Engineering & Life

Jayanth's Blog

Thoughts on AWS, Terraform, Kubernetes, platform engineering, and the quieter things in life.

197Posts
19Topics
2020Min of reading
Sep 4, 2026Latest
$ |
197 posts
Azure Architecture Series #23 — Resource Moves: What Can Move, What Cannot, and What Breaks
Every estate eventually needs to move something. A resource was created in the wrong group during a rush. A team splits and takes its workloads with it. A subsc…
Week 3 — The Pin Held. The Default Moved Anyway.
Weeks 1 and 2 built governance: a landing zone with a deny, then policies that repair what they find. Both assumed somebody was creating resources correctly in…
AWS Daily Intelligence #25 - Aurora MySQL Gets Delayed Replication, and an Hour of Lag Becomes a Recovery Window
Aurora MySQL gained two replication features yesterday, onversion 8.4.8 and higher, in all AWS Regions where Aurora MySQL is available. Multi-source replication…
Week 3 — Organization Policy on Google Cloud: Twelve Policies, or Twenty-Six?
This week is the first one that runs entirely as the CI identity Week 2 built — no human credential anywhere, applying with a role that week granted in advance.…
GCP Architecture Series #22 — The Organization Policies Worth Setting on Day One
The usual day-one list is copied from a guide, applied at the organization node, and produces one of these four surprises within a week.
Azure Architecture Series #22 — Management Locks: CanNotDelete and ReadOnly
Four posts have now been spent on Azure RBAC, and every one of them described a system that grants. Role assignments add permissions. Custom roles add permissio…
AWS Architecture Series #42 — The credential that has to work when nothing else does
At 02:40 the corporate identity provider stops answering. Every engineer in the company is federated through it, so nobody can sign in to any AWS account. There…
AWS Daily Intelligence #24 - SnapStart Reaches Container Images, and One Snapshot Becomes Every Environment
AWS Lambda SnapStart now works for functions packaged as container images, not only as ZIP archives. Same runtimes as before —Java 11 and later, Python 3.12 and…
GCP Architecture Series #21 — Dry-Run Mode: Testing a Policy Before It Denies Anything
Post #20 ended by saying no custom constraint should reach production without being watched first. This is how that is done, and the four ways it goes wrong.
Azure Architecture Series #21 — Deny Assignments, and What Replaced Blueprints
Post #18 established that Azure RBAC is additive: effective permissions are the sum of the role assignments, and a narrower assignment lower down does not tight…
AWS Architecture Series #41 — The log you cannot alter
The previous post argued that the recording controls — an organisation trail, the Config recorder, GuardDuty — have to be on from an account's first minute, bec…
AWS Daily Intelligence #23 - A Signing Key in Cleartext, and Why Upgrading the SDK Is Only Half the Fix
AWS publishedCVE-2026-83551yesterday, in the Amazon SageMaker Python SDK. An HMAC secret key is stored in cleartext within pipeline definitions and accessible v…
GCP Architecture Series #20 — Boolean, List and Custom Constraints
Every one of these comes from writing a constraint that looked obviously correct and behaved otherwise.
Azure Architecture Series #20 — Custom Roles: Assignable Scopes and Their Limits
Post #19 ended where most estates begin this conversation: the built-in roles are either too broad or too narrow, so somebody proposes a custom role. That is of…
AWS Architecture Series #40 — The controls you cannot add later
A platform team has an account baseline. It is written down, it is applied by a pipeline, and it is good. During a rush eight months ago an account was created…
AWS Daily Intelligence #22 - AWS Agent Registry Goes GA, and the Approval Queue Becomes an Allowlist
AWS Agent Registry reached general availability yesterday: a fully managed discovery service that provides a centralized catalog for organizing, curating, and d…
GCP Architecture Series #19 — Organization Policy Service: Constraints and How They Inherit
Organization Policy is usually adopted after an incident, in a hurry, and the four surprises below all arrive in the first fortnight.
Azure Architecture Series #19 — The Built-in Roles Worth Knowing, and the Ones Routinely Misused
Post #18 established the mechanics: three elements, additive permissions, no subtraction. This post is about the part everyone actually touches — the role picke…
AWS Architecture Series #39 — The account the guardrails cannot reach
A company has done the multi-account work properly. There are eighty accounts under an organisation, arranged into OUs by environment and business unit, and the…
GCP Architecture Series #18 — Resource Naming Standards That Survive Three Years
Naming looks like the cheapest decision in a platform build and it is the one with the longest half-life. Four things go wrong, and all four are discovered long…
Azure Architecture Series #18 — Azure RBAC: Role Definitions, Assignments and Scope
Four posts on Azure Policy have built a particular set of reflexes: a definition states a rule, an assignment binds it to a scope, exclusions carve holes, and l…
AWS Architecture Series #38 — Three analyzers, three questions
A security team decides to get systematic about IAM. They turn on Access Analyzer across the organisation, in every Region, with every analyzer type available,…
GCP Architecture Series #17 — Labels Versus Tags: Two Systems That Look Alike and Are Not
The confusion is reasonable. They are both key-value pairs, both attach to resources, and the console puts them near each other. Then four things happen that ma…
Azure Architecture Series #17 — Deny, Audit or deployIfNotExists: Choosing an Effect
Three posts have circled this choice. #14 listed the eleven effects and the fixed order they run in. #15 showed how each one lands in a compliance percentage. #…
How was your experience?
Your feedback helps improve this site.
PoorExcellent