Field notes

The SAMURAI Blog

Practical writeups on multi-vendor networks, fabric design, change detection, and the engineering behind running thousands of endpoints through one pipeline.

SHA-256
Engineering2026-05-20

How we detect changes without relying on audit logs

How stripping volatile fields and hashing the rest eliminates false-positive diffs, and why timestamp-based comparisons fail at scale.

8 min readRead
Deep Dive2026-05-06

Multi-vendor path tracing: the hard parts

Tracing a packet across IOS, NX-OS, and PAN-OS means reconciling three different ACL syntaxes, two route table formats, and zero shared conventions.

12 min readRead
Architecture2026-04-22

Correlating 13,000 endpoints without a CMDB

MAC tables, ARP, DHCP snooping, CDP/LLDP, 802.1X, and APIC hosts: stitched together in the right order, they replace a stale spreadsheet.

10 min readRead
SP1SP2LF1LF2LF3LF4
Operations2026-04-08

APIC clustering: failover without the flapping

Configurable thresholds, cooldown windows, and atomic database operations keep your ACI fabric monitored even when controllers go down.

7 min readRead
Product2026-03-25

From six browser tabs to one dashboard

The operational pain that started SAMURAI, and the design decisions that let a single pane of glass replace Cisco Prime, Panorama, FMC, and SSH terminals.

6 min readRead
#
Operations2026-03-11

Deploying SAMURAI in air-gapped environments

Docker image pull, offline IEEE OUI database, and TLS certificate pinning: everything you need to run SAMURAI without internet access.

9 min readRead

Field notes, straight to your inbox.

Deep dives on multi-vendor architecture, fabric design, change-detection algorithms, and the engineering behind SAMURAI.

Occasional emails, only when there is something worth reading. Unsubscribe any time.