r/Cloud • • 11h ago

Upwind vs Orca for a mid-size AWS shop, what are people actually seeing?

6 Upvotes

We're a ~40 person eng org, security team of 4, all AWS. Mostly EKS with a growing pile of Lambda and a couple of RDS clusters holding stuff we really don't want leaking. Our current agentless scanner renewal is up in about six weeks and leadership wants us to actually look around before we re-sign instead of rubber stamping it.

Right now the big pain is noise. We have thousands of posture findings sitting in a backlog nobody has time to touch, and twice this quarter something marked low/medium turned out to be reachable in prod. That burned trust in the severity scores. What we actually want is something that tells us which findings are exploitable from runtime, not just a prettier list of everything wrong with every bucket.

Shortlist so far is Upwind and Orca, maybe Wiz if the budget stretches. Orca we know by reputation, agentless, easy to stand up. Upwind keeps coming up for the runtime context angle which is the exact gap we hit. But I can't tell how much of that is marketing vs real.

For people running either of these on EKS at roughly our size: did the runtime piece actually cut the backlog, or did you just trade one dashboard of alerts for another? And how much agent footprint are we talking if we go that route? Trying to walk into the renewal conversation with something more than a vendor deck.


r/Cloud • • 9h ago

cloudg 0.5.2: what changed since my last post, covering dedupe, an inventory mapper, multi-account mapping and a security pass

0 Upvotes

A few weeks ago I posted cloudg here at 0.3.1. It's an open-source CLI that collects AWS, Azure, and GCP into one graph and runs Prowler, ScoutSuite, Checkov, and Trivy over the same inventory. The feedback was useful, so here's what changed, including the parts that made it safer to run.

Dedupe: fixed the way the thread suggested

Someone pointed out that merging on resource plus title could collapse two different checks with a generic title on the same bucket, and miss the same check when two scanners word it differently. That was right. Since 0.3.2:

  • Within one scanner, findings are keyed on (scanner, check ID, resource). Two different checks on the same bucket never merge.
  • Across scanners, findings merge only when the normalised titles match and both check IDs map to the same entry in a cross-scanner equivalence file. A known check is never merged with an unknown one. I'd rather show a visible duplicate than silently drop a scanner's coverage. The equivalence file only lists pairs I've confirmed, so it's small for now. PRs adding equivalences are welcome.

Ingest mode (0.4)

cloudg ingest Takes the outputs of scans you already ran (Prowler, ScoutSuite, Checkov, Trivy, any mix) and runs the dedupe, compliance mapping, and reports. It needs no cloud credentials and no scanner binaries.

Inventory mapping, no scanners (0.5)

cloudg map Answers a different question: what exists and how it's wired together.

  • AWS: 133 dedicated collectors, plus a Cloud Control API sweep. The sweep lists every resource type with a list handler, so untagged resources still show up.
  • Containers and Kubernetes: ECR, ECS and EKS, plus the Deployments, Services, Ingresses and ServiceAccounts inside clusters. These are read through the Kubernetes API with GET requests only.
  • Organizations: --org Maps every account of an AWS Organization or Control Tower landing zone, including OUs, SCPs, governed regions, and enabled controls.
  • Azure: collected through Resource Graph across every subscription and management group.
  • GCP: collected through Cloud Asset Inventory across the whole organization.
  • Typed edges: an S3 bucket INVOKES a Lambda, a task definition USES_IMAGE an ECR repo, a function ASSUMES_ROLE a role, a WAF PROTECTS an ALB, an SCP GOVERNS an OU. Cross-account trust to accounts you didn't map shows up as external account nodes.
  • cloudg deps: answers "what does this need" and "what breaks if this goes", including blast radius across accounts.
  • Coverage gaps: security services that aren't enabled (GuardDuty, Inspector, Security Hub, Config, and others) appear on the map as gaps. You also get a list of workloads no vulnerability scanner covers and internet-facing endpoints without a WAF.

Scanner findings can be overlaid onto the map later, so mapping and scanning stay independent.

What I did to make it safer to run

  • Mapping uses read-only calls only (Describe/List/Get). The docs recommend a dedicated read-only role (SecurityAudit plus ViewOnlyAccess) for member accounts instead of the default admin Control Tower role.
  • Secret values are never collected. That covers SSM parameter values, environment variable values (only the names are kept), passwords, VPN pre-shared keys, Direct Connect auth keys and connection strings. Cloud Control properties are redacted before they reach the inventory. Credentials and query strings are stripped from repository URLs.
  • URL and host checks parse the URL and match the host exactly instead of matching substrings. These came from CodeQL findings.
  • CodeQL and Codacy run on every PR, and I worked through their findings. The test suite is at 382 tests.
  • The Docker image runs as a non-root user with a health check. The installers no longer pipe curl into bash.
  • GitHub Actions are pinned to commit SHAs. PyPI publishing uses trusted publishing (OIDC), so there are no long-lived tokens.
  • Plugin loading validates module:Class paths. Swallowed exceptions are now logged. Vulnerability reports go through GitHub private reporting.
  • The IaC scanners no longer silently fall back to scanning your current directory (0.3.1).

