5 August 2026 · 13 min read
A tag policy standardises the values of tags that already exist. It does not require a tag to exist, and an untagged resource is never evaluated rather than reported non-compliant. Six AWS-native mechanisms compared, then the one that closes the gap written out in TypeScript: tags applied in two tiers and coverage proven by a CDK aspect that fails the build.
OrganizationsConfigIAMResource ExplorerCloudFormation
29 July 2026 · 8 min read
Terraform has two abstraction layers, CDK has four, and CDK derives every CloudFormation logical ID from the construct path. Extracting a bucket into a reusable construct changes its identity, and CloudFormation reads that as destroy and create. What Terraform's moved block repairs, what cdk refactor repairs, and where each option fits.
CDKCloudFormationS3
21 July 2026 · 5 min read
A NAT gateway bills $0.045 per gigabyte on all outbound traffic, including the AWS-bound share, and it neither logs nor filters destinations. What VPC endpoints and a self-managed egress proxy each cost next to it, and where each one fits.
NAT GatewayVPC EndpointsPrivateLinkECRS3GuardDuty
15 July 2026 · 8 min read
Multi-AZ covers physical disasters. A second region covers software failures only if engineered right. DORA names neither: it asks for recovery objectives per application, segregated backups, and proof.
EC2DynamoDBRoute 53LambdaIAM
13 July 2026 · 9 min read
Session Manager closes port 22 entirely: no public IPs, no bastion, no SSH keys. What startups get for free and what enterprises must add for OS-level attribution before an audit.
Session ManagerSystems ManagerIAMEC2CloudTrailCloudWatch
10 July 2026 · 5 min read
An external auditor never needs a login in your organization. A cross-account IAM role with an External ID gives temporary, read-only, fully logged API access: CloudFormation templates included for one account or a whole AWS Organization.
IAMOrganizationsCloudTrailSecurity HubGuardDuty