<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Sergey Kravchenko</title>
    <description>The latest articles on DEV Community by Sergey Kravchenko (@krawa76).</description>
    <link>https://dev.to/krawa76</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F345970%2Faa3309fe-515e-49c6-a0d0-88f6457e51e4.jpeg</url>
      <title>DEV Community: Sergey Kravchenko</title>
      <link>https://dev.to/krawa76</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/krawa76"/>
    <language>en</language>
    <item>
      <title>How We Manage More Than 11,000 Application Configuration Parameters</title>
      <dc:creator>Sergey Kravchenko</dc:creator>
      <pubDate>Wed, 07 Oct 2026 19:34:58 +0000</pubDate>
      <link>https://dev.to/krawa76/how-we-manage-more-than-11000-application-configuration-parameters-21f2</link>
      <guid>https://dev.to/krawa76/how-we-manage-more-than-11000-application-configuration-parameters-21f2</guid>
      <description>&lt;p&gt;At AutoFi, we operate a containerized microservices infrastructure across several architectural stacks and multiple environments. Hundreds of services run on Amazon ECS and are built and supported by several development teams.&lt;/p&gt;

&lt;p&gt;Most service configuration is provided through environment variables backed by AWS Systems Manager Parameter Store. Across our infrastructure, we manage more than 11,000 parameters.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fm6b61rzslyke64k7tn14.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fm6b61rzslyke64k7tn14.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We have historically operated with a very small DevOps team, so it is no surprise that managing this many parameters eventually became a significant challenge.&lt;/p&gt;

&lt;p&gt;Some of our main problems were:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DevOps became a bottleneck whenever a developer needed to retrieve or update a parameter.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;There was no convenient way to view, sort, and filter multiple parameter names and values.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Searching for a parameter name across AWS accounts, regions, and other infrastructure locations was difficult.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Searching by parameter value required exporting all parameters and searching the resulting file.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Comparing configuration across services and environments was cumbersome - for example, determining the difference between the staging and production configurations of the &lt;code&gt;consumer&lt;/code&gt; service.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;We could not easily copy parameters in bulk between services or environments - for example, copying all &lt;code&gt;consumer&lt;/code&gt; parameters from staging to UAT.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;We could not schedule parameter changes and automatic rollbacks - for example, enabling debug logging temporarily and returning to the normal log level two hours later.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;After several rounds of automation, we arrived at the following design:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Separate secrets from parameters that can be considered public within our organization.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Store secrets in a secrets manager (third party) and synchronize them one-way to the infrastructure parameter store. Secrets remain under DevOps control, and developers do not have direct read or write access to their values.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Store non-secret parameters in a separate database that supports searching by name and value, then synchronize them one-way to the infrastructure parameter store.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Allow developers to view all non-secret parameters and change parameters in non-production environments. Production changes are submitted for DevOps approval.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Record every change in an audit log and send a notification to our &lt;code&gt;#infrastructure&lt;/code&gt; Slack channel.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;We implemented the missing data layer and user interface as a new Infrastructure Configuration subsystem in our internal DevOps Portal.&lt;/p&gt;

&lt;p&gt;Here is what it looks like.&lt;/p&gt;

&lt;h2&gt;
  
  
  Parameter List
&lt;/h2&gt;

&lt;p&gt;The main page allows users to view parameter names and values for any combination of stack, environment, and application. They can sort and filter the list by name or value, as well as add parameters, edit them, and attach comments.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhyu7auz5co9z943vtgly.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhyu7auz5co9z943vtgly.png" alt=" " width="800" height="739"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Approval Workflow
&lt;/h2&gt;

&lt;p&gt;If a parameter belongs to a group that requires approval - for example, parameters in a production environment - the change is placed in an approval queue.&lt;/p&gt;

&lt;p&gt;These groups are configurable in the Portal settings. The DevOps team receives a Slack notification and can review and approve the update before it proceeds.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw95oo4v861g2szrpnlks.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw95oo4v861g2szrpnlks.png" alt=" " width="800" height="819"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhk5jlqsbwtwpxvsoh8ew.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhk5jlqsbwtwpxvsoh8ew.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Synchronization
&lt;/h2&gt;

