<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>sjramblings.io</title><description>Cloud engineering, infrastructure as code, and agentic AI insights by Stephen Jones</description><link>https://sjramblings.io/</link><language>en-au</language><item><title>AWS Config Just Added 30 Resource Types. The Bedrock AgentCore Ones Matter Most.</title><link>https://sjramblings.io/aws-config-30-new-resource-types-bedrock-agentcore/</link><guid isPermaLink="true">https://sjramblings.io/aws-config-30-new-resource-types-bedrock-agentcore/</guid><description>AWS Config now tracks Bedrock AgentCore Gateways, Memory, and 28 other resource types. What this means for AI agent governance, Cognito audit trails, and compliance at scale.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Agent Plugins Are the Future — But You Might Be Giving Away Your Best Engineering</title><link>https://sjramblings.io/agent-plugins-marketplace-intelligence/</link><guid isPermaLink="true">https://sjramblings.io/agent-plugins-marketplace-intelligence/</guid><pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate></item><item><title>PageIndex Deep Dive: The Good, The Bad, and The Ugly of Vectorless RAG</title><link>https://sjramblings.io/pageindex-deep-dive-vectorless-rag/</link><guid isPermaLink="true">https://sjramblings.io/pageindex-deep-dive-vectorless-rag/</guid><description>What if everything we know about RAG is built on a flawed assumption? A deep dive into PageIndex&apos;s tree-based reasoning approach to document retrieval — no vectors, no chunking, no embedding databases.</description><pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Your AWS Certificates Just Got Shorter: What the 198-Day Validity Change Actually Means</title><link>https://sjramblings.io/aws-acm-certificate-validity-shorter-lifetimes/</link><guid isPermaLink="true">https://sjramblings.io/aws-acm-certificate-validity-shorter-lifetimes/</guid><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Is Infrastructure as Code the Next Abstraction to Fall?</title><link>https://sjramblings.io/is-infrastructure-as-code-the-next-abstraction-to-fall/</link><guid isPermaLink="true">https://sjramblings.io/is-infrastructure-as-code-the-next-abstraction-to-fall/</guid><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Open-Weight Models Just Landed in Sydney: What This Means for Australian AI Sovereignty</title><link>https://sjramblings.io/aws-bedrock-open-weight-models-sydney-australian-sovereignty/</link><guid isPermaLink="true">https://sjramblings.io/aws-bedrock-open-weight-models-sydney-australian-sovereignty/</guid><pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AWS Finally Launches Nested Virtualisation on EC2: Better Late Than Never</title><link>https://sjramblings.io/aws-ec2-nested-virtualization-finally/</link><guid isPermaLink="true">https://sjramblings.io/aws-ec2-nested-virtualization-finally/</guid><pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Building Your Own AI Agent Stack. What I Learned From 10 Open Source Projects</title><link>https://sjramblings.io/building-your-own-ai-agent-stack/</link><guid isPermaLink="true">https://sjramblings.io/building-your-own-ai-agent-stack/</guid><pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Build vs. Buy Just Flipped. Most Teams Haven&apos;t Noticed Yet.</title><link>https://sjramblings.io/build-vs-buy-just-flipped/</link><guid isPermaLink="true">https://sjramblings.io/build-vs-buy-just-flipped/</guid><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Your Inference Bill Is Going Up. Even as Costs Go Down.</title><link>https://sjramblings.io/inference-tax-nobody-budgeted-for/</link><guid isPermaLink="true">https://sjramblings.io/inference-tax-nobody-budgeted-for/</guid><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The Real Skill Isn&apos;t Coding Anymore. It&apos;s Describing What You Want.</title><link>https://sjramblings.io/get-shit-done-describing-what-you-want/</link><guid isPermaLink="true">https://sjramblings.io/get-shit-done-describing-what-you-want/</guid><pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AWS STS Finally Lets You Write Trust Policies That Actually Mean Something</title><link>https://sjramblings.io/aws-sts-identity-provider-claims-validation/</link><guid isPermaLink="true">https://sjramblings.io/aws-sts-identity-provider-claims-validation/</guid><pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The Friction Was the Point</title><link>https://sjramblings.io/the-friction-was-the-point/</link><guid isPermaLink="true">https://sjramblings.io/the-friction-was-the-point/</guid><pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Chronos Forecasting – LinkedIn Post</title><link>https://sjramblings.io/chronos-forecasting-linkedin-post/</link><guid isPermaLink="true">https://sjramblings.io/chronos-forecasting-linkedin-post/</guid><description>Chronos forecasting from Amazon Science offers an end-to-end approach that brings consistency, speed, and reliability to multi-horizon forecasts.