Up

Upstood

Services

Company

Let's talk

ARTICLES

AWS engineering articles

Long-form writeups from real audit and remediation work: what we find in AWS accounts, why it matters, and how we fix it

5 August 2026 · 13 min read

AWS Tag Policies, Config Rules, and SCPs: What Each One Actually Enforces

A tag policy standardises the values of tags that already exist. It does not require a tag to exist, and an untagged resource is never evaluated rather than reported non-compliant. Six AWS-native mechanisms compared, then the one that closes the gap written out in TypeScript: tags applied in two tiers and coverage proven by a CDK aspect that fails the build.

OrganizationsConfigIAMResource ExplorerCloudFormation

29 July 2026 · 8 min read

Terraform Modules vs CDK Constructs | What the Extra Layers Change

Terraform has two abstraction layers, CDK has four, and CDK derives every CloudFormation logical ID from the construct path. Extracting a bucket into a reusable construct changes its identity, and CloudFormation reads that as destroy and create. What Terraform's moved block repairs, what cdk refactor repairs, and where each option fits.

CDKCloudFormationS3

10 July 2026 · 5 min read

Give your auditor AWS access without sharing a single credential

An external auditor never needs a login in your organization. A cross-account IAM role with an External ID gives temporary, read-only, fully logged API access: CloudFormation templates included for one account or a whole AWS Organization.

IAMOrganizationsCloudTrailSecurity HubGuardDuty

Upstood

Home
Let's talk
Upstood | 2026

VAT: IT14214770969 · Via Cufra 17 · 20159 Milano - Italia · Tel: +39 3447504971 · info@upstood.com