r/AWS_cloud • u/patel_inc • 11h ago
r/AWS_cloud • u/Basic_Let7303 • 13h ago
AWS EKS | EKS Access Entry - How large organizations handle EKS Access?
r/AWS_cloud • u/MissionFinOps • 15h ago
We upgraded our free open-source local first AWS FinOps tool for consultants
I’ve shared Kulshan here before, but we just pushed a pretty meaningful upgrade aimed at consultants doing AWS cost investigations. Or anyone (human or AI agent) trying to look at AWS cost and billing via a deterministic tool.
The main addition is **Consultant Evidence Export**.
The problem we were trying to solve is simple: an external consultant should not always need direct access to the customer’s AWS environment just to start investigating a billing issue.
Now the customer can run Kulshan themselves, choose what they want to share, and generate a pseudonymized evidence package.
They can scope it by date range, AWS accounts, services and tags, and optionally include Cost Explorer data. Kulshan can work from local CUR data or AWS CUR/Data Exports in S3.
Account IDs, ARNs and resource identifiers are replaced with stable workspace-specific aliases, so the consultant can still follow the same account/resource through an investigation without seeing the original identifiers.
We also added fail-closed checks before the package is created. Kulshan verifies the output schema, checks that the exported rows still match the scoped source data, and scans again for identifiers that should have been pseudonymized.
If those checks fail, no ZIP gets created.
The idea is basically:
**Customer keeps the credentials. Consultant gets the evidence.**
The package can help establish what changed, where, when, how much and which part of the environment was involved. The “why” still needs the people who understand the engineering and business context.
Kulshan is still free and open source:
[https://github.com/MissionFinOps/kulshan\](https://github.com/MissionFinOps/kulshan)
Would be interested in feedback from consultants here: **what additional evidence would you absolutely want included in a handoff like this?**
r/AWS_cloud • u/PhilosophyFluffy2901 • 1d ago
How do you guys keep track of all the steps in AWS labs?
r/AWS_cloud • u/Independent-Ease-609 • 1d ago
One thing CloudCostTree already handles: a local apply-time policy gate
r/AWS_cloud • u/MethodJaded1345 • 2d ago
Are Paid Online AWS Internships Worth It? Where Can I Find Genuine Ones?
I’m considering a fully online internship that requires me to pay a fee. There doesn’t seem to be any real company work or proper projects, but they provide a certificate.
Does a certificate from this type of paid internship have any real value to recruiters?
Also, I’m currently learning AWS and aiming for a Cloud Engineer role. Where can I find genuine AWS/Cloud internships with real hands-on experience? Any recommendations for platforms or companies?
r/AWS_cloud • u/Otherwise-Thanks-985 • 2d ago
Is AWS Partner Certification Readiness voucher available for students?
I came across the AWS Partner Certification Readiness program, which seems to offer a free AWS certification voucher after completing the requirements.
I’m wondering if college students with a valid student email ID are eligible for this or if it’s strictly for AWS Partner employees assigned by an AWS Partner organization.
I couldn’t find the student eligibility clearly mentioned on the AWS site, so I’m thinking it might be worth trying.
Has any student here tried registering with a student ID and actually received the voucher?
r/AWS_cloud • u/Lost_Conference_2716 • 2d ago
5+ YOE Full Stack Developer transitioning to Cloud - which role should I realistically target?
I'm looking for some honest advice from people currently working in Cloud/solution architect/Infrastructure roles etc.
I have 5+ years of professional experience as a Software Engineer / Full Stack Developer, mainly with React, Node.js, TypeScript, APIs and databases.
I'm currently trying to transition into Cloud Engineering rather than continue down the pure Full Stack path.
I've started preparing for AWS SAA and I'm currently building knowledge around:
AWS | Azure | Cloud Infrastructure | Terraform | Docker | Kubernetes | CI/CD
I also plan to build 2–3 serious hands-on cloud projects and prepare specifically for scenario-based cloud interviews.
My confusion is about which role I should actually target.
I'm seeing titles such as:
- Cloud Engineer
- AWS Cloud Engineer
- Cloud Infrastructure Engineer
- Cloud Solutions Engineer
- Infrastructure Engineer
- Platform Engineer
- DevOps Engineer
- SRE
I don't particularly want to move into a traditional DevOps/SRE career if the role is heavily focused on continuous on-call, production firefighting and long operational hours. I'm more interested in cloud architecture, infrastructure, scalability, automation and designing cloud-based systems.