&lt;p&gt;Approved changes are not applied to the infrastructure immediately. Instead, they accumulate on the &lt;code&gt;Sync&lt;/code&gt; tab until someone starts the synchronization process manually.&lt;/p&gt;

&lt;p&gt;We chose this approach so that multiple changes can be synchronized together, minimizing the number of service restarts. Services that depend on the modified parameters are restarted automatically after the new values are written to the infrastructure.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fi7ui2ubel05wlxxa2jh5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fi7ui2ubel05wlxxa2jh5.png" alt=" " width="798" height="266"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Configuration Comparison
&lt;/h2&gt;

&lt;p&gt;One common task is comparing the configuration of the same service across environments - for example, finding the differences between the staging and production configurations of the &lt;code&gt;consumer&lt;/code&gt; service.&lt;/p&gt;

&lt;p&gt;We exposed configuration data through our DevOps Portal MCP server and use an AI agent to perform these comparisons using natural-language requests.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwbmzyi198kyjq22h05n3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwbmzyi198kyjq22h05n3.png" alt=" " width="800" height="446"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Scheduled Changes and Automatic Rollbacks
&lt;/h2&gt;

&lt;p&gt;A parameter update can also be scheduled for a specific time. Optionally, the Portal can restore the previous value automatically after a specified period.&lt;/p&gt;

&lt;p&gt;For example, we can temporarily increase application logging verbosity and then automatically return the log level to normal, reducing the risk that someone forgets to revert it and allowing us to control pressure on our log ingestion and storage systems.&lt;/p&gt;

&lt;p&gt;Scheduling is also useful when several related parameters must be changed - and later rolled back - at the same time.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3cjidxttmn7sjib8mxpm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3cjidxttmn7sjib8mxpm.png" alt=" " width="800" height="920"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Bulk Copy
&lt;/h2&gt;

&lt;p&gt;When creating a new service or environment, we often need to copy an existing configuration and use it as a starting point.&lt;/p&gt;

&lt;p&gt;The bulk-copy workflow lets users select a source stack, environment, and application; choose the destination; and specify how existing parameters should be handled.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frmqlnwsz41tdgebu7r1i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frmqlnwsz41tdgebu7r1i.png" alt=" " width="800" height="412"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Text Editor
&lt;/h2&gt;

&lt;p&gt;For operations involving many parameters, users can switch to text-editor mode and add or update parameters in bulk using a simple &lt;code&gt;NAME = VALUE&lt;/code&gt; format.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7hb3q81his43wpjfteqs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7hb3q81his43wpjfteqs.png" alt=" " width="800" height="585"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Representing Secrets as&amp;nbsp;Symbols
&lt;/h2&gt;

&lt;p&gt;We use a separate system and workflow to manage secrets. However, developers still need to know which configuration entries exist, including entries whose values they are not allowed to access.&lt;/p&gt;

&lt;p&gt;To provide a complete view without exposing sensitive data, we introduced a parameter type called a &lt;code&gt;symbol&lt;/code&gt;. A symbol has a name but no value in the Portal.&lt;/p&gt;

&lt;p&gt;A daily automation pipeline retrieves secret names - but never their values - from the infrastructure and imports them into the Portal through its API. Developers can therefore see the complete configuration structure while the actual secret values remain protected.&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;Building the Infrastructure Configuration subsystem required meaningful architecture and development effort, but it changed how configuration management works across our organization.&lt;/p&gt;

&lt;p&gt;Developers can now independently search, review, compare, copy, and initiate changes to most application configuration. At the same time, DevOps retains control over secrets, production approvals, infrastructure synchronization, and auditing.&lt;/p&gt;

&lt;p&gt;For our small DevOps team, this has removed a significant operational bottleneck while giving development teams faster and more transparent access to the configuration they depend on.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://waitlist.devopsportal.ai" rel="noopener noreferrer"&gt;DevOps Portal private beta&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Originally published in &lt;a href="https://medium.com/autofi-devops/how-we-manage-more-than-11-000-application-configuration-parameters-12c74fcbe687" rel="noopener noreferrer"&gt;AutoFi DevOps on Medium&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>devops</category>
      <category>aws</category>
      <category>ai</category>
      <category>cloud</category>
    </item>
  </channel>
</rss>
