Aws
- I answered 114 AWS Well-Architected Review questions from my terminal
- I replaced the AWS CLI completer with a datalake
- FinOps portfolio: 71 tickets over 5 years
- Three holes in the partition wall
- One module block per service per tenant
- Every tool I've ever used is a CloudFormation frontend
- from feature_flags import *
- The Allow SCP that worked until it didn't
- The $233 Day, Part 2: The Inference Iceberg
- The $173 Training Run
- Your employees are tenants and you should bill them like it
- I assumed GovCloud was AWS with a different region code. It took two weeks to prove me wrong.
- I debugged a Lambda timeout for 6 hours. The fix was 4 CLI commands.
- Zero-touch multi-tenant deploys: removing myself from the critical path
- Per-Tenant CloudWatch Log Isolation on EKS, or: Why I Stopped Using aws-for-fluent-bit
- Why we removed aws-for-fluent-bit from EKS
- Stop copying AWS managed policies — deny what you don't want instead
- The IAM policy controls access — the document controls how people feel about it
- IAM trust policies silently accept wildcards in principals — and silently deny everything
- IAM eventual consistency is 4 seconds — if your policy still doesn't work, you have a bug
- The Over-Mighty Subject: why your site repos have too much power
- I replaced $489/mo in AWS Client VPN with a $3 t4g.nano running Headscale
- Cross-repo auto-deploy with GitHub Actions: the orchestrator pattern
- Your CI/CD dispatch token can rewrite your infrastructure code
- Your terraform apply is silently rolling back your container images
- Terraform module for multi-provider DNS: define once, deploy to Route53 + Cloudflare
- ElastiCache auth-token to RBAC migration has a Terraform provider bug
- Amazon WorkSpaces are invisible to SSM and CloudWatch (and how to fix it)
- SimpleAD is Samba 4 — you can create users with ldapadd instead of ClickOps
- What building infrastructure for a startup actually looks like
- 90 AWS resources in 5 minutes — automating multi-tenant SaaS tenant lifecycle
- Your ACM certificate request is a beacon — scanners are watching Certificate Transparency logs