Is there anything worse than onboarding a new dev with an outdated diagram? You spend 20 minutes explaining "oh ignore that box, we deleted that last year". It is confusing and inefficient. We found a better way using Kiro. It scans your live AWS environment.
Sandro Volpicella
@sandrovolpicella.com
I teach developers about the cloud ⛅ 👨🏽💻 Platform Lead @hashnode 📕 New Book: https://cloudwatchbook.com ⛅ AWS Fundamentals Book: https://awsfundamentals.com 😼 Builds https://kitlytics.com 🤗 AWS Community Builder
I refuse to spend another Friday afternoon in Drawio. Documentation is important. But manual documentation is painful. We have been experimenting with MCP servers and AI to solve this. The tool connects directly to your infrastructure. It reads your Terraform or CDK.
I've been running centralized logging for our AWS accounts. CloudWatch log centralization has two gotchas that caught me off guard. Gotcha #1: Settings Don't Transfer 🚨 Log Group settings get stripped during the copy. Retention policies? Gone. Data protection policies? Gone.
Your architecture diagram is lying to you. It was probably correct on day one. But then you added a Lambda function. Changed a DynamoDB index. And forgot to update the doc. We all do this. That is why we started using AI to fix it.
Supply chain attacks are rising. And your `node_modules` folder is the perfect target. OWASP dropped their Top 10 for NPM security. It's a wake-up call for many of us. I summarized the key points you need to know. 𝟏. 𝐃𝐨𝐧'𝐭 𝐭𝐫𝐮𝐬𝐭 𝐬𝐜𝐫𝐢𝐩𝐭𝐬
Stop dragging boxes around in Drawio. Seriously. It is 2026. We should have 𝐚𝐮𝐭𝐨𝐦𝐚𝐭𝐞𝐝 this years ago. We recorded a video showing how to use AI to generate your AWS diagrams. It pulls data right from your 𝐥𝐢𝐯𝐞 𝐞𝐧𝐯𝐢𝐫𝐨𝐧𝐦𝐞𝐧𝐭.
Stop using 𝐒𝟑 𝐒𝐭𝐚𝐧𝐝𝐚𝐫𝐝 as your default storage class. Unless you know exactly how your data will be accessed, you are likely overpaying. I used to default to Standard for everything. Then I looked at our bill.
Everyone tells you to move old data to Glacier to save money. But they usually forget to mention the pain. • Retrieval fees hurt. • Waiting 5-12 hours for data sucks. That is why I prefer 𝐒𝟑 𝐈𝐧𝐭𝐞𝐥𝐥𝐢𝐠𝐞𝐧𝐭-𝐓𝐢𝐞𝐫𝐢𝐧𝐠. It solves the biggest problem with archiving:
We pull in thousands of dependencies. We trust them blindly. That is a mistake. 💣 OWASP just released their top 10 security practices for NPM. I went through them so you don't have to. Here is what you need to change in your workflow:
Sometimes you need to give frontend developers the ability to choose their own data. And if you want to build that in a serverless way you need to use AppSync! We have all been there. The frontend asks for one more field. The backend team puts it on the backlog.
I see Opus is debugging in the same way I do: make the background red and figure out why there is so much fricking space at the top 😬
My current claude-code workflow: 1. cc (alias for alias cc='claude --dangerously-skip-permissions') 2. /spec <idea of the feature> - give all context needed, interviews me with all important things, lots of depth. 3. Specfile is created in Markdown (not JSON/YML -> MD)
One nugget I really took from the podcast of Steinberger & Friedman is this prompt: With everything you have seen right now, is there anything to improve. In the image is the exact prompt I'm using and I really like the results.
