|
AWS FOR THE REAL WORLD
β±οΈ
Reading time: 12 minutes
π―
Main Learning: Wrapping a multi-account AWS org in multiple layers of guardrails, featuring SCPs, RCPs, CloudTrail and Bugdet Actions
π
Hey Reader ππ½ That's why we've carefully crafted our AWS Organization's setup. ποΈ In this issue, we want to walk you through our most important guardrails! Including all the whats and whys. π Sponsored by Archera
If you take one thing away: the value of a multi-account setup is what you build around the accounts, not the accounts themselves. A "bare" AWS Organization with no SCPs, no audit trail, and no spending guardrails is just multiple places (=accounts) for the same mistake(s) to happen. |
We teach AWS for the real world - not for certifications. Join more than 10,500 developers learning how to build real-world applications on AWS.
AWS FOR THE REAL WORLD β±οΈ Reading time: 6 minutes π― Main Learning: One stack, reused for every project. Hono on Lambda, Postgres with Drizzle, a TanStack SPA on S3 and CloudFront, and Better Auth for login. π Blog Post Hey Reader ππ½we've build a lot of fullstack applications so far: client projects side projects (this one, shopify apps, etc.) example tutorial apps Over the past few years we switched up tech stacks a lot. That taught us what actually matters in a stack and what is just...
AWS FOR THE REAL WORLD β±οΈ Reading time: 10 minutes π― Main Learning: Wildcards come from the tooling, not from laziness. Put least privilege at the account level and let an agent write the policies. π Blog Post Hey Reader ππ½ I have shipped my share of s3:* at unusual hours and told myself I would refactor it later - which obviously never happened π So when someone on r/aws asked why developers can't write least privilege policies and put it down to laziness, I was excited to read through all...
AWS FOR THE REAL WORLD β±οΈ Reading time: 11 minutes π― Main Learning: Most teams should stay serverless. EKS only pays off at real scale. π Blog Post Hey Reader ππ½For years we told everyone the same thing: don't run Kubernetes! And we meant it. Running k8s yourself is a second full-time job. Cluster upgrades, etcd backups, some networking plugin that falls over on a Tuesday and nobody can say why.We're serverless people through and through. Lambda first, a queue behind it, scale to zero, go...