Engineering & Life

Jayanth's Blog

Thoughts on AWS, Terraform, Kubernetes, platform engineering, and the quieter things in life.

205Posts
19Topics
2139Min of reading
Sep 5, 2026Latest
$ |
205 posts
AWS Weekly Intelligence #5 - 31 August-4 September 2026
5 September 2026 · Everything AWS shipped, 31 August – 4 September
Week 17 - An MCP Server That Answers What My AWS Account Is Doing
On 30 August I opened a bill I did not expect and asked a simple question:what is running, what is it costing, and did I leave anything behind?
Azure Weekly Intelligence #4 - 31 August-4 September 2026
Fourteen announcements, distributed unevenly: nine landed on Tuesday 1 September, two on Wednesday, one on Thursday, two on the Monday, and nothing at all on Fr…
AWS Daily Intelligence #26 - Four Bulletins in a Day, and Three of Them Are the Same Bug
AWS published four security bulletins yesterday. Two are in its own MCP servers, one is an incomplete fix for a bulletin from earlier this year, and one is in t…
GCP Weekly Intelligence #4 - 31 August-4 September 2026
The security news is the news.GCP-2026-058is rated Critical and describes a missing project permission check in the GKE Multi-Cloud APIs that let an attacker re…
GCP Architecture Series #23 — Cloud Asset Inventory: What Exists, and What Changed
Cloud Asset Inventory is reached for at exactly the moment somebody needs an answer quickly, which is also the moment its limits are least welcome.
Azure Architecture Series #24 — Deployment Scopes: Tenant, Management Group, Subscription, Resource Group
Twenty-three posts have treated the management hierarchy as a place where governance is attached: policies at a management group, role assignments at a subscrip…
AWS Architecture Series #43 — The account that watches everything
A security team is asked to consolidate. Detection tooling has grown up across three accounts, findings arrive in two consoles, and nobody can say authoritative…
Azure Architecture Series #23 — Resource Moves: What Can Move, What Cannot, and What Breaks
Every estate eventually needs to move something. A resource was created in the wrong group during a rush. A team splits and takes its workloads with it. A subsc…
Week 3 — The Pin Held. The Default Moved Anyway.
Weeks 1 and 2 built governance: a landing zone with a deny, then policies that repair what they find. Both assumed somebody was creating resources correctly in…
AWS Daily Intelligence #25 - Aurora MySQL Gets Delayed Replication, and an Hour of Lag Becomes a Recovery Window
Aurora MySQL gained two replication features yesterday, onversion 8.4.8 and higher, in all AWS Regions where Aurora MySQL is available. Multi-source replication…
Week 3 — Organization Policy on Google Cloud: Twelve Policies, or Twenty-Six?
This week is the first one that runs entirely as the CI identity Week 2 built — no human credential anywhere, applying with a role that week granted in advance.…
GCP Architecture Series #22 — The Organization Policies Worth Setting on Day One
The usual day-one list is copied from a guide, applied at the organization node, and produces one of these four surprises within a week.
Azure Architecture Series #22 — Management Locks: CanNotDelete and ReadOnly
Four posts have now been spent on Azure RBAC, and every one of them described a system that grants. Role assignments add permissions. Custom roles add permissio…
AWS Architecture Series #42 — The credential that has to work when nothing else does
At 02:40 the corporate identity provider stops answering. Every engineer in the company is federated through it, so nobody can sign in to any AWS account. There…
AWS Daily Intelligence #24 - SnapStart Reaches Container Images, and One Snapshot Becomes Every Environment
AWS Lambda SnapStart now works for functions packaged as container images, not only as ZIP archives. Same runtimes as before —Java 11 and later, Python 3.12 and…
GCP Architecture Series #21 — Dry-Run Mode: Testing a Policy Before It Denies Anything
Post #20 ended by saying no custom constraint should reach production without being watched first. This is how that is done, and the four ways it goes wrong.
Azure Architecture Series #21 — Deny Assignments, and What Replaced Blueprints
Post #18 established that Azure RBAC is additive: effective permissions are the sum of the role assignments, and a narrower assignment lower down does not tight…
AWS Architecture Series #41 — The log you cannot alter
The previous post argued that the recording controls — an organisation trail, the Config recorder, GuardDuty — have to be on from an account's first minute, bec…
AWS Daily Intelligence #23 - A Signing Key in Cleartext, and Why Upgrading the SDK Is Only Half the Fix
AWS publishedCVE-2026-83551yesterday, in the Amazon SageMaker Python SDK. An HMAC secret key is stored in cleartext within pipeline definitions and accessible v…
GCP Architecture Series #20 — Boolean, List and Custom Constraints
Every one of these comes from writing a constraint that looked obviously correct and behaved otherwise.
Azure Architecture Series #20 — Custom Roles: Assignable Scopes and Their Limits
Post #19 ended where most estates begin this conversation: the built-in roles are either too broad or too narrow, so somebody proposes a custom role. That is of…
AWS Architecture Series #40 — The controls you cannot add later
A platform team has an account baseline. It is written down, it is applied by a pipeline, and it is good. During a rush eight months ago an account was created…
AWS Daily Intelligence #22 - AWS Agent Registry Goes GA, and the Approval Queue Becomes an Allowlist
AWS Agent Registry reached general availability yesterday: a fully managed discovery service that provides a centralized catalog for organizing, curating, and d…
How was your experience?
Your feedback helps improve this site.
PoorExcellent