teknik khusus agar tetap aman dan nyaman. Baik bagi pengendara motor maupun mobil, kondisi jalan seperti ini seringkali menantang konsentrasi dan keterampilan. Artikel ini akan membahas tips aman berkendara di jalan menanjak dan turunan yang wajib Anda ketahui untuk menghindari risiko kecelakaan dan menjaga keselamatan selama perjalanan.
Jalan menanjak dan turunan memiliki karakteristik yang berbeda dari jalan datar. Pada tanjakan, mesin kendaraan bekerja lebih keras untuk mengatasi medan yang lebih berat. Sedangkan di turunan, kendaraan cenderung melaju lebih cepat karena gravitasi, sehingga rem bekerja lebih intensif.
Kesalahan kecil seperti salah menginjak pedal gas atau rem bisa berakibat fatal. Oleh karena itu, penting untuk memahami teknik berkendara yang benar agar tetap aman.
Sebelum berkendara di tanjakan yang curam, pastikan kondisi kendaraan Anda optimal, terutama:
Saat menghadapi jalan menanjak, gunakan gigi rendah agar tenaga mesin lebih besar. Hal ini membuat kendaraan tidak cepat kehilangan tenaga dan memudahkan pengendalian.
Lagu kebangsaan menjadi simbol persatuan dan identitas suatu bangsa. Bagi Indonesia, lagu Indonesia Raya bukan hanya sekadar lagu, tetapi juga merupakan representasi dari semangat dan cita-cita kemerdekaan. Artikel ini akan membahas sejarah lagu Indonesia Raya serta makna yang terkandung di dalamnya.
Lagu Indonesia Raya diciptakan oleh Wage Rudolf Supratman pada tahun 1928. Saat itu, Indonesia masih berada di bawah penjajahan Belanda, dan lagu ini mengobarkan semangat perjuangan kemerdekaan di kalangan pemuda dan rakyat Indonesia.
Lagu ini pertama kali diperdengarkan pada Kongres Pemuda II yang digelar pada 28 Oktober 1928, bertepatan dengan momen bersejarah Sumpah Pemuda. Lagu Indonesia Raya menjadi lambang persatuan bangsa yang beraneka ragam suku, budaya, dan bahasa. Melalui lagu ini, para pemuda menyuarakan tekad untuk bersatu dalam satu tanah air, satu bangsa, dan satu bahasa: Indonesia.
Setelah diciptakan, lagu Indonesia Raya menjadi alat mobilisasi yang kuat dalam memperjuangkan kemerdekaan. Lagu ini sering dinyanyikan dalam berbagai kesempatan rahasia untuk mengobarkan semangat nasionalisme.
Namun, karena dianggap berbahaya oleh pemerintah kolonial Belanda, lagu ini sempat dilarang untuk diperdengarkan secara luas. Walaupun demikian, lagu ini tetap hidup di hati para pejuang kemerdekaan hingga akhirnya Indonesia meraih kemerdekaan Continue reading
The biggest addition in v26.02 is a complete set of BGP diagnostics and visibility tools. These give network administrators new insights into routing behavior directly within NFA. The new BGP diagnostics panel introduces ping and traceroute checks, allowing engineers to run connectivity and path diagnostics without leaving the NFA interface. Additionally, a BGP Data Lookup feature enables direct queries against NFA’s internal BGP tables, supporting exact-match and more-specific match modes for precise prefix investigations. Finally, BGP History Lookup provides access to historical route events, including key attributes such as prefix, next-hop, AS path, and more. This makes it easier to trace routing changes over time and connect them with traffic events.


In part one, we covered the basics of pytest and wrote our first network tests. We tested BGP and OSPF on a single device, then extended it to multiple devices. We also looked at parametrization and how it helps treat each device and each neighbour as an independent test.
In this part, we will cover inventory management with Nornir and pytest fixtures.

Nornir is a Python automation framework designed for network engineers. Instead of writing your own logic to connect to devices, manage inventory, and run tasks in parallel, Nornir handles all of that for you. We have a dedicated series on Nornir, which you can check out here, so we are not going to do a deep dive in this post.
The reason we are using Nornir here is for inventory and task management. Instead of hardcoding a list of IP addresses in our collection file, we define our devices in a hosts file with groups, credentials, and Continue reading