This is my OpenClaw Setup. I actually let it run on my RaspberryPi locally. Not a huge benefit compared to a VM on AWS but I had it already at home. Let's go through some of the components: 𝐇𝐚𝐫𝐝𝐰𝐚𝐫𝐞: Raspberry Pi 5 8 GB. 𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐢𝐧𝐠:
Next Milestone reached 👑 Both our Shopify apps now have Built for Shopify. What that means for non-shopify folks: - You can target ads better for specific store plans - Better organic reach - You prove that you meet a high-bar of UX/functional standards
With just seven lines of code (and a small script 👀), you can connect your Claude code to your privately deployed database in RDS! This gives your AI assistant access to: - database schema - example data - changes after actions (e.g., it clicks in the UI and sees what happened in the DB)
I LOVE seeing content like that. If you're interested in: - bootstrapping - open source - tech check it out! I followed David Boyne since he was at AWS and I really love his implementations, graphics, and talks. Thanks for the share Jeremy! 😊
AI writes amazing code. But it has a huge blind spot. Most models are trained on data that is 6-12 months old. That means they could suggest packages with known vulnerabilities, outdated versions and versions that don’t even exist I hate this feedback loop:
I love seeing open-source projects like that. Actionlint became the de-facto standard for GitHub actions linting. And it is open-source developed by Linda_pp (apparently a 🐶) You can simply lint your GitHub actions workflows like that.
Everyone says more context makes Claude worse. You are just giving it the WRONG context. The correct context for me? Database connection. Now there is an issue with connecting it to your database. Your database is typically not connected to the public internet, and it shouldn't be anyway.
Most people set up AWS Config and think they're covered. But until this week, 30+ resource types were flying completely under the radar. 🫣 AWS just added support for 𝟑𝟎 𝐧𝐞𝐰 𝐫𝐞𝐬𝐨𝐮𝐫𝐜𝐞 𝐭𝐲𝐩𝐞𝐬 to AWS Config.
I just found 35GB of forgotten data in one of our S3 buckets. We were paying standard storage prices for files nobody had touched in months. This is why I enable 𝐒𝟑 𝐈𝐧𝐭𝐞𝐥𝐥𝐢𝐠𝐞𝐧𝐭-𝐓𝐢𝐞𝐫𝐢𝐧𝐠 almost everywhere now. It can cut your storage bill by 40-70%.
The NPM ecosystem is huge. But it is also a security minefield. 💣 OWASP released their top 10 security best practices. Here is the checklist you need to follow:
Amazon API Gateway is much more than a simple integration into you Lambda function. It isn't just a door to your backend. It is a superpower for your serverless applications. We see this pattern all the time. Developers treat API Gateway as a "dumb pipe" that just forwards traffic.
Manual cloud diagrams might be a thing of the past. We have been testing Kiro with MCP servers. The concept is simple. 𝐃𝐨𝐧’𝐭 𝐝𝐫𝐚𝐰. Let the AI 𝐝𝐢𝐬𝐜𝐨𝐯𝐞𝐫 your stack. It looks at your IaC or connects to your AWS account. Then it generates the map for you.
I try to solve everything with Lambda. But sometimes it is simply the wrong tool. Especially when you need a 𝐡𝐮𝐦𝐚𝐧 𝐢𝐧 𝐭𝐡𝐞 𝐥𝐨𝐨𝐩. Think about approvals, reviews, or manual checks. For this, 𝐒𝐭𝐞𝐩 𝐅𝐮𝐧𝐜𝐭𝐢𝐨𝐧𝐬 are the way to go.
> 1,000 subscribers in under 4 weeks I think there is great value in teaching AWS & FullStack AWS Content in Video Format. If you haven't seen it yet, we started a YouTube Channel with AWS Fundamentals: www.youtube.com/@aws-fundam... Hop over & check it out. Videos so far:
Gateway Endpoint: - Free - Only S3 & DynamoDB - Secure with VPC Policies - Can be accessed only from within the VPC - Doesn't use PrivateLink Interface Endpoint - Charged per hour and GB - Can be accessed outside of the VPC (ENI / IP. Still not public internet) - Uses PrivateLink
I love using monorepos. Typically I have the following structure: - apps: Different applications with full infrastructure attached - packages: Shared constructs, libraries, frameworks
I honestly hate updating architecture diagrams. You spend hours moving boxes in Drawio. Then you deploy one change. And the diagram is useless. We finally found a way to stop this loop. Using Kiro, we let AI scan our AWS environment directly.