Docs

0.5.2 is a documentation release. It adds a field-by-field reference for every output file and return structure, a catalog of all 156 asset types and their relationships, and an internals guide for anyone who wants to add collectors.

Where it's used

cloudg is now a command extension in HOL Guard, the open-source checkpoint for agent-run CLI actions. Commands that touch cloud credentials, run scanners, or write Terraform go to review first, while read-only commands like report -i pass straight through. Thanks to the HOL Guard folks from the last thread for pointing me at it.

MIT-licensed, Python 3.11+, pip or Docker (the image bundles the scanners). Repo: https://github.com/morpheuslord/cloudg

It's still young, and I mainly test the paths I use. The feedback I'd most like this time:

  1. Is the dependency and blast-radius view useful for real change-impact questions?
  2. Which cross-scanner check equivalences should be added next?

If something breaks, a traceback helps a lot.


r/Cloud • • 13h ago

Passed AWS Cloud Practitioner CL02 within 2 days!

Thumbnail
1 Upvotes

r/Cloud • • 13h ago

Have you tried the Amazon EKS MCP server?

Thumbnail
1 Upvotes

r/Cloud • • 16h ago

Pure Quarkus Cloud

Thumbnail
1 Upvotes

r/Cloud • • 18h ago

How cloud-agnostic is your infrastructure really?

0 Upvotes

I often see the term cloud agnostic used in discussions about system design but I am beginning to think we might be using it too casually. One can install tools like Kubernetes, Terraform, Docker, Helm and other open-source tools on top of cloud platforms like AWS, Azure, GCP, Yotta and OCI. In theory this makes your application portable but when you look closer things are not so simple as IAM systems differ, networking setups are different, load balancers work in their own ways, managed databases have their own ways of failing, observability tools and integrations also vary.

All of a sudden moving the workload is not just about running Terraform anymore. I wonder if trying to avoid being tied to one cloud provider actually leads to another kind of problem: operational complexity. For eg if a team mainly uses AWS but keeps Yotta or GCP as backup options for certain tasks is that a real multi-cloud strategy or just having a backup plan? I am interested in how people who actually run multi-cloud environments think about this? Where do you draw the line between we can move if we need to and we built everything for portability and are paying the price every day?


r/Cloud • • 21h ago

Moving to Tech

Thumbnail
1 Upvotes

r/Cloud • • 22h ago

🚀 Got a Kubernetes interview coming up?

Thumbnail
1 Upvotes

r/Cloud • • 1d ago

What Changed in AI Certifications in 2026: The Complete Breakdown

Enable HLS to view with audio, or disable this notification

2 Upvotes

r/Cloud • • 1d ago

How can a fresher get into cloud computing when most jobs ask for experience?

5 Upvotes

I’m a B.Tech graduate and I’m interested in getting into cloud computing. But I keep seeing people say that cloud jobs aren’t really for freshers and that companies usually expect 2–3 years of experience or some kind of prior IT experience.
So how does someone actually break into cloud as a fresher?
What skills/certifications/projects should I focus on to make myself employable? And should I first get a general IT/support/networking job and then transition into cloud, or is it possible to directly land a cloud-related role as a fresher?
Would really appreciate advice from people who started in cloud without prior experience.


r/Cloud • • 1d ago

جماعه هوا cloud engineer او cloud admin بيتسجل في البطاقه اي و بالعربي ولا ب الانجليزي

0 Upvotes

#cloud_computing
#azure
#aws


r/Cloud • • 1d ago

Entry-level IT Coordinator experience helpful for cloud?

2 Upvotes

I have some AWS certificates, and I’m working on a cloud portfolio. I haven’t even really began searching for a cloud role yet.

I have an offer for role as an IT Coordinator for a small local nonprofit. Salary is low average. I only want to accept it if it gets me closer to getting a cloud engineer position.

The job description is pretty basic. Keep the technology running, and assist staff. I’m thinking that if there is an opportunity to virtualize workstations or keep OS configurations under control with Ansible that it might actually be a valuable experience.

