Biotech Software Engineering Blog

Architecture diagram showing trust boundaries in a confidential computing system for biotech data processing
Security Cloud Computing Confidential Computing Biotech Architecture

Zero-Knowledge Architecture for Your Lab

Teddy Kalp
Teddy Kalp
Posted on Mar 13, 2026

You've decided your biotech data needs processing-time encryption. Now comes the hard part: choosing a key ownership model, defining trust boundaries, and building an architecture your compliance team and your bioinformaticians can both live with.


Hardware security module representing AWS Nitro Enclave isolation for biotech data processing
Security Cloud Computing Confidential Computing Biotech AWS

AWS Nitro Enclaves for Biotech Data

Teddy Kalp
Teddy Kalp
Posted on Mar 01, 2026

Your genomics pipeline decrypts data into plaintext memory every time it runs. AWS Nitro Enclaves fix that. Here's how the architecture works and what it means for proteomics, genomics, and clinical workloads.


Secure server infrastructure representing confidential computing for biotech data
Security Cloud Computing Confidential Computing Biotech

Why Biotech Can't Trust the Cloud

Teddy Kalp
Teddy Kalp
Posted on Feb 03, 2026

A pharmaceutical company has 50TB of genome data and AWS could process it in days. But their legal team says no. Here's why biotech can't trust the cloud and how confidential computing and hardware-enforced security fixes it.


The MicroK8s project logo
Pipelines DevOps

Setting up NF Core with MicroK8s

Teddy Kalp
Teddy Kalp
Posted on Feb 01, 2025

A step-by-step guide on setting up and running Nextflow workflows on a MicroK8s Kubernetes cluster, demonstrating how to leverage Terraform provisioning, persistent storage, and containerized execution to enable scalable, reproducible scientific data analysis, including executing NF Core pipelines for streamlined bioinformatics and genomics research.


The Galaxy Project logo
Pipelines DevOps

Use Case: The Galaxy Project

Teddy Kalp
Teddy Kalp
Posted on Jan 15, 2025

A step-by-step guide to deploying the Galaxy Project, a scalable, web-based computational workbench for scientific workflows, on an AWS EC2 instance using Terraform, Kubernetes, Helm, and CVMFS, enabling researchers to efficiently analyze complex datasets in a cloud-based environment.


The CernVM File System (CVMFS) project logo
DevOps

Putting it All Together: CVMFS In Action

Teddy Kalp
Teddy Kalp
Posted on Jan 14, 2025

A step-by-step guide to setting up Nextflow on a MicroK8s Kubernetes cluster for scientific data processing, enabling scalable, reproducible, and modular computational workflows.


The Kubernetes and Helm project logos
DevOps

Kubernetes and Helm: Orchestration

Teddy Kalp
Teddy Kalp
Posted on Jan 13, 2025

A step-by-step guide to setting up a Kubernetes cluster with integrated CVMFS (CERN Virtual Machine File System) support on MicroK8s, leveraging Helm for streamlined deployment, configuring persistent storage with NFS, and ensuring efficient data access for high-performance workloads.


The HashiCorp Terraform logo
DevOps

Terraform: Provisioning AWS with Code

Teddy Kalp
Teddy Kalp
Posted on Jan 12, 2025

A step-by-step guide on using Terraform to deploy an AWS EC2 instance for a MicroK8s Kubernetes cluster, covering prerequisites, security setup, configuration files, and automation best practices.


Server racks representing automated DevOps infrastructure
DevOps

DevOps: What? Why? How?

Teddy Kalp
Teddy Kalp
Posted on Jan 11, 2025

Explore how DevOps practices enhance the deployment and management of CVMFS by automating complex processes, improving collaboration, and leveraging tools like Docker, Terraform, AWS, and Kubernetes to create a scalable, efficient, and reproducible development environment.