<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AWS — Things Worth Sharing</title><description>Posts tagged AWS.</description><link>https://cloudsecop.net/</link><item><title>Migrating AWS/Vercel to Cloudflare: a real playbook</title><link>https://cloudsecop.net/en/blog/migration-aws-to-cloudflare-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/migration-aws-to-cloudflare-en/</guid><description>Playbook for migrating a production app from AWS (Lambda, DynamoDB, RDS, S3, SQS, ElastiCache) to Cloudflare: per-primitive mapping, 3 strategies, cutover, rollback, 10 pitfalls.</description><pubDate>Sun, 28 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Migration</category><category>AWS</category><category>Serverless</category><author>KhaVan</author></item><item><title>Cloudflare Developer Platform cost model: tiers vs AWS</title><link>https://cloudsecop.net/en/blog/cost-model-production-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cost-model-production-en/</guid><description>Per-primitive Cloudflare pricing (Workers, D1, KV, R2, Queues, DOs, Vectorize, Workers AI), tier breakpoints, AWS comparison, and 3 scale scenarios from blog to 100M req/month.</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Cost</category><category>AWS</category><category>Pricing</category><author>KhaVan</author></item><item><title>AWS Security Maturity Model v2: 4 phases in practice</title><link>https://cloudsecop.net/en/blog/aws-security-maturity-model-v2-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/aws-security-maturity-model-v2-en/</guid><description>Practical walk-through of AWS Security Maturity Model v2: 74 controls across four phases (Quick Wins, Foundational, Efficient, Optimized), real ordering, traps, and Org mapping.</description><pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>AWS SMM Assessment Tool: scoring posture in an afternoon</title><link>https://cloudsecop.net/en/blog/aws-security-maturity-model-assessment-tool-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/aws-security-maturity-model-assessment-tool-en/</guid><description>Field notes from the AWS Security Maturity Model Assessment Tool across four phases (Quick Wins, Foundational, Efficient, Optimized): architecture, workflow, JSON/Excel export.</description><pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Assessment</category><category>Governance</category><author>KhaVan</author></item><item><title>AWS KMS Key Policies: get this right or lose your data</title><link>https://cloudsecop.net/en/blog/kms-key-policies-deep-dive-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/kms-key-policies-deep-dive-en/</guid><description>How KMS key-policy evaluation works: cross-account access, condition keys, grants, key rotation, production patterns. With JSON policy examples and a production checklist.</description><pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>KMS</category><category>Encryption</category><category>IAM</category><author>KhaVan</author></item><item><title>GuardDuty auto-remediation: isolate EC2 and revoke IAM</title><link>https://cloudsecop.net/en/blog/guardduty-auto-remediation-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/guardduty-auto-remediation-en/</guid><description>An auto-remediation pipeline for GuardDuty using EventBridge and Lambda: isolate instances, snapshot for forensics, revoke credentials, and scale it across an Organization.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Automation</category><category>EventBridge</category><author>KhaVan</author></item><item><title>AWS IAM Access Key rotation: Lambda + Secrets Manager</title><link>https://cloudsecop.net/en/blog/iam-key-auto-rotation/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/iam-key-auto-rotation/</guid><description>An AWS-native solution for rotating, disabling, and deleting IAM access keys on policy — the multi-account architecture, trade-offs, and what operating it actually takes.</description><pubDate>Sun, 19 Jan 2025 00:00:00 GMT</pubDate><category>AWS</category><category>IAM</category><category>Security Automation</category><category>Secrets Manager</category><category>Lambda</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS to GCP: keyless auth</title><link>https://cloudsecop.net/en/blog/cross-cloud-workload-identity-federation/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cross-cloud-workload-identity-federation/</guid><description>Workload Identity Federation deep dive: why Service Account Keys are anti-pattern, AWS STS → Google STS exchange, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Running CSPM across a dozen AWS Landing Zones</title><link>https://cloudsecop.net/en/blog/cspm-multiple-aws-landing-zones/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cspm-multiple-aws-landing-zones/</guid><description>How I built an in-house CSPM engine scanning many AWS Landing Zones in parallel with Prowler, storing findings in D1 and artifacts in R2, into one Security Operations dashboard.</description><pubDate>Tue, 24 Dec 2024 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>CSPM</category><category>Prowler</category><category>Cloudflare</category><author>KhaVan</author></item></channel></rss>