Skip to content
John Nessime
Search this website

IAM

  1. Home>
  2. IAM
Read more about the article A Secure-by-Default AWS Account Baseline in Terraform

A Secure-by-Default AWS Account Baseline in Terraform

  • Post category:Cloud Computing/DevOps/Web Security

A fresh AWS account ships wide open by default. Here are the seven decisions that make one defensible from the start — OIDC instead of static keys, encrypted state, an isolated database tier, free gateway endpoints — with a working Terraform reference implementation on GitHub.

Continue ReadingA Secure-by-Default AWS Account Baseline in Terraform

Recent Posts

  • A Secure-by-Default AWS Account Baseline in Terraform
  • Prometheus + Grafana From Scratch on One Server
  • Pulumi vs Terraform: Choosing a Lane
  • TLS Certificate Errors: Chain Issues, SANs, and Expiry Automation
  • DNS Troubleshooting: How to Find the Real Cause in Minutes, Not Hours

Recent Comments

No comments to show.
© 2025 · John Nessime · Cairo, Egypt · All rights reserved