Home Resume
Engineering & Life

Jayanth's Blog

Thoughts on AWS, Terraform, Kubernetes, platform engineering, and the quieter things in life.

143Posts
19Topics
1223Min of reading
Aug 23, 2026Latest
$ |
143 posts
Azure Architecture Series #6 — Regions, Geographies and Sovereign Clouds: Where Your Data Actually Lives
A team stands up its first Azure environment in the region the tutorial used. Eighteen months later two things arrive in the same week. Legal asks, for a custom…
GCP Architecture Series #5 — Project IDs: The Name You Only Get to Choose Once
A platform team is standing up its first dozen projects. Someone asks what to call them, the question feels like bikeshedding, and they agree a pattern in ten m…
AWS Daily Intelligence #12 - The Sign-In Page Changed, and Only Your Scripts Will Notice
AWS is redesigning the console sign-in page. The visible change is the entry point: instead of choosingRoot userorIAM userbefore you type anything, you enter an…
AWS Architecture Series #25 — Oracle to Aurora PostgreSQL: What "Converted" Actually Means
The reason for the project is the licence. Move off Oracle, onto Aurora PostgreSQL, stop paying. The assessment comes back saying most of the schema conve…
Azure Architecture Series #5 — Resource Types and API Versions: The Dependency You Pin Without Noticing
A team has a Bicep file that has deployed storage accounts cleanly for three years. Someone reads the documentation for a property that hardens the account, add…
GCP Architecture Series #4 — Enabling Services: The Project Surface Nobody Decided
An architecture review asks a platform team a reasonable question: which Google Cloud services does your platform use? They expect to answer it from Terraform,…
AWS Architecture Series #24 — Cutover, Rollback, and the Button That Ends Both
The migration runbook has a rollback section, and it is one line long:if the application fails validation, fail back to the source server, which is still…
Azure Architecture Series #4 — Resource Providers and Registration: What "Not Registered" Really Means
A platform team has been deploying the same Bicep file for a year. It builds a standard application stack, it runs in three regions, and it has never once faile…
Week 14 - VPC Flow Logs + Network Intelligence: The Logs Everyone Enables and Nobody Reads
Someone turns on flow logs account-wide during a compliance push. The logs land in a bucket. Nobody has permission to read that bucket, and nobody has built a t…
GCP Architecture Series #3 — Resource Manager: The Control Plane Is Asynchronous and Your Pipeline Is Not
A platform team automates project vending. The pipeline does four things in order: create the project, attach it to the billing account, grant the deploying ser…
Azure Architecture Series #3 — Azure Resource Manager: The Control Plane Every Request Passes Through
A platform team runs a release pipeline that has worked for a year. One Thursday it starts failing halfway through, with HTTP 429, too many requests. Nothing in…
AWS Architecture Series #23 — DMS and CDC: What "Ongoing Replication" Does Not Promise
The migration plan has one sentence that everything else depends on:DMS keeps the target in sync, so the cutover window is minutes, not hours.It is writte…
AWS Weekly Intelligence #2 - 10-14 August 2026
15 August 2026 · Everything AWS shipped, 10–14 August
GCP Weekly Intelligence #1 - 10-14 August 2026
A mid-sized week with two things in it that have dates attached, which is unusual and is where to start. App Engine begins forcing TLS 1.2 and later, and the op…
Azure Weekly Intelligence #1 - 10-14 August 2026
Ten announcements in five days, spread thinly: one Monday, one Tuesday, four Wednesday, three Thursday, one Friday. Nothing new launched. Every item was either…
AWS Daily Intelligence #11 - S3 Access Denied Now Names the Policy, Except When It Cannot
15 August 2026 · Amazon S3 · AWS Identity and Access Management
AWS Architecture Series #22 — Discovery After Application Discovery Service
The migration is approved, the discovery phase starts on Monday, and the runbook says to deploy AWS Application Discovery Service. Someone opens the conso…
GCP Architecture Series #2 — Cloud Identity: The Boundary Somebody Else Already Drew
A platform team is asked to design a landing zone. They open the console expecting to create an organization and discover one already exists. Nobody on the team…
Azure Architecture Series #2 — Microsoft Entra ID as the Identity Plane: Tenant, Directory and the Trust a Subscription Depends On
A mid-sized software company is acquired. The integration plan is unremarkable and someone writes the obvious line into it: move the acquired company's Azure su…
GCP Architecture Series #1 — Organizations, Folders and Projects: Why the Project Is the Unit That Matters
A data platform team gets approval to build on Google Cloud. They need somewhere to put things, so they create one project for production, one for development,…
Azure Architecture Series #1 — Tenants, Management Groups and Subscriptions: Where the Blast Radius Actually Sits
A financial services platform team starts building in Azure the week their programme is approved. They need somewhere to put things, so they create one subscrip…
AWS Daily Intelligence #10 - EKS Control Plane Parameters and the Knob That Backfires
14 August 2026 · Amazon Elastic Kubernetes Service
AWS Architecture Series #21 — Wave Planning: The Dependency Graph Decides, Not the Spreadsheet
Wave 1 goes out on a Friday night. Six servers, an application nobody thought was complicated. By Saturday morning it is up in AWS and failing: it cannot…
AWS Daily Intelligence #9 - IAM Role Manager and the PowerUserAccess Default
13 August 2026 · AWS Identity and Access Management
How was your experience?
Your feedback helps improve this site.
PoorExcellent