// blog
Notes from the build.
Practical guides on AWS, DevOps and AI engineering — the things we set up for clients, written down.

Checkov and Infracost: catching security and cost problems before Terraform applies
Two checks on every infrastructure pull request: Checkov for security and best practices, Infracost for what the change will cost. Real output, CI setup, and how to keep both useful.

ISO 27001 and SOC 2 for startups: doing it once, on AWS
What ISO 27001 and SOC 2 actually ask for, how they differ, which one to start with, and how to build controls on AWS that produce audit evidence on their own.

A real AWS test account vs MiniStack, Floci and LocalStack
Local AWS emulators are fast and free, but they aren't AWS. How a separate test account compares with MiniStack, Floci and LocalStack, and how to use both.

Autoscaling Bitbucket Pipelines runners on EKS with Terraform
Run Bitbucket Pipelines on your own EKS cluster with x86 and Arm runners that scale with demand. Deploy Atlassian's runner autoscaler with one Terraform module, tune it, and let pipelines reach AWS with OIDC instead of keys.

From AI prototype to production: a checklist
Evaluations, guardrails, prompt injection, cost limits, observability and fallbacks — what an LLM feature needs before real users rely on it.

Three environments, three AWS accounts: isolation with Terragrunt
Why dev, staging and prod belong in separate AWS accounts, and how to wire Terragrunt so each environment uses its own state, role and guardrails.

ECS or EKS? Choosing where to run containers on AWS
A practical comparison of Amazon ECS and EKS for startups and small teams — cost, complexity, and when Kubernetes is actually worth it.

Terragrunt: keeping multi-environment Terraform DRY
How Terragrunt removes copy-pasted backend and provider config across environments and AWS accounts, with a practical folder layout and examples.

RAG that actually works: building an assistant over your documents
Why most retrieval-augmented generation demos disappoint in production, and the chunking, retrieval and evaluation practices that fix them.

Managing a private EKS cluster with AWS Client VPN
Take your Kubernetes API server off the internet and give engineers access through AWS Client VPN with single sign-on. Architecture, Terraform, multi-Region costs, and how it compares with a Session Manager bastion host.

Deploying to AWS from GitHub Actions without long-lived keys
Replace stored AWS access keys with short-lived OIDC credentials, and set up a test-then-deploy pipeline with approvals and safe concurrency.

How to cut your AWS bill without re-architecting anything
Eight practical checks that reduce AWS spend in days, not months — from orphaned volumes and NAT Gateway traffic to log retention and Savings Plans.

Moving from x86 to Graviton: what it saves and how to switch safely
Graviton instances cost about 20% less per hour than the matching Intel generation, including burstable t4g versus t3. Here's what that means for your bill, where the performance claims come from, and a low-risk migration path.