-
August 11, 2026
Letting Claude loose on an AWS account with Prowler
Running Prowler across an AWS account with an agent, a read-only role, and a bastion — then triaging 1,684 findings.
8-minute read
·
AwsSecurityProwlerAiAutomation
-
June 16, 2026
Karpenter consolidation without the pager fatigue
Tuning consolidation and spot interruption handling so the alerting channel stays worth reading.
5-minute read
·
KarpenterAwsEksSpotCost-Optimization
-
June 2, 2026
IRSA to Pod Identity: notes from the migration
Migration notes, the annotation that becomes a lie, and the host port 80 conflict that took down ingress.
7-minute read
·
AwsEksIamKubernetesSecurity
-
May 19, 2026
Terragrunt: deleting the boilerplate you were told to write
Hoisting version pins, generating providers, and deriving config from paths to shrink leaf units.
5-minute read
·
TerragruntTerraformIacAws
-
April 21, 2026
EKS Access Entries: one ARN, one cluster, no sharing
Access entries are scoped per cluster, not shared. Three ways to collide with one, and how to dedupe in Terraform.
4-minute read
·
AwsEksTerraformIamSecurity
-
April 7, 2026
Fargate profiles and the art of waiting your turn
EKS allows one Fargate profile mutation at a time. Here's why your destroy fails and how depends_on fixes it.
4-minute read
·
AwsEksTerraformFargate
-
July 15, 2025
Cutting the EKS bill: what actually moved the needle
What actually moved the needle on an EKS bill, ranked by return per hour of effort.
5-minute read
·
AwsEksCost-OptimizationKarpenter