An empirically tested comparison of cross-account authorization, multi-Region replication, KMS policy design, rotation, failure modes, operational tradeoffs, and cost.
Sharing Secrets Across an AWS Organization with SSM Parameter Store and Secrets Manager: RAM, KMS, and Regional Replication
Who’s Talking to Prod? Auditing Cross-Environment Traffic Before You Segment a Flat AWS Network
Transit gateway flow logs plus Athena told us which of 130 AWS accounts were crossing the sandbox/nonprod/prod boundary, for about 45 cents of query spend. Here is the capture pattern, the queries, the five things that skew the results, and how we turned raw IPs into something a team would act on.
Upgrading & Migrating a Legacy HashiCorp Vault Cluster from Consul Backend on EC2 to Raft Backend on EKS
HashiCorp Vault (open source) has been our chosen secrets management solution for several years. We self-hosted & operated a Vault 1.5 cluster
Migrate Amazon EKS from Ingress NGINX to F5 NGINX Ingress Controller
In Kubernetes, an ingress controller acts as an entry point for the cluster: it sits at the edge, accepts incoming HTTP and
Migrate from Amazon FSx for NetApp ONTAP Generation 1 to Generation 2 File System
Amazon FSx for NetApp ONTAP (FSxN) is a fully-managed AWS service that brings NetApp’s ONTAP file system to AWS. It seamlessly supports
Migrate Amazon EKS Apps from NFS CSI to NetApp Trident CSI Driver
In one of our projects here at QloudX, we run hundreds of microservices in an Amazon EKS cluster, with persistent backend storage
How to Run Terraform in AWS Lambda (if you must)
Terraform in Lambda For most Terraform use cases, Lambda may not be the right choice. In most cases, a standard CI/CD pipeline
Reduce Inter-AZ Data Transfer Cost in Amazon EKS
Introduction Operating Amazon’s Elastic Kubernetes Service (EKS) at scale comes eith its own challenges. Having done this for several years now, we
How We Upgraded to NGINX 1.25 Ingress Controller in Our EKS Clusters
Introduction In one of our Kubernetes-centric projects here at QloudX, we host hundreds of containerized applications on Amazon’s Elastic Kubernetes Service (EKS).

