Engineering & Life

Jayanth's Blog

Thoughts on AWS, Terraform, Kubernetes, platform engineering, and the quieter things in life.

347Posts
19Topics
3915Min of reading
Oct 7, 2026Latest
$ |
347 posts
AWS Daily Intelligence #48 - The client cannot tell which path it took
ACM now supports “AWS PrivateLink for ACME public certificate issuance, allowing you to request and renew public TLS certificates over a private network path th…
GCP Architecture Series #55 — Organization-Level Roles, and the Super Admin Problem
Seven posts in a row have turned up the same thing. #51: super admins bypass single sign-on, so IdP-enforced MFA does not apply to them. #53: exclude an Organiz…
Azure Architecture Series #55 — Cross-Tenant Access: Trusting Someone Else's MFA
#53 covered what a guest is and who may invite one. This is the layer underneath it, and it is the one that actually decides whether a partner can get in: cross…
AWS Architecture Series #75 — Passing because there was nothing to check
#43 built the account these findings land in, and #74 was about what a GuardDuty severity does and does not encode. This is the same question asked of the numbe…
AWS Daily Intelligence #47 - The failures were the part that was not logged
AWS Private CA now emits IssueCertificateDetails , described as “a new AWS CloudTrail service event that records the complete certificate content, issuing CA in…
GCP Architecture Series #54 — Privileged Access Manager and Just-in-Time Elevation
Every post since #31 has been about narrowing standing access, and #52 ended on the idea that expiry beats revocation because it turns an urgent action into a d…
Azure Architecture Series #54 — External ID: A Separate Tenant, and a Different Feature Set
#53 was about partners in your own directory. This is about the other external population entirely: the people who use your product. They are not guests, they a…
AWS Architecture Series #74 — The low findings are what make the critical one
#43 built the account that receives these findings and #45 covered turning detection on across an organisation. Both leave you with the same problem: a queue, a…
GCP Architecture Series #53 — Context-Aware Access
Everything up to #52 answered "who is this principal". This post is the next question: under what conditions should the answer still be yes. It is the right que…
Azure Architecture Series #53 — B2B Collaboration: What a Guest Is Before You Grant Anything
Every tenant has guests, and most organisations acquired them without a decision being made. Somebody shared a Teams channel, a SharePoint site or a Power BI re…
AWS Architecture Series #73 — The label that stops every rotation after it
#16 answered the placement question — when a value belongs in Secrets Manager rather than Parameter Store — and concluded that rotation is the capability you ca…
GCP Architecture Series #52 — Google Groups as the Unit of Access
Twenty-one posts have been building toward this one. #49 recommended groups over direct bindings, #51 noted that a group in a binding can contain people you do…
Azure Architecture Series #52 — Entra Domain Services Versus Domain Controllers on VMs
The last three posts have been about an on-premises directory feeding a cloud tenant. This one inverts the premise: you have an application that needs Kerberos,…
AWS Architecture Series #72 — The permission you can run out of
#5 established the rule that governs KMS access: the key policy is the authoritative control, and IAM grants nothing the key policy has not also permitted. This…
Week 21 - Blue/Green on ECS: The Rollback That Never Had To Happen
You have a website running. You want to put a new version of it live. The obvious way is to stop the old one and start the new one, which means a gap where the…
AWS Weekly Intelligence #9 - 28 September-2 October 2026
79 announcements across five working days , weighted heavily towards security and governance, with Wednesday 30 September carrying 25 of them on its own. Five d…
GCP Weekly Intelligence #8 - 28 September - 2 October 2026
217 notes across 61 products and five days, against 132 last week — and the security bulletins returned after two quiet weeks, with three disclosures all landin…
Azure Weekly Intelligence #8 - 28 September-2 October 2026
Thirty-nine announcements across five working days, and the shape of them is unusual: eight were retirements and nineteen were SQL-family . The SQL concentratio…
AWS Daily Intelligence #46 - The most cautious deployment the API accepts cannot finish
ECS now offers blue/green, linear and canary deployments for services using VPC Lattice , “enabled for both new and existing ECS services in all AWS Regions whe…
GCP Architecture Series #51 — Single Sign-On with a Third-Party Identity Provider
#50 covered provisioning: getting accounts into Cloud Identity from an on-premises directory. This is the other half of the same pattern. The SAML mechanics are…
Azure Architecture Series #51 — Seamless SSO: One Computer Account Holds the Whole Thing
#50 ended on the writeback direction. This post is about a feature that goes the other way again and is easy to dismiss, because it is free, it is a checkbox in…
AWS Architecture Series #71 — Every CA certificate expiry is an outage with a date on it
#70 closed by saying that Roles Anywhere moves half your authorisation decision into your PKI. This is that PKI. And the thing about a private CA is that creati…
AWS Daily Intelligence #45 - A Regional override replaces the default, it does not extend it
GuardDuty now supports AWS Organizations declarative policies, so you can “centrally enable GuardDuty threat detection across every account and Region in your A…
GCP Architecture Series #50 — Directory Synchronisation from On-Premises
#49 established that an IAM binding names an identity, and that the account behind it is resolved in Cloud Identity. This post is about how accounts get into Cl…
How was your experience?
Your feedback helps improve this site.
PoorExcellent