</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Marketing skills for AI agents: Why builders should care</title><link>https://sjramblings.io/marketing-skills-for-ai-agentswhy-builders-should-care/</link><guid isPermaLink="true">https://sjramblings.io/marketing-skills-for-ai-agentswhy-builders-should-care/</guid><description>If you are building with AI agents, you should also equip them with marketing skills. Not marketing in the cringe sense — marketing in the engineering sense.</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate></item><item><title>From Network Plumbing to Application Intent: What AWS Networking Reveals About Infrastructure&apos;s New Role</title><link>https://sjramblings.io/network-application-centric-architecture/</link><guid isPermaLink="true">https://sjramblings.io/network-application-centric-architecture/</guid><description>Network infrastructure is no longer invisible plumbing. It&apos;s becoming intent-driven and application-aware. What this means for your architecture strategy.</description><pubDate>Sun, 14 Dec 2025 00:00:00 GMT</pubDate></item><item><title>The AI Agent Governance Gap: Why Policy and Evaluations Matter More Than the Model</title><link>https://sjramblings.io/bedrock-agentcore-policy-evaluations/</link><guid isPermaLink="true">https://sjramblings.io/bedrock-agentcore-policy-evaluations/</guid><description>AWS adds policy controls and quality evaluations to AgentCore. Finally, the operational discipline AI agents needed all along.</description><pubDate>Sat, 13 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Beyond Vibe Coding: The Renaissance Developer Framework for Infrastructure Leaders</title><link>https://sjramblings.io/renaissance-developer-framework/</link><guid isPermaLink="true">https://sjramblings.io/renaissance-developer-framework/</guid><description>Werner Vogels&apos; final keynote reveals the five qualities driving the next era of software engineering. Why this matters for your infrastructure strategy.</description><pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Finally! AWS Transit Gateway Gets Flexible Cost Allocation</title><link>https://sjramblings.io/aws-transit-gateway-flexible-cost-allocation/</link><guid isPermaLink="true">https://sjramblings.io/aws-transit-gateway-flexible-cost-allocation/</guid><description>AWS just launched flexible cost allocation for Transit Gateway, solving one of the biggest pain points in multi-account networking. Learn how to implement metering policies to properly allocate costs across your organization.</description><pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Understanding LLM Prompt Injection: The Security Risk You Can&apos;t Ignore</title><link>https://sjramblings.io/understanding-llm-prompt-injection/</link><guid isPermaLink="true">https://sjramblings.io/understanding-llm-prompt-injection/</guid><description>Explore LLM prompt injection vulnerabilities, from direct and indirect attacks to multimodal exploits. Learn practical mitigation strategies to secure your AI applications.</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate></item><item><title>I Used Amazon Q CLI to Build a Feature for Amazon Q CLI (And It Was Mind-Bending)</title><link>https://sjramblings.io/used-amazon-q-cli-build-feature-amazon-q-cli-mind-bending/</link><guid isPermaLink="true">https://sjramblings.io/used-amazon-q-cli-build-feature-amazon-q-cli-mind-bending/</guid><description>Ever wondered what it&apos;s like to use an AI tool to improve itself? I just spent 2 hours using Amazon Q CLI to build a new feature for Amazon Q CLI, and the...</description><pubDate>Thu, 11 Sep 2025 00:00:00 GMT</pubDate></item><item><title>Claude Code Multi-Agent Orchestration: How AI Agent Teams Work Together</title><link>https://sjramblings.io/multi-agent-orchestration-claude-code-when-ai-teams-beat-solo-acts/</link><guid isPermaLink="true">https://sjramblings.io/multi-agent-orchestration-claude-code-when-ai-teams-beat-solo-acts/</guid><description>Learn Claude Code multi-agent orchestration patterns. How to coordinate AI agent teams with architect, builder, validator, and scribe roles for complex software projects.</description><pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate></item><item><title>AWS ap-southeast-6 (New Zealand Region): Services, Pricing &amp; Migration Guide</title><link>https://sjramblings.io/aws-lands-in-new-zealand-what-the-ap-southeast-6-region-means-for-kiwi-cloud-builders/</link><guid isPermaLink="true">https://sjramblings.io/aws-lands-in-new-zealand-what-the-ap-southeast-6-region-means-for-kiwi-cloud-builders/</guid><description>Everything about the AWS New Zealand region (ap-southeast-6). Day-one services, pricing reality check, migration framework, and practical next steps for Kiwi cloud builders.</description><pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate></item><item><title>AWS VPC Route Server: The Game-Changer for Dynamic Routing You&apos;ve Been Waiting For</title><link>https://sjramblings.io/aws-vpc-route-server-the-game-changer-for-dynamic-routing-youve-been-waiting-for/</link><guid isPermaLink="true">https://sjramblings.io/aws-vpc-route-server-the-game-changer-for-dynamic-routing-youve-been-waiting-for/</guid><description>AWS just dropped a networking feature that&apos;s going to change how we think about VPC routing forever. VPC Route Server brings dynamic routing capabilities...</description><pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate></item><item><title>Building AI-Powered Life Management Systems: The AWS Infrastructure Approach</title><link>https://sjramblings.io/building-ai-powered-life-management-systems-aws-infrastructure-approach/</link><guid isPermaLink="true">https://sjramblings.io/building-ai-powered-life-management-systems-aws-infrastructure-approach/</guid><description>Daniel Miessler just dropped a fascinating deep-dive into building what he calls a &quot;Personal AI Infrastructure&quot; (PAI) - essentially an AI-powered life...</description><pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate></item><item><title>Personal AI Infrastructure (PAI): How to Build Your Own AI System</title><link>https://sjramblings.io/building-personal-ai-infrastructure-beyond-tools-systems/</link><guid isPermaLink="true">https://sjramblings.io/building-personal-ai-infrastructure-beyond-tools-systems/</guid><description>Learn how to build your own Personal AI Infrastructure (PAI). A practical guide to creating AI systems that amplify human capabilities — architecture patterns, Claude Code integration, and real implementation.</description><pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate></item><item><title>AWS Bedrock AgentCore Starter Toolkit: Deploy AI Agents in 3 Commands</title><link>https://sjramblings.io/the-bedrock-agentcore-toolkit-a-new-easy-button-for-ai-agents/</link><guid isPermaLink="true">https://sjramblings.io/the-bedrock-agentcore-toolkit-a-new-easy-button-for-ai-agents/</guid><description>Get started with the AWS Bedrock AgentCore Starter Toolkit. Deploy AI agents to AgentCore in 3 commands — configure, launch, test. Includes SAM CLI comparison and step-by-step walkthrough.</description><pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate></item><item><title>🕹️ AWS-Powered Tetris: Building a Retro Game with Amazon Q and Amplify</title><link>https://sjramblings.io/aws-powered-tetris-building-a-retro-game-with-amazon-q-and-amplify/</link><guid isPermaLink="true">https://sjramblings.io/aws-powered-tetris-building-a-retro-game-with-amazon-q-and-amplify/</guid><description>There&apos;s something magical about the games we grew up with. The simple mechanics, the blocky graphics, and the maddeningly catchy music are etched into our...</description><pubDate>Sun, 15 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Cost-Effective Workflow Automation: Deploying n8n on Amazon Lightsail</title><link>https://sjramblings.io/cost-effective-workflow-automation-deploying-n8n-on-amazon-lightsail/</link><guid isPermaLink="true">https://sjramblings.io/cost-effective-workflow-automation-deploying-n8n-on-amazon-lightsail/</guid><description>Recently I&apos;ve been trying out n8n as a workflow automation tool and I&apos;m really enjoying the flexibility it offers. Of course, being an AWS Community Builder I...</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Unlocking Cloud Savings: Your Guide to fsx and s3 Intelligent-Tiering with Python Magic! 