Why I hand-rolled every module
Why security-critical infrastructure got raw resources rather than community wrapper modules, and what that actually cost in lines and in review.

Why security-critical infrastructure got raw resources rather than community wrapper modules, and what that actually cost in lines and in review.

Applying a security baseline to a fresh AWS account: audit logging, config recording, threat detection and an operator role that is not root.

Replacing long-lived AWS access keys in CI with OIDC federation, so the pipeline mints a short-lived token instead of holding a secret.

AWS tagging in two layers: account-wide invariants on the provider default tags, resource specifics in the module, and which one wins on a clash.

The bootstrap stack has to create the bucket its own state lives in. Applying once with a local backend, then migrating the state into it.

Reading an aws-nuke dry run: the screenfuls of red are harmless noise, and the real hazard is one quiet line in the middle of them.

A checkov finding you must suppress rather than fix: that KMS policy statement is the escape hatch that stops you locking yourself out for good.

An OpenTofu state bucket that defends itself against corruption, deletion and its own operator, using lockfiles and prevent_destroy.

An AWS bootstrap module that does exactly three things, and writes down what it deliberately does not do. Scope as a design decision.

A checksum hosted beside your download stops accidents, not a compromised platform. Why the signing key has to live somewhere you control.
