Blog
Why security-critical infrastructure got raw resources rather than community wrapper modules, and what that actually cost in lines and in review.
Applying a security baseline to a fresh AWS account: audit logging, config recording, threat detection and an operator role that is not root.
Replacing long-lived AWS access keys in CI with OIDC federation, so the pipeline mints a short-lived token instead of holding a secret.
AWS tagging in two layers: account-wide invariants on the provider default tags, resource specifics in the module, and which one wins on a clash.
Why a clap global flag stops working inside a passthrough subtree: the tokens get captured as trailing args before the flag is ever parsed.
Storage answers where a secret lives, not what happens to it in memory. Wrapping secrets so they redact in Debug and zero on drop.
The bootstrap stack has to create the bucket its own state lives in. Applying once with a local backend, then migrating the state into it.
Reading an aws-nuke dry run: the screenfuls of red are harmless noise, and the real hazard is one quiet line in the middle of them.
A checkov finding you must suppress rather than fix: that KMS policy statement is the escape hatch that stops you locking yourself out for good.
O_APPEND only guarantees non-interleaved writes below PIPE_BUF, which is 4096 bytes on Linux. A fat JSONL event above that splices two lines.