🚀</title><link>https://sjramblings.io/unlocking-cloud-savings-your-guide-to-fsx-and-s3-intelligent-tiering-with-python-magic/</link><guid isPermaLink="true">https://sjramblings.io/unlocking-cloud-savings-your-guide-to-fsx-and-s3-intelligent-tiering-with-python-magic/</guid><description>Learn how to estimate fsx storage costs with s3 Intelligent-Tiering using Python and CloudWatch metrics. Bridge the gap between your fsx file system and potential cloud storage savings with data-driven insights and the AWS Pricing Calculator.</description><pubDate>Wed, 05 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Streamline Your Cloud Compliance: Mastering Time-Based AMI Copies with AWS</title><link>https://sjramblings.io/streamline-your-cloud-compliance-mastering-time-based-ami-copies-with-aws/</link><guid isPermaLink="true">https://sjramblings.io/streamline-your-cloud-compliance-mastering-time-based-ami-copies-with-aws/</guid><description>Hey there, Tech Friends! 👋</description><pubDate>Tue, 04 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HashiCorp Vault Auto Unseal Guide: AWS KMS, Transit &amp; Configuration</title><link>https://sjramblings.io/streamline-vault-operations-a-guide-to-mastering-auto-unseal/</link><guid isPermaLink="true">https://sjramblings.io/streamline-vault-operations-a-guide-to-mastering-auto-unseal/</guid><description>Complete guide to HashiCorp Vault auto unseal. Compare AWS KMS vs Transit secret engine methods with step-by-step configuration examples for production environments.</description><pubDate>Sun, 02 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Unleash the Power of EBSight for Optimal AWS Storage Management 🚀</title><link>https://sjramblings.io/unleash-the-power-of-ebsight-for-optimal-aws-storage-management/</link><guid isPermaLink="true">https://sjramblings.io/unleash-the-power-of-ebsight-for-optimal-aws-storage-management/</guid><description>Hey there, tech aficionados! 👋</description><pubDate>Mon, 17 Feb 2025 00:00:00 GMT</pubDate></item><item><title>Mastering AWS Security: Why You Should Avoid Using the Root User for Everyday Tasks</title><link>https://sjramblings.io/mastering-aws-security-why-you-should-avoid-using-the-root-user-for-everyday-tasks/</link><guid isPermaLink="true">https://sjramblings.io/mastering-aws-security-why-you-should-avoid-using-the-root-user-for-everyday-tasks/</guid><description>Hey there, tech enthusiasts! Ever felt that little thrill of power when you get root access on a system? It&apos;s like holding the keys to the kingdom, right?</description><pubDate>Sun, 16 Feb 2025 00:00:00 GMT</pubDate></item><item><title>A Reminder of the Power of AWS Config</title><link>https://sjramblings.io/a-reminder-of-the-power-of-aws-config/</link><guid isPermaLink="true">https://sjramblings.io/a-reminder-of-the-power-of-aws-config/</guid><description>Discover how AWS Config Aggregators unlock powerful insights across your entire AWS Organisation. Learn to audit security groups at scale using advanced queries instead of manual CLI commands on every account.</description><pubDate>Wed, 13 Nov 2024 00:00:00 GMT</pubDate></item><item><title>Streamline Your Azure DevOps Pipelines: Harnessing Variables and makefile Magic</title><link>https://sjramblings.io/streamline-your-azure-devops-pipelines-harnessing-variables-and-makefile-magic/</link><guid isPermaLink="true">https://sjramblings.io/streamline-your-azure-devops-pipelines-harnessing-variables-and-makefile-magic/</guid><description>👋 Hey there!</description><pubDate>Sun, 03 Nov 2024 00:00:00 GMT</pubDate></item><item><title>HashiCorp Vault Production Hardening Guide: Security Best Practices (2026)</title><link>https://sjramblings.io/secure-your-secrets-best-practices-for-hardening-hashicorp-vault-in-production/</link><guid isPermaLink="true">https://sjramblings.io/secure-your-secrets-best-practices-for-hardening-hashicorp-vault-in-production/</guid><description>The definitive HashiCorp Vault production hardening guide. Covers TLS, mTLS, audit logging, firewall rules, single-tenancy, and operational security best practices for enterprise deployments.</description><pubDate>Fri, 01 Nov 2024 00:00:00 GMT</pubDate></item><item><title>HashiCorp Vault Secrets Management: Best Practices, Rotation &amp; Dynamic Secrets</title><link>https://sjramblings.io/hashicorp-vault-the-key-to-secrets-management/</link><guid isPermaLink="true">https://sjramblings.io/hashicorp-vault-the-key-to-secrets-management/</guid><description>Complete guide to HashiCorp Vault secrets management best practices. Covers secret engines, dynamic secrets, secret rotation policies, and production configuration with real examples.</description><pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate></item><item><title>Ensuring Seamless Connectivity - The Crucial Role of Failover testing in AWS Direct Connect</title><link>https://sjramblings.io/aws-direct-connect-failover-testing-importanc/</link><guid isPermaLink="true">https://sjramblings.io/aws-direct-connect-failover-testing-importanc/</guid><description>👋 Hey there!</description><pubDate>Tue, 21 May 2024 00:00:00 GMT</pubDate></item><item><title>github Self-Hosted Runners on AWS CodeBuild</title><link>https://sjramblings.io/github-self-hosted-runners-on-aws-codebuild/</link><guid isPermaLink="true">https://sjramblings.io/github-self-hosted-runners-on-aws-codebuild/</guid><description>👋 Hey there!</description><pubDate>Fri, 12 Apr 2024 00:00:00 GMT</pubDate></item><item><title>Creating shared github-actions</title><link>https://sjramblings.io/creating-shared-github-actions/</link><guid isPermaLink="true">https://sjramblings.io/creating-shared-github-actions/</guid><description>* Workflow Before * Workflow After * The Workflow * Creating a shared (reusable) workflow + Workflow Repository + Adapt the workflow for reuse * Calling the...</description><pubDate>Mon, 12 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Do Not Default to PAT</title><link>https://sjramblings.io/do-not-default-to-pat/</link><guid isPermaLink="true">https://sjramblings.io/do-not-default-to-pat/</guid><description>👋 Hey there!</description><pubDate>Tue, 23 Jan 2024 00:00:00 GMT</pubDate></item><item><title>Searching github Organisations</title><link>https://sjramblings.io/searching-github-organisations/</link><guid isPermaLink="true">https://sjramblings.io/searching-github-organisations/</guid><description>👋 Hey there!</description><pubDate>Thu, 07 Dec 2023 00:00:00 GMT</pubDate></item><item><title>AWS Windows SSM Port Forwarding, too easy</title><link>https://sjramblings.io/windows-ssm-port-forwarding-too-eas/</link><guid isPermaLink="true">https://sjramblings.io/windows-ssm-port-forwarding-too-eas/</guid><description>👋 Hey there!</description><pubDate>Mon, 20 Nov 2023 00:00:00 GMT</pubDate></item><item><title>Supercharge Your AWS CloudWatch Metrics with Lambda Powertools</title><link>https://sjramblings.io/supercharge-your-aws-cloudwatch-metrics-with-lambda-powertools/</link><guid isPermaLink="true">https://sjramblings.io/supercharge-your-aws-cloudwatch-metrics-with-lambda-powertools/</guid><description>In this post, I&apos;ll show you how easy it is to publish custom metrics into AWS CloudWatch using AWS Lambda Powertools and the Cloudwatch EMU Specification</description><pubDate>Mon, 07 Aug 2023 00:00:00 GMT</pubDate></item><item><title>How to sync containers from github Container Registry to AWS ECS</title><link>https://sjramblings.io/how-to-sync-containers-from-ghcr-to-aws-ecs/</link><guid isPermaLink="true">https://sjramblings.io/how-to-sync-containers-from-ghcr-to-aws-ecs/</guid><description>Back in June last year I wrote about syncing containers from DockerHub to AWS ECS.</description><pubDate>Tue, 25 Jul 2023 00:00:00 GMT</pubDate></item><item><title>github-actions in CodeBuild</title><link>https://sjramblings.io/github-actions-in-codebuild/</link><guid isPermaLink="true">https://sjramblings.io/github-actions-in-codebuild/</guid><description>This month AWS released support for github-actions in CodeBuild.</description><pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate></item><item><title>Getting Started with Steampipe on Azure</title><link>https://sjramblings.io/getting_started_with_steampipe_on_azure/</link><guid isPermaLink="true">https://sjramblings.io/getting_started_with_steampipe_on_azure/</guid><description>It&apos;s been a while since I gave Steampipe a run, and wow, has it had some excellent updates!</description><pubDate>Fri, 28 Apr 2023 00:00:00 GMT</pubDate></item><item><title>Route 53 Resolver Magic</title><link>https://sjramblings.io/route53_resolver_magic/</link><guid isPermaLink="true">https://sjramblings.io/route53_resolver_magic/</guid><description>This post covers some core concepts of Route 53 Resolvers and how they can help establish inbound and outbound name resoltion with your on-premise and AWS...</description><pubDate>Wed, 12 Apr 2023 00:00:00 GMT</pubDate></item><item><title>Unlock the Hidden Power of VPC Sharing in AWS</title><link>https://sjramblings.io/unlock-the-hidden-power-of-vpc-sharing-in-aws/</link><guid isPermaLink="true">https://sjramblings.io/unlock-the-hidden-power-of-vpc-sharing-in-aws/</guid><description>As rightly stated here by Aidan Steele (AWS Hero), VPC Sharing appears to be the forgotten superpower.</description><pubDate>Wed, 12 Apr 2023 00:00:00 GMT</pubDate></item><item><title>AWS GP3 Volumes</title><link>https://sjramblings.io/aws-gp3-volumes/</link><guid isPermaLink="true">https://sjramblings.io/aws-gp3-volumes/</guid><description>AWS made the following announcement at Reinvent2020</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Cloudformation FirewallPolicy UPDATE_FAILED</title><link>https://sjramblings.io/cloudformation-firewallpolicy-update_failed/</link><guid isPermaLink="true">https://sjramblings.io/cloudformation-firewallpolicy-update_failed/</guid><description>While I have a fond love for Cloudformation, sometimes I find myself banging my head against a wall when trying to get past an error.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>AWS Managed Prefix Lists</title><link>https://sjramblings.io/aws_managed_prefixes/</link><guid isPermaLink="true">https://sjramblings.io/aws_managed_prefixes/</guid><description>Some time ago AWS released a new feature called Customer Managed Prefix Lists.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Build a Terraform Community Org on github Enterprise</title><link>https://sjramblings.io/build_a_terraform_community_org_on_github_enterprise/</link><guid isPermaLink="true">https://sjramblings.io/build_a_terraform_community_org_on_github_enterprise/</guid><description>Infrastructure as Code (IAC) is great, people can knock up some Terraform and smash out some stacks in next to no time, delivering value to the business...</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Config Conundrum</title><link>https://sjramblings.io/config_conundrum/</link><guid isPermaLink="true">https://sjramblings.io/config_conundrum/</guid><description>At our organisation we use custom config rules to help us achieve near real-time compliance and remediation.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Bootstrap Terraform on AWS</title><link>https://sjramblings.io/bootstrap_terraform_on_aws/</link><guid isPermaLink="true">https://sjramblings.io/bootstrap_terraform_on_aws/</guid><description>Terraform is a great product for managing infrastructure on AWS however many people start by creating an iam user and sharing access keys into configuration...</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>AWS Config Rules Blessed with Cloudformation cfn-guard Support!</title><link>https://sjramblings.io/aws-config-rules-blessed-with-cloudformation-cfn-guard-support/</link><guid isPermaLink="true">https://sjramblings.io/aws-config-rules-blessed-with-cloudformation-cfn-guard-support/</guid><description>They said it was coming, and here it is! Support for defining custom cfn-guard rules for AWS Config via Cloudformation.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Up and running with AWS Network Firewall - Part 1</title><link>https://sjramblings.io/getting-started-with-aws-network-firewall/</link><guid isPermaLink="true">https://sjramblings.io/getting-started-with-aws-network-firewall/</guid><description>This post is the first in a series to share my learnings as I get to grips with AWS Network Firewall.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Getting Started with AWS CloudFormation Guard (cfn-guard): Policy-as-Code Guide</title><link>https://sjramblings.io/getting-started-with-cfn-guard/</link><guid isPermaLink="true">https://sjramblings.io/getting-started-with-cfn-guard/</guid><description>Learn AWS CloudFormation Guard (cfn-guard) for policy-as-code validation. Parse AWS Config resources, write Guard rules, and enforce compliance without Lambda functions.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>github-actions AWS Authentication with OIDC for github Enterprise</title><link>https://sjramblings.io/github-actions-aws-authentication-with-oidc-for-github-enterprise/</link><guid isPermaLink="true">https://sjramblings.io/github-actions-aws-authentication-with-oidc-for-github-enterprise/</guid><description>There are many blog posts about how to use github-actions OIDC with AWS; however, they all refer to using Github.com and don&apos;t provide some easy steps if you...</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>github-actions - How did I not see that</title><link>https://sjramblings.io/github-actions-how-did-i-not-see-that/</link><guid isPermaLink="true">https://sjramblings.io/github-actions-how-did-i-not-see-that/</guid><description>This post is about a mistake I made that wasted a fair bit of time on my side until the folks over in Support set me straight :)</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Fix &quot;Resource Not Accessible by Integration&quot; in GitHub Actions (2026 Guide)</title><link>https://sjramblings.io/github-actions-resource-not-accessible-by-integration/</link><guid isPermaLink="true">https://sjramblings.io/github-actions-resource-not-accessible-by-integration/</guid><description>Getting &quot;Resource not accessible by integration&quot; in GitHub Actions? Fix HTTP 403, GraphQL createPullRequest, and GITHUB_TOKEN permission errors. Step-by-step with real examples.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Github Runner ECS Authentication</title><link>https://sjramblings.io/github-runner-ecs-authentication/</link><guid isPermaLink="true">https://sjramblings.io/github-runner-ecs-authentication/</guid><description>Using this fantastic open-source project, we have enabled github-actions using ephemeral self-managed runners on AWS SPOT.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>HashiCorp packer amazon-linux cracklib gotcha</title><link>https://sjramblings.io/hashicorp-packer-gotcha/</link><guid isPermaLink="true">https://sjramblings.io/hashicorp-packer-gotcha/</guid><description>While setting up packer for the first time in ages I found a little cracklib quirk when using amazon linux while following the instructions from the website.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>How to simplify your CI/CD with Makefiles</title><link>https://sjramblings.io/how-to-simplify-your-ci-cd-with-makefiles/</link><guid isPermaLink="true">https://sjramblings.io/how-to-simplify-your-ci-cd-with-makefiles/</guid><description>*Make is a build automation tool that automatically builds executable programs and libraries from source code by reading files called Makefiles which specify...</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>How to sync containers to AWS ECS the easy way</title><link>https://sjramblings.io/how-to-sync-containers-to-aws-ecs-the-easy-way/</link><guid isPermaLink="true">https://sjramblings.io/how-to-sync-containers-to-aws-ecs-the-easy-way/</guid><description>Back in November 2021 AWS announced that you can cache containers from DockerHub through to ECS.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>How to use cfn-guard with AWS Config</title><link>https://sjramblings.io/how-to-use-cfn-guard-with-aws-config/</link><guid isPermaLink="true">https://sjramblings.io/how-to-use-cfn-guard-with-aws-config/</guid><description>I&apos;m not sure when but AWS Config now supports using Guard rules to determine the compliance of resources. This is a pretty neat integration and one of the...</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Prowler on AWS</title><link>https://sjramblings.io/prowler_on_aws/</link><guid isPermaLink="true">https://sjramblings.io/prowler_on_aws/</guid><description>Prowler is an awesome open source tool for auditing AWS settings within an account or many accounts across an organisation.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Security Hub now supports Custom AWS Config Rules</title><link>https://sjramblings.io/security-hub-now-supports-custom-aws-config-rules/</link><guid isPermaLink="true">https://sjramblings.io/security-hub-now-supports-custom-aws-config-rules/</guid><description>AWS recently announced an integration that I&apos;m a little excited about!</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Semgrep Rules for AWS &amp; Azure: Enforce Code Standards with Custom Rules</title><link>https://sjramblings.io/semgrep/</link><guid isPermaLink="true">https://sjramblings.io/semgrep/</guid><description>Build custom Semgrep rules for AWS and Azure infrastructure code. Enforce Terraform module pinning, variable descriptions, and security standards across your engineering team.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Terraform, github-actions &amp; OIDC on AWS</title><link>https://sjramblings.io/terraform-github-actions/</link><guid isPermaLink="true">https://sjramblings.io/terraform-github-actions/</guid><description>I&apos;ve posted here how to configure the OIDC AWS Provider &amp; github Enterprise integration; however, nothing is better than an example of it working, and this...</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Up and running with AWS Network Firewall - Part 2</title><link>https://sjramblings.io/up-and-running-with-aws-network-firewall-part-2/</link><guid isPermaLink="true">https://sjramblings.io/up-and-running-with-aws-network-firewall-part-2/</guid><description>The second post in my series as I share my learnings with AWS Network Firewall.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>When Forking is not an option for your public git repos</title><link>https://sjramblings.io/when-forking-is-not-an-option-for-your-public-git-repos/</link><guid isPermaLink="true">https://sjramblings.io/when-forking-is-not-an-option-for-your-public-git-repos/</guid><description>I&apos;m curious if this is an everyday use case, but I need to sync a public repo to our internal github Enterprise instance.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>When Enterprise IT systems migrate to AWS</title><link>https://sjramblings.io/when-legacy-cots-meets-cloud/</link><guid isPermaLink="true">https://sjramblings.io/when-legacy-cots-meets-cloud/</guid><description>So we&apos;ve all seen the marketing slides....</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Up and running with AWS Network Firewall - Part 3</title><link>https://sjramblings.io/up-and-running-with-aws-network-firewall-part-3/</link><guid isPermaLink="true">https://sjramblings.io/up-and-running-with-aws-network-firewall-part-3/</guid><description>The third post in my series as I share my learnings with AWS Network Firewall.</description><pubDate>Mon, 13 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Possibly the Greatest Log Insights CloudTrail Query Ever!</title><link>https://sjramblings.io/the-greatest-log-insights-cloudtrail-query-ever/</link><guid isPermaLink="true">https://sjramblings.io/the-greatest-log-insights-cloudtrail-query-ever/</guid><description>AWS CloudTrail has a wealth of information that often gets forgotten and unchecked.</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate></item><item><title>The Power of Self-Hosted github-actions</title><link>https://sjramblings.io/the-power-of-self-hosted-github-actions/</link><guid isPermaLink="true">https://sjramblings.io/the-power-of-self-hosted-github-actions/</guid><description>github-actions is a CI/CD (Continuous Integration/Continuous Deployment) platform integrated into github, allowing users to automate software development...</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Integrating github with AWS EventBridge</title><link>https://sjramblings.io/integrating-github-with-aws-eventbridge/</link><guid isPermaLink="true">https://sjramblings.io/integrating-github-with-aws-eventbridge/</guid><description>Ever since I saw this announcement, I&apos;ve been dying to get a chance to set it up and play with it. That time is now!</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Unleashing the power of AWS Athena on Transit Gateway Flow Logs</title><link>https://sjramblings.io/unleashing-the-power-of-aws-athena-on-transit-gateway-flow-logs/</link><guid isPermaLink="true">https://sjramblings.io/unleashing-the-power-of-aws-athena-on-transit-gateway-flow-logs/</guid><description>AWS Transit Gateway Flow Logs provide valuable insights into the traffic flowing through your network. However, analyzing this data can be challenging...</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Dude Scale My Runners</title><link>https://sjramblings.io/dude-scale-my-runners/</link><guid isPermaLink="true">https://sjramblings.io/dude-scale-my-runners/</guid><description>In our github Enterprise Instance, we use the super-linter to keep all our users honest and lint everything.</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate></item><item><title>Process github Workflow Events with AWS Stepfunctions</title><link>https://sjramblings.io/process-github-workflow-events-with-aws-stepfunctions/</link><guid isPermaLink="true">https://sjramblings.io/process-github-workflow-events-with-aws-stepfunctions/</guid><description>This is the next part of integrating github Enterprise Managed User events into the AWS Serverless ecosystem.</description><pubDate>Thu, 09 Mar 2023 00:00:00 GMT</pubDate></item><item><title>AWS Prefix Lists for the Organization</title><link>https://sjramblings.io/aws-prefix-list-for-the-organization/</link><guid isPermaLink="true">https://sjramblings.io/aws-prefix-list-for-the-organization/</guid><description>this is meta description</description><pubDate>Thu, 09 Mar 2023 00:00:00 GMT</pubDate></item></channel></rss>