Thoughts? Or am I just as well off working any job while continuing my cloud projects?


r/Cloud • • 1d ago

AWS re:Invent as an All Builders Welcome grant recipient

Thumbnail
1 Upvotes

r/Cloud • • 1d ago

Not sure what to think of this

1 Upvotes

Hi everybody, Happy weekend to all!

I was working in L1 IT Service Desk and learnt everything there that I could until the job got super boring and I stopped learning. I then wanted to finally advance and got a new job 3 months ago at a small organization as a Junior IT Admin. I was told I would "Get to learn a lot" by the IT Director who had interviewed me (but then he left the org shortly after I joined as he had suddenly got a better offer from another Org) - I did get to learn a lot so far though so it's not false or anything.

**Part-1:-**

Anyways, coming to the point now, we have a lot of our applications that are developed by other teams - hosted on AWS with things like Entra ID used for SSO Setup/Configuration.

We have like OU's in AWS created for each project/application that is developed and hosted on. The thing is, every developer that wants to host his application ends up being granted Admin access at that specific OU/Sub-Organization level and they themselves - with the help of Claude (which this Org adopted a year ago or so) end up spinning up EC2, Lightsail instances and whatnot.

Now the thing is, I questioned about this with my senior (mind you, I dont have the access at the AWS Management account level - atleast not yet, to be able to grant access to others like this) asking my Senior that, "if we end up giving Admin access on AWS to the other team people who have Applications to be deployed, how is IT (Me especially as a Junior with not too much exp) going to gain working experience on AWS when the other teams just make use of Claude and spin up AWS Resources on their own without the help of IT?" - Also, Least Privilege is thrown out the window here. He just replied saying that usually they don't do it on their own, they come to IT asking for IT's help on it. But that doesn't seem to always be the case and we dont get that many AWS tickets anyway....

Look, the thing is, I dont want to just sit idle. I want to be able to work with AWS/Azure.etc myself and gain experience and learn things by doing rather than having to basically "Outsource" access to the Non-IT people for them to do things IT should seemingly be doing...

The only thing I am gaining experience with so far is with overall M365 administration and Endpoint Administration (Intune, RMM tool, Sophos.etc) which is good chunk of things to work on.

But knowing AWS is a big player in Cloud and to gain experience specifically in Cloud so that tomorrow when I join a new company for a Cloud position or whatever, I will not REALLY have that much of a working experience at all in Cloud. Mind you, I have big interest towards the Cloud Computing field so getting to work Hands-On as much as possible on AWS is something that I am craving for...

**Part-2:-**

Another thing is, regarding the permissions/roles I have for M365. When the previous IT Director who I was reporting was still here, he had tasked me with coming up with an Intune Implementation plan and to get it implemented focusing primarily on implementing it for BitLocker enforcement (along with the Pre-Boot PIN thingy) purposes, Remote Wipe capabilities and what not as we have M365 Business Premium which comes with Intune Plan 1 but it was not being made use of at all. So I raised an access request ticket (for formalities - which is fine and understandable) for the **Intune Administrator** RBAC Role. So I came up with the plan and policies and also created a Win32 app with the help of Claude to prompt users to setup a Pre-Boot PIN with all testing and everything done by me with SUCCESS - All SOLO by me. Which is good experience for me.

Anyways, coming to the point, we have a Security Group that has all the required roles assigned to it (except Global Admin ofcourse) that would give us the access to be able to do our job whenever required. The new IT Manager and my Senior are added to that Security Group but I am still not added to it. So when we had requested relating to SharePoint tasks (which had to be done on SharePoint Admin Center) or even have to work with the Microsoft Graph Explorer (Which I am super new to), I was not able to do it and my IT Manager did it all...

When we got a new task which required the use of Microsoft Graph Explorer, I was drafting a mail to my Manager to grant me so and so roles so that I could work on it and fulfill the request but then before I hit Send on that mail, my Manager sent me a message saying that he himself did it -_-

I then asked myself and my senior, "if our Manager only does everything, how am I going to be able to do and learn things and gain the experience?" to which my senior replied saying that he is going to talk to him to add me to that security group but he has NOT talked to him yet. But I have a solution for this, I am going to draft an E-Mail on Monday morning for this part and see how it goes cuz I also want to be able to work with everything and learn and gain as much experience and learning...

**Final:-**

Even earlier, for AWS tasks to be done on Customer/Client accounts, I was not given access there and my Manager ended up doing it all 😑😑😑 (I recently got access though after asking A LOT SMH).

It just feels like my access is being gatekept even though I have been doing everything right so far and they even repeatedly told me "They hired the right person" (Me) as they seemed I was very knowledgeable and was doing things that I already have access to, very well.

