Category: Cloud & AWS
-

Autoscaling and right-sizing for traffic that comes in bursts
Autoscaling has a reputation as the thing that saves you money, and that reputation is half-earned. It saves money when it’s scaling down workloads that were genuinely idle. Just as often it papers over the real problem, which is that the thing was sized wrong to begin with, and now you’re paying to automatically provision…
-

Edge protection for a small app, without the enterprise invoice
Security theatre around small apps usually goes like this. Someone reads about a breach, gets nervous, and the conversation jumps straight to a managed WAF product with a per-request price and a sales call attached. Meanwhile the app has no rate limiting, no bot filtering, and a public endpoint that will happily answer a SQL…
-

The boring glue: scaffolding a new service in one script
The logic of a new service is usually the small part. You can write the actual thing it does in an afternoon. What eats the week is the glue: the Dockerfile, the build spec, the task definition, the secret, the health check, the twelve small correct decisions that have nothing to do with what the…
-

Running a fleet of small services without a fleet of headaches
The interesting thing about ending up with a dozen small services is that no one decides to. You build one, it works, someone wants another, and by the time you look up you’re running a dozen-odd of them. Each was reasonable on its own. The problem is that the last one costs you far more…
-

A gateway in front of the fleet, and why it has a circuit breaker
Once you’re running a handful of small services, a question arrives that you can’t dodge: how does anything actually reach them? The lazy answer is to expose each service directly and let callers keep a list. That works until the list is wrong, or one service is having a bad day and takes its callers…
-

Load-testing an app before a live event, and trusting the number
A scheduled live event is a capacity problem with the guesswork removed. Most of the time you’re speculating: maybe you’ll get popular, maybe a link goes big. Not here. On a known date, at a known time, a known-ish number of people all arrive at once, and the thing either holds or it doesn’t, in…
-

Giving a new app its own lane in a VPC you already share
Two failure modes show up when you need to add an app to an account that already runs something important. The first is the cowboy move: drop the new thing into the existing stack, share the load balancer, share the filesystem, and discover six months later that you can’t touch one app without risking the…
-

Why Your AWS Bill Keeps Creeping Up (and the Boring Fixes That Work)
Every few months a familiar meeting happens somewhere in every company that runs on AWS. Finance forwards the bill, someone senior asks why it went up again, and the engineering answer is a shrug dressed up as a roadmap. The truth is usually less dramatic than either side fears: nothing is broken, nothing was hacked,…
-

Why your long-running AI request dies at 60 seconds, and the async pattern that fixes it
If you are building anything on top of a large language model, there is a wall waiting for you at roughly sixty seconds. It does not matter how well your code is written. One day a user uploads a document, the request sits there while the model thinks, and then the browser shows the least…
-

Automating dependency vulnerability scanning without over-privileging yourself
Automating a security scan sounds simple until you try to schedule it on a shared cloud account. The scanning logic is the easy part. The hard part is doing it without handing yourself, or the job, more power than the task actually needs. This is a walk through building a recurring dependency vulnerability sweep, and…
