Blog Posts
- Home /
- Blog Posts

HashiCorp Vault Production Hardening Guide: Security Best Practices (2026)
So, you’ve got Vault up and running, and you’re feeling pretty good about storing and managing secrets. But here’s the thing—running Vault in production is a whole different game. It’s not just about turning it on; it’s about hardening it to ensure that your Vault instance is secure, reliable, and resilient against attacks.
Read More
HashiCorp Vault Secrets Management: Best Practices, Rotation & Dynamic Secrets
What is HashiCorp Vault? HashiCorp Vault is a secrets management platform that centralises how your organisation stores, accesses, and distributes sensitive data — API keys, database credentials, certificates, encryption keys, and more. Rather than scattering secrets across config files, environment variables, and shared spreadsheets, Vault gives you a single source of truth with fine-grained access control, automatic rotation, and a full audit trail.
Read More
Ensuring Seamless Connectivity - The Crucial Role of Failover testing in AWS Direct Connect
👋 Hey there! Setting up the Direct Connect service is reserved for a select few. Typically, the network dudes handle this intricate task. However, understanding this service is crucial, especially when establishing hybrid cloud connectivity.
Read More
github Self-Hosted Runners on AWS CodeBuild
👋 Hey there! I’ve written before about establishing Self-Hosted Runners within github.com here. However, this involves deploying API endpoints and integrating with github via a WebHook. It’s not hard to establish, but it’s extra work to look after, update, and manage.
Read More
Creating shared github-actions
Table of contents Workflow Before Workflow After The Workflow Creating a shared (reusable) workflow Workflow Repository Adapt the workflow for reuse Calling the shared workflow Summary 👋 Hey there!
Read More
Do Not Default to PAT
👋 Hey there! Scenario: You need to automate something in github, and after a couple of searches in Google, you see that you can create a PAT and use that.
Read More
Searching github Organisations
👋 Hey there! As a DevOps 🧑💻 team grows, so does the number of repositories. If you use Infrastructure As Code and automation tools like Terraform or Ansible, you will likely have many repos that map to reusable modules. The modules are then combined to deliver full deployments. 🚀
Read More
AWS Windows SSM Port Forwarding, too easy
👋 Hey there! Recently, I had to configure some Windows boxes for a project and was reminded of how simple it was to access them without needing a Bastion host by using SSM port forwarding. 🙌
Read More
AWS Lambda Powertools Metrics: Custom CloudWatch Metrics Made Simple
In this post, I’ll show you how easy it is to publish custom metrics into AWS CloudWatch using AWS Lambda Powertools and the Cloudwatch EMU Specification
Read More
How to sync containers from github Container Registry to AWS ECS
Back in June last year I wrote about syncing containers from DockerHub to AWS ECS.
Read MoreCategories
Tags
- Actions
- Agent-Plugins
- Agentcore
- Agentic-Ai
- Agents
- Ai
- Ai-Agents
- Ai-Workflows
- Airia
- Amazon Bedrock
- Amazon-Q-Dev-Cli
- Ami
- Anthropic
- Architecture
- Audit
- Authentication
- Automation
- Autonomous
- Aws
- Aws-Organizations
- Azure
- Azure-Devops
- Bedrock
- Bgp
- Build-Games-Challenge
- Building
- Cdk
- Certificates
- Ci-Cd
- Ciso
- Claude
- Claude-Code
- Cli
- Cloud
- Cloud-Computing
- Cloud-Governance
- Cloud-Infrastructure
- Cloud-Security
- Cloudflare
- Cloudformation
- Cloudtrail
- Cloudwatch
- Codebuild
- Coding
- Community
- Compliance
- Config
- Containers
- Context-Database
- Context-Management
- Cost
- Cost-Optimization
- Crypto-Agility
- Cryptography
- Data-Sovereignty
- Data-Visualisation
- Developer Tools
- Developer-Culture
- Development
- Devops
- Directconnect
- Docker
- Document-Processing
- Ebs
- Ec2
- Ecs
- Elixir
- Engineering-Culture
- Enterprise
- Enterprise-Architecture
- European-Sovereign-Cloud
- Eventbridge
- Extensions
- Finops
- Firewall
- Fsx
- Ghcr
- Git
- Github
- GitHub Actions
- Github-Pages
- Governance
- Hackathon
- Hashicorp
- Hashicorp-Vault
- Http
- Hybrid-Cloud
- Iac
- IAM
- Identity
- Inference-Profiles
- Infrastructure
- Infrastructure as Code
- Iot
- Jwt
- Lambda
- Landing-Zone
- Latency
- Legacy
- Lightsail
- Llm
- Logging
- Make
- Makefile
- Mcp
- Meta
- Multi-Cloud
- N8n
- Network-Firewall
- Networking
- New-Zealand
- Nova
- Observability
- OIDC
- Open Source
- Openai
- Opensource
- Openviking
- Opinion
- Orchestration
- Packer
- Patterns
- Pipeline
- Policy-Controls
- Pqc
- Productivity
- Prompt-Injection
- Prowler
- Python
- Q-Developer
- Quantum
- Rag
- Regions
- Risk-Management
- Route53
- S3
- Scp
- Secrets
- Secrets-Management
- Security
- Securityawareness
- Semgrep
- Serverless
- Service-Control-Policies
- Skills
- Sovereign-Cloud
- Sovereignty
- Ssm
- Steampipe
- STS
- Systems
- Systems-Thinking
- Technology
- Terraform
- Testing
- Time-Series
- TLS
- Transit-Gateway
- Troubleshooting
- Tutorial
- Vault
- Vector-Search
- Virtualisation
- Vpc
- Vpc-Lattice
- Yaml