<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Part 3: Designing for Scale and Reliability on Designing Network Automation at Scale</title><link>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/</link><description>Recent content in Part 3: Designing for Scale and Reliability on Designing Network Automation at Scale</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 14:10:38 +0200</lastBuildDate><atom:link href="https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/index.xml" rel="self" type="application/rss+xml"/><item><title>10 - Platform Engineering and CI/CD</title><link>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/10-platform-engineering/</link><pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate><guid>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/10-platform-engineering/</guid><description>&lt;h1 id="10-platform-engineering-and-cicd">10. Platform Engineering and CI/CD&lt;a class="anchor" href="#10-platform-engineering-and-cicd">#&lt;/a>&lt;/h1>
&lt;p>A network engineer at a mid-size financial services firm needed to modify a firewall rule to allow a new internal service to reach an authentication endpoint. The change itself took about ten minutes to understand and design. What followed was different. She needed to open a ticket in the ITSM system and fill out a form that asked questions her team had never agreed on. She needed to submit a change request to a separate portal, which triggered a workflow that sent an automated notification to a stale distribution list. She needed to manually run a validation script on her laptop, copy the output into a comment on the ticket, and wait for a reviewer to read it.&lt;/p></description></item><item><title>11 - Scaling and Reliability</title><link>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/11-scaling-and-reliability/</link><pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate><guid>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/11-scaling-and-reliability/</guid><description>&lt;h1 id="11-scaling-and-reliability">11. Scaling and Reliability&lt;a class="anchor" href="#11-scaling-and-reliability">#&lt;/a>&lt;/h1>
&lt;p>The firmware upgrade had been planned for three weeks.&lt;/p>
&lt;p>Eight hundred campus switches, three vendors, a maintenance window from midnight to 6 AM. The automation platform was well-tested on the campus fleet. The team had run smaller upgrades through it before. Forty-eight workers ran in parallel, chosen to balance speed against device load. At midnight, the job started.&lt;/p>
&lt;p>By 2:14 AM, 47 of the 48 workers had completed. Seven hundred and eighty-seven switches had been upgraded successfully. The forty-eighth worker was still running. The orchestrator showed it as active; no error had been raised. One of the devices it was targeting was not responding to any management plane query, but it had not explicitly rejected the connection either. The worker was waiting for a response that was not going to arrive.&lt;/p></description></item><item><title>12 - Security, Governance and Compliance</title><link>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/12-security-and-compliance/</link><pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate><guid>https://designingnetworkautomation.com/series/part3-designing-for-scale-and-reliability/12-security-and-compliance/</guid><description>&lt;h1 id="12-security-governance-and-compliance">12. Security, Governance and Compliance&lt;a class="anchor" href="#12-security-governance-and-compliance">#&lt;/a>&lt;/h1>
&lt;p>The audit finding arrived on a Tuesday morning.&lt;/p>
&lt;p>A PCI compliance review had examined six months of firewall change history across the organization&amp;rsquo;s network. The auditors had a straightforward request. For each of the firewall changes: who authorized it, what change ticket it was associated with, evidence that pre-deployment validation occurred, and the network state before and after.&lt;/p>
&lt;p>The automation platform had made 847 changes to the firewall configuration during those six months. It had made them correctly. The validation logic had been tested and applied. The rollback procedures had worked in the two cases where they were needed. No production incident had been caused by automation during that period. By every operational metric, the platform had performed well.&lt;/p></description></item></channel></rss>