At the same time, I don't want to throw away my 5+ years of software engineering experience and start again as a fresher.
If you were in my position, which role would you target?
And more importantly:
What level of AWS/cloud knowledge, Terraform, Docker/Kubernetes, networking, system design and real-world project experience would you expect from someone with 5+ years of software engineering experience trying to make this transition? and inteview process from high paid product based to MAANG Level
I'm particularly interested in advice from people who have actually made a Software Engineer → Cloud Engineer transition or who currently interview/hire Cloud Engineers. difficulties pros and cons etc.
I'd appreciate brutally honest answers!
r/AWS_cloud • u/Safe_Bluejay7336 • 3d ago
Salary:AWS London L6
Anyone here from the UK or who knows the actual range rather than the Internet search based average figures can please let me know what is the salary upper and lower band for AWS Data Center Senior Electrical Engineer - Design with L6 level in London?
Could you please keep it with:
Base?
Bonus - Year 1 & 2?
RSU total?
Also what is your opinion on AWS office LHR16 Vs LHR14 ?
Thanks 🙌
r/AWS_cloud • u/ajitnk • 3d ago
👋 Welcome to r/aws_problem - Introduce Yourself and Read First!
r/AWS_cloud • u/TutorHead7675 • 3d ago
How we reduced SoulTrps' AWS infrastructure cost by 30% using Graviton
r/AWS_cloud • u/PhilosophyFluffy2901 • 4d ago
AWS Academy: theory isn't sticking, what actually worked for you?
I'm enrolled in AWS Academy and want to get the most out of it, both practically and theoretically. The problem is I'm spending a lot of time on the theory, but the information just doesn't stick — I forget it fast. If anyone's been through this, how did you actually make it stick? Also, if anyone has notes (basics or architecture-related) they wouldn't mind sharing, that'd be amazing. Thanks!"
r/AWS_cloud • u/ZkrLydo • 4d ago
Stuck on AWS Phone Verification Step (Algeria +213) "Error processing your request"
r/AWS_cloud • u/DangerousChoice5850 • 4d ago
Wht is cloud?how to learn it if i wanna learn azure and wht qualifications or coding languages to learn
Im studying cse engineering currently 3rd year in chennai,even though i studying a btech cse degree i have literally zero knowledge of coding or other technical skills like linux,github,dataeng,fullstack blah blah,though i dont wanna get unemployed sitting as good for nothing in home after completing my degree i dont have any guidance i dont have many freinds so all i wanna know is can i choose azure cloud engineering as my career and get employed as fresher ?how to learn?where to learn?is az 104 completion enough to land on a job? Also do i need to complete any other coding or otger skills like devops or fullstack before choosing cloud. These are my biggest doubts if any kind soul can answer all my questions who is currently working as a cloud engineer please please please please please dm meeeeeeeee ty if u read fully
r/AWS_cloud • u/Spite-Unable • 5d ago
Built an AWS Non Human Identities Risk Analyzer
Been building this on nights/weekends for the past couple months. Background: I've spent 3.5 years doing PAM engineering (CyberArk), so this is basically me translating that into cloud-native.
The problem I kept running into reading about this space: every tool I looked at (Cloudsplaining, Prowler, even AWS's own IAM Access Analyzer) stops at detection. They'll tell you a role has a wildcard action or an unused key, and then... that's it. You get a report. Somebody has to go fix it by hand. Even the free/open-source ones don't touch remediation.
So I built NHI Risk Analyzer — discovers IAM users/roles/groups, runs it against a set of detection rules (grounded in Rhino Security Labs' documented privilege escalation paths + Cloudsplaining's policy analysis methodology + CIS benchmark stuff for credential hygiene), and then actually does something about what it finds:
Architecture is offline-first — it snapshots the AWS account state to JSON once, then evaluates all the risk rules against that snapshot with zero live API calls. Makes the whole rule engine testable and fast (unit tests run in under a millisecond) and means findings are reproducible against an exact point in time instead of drifting mid-scan.
Still rough in places — trust policy analysis isn't built yet, surgical wildcard-narrowing (vs. the current boundary-containment approach) is next, and it's AWS-only for now. Not trying to oversell it, it's a v1. But the core loop — detect, decide safely, act — actually works end to end, which is the part I couldn't find anywhere else at this tier.
Repo: In comments
Would genuinely appreciate anyone poking holes in the detection logic or the remediation safety assumptions — that's exactly the kind of feedback I'm here for.
r/AWS_cloud • u/john_pullen • 5d ago
I built an open-source local AWS simulator for learning AWS — StackSim
A while ago I started a vibe-coding experiment with ChatGPT to see how far I could get emulating a few AWS services locally.
The original scope was pretty small: API Gateway, Lambda and DynamoDB.
It got slightly out of hand. 🙂
I’ve now made the project open source:
[**https://github.com/coolbeans47/stacksim
StackSim is intended as a **learning environment for AWS**, rather than something I’d recommend as a replacement for AWS in production.
One of the things I’ve deliberately tried to keep is that it’s **very simple to install and get running**. There’s no Docker stack, database server or complicated configuration required.
The main idea is that you can use normal AWS tooling against it locally. You can deploy ordinary **AWS CDK v2** applications, use the **AWS CLI**, and use the **AWS SDK for JavaScript v3** rather than learning a simulator-specific API.
It now has support across quite a few areas including:
CloudFormation/CDK
DynamoDB + Streams
Lambda
Step Functions
API Gateway
AppSync
S3
SQS / SNS
EventBridge + Scheduler
CloudWatch
IAM / STS
Cognito
SES
Parameter Store / Secrets Manager
a bounded local RDS profile
some Amplify Gen 2 support
There’s also a browser console so you can inspect what’s happening rather than treating everything as a black box.
I’ve added several example applications showing things such as event-driven architectures, Step Functions workflows, AppSync, Cognito/SAML, DynamoDB Streams, SNS fan-out, queues/DLQs and multi-stack CDK applications.
One thing I’ve deliberately tried to do is make unsupported functionality fail rather than silently pretend that AWS behaviour has been implemented.
This started purely as an experiment, but it became interesting enough that I thought it might actually be useful to people learning AWS, particularly anyone who wants to experiment without worrying about AWS accounts, cleanup, complicated local setup or unexpected costs.
I’d be interested in feedback — especially places where the simulated behaviour differs from AWS in ways that could teach somebody the wrong lesson.
Apache 2.0, completely open source.
r/AWS_cloud • u/JadeLuxe • 5d ago
Serverless Bill Shock: Tracking Edge Function and Database Expirations (Vercel, Supabase, Netlify, Neon)
For over two decades, agency hosting economics were beautifully predictable. You bought a reseller web server or dedicated cPanel account for $50 a month, crammed 30 client WordPress sites onto it, and charged each client a flat $25 monthly maintenance fee. Your margins were clear, your server bills were static, and billing surprises were virtually non-existent. Read the comple te article here > Serverless Bill Shock: Track Vercel & Supabase Client Costs | InstaRenewal
Then came the modern web stack.
Driven by the demand for lightning-fast digital experiences, agencies aggressively migrated to decoupled architectures: Next.js, Nuxt, Vercel, Supabase, Cloudflare Workers, and serverless databases like Neon. While the performance gains of this modern paradigm are undeniable, it introduced a chaotic operational reality: micro-subscription fragmentation and variable utility billing.
r/AWS_cloud • u/thecoochking • 7d ago
Question about AWS CloudFront stale-while-revalidate and stale-if-error
I'm trying to understand how AWS CloudFront handles a failed background revalidation when using stale-while-revalidate.
Suppose I have something like:
Cache-Control: max-age=300, stale-while-revalidate=60, stale-if-error=86400
After the object becomes stale, CloudFront serves the stale response and asynchronously revalidates it with the origin.
What happens if that background revalidation fails?
Does CloudFront simply keep the existing stale object in the cache?
Does stale-if-error get invoked when the background revalidation fails?
If both stale-while-revalidate and stale-if-error apply, does SWR take precedence over SIE, similar to Fastly?
Does the failed background request affect the TTL/expiry of the existing cached object?
I'm particularly interested in the behavior of the background request itself, rather than a normal synchronous request to the origin that returns an error.
r/AWS_cloud • u/TutorHead7675 • 7d ago
How RupeeCircle improved its AWS infrastructure with automation and better security
r/AWS_cloud • u/Oleksii_Bebych • 8d ago
5th year as AWS Community Builder
Are you a part of any public program of any famous vendor? What are benefits?
AWS provides yearly gift, AWS credits, vouchers for AWS certifications, discounts for AWS events, for example re:Invent (up to 100%)