Engineering & Life

Jayanth's Blog

Thoughts on AWS, Terraform, Kubernetes, platform engineering, and the quieter things in life.

247Posts
19Topics
2630Min of reading
Sep 15, 2026Latest
$ |
247 posts
AWS Daily Intelligence #32 - The table had two writers and no owner
AWS Glue zero-ETL integrations now detect table property conflicts and track integration ownership , announced on Sunday.
GCP Architecture Series #33 — Allow Policies, Bindings, and the Union Rule
#31 covered principals and #32 covered roles. This post is the object that joins them, and it has exactly one arithmetic operation: addition.
Azure Architecture Series #34 — App Registrations and Service Principals
Phase 2 has spent three posts on human identity: what it costs, how it is contained, how it is automated. This post is the turn to workload identity, and it sta…
AWS Architecture Series #53 — The write was atomic. The event was not.
The previous post established idempotency — the property that makes an at-least-once pipeline safe to consume. This one is about getting the events into that pi…
GCP Architecture Series #32 — Roles: Basic, Predefined and Custom
Post #31 took one half of a binding. This is the other half, and the half where most of the received wisdom is now out of date.
Azure Architecture Series #33 — Dynamic Membership Rules
Post #32 left a principle hanging: a rule that writes membership is a rule that writes privilege . That was an inference from why role-assignable groups forbid…
AWS Architecture Series #52 — The retry you did not write
The last four posts were about money. This one opens a different block — the patterns that decide whether a distributed system is correct — and it starts with t…
GCP Architecture Series #31 — IAM Principals: Users, Groups, Domains and Service Accounts
The principal is the half of a policy nobody reviews. All four of these come from choosing the wrong kind, or from not knowing what counts.
Azure Architecture Series #32 — Users, Groups and Administrative Units
The Azure resource model taught one reflex above all others: a container passes things down . A policy assigned at a management group applies to every subscript…
AWS Architecture Series #51 — The alarm rings after the money is gone
The last three posts were about what things cost, who owes it, and who gets the discount. This one is about the control that was supposed to prevent the convers…
AWS Weekly Intelligence #6 - 7-11 September 2026
Four working days, because Monday was Labor Day and the What’s New feed returned nothing at all. They still produced 53 announcements , and the most consequenti…
Week 18 - EKS Self-Service: A Namespace Is Not a Boundary
A developer needs somewhere to run a container. In most organisations that is a ticket: somebody senior creates a space on the cluster, sets limits so the new t…
Week 4 — Vending a Subscription Takes Four Minutes. Getting Rid of One Takes Three Days.
The bootstrap for this lab created three subscriptions by hand, one at a time, watching each one finish. That is fine for three. It is not fine for an organisat…
Azure Weekly Intelligence #5 - 7-11 September 2026
Eight announcements across five days, two a day from Tuesday to Friday and none on Monday — the flattest and thinnest week this series has covered. The announce…
AWS Daily Intelligence #31 - The denylist had fewer spellings than the address
AWS published CVE-2026-89049 on Thursday: a server-side request forgery in the Session Manager port forwarding functionality in SSM Agent, affecting every versi…
Week 4 — Shared VPC on Google Cloud: The Identity I Built Could Not Do This Week
This week was number twelve until nine days ago. It moved, and the reason is a dependency the original order had backwards.
GCP Weekly Intelligence #5 - 7-11 September 2026
162 notes, the lightest week this series has covered, and the most thematically consistent. VPC Service Controls is the thread: the Cloud Trace Observability AP…
GCP Architecture Series #30 — Landing Zone Design for a Real Organisation
The blueprint is an opinionated target architecture, but a real organisation may already have identity, networking, governance and workload decisions that const…
Azure Architecture Series #31 — Entra ID Editions: Free, P1, P2, and What Each Unlocks
Phase 1 of this series took the Azure resource model apart over thirty posts, and in all of them the question of price came up exactly once, in passing, on quot…
AWS Architecture Series #50 — Bought in one account, spent in another
The previous post built an allocation model: tags for what can be labelled, backfill for what was labelled late, split charge rules for what has no single owner…
AWS Daily Intelligence #30 - One bit that says whether it is AWS, and it is not ready today
On 10 September AWS extended the network health indicator to paths that cross a Transit Gateway inter-Region peering connection. It exists to settle the argumen…
GCP Architecture Series #29 — The Enterprise Foundations Blueprint, Section by Section
The blueprint is usually met as a repository somebody cloned, and all four of these follow from treating it as a template rather than as a sequence.
Azure Architecture Series #30 — Landing Zones and the Cloud Adoption Framework Accelerator
This series began with management groups and subscriptions, and has spent twenty-nine posts on the mechanisms underneath an Azure estate: policy, RBAC, locks, d…
AWS Architecture Series #49 — The bill does not divide
The previous post was about what logging costs. This one is about the question that follows every cost conversation eventually: whose is it?
How was your experience?
Your feedback helps improve this site.
PoorExcellent