Building a Hotel Data Lake on AWS That Agrees With the Night Audit

Hotel source data is mutable in the past, so an append-only pipeline drifts away from the PMS without anyone noticing until month close. A practical guide to room-night grain, bitemporal modeling with Apache Iceberg, PMS ingestion, guest data scope, and file physics at hotel volumes.

Continue ReadingBuilding a Hotel Data Lake on AWS That Agrees With the Night Audit

Turning External Documents Into Structured Data With Amazon Textract

Amazon Textract almost never fails loudly. A working guide to turning external PDFs and scans into structured data: picking the right operation per document family, parsing the block graph, routing on per-field confidence, and catching the limits that silently truncate your records.

Continue ReadingTurning External Documents Into Structured Data With Amazon Textract

Cloudflare R2 vs Amazon S3 for Media Offloading: Where the Bill Actually Comes From

Free egress is not free serving. R2 still bills every read, S3 does not bill origin transfer to CloudFront, and the variable that decides both bills is cache hit ratio. An evenhanded comparison of Cloudflare R2 vs Amazon S3 for media offloading, with the four levers that move the number and a decision procedure you can run against your own traffic.

Continue ReadingCloudflare R2 vs Amazon S3 for Media Offloading: Where the Bill Actually Comes From

Amazon Macie PII Detection: The Buckets It Never Opened

A Macie bucket labeled "Not sensitive" often just means Macie never read it. Extensionless objects, unsupported storage classes, unreachable KMS keys and quota truncation all produce silence that looks identical to a clean result. Here's how to measure coverage, fix the four gaps, tune identifiers, and keep the bill honest.

Continue ReadingAmazon Macie PII Detection: The Buckets It Never Opened

Tenant Isolation on AWS: Building a Multi-Tenant Workshop Platform That Doesn’t Leak

A missing tenant filter doesn't throw an error, it returns a 200 with too many rows. This is how to build a multi-tenant workshop management platform on AWS where the isolation boundary sits below your application code: STS session tags feeding IAM conditions, DynamoDB leading keys, scoped S3 prefixes, forced PostgreSQL row-level security, and a control plane that verifies each new tenant is fenced before anyone logs in.

Continue ReadingTenant Isolation on AWS: Building a Multi-Tenant Workshop Platform That Doesn’t Leak

Building a Secure Client Document Vault Your Accounting Firm Can Defend

Most accounting-firm document vaults do not fail at the bucket. They fail at the edges: a download link that outlives the engagement, a KMS key policy as wide as the bucket policy, a retention lock that cannot be undone, and an audit trail nobody switched on. Six failure families, and the control that closes each.

Continue ReadingBuilding a Secure Client Document Vault Your Accounting Firm Can Defend

Cut AWS Costs Without Breaking Production: A Blast-Radius Playbook

Most AWS cost work goes wrong because it starts with the biggest line item, which is also the riskiest. Order the work by blast radius instead: free networking and storage fixes first, performance envelopes one workload at a time, and commitments last. Includes the commands to find the waste and the cuts that look harmless and are not.

Continue ReadingCut AWS Costs Without Breaking Production: A Blast-Radius Playbook