Engineering / cloud
Cloud infrastructure
Cloud systems are easier to operate when the important decisions are visible before the first resource exists.
The useful abstraction
A cloud account is not an architecture. The architecture is the set of boundaries around identity, network reachability, data, and failure. I start with those boundaries, then choose services that keep them legible.
- Separate workloads by account, project, or namespace before access policies become a maze.
- Prefer private-by-default network paths and explicit egress over a flat subnet that is easy to demo.
- Treat cost, recovery time, and blast radius as design inputs rather than post-deployment reports.
Infrastructure as code
Terraform is most valuable as a reviewable change set. Modules should describe a stable responsibility, expose a small interface, and leave provider details visible enough that a reviewer can reason about the plan.
If a module hides the decision that matters, it has reduced typing at the cost of reviewability.
Operational hand-off
A cloud design is not finished at apply. It needs ownership, alerts with a human question behind them, a recovery path that has been exercised, and a record of the assumptions that would make the design unsafe.