- Infrastructure
- Where it hidesResources created by hand in one provider's console, known only to whoever clicked them.
- InsteadTerraform or OpenTofu in your repository, reviewed and applied like any other code.
- Compute
- Where it hidesBuild and deploy steps written against a single platform's proprietary tooling.
- InsteadOCI container images that Kubernetes, Cloud Run or ECS can all run unchanged.
- Data
- Where it hidesProprietary database features in the hot path, with no tested way to get the data out.
- InsteadPostgres where it fits, migrations in version control, and an export you have actually restored.
- Observability
- Where it hidesOne vendor's agent and query language woven through every service.
- InsteadOpenTelemetry instrumentation, so the backend that stores it is a configuration choice.
- Payments
- Where it hidesCheckout, webhooks and stored cards written directly against one processor's API.
- InsteadA gateway seam in your own code, and the processor's data-export route documented before you need it.
- Secrets and access
- Where it hidesCredentials pasted into vendor dashboards, with no record of what uses them.
- InsteadOne secret manager, referenced by name, rotated on a schedule you can see.