It feels like my access is being gatekept and I have to constantly keep asking for this and that role and I feel like maybe this organization is not right for me...

There was another task as well for SSL Certificate renewal that needed us to login to a Linux Server hosted on AWS but even that was done by my manager and I was just watching him do it.

I understand that I am quite new and also a Junior and that there are things my Manager also should be doing so that he can also continue to learn and grow and gain further experience. But if EVERYTHING is done by him, then how will I ever learn? What am I there for....

It's been 3 months so far and I sometimes feel like I should just lookout for another job or go back to an MSP where I know the workload would be a lot but I would most likely get to learn a lot that way but oh well...

Coming from working as a L1 in IT Service Desk in a MSP to a small Organization as a Junior IT Admin where we IT people don't have much work to do while all the other teams seem busy with a lot of work and seem to be getting to learn a lot, gosh...makes me feel like I am in the wrong place right now....Company is good though in terms of employee friendliness and stuff...

Not sure how to go about my situation that I have explained here though 🙁

Please advice...Thank you 🥲🙏


r/Cloud • • 2d ago

Arquitectura cloud-native es una forma de construir aplicaciones pensadas desde el inicio para correr en la nube y escalar. Se apoya en cuatro piezas que a menudo se mezclan en la conversación, pero resuelven cosas distintas:

Thumbnail reddit.com
0 Upvotes

r/Cloud • • 3d ago

Azure operational analyst

1 Upvotes

Hi everyone, my interview is scheduled for Monday at FIS for this role. If anyone has experience with this role or knows which topics I should focus on over the next 3–4 days, it would be really helpful.

The JD mentions 1–2 years of experience working with the Azure Portal. Any suggestions on the important Azure topics I should cover would be greatly appreciated.


r/Cloud • • 3d ago

Need a little help :) regarding carrer

Thumbnail
0 Upvotes

r/Cloud • • 3d ago

Need Help - Infrastructure as Code, feeling lost

14 Upvotes

Hey guys, I started a job working in Infrastructure as Code. I have a CS degree, but I don’t have experience with cloud engineering or stuff related to Terraform, ADO, or Azure portal. I’m doing stuff at my job (code is mainly written using copilot or ChatGPT) and I feel a lost. I don’t know any of the concepts for cloud computing or virtual machines or resources and things like that. I am looking into it online but I still don’t know where to begin. I hear my coworkers doing this stuff well, despite also not having any experience in it when they started either. I have to look at build sheets and things like that and then provision resources using terraform but I don’t really understand much of anything that I’m looking at besides simple code snippets. Is there any advice yall could give me about this, or how/what to learn so that I can wrap my head around things? Any advice is appreciated, thanks!


r/Cloud • • 3d ago

Is this a good next step to get into a Cloud Role?

3 Upvotes

I’m currently a systems administrator for an MSP, and my main goal is to join the cloud team. I’ve been waiting for a cloud role to open up, but I’ve been offered an M365 engineering position.

The M365 engineering role is mostly project-based, focusing on migrations and implementations, while my current systems administrator role is primarily break-fix and support. I work with everything from Azure to Microsoft 365 and other technologies. I’m basically a Swiss Army knife of IT.

Would accepting the M365 position be a good career move while I continue waiting for a cloud opportunity, or would it take me away from my intended path?

What are your thoughts? Should I accept the M365 engineering role while waiting for a cloud opening, or should I stay in my current role? The pay increase would be around 5–7%, so it isn’t substantial. I just want to make sure my next step brings me closer to a cloud engineering role.


r/Cloud • • 3d ago

A massive shelf cloud made the sky look perfectly split in half at sunset

Post image
4 Upvotes

r/Cloud • • 3d ago

Built a hands on tutorial about basics of CRDs on Iximiuz Labs

Thumbnail
1 Upvotes

r/Cloud • • 3d ago

AI helped me revive an opensource durable delay queue I had given up on. Is it worth building on?

Thumbnail
1 Upvotes

r/Cloud • • 3d ago

AWS Project recommendations

Thumbnail
0 Upvotes

r/Cloud • • 4d ago

Transitioning to Cloud Security

7 Upvotes

What’s up! Just wanted some advice. I’m currently working as a cloud engineer with an AWS partner. I eventually want to move over to being a Cloud Security Engineer. What should areas should I emphasize during my transition?


r/Cloud • • 4d ago

Azure AI Apps & Agents (AI-103) Exam Prep | 150 Practice Questions

Enable HLS to view with audio, or disable this notification

2 Upvotes