Cloud / AWS in practice
Cloud optimization is not a search for cheaper instances. Teams control cost and reliability together only when billing mechanics, permissions, networking, delivery, and operational ownership share one design.
From billing mechanics to security-driven spend
Begin with hidden AWS costs to learn how line items grow, then use the LLMjacking case to trace how a security incident becomes operational spend. Continue structural application change in the separate modernization hub.
What does leaving EKS Extended Support take?Cloud / AWS in practice · September 10, 2026Client A returned to standard EKS support. The work covered AL2023 nodes, image downloads and storage checks, with external collection left for follow-up.→
Where ECS deployment time leaked — why Early Success Criteria was not a one-setting fixCloud / AWS in practice · September 8, 2026We cut CI waiting time for a one-task ECS development service from 197 to 120 seconds. Service configuration alone was not enough; the workflow signal and IAM permissions had to change too.→
How much did Blacksmith Docker cache cut our development cycle? Evidence from 1,527 jobsCloud / AWS in practice · Updated August 12, 2026We examine how persistent Blacksmith builders, serialized cache writers, and parallel image and CI jobs changed production performance and development-cycle economics.→
What should an AI gateway control? Enterprise requirements and implementation pathsCloud / AWS in practice · July 29, 2026A practical framework for putting security, key exposure, departmental cost, guardrails, and observability behind one enterprise AI gateway, with four implementation paths compared.→
How MCP 2026-07-28 changes AgentCore operationsCloud / AWS in practice · July 27, 2026How MCP's request-oriented model changes deployment and state ownership across AgentCore Runtime, Gateway, and targets, with a practical dual-version migration path.→
An AWS Account With No Keys and No Docs — How $1,650/mo Became $400Cloud / AWS in practice · July 20, 2026We re-read a six-year-old service's abandoned AWS account through API inventory and measured metrics, then executed an Aurora major upgrade and rightsizing with zero-downtime tooling. Monthly cost dropped to a quarter without touching application code.→
A $455K AWS Cost Alert Arrived — The Response Made It WorseCloud / AWS in practice · July 19, 2026An AWS alert put one day of S3 data transfer at $455,000. The estimate was wrong, but we still had to investigate account compromise. The incident shows why billing communication is part of cloud security.→
Invisible on the Console, Only on the Invoice — AWS's Hidden CostsCloud / AWS in practice · Updated July 16, 2026Nobody broke in, yet money leaks every month. Missing VPC endpoints, cross-AZ data transfer, always-billed public IPv4, logs kept forever. AWS hidden costs with real Seoul-region rates and how to claw them back.→
Anatomy of an AWS Bill Shock — LLMjacking, and the Costs You Never SeeCloud / AWS in practice · Updated July 16, 2026One leaked access key can burn tens of thousands of dollars a day on Bedrock. How LