The Cloud Playbook
Subscribe
Sign in
Home
Podcast
Notes
Platform Engineering
AWS Cloud
Compliance
FinOps
Engineering Leadership
Products
Sponsorship
Archive
About
Latest
Top
Discussions
TCP #140: How to Keep Your AWS Data Lake From Becoming a Data Swamp
A Terraform reference pattern for controlling schema, ownership, partitioning, permissions, and cost before your serverless data lake becomes untrusted.
Sep 6
•
Amrut Patil
2
August 2026
TCP #139: The strangler fig that strangled nothing after 18 months
How to sequence which seam gets cut first, second, and third, so the pattern converges instead of stalling at two services forever.
Aug 16
•
Amrut Patil
TCP #138: The rehost business case that was true in the slide deck
Three line items that turn a lift-and-shift savings story into a loss, and where each one hides until the first invoice.
Aug 9
•
Amrut Patil
1
TCP #137: The migration strategy meeting that never needed to be a meeting.
Four questions that sort any workload into rehost, replatform, refactor, repurchase, retain, or retire, before the debate starts.
Aug 1
•
Amrut Patil
July 2026
TCP#136: You picked your secret store by cost. That was the wrong axis.
Secrets Manager, Parameter Store, and KMS-encrypted env compared on the axes that actually decide the right store per secret.
Jul 26
•
Amrut Patil
TCP #135: The GuardDuty org-wide gotchas that break your Terraform run
Delegated admin, per-feature enablement, severity routing, and the multi-region and provider traps, all as code
Jul 23
•
Amrut Patil
TCP #134: GuardDuty org-wide is a one-click decision with a six-month tail.
The pre-flight decisions on delegated admin, cost, and alert routing that decide whether GuardDuty becomes signal or noise.
Jul 19
•
Amrut Patil
1
TCP #133: Permission sets belong in a pipeline, not in the Identity Center console
The controls-as-code system for permission sets: repo structure, CI/CD deployment, privilege review gates, and drift detection
Jul 16
•
Amrut Patil
TCP #132: Your Control Tower guardrails belong in Terraform, not the console
The controls-as-code system for preventive, detective, and proactive guardrails, with review, drift detection, and rollout order.
Jul 12
•
Amrut Patil
1
TCP #131: The multi-account checklist regulated SaaS teams should have written
Account strategy, identity, networking, tenancy, and audit — each section with owners, cadences, and evidence.
Jul 9
•
Amrut Patil
1
TCP #130: Multi-Account AWS Environments Fail When Nobody Owns the Boundaries
Why account sprawl, tenant separation, and shared services break down without explicit control-plane ownership.
Jul 5
•
Amrut Patil
TCP #129: The scoring framework that picks ECS, EKS, or Lambda.
A weighted decision matrix across team maturity, operations, compliance, cost, and ownership with worked examples.
Jul 2
•
Amrut Patil
1
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts