Skip to content
John Nessime
Search this website

AWS

  1. Home>
  2. AWS
Read more about the article A Secure-by-Default AWS Account Baseline in Terraform

A Secure-by-Default AWS Account Baseline in Terraform

  • Post category:Cloud Computing/DevOps/Web Security

A fresh AWS account ships wide open by default. Here are the seven decisions that make one defensible from the start — OIDC instead of static keys, encrypted state, an isolated database tier, free gateway endpoints — with a working Terraform reference implementation on GitHub.

Continue ReadingA Secure-by-Default AWS Account Baseline in Terraform
Read more about the article Pulumi vs Terraform: Choosing a Lane

Pulumi vs Terraform: Choosing a Lane

  • Post category:Cloud Computing/DevOps/Technical Guides

The licence changed, the community forked, IBM bought HashiCorp, CDKTF was archived, and Pulumi started speaking HCL. Here is an honest read of where Pulumi vs Terraform actually stands in 2026, and how to pick a lane you will not regret.

Continue ReadingPulumi vs Terraform: Choosing a Lane

Recent Posts

  • A Secure-by-Default AWS Account Baseline in Terraform
  • Prometheus + Grafana From Scratch on One Server
  • Pulumi vs Terraform: Choosing a Lane
  • TLS Certificate Errors: Chain Issues, SANs, and Expiry Automation
  • DNS Troubleshooting: How to Find the Real Cause in Minutes, Not Hours

Recent Comments

No comments to show.
© 2025 · John Nessime · Cairo, Egypt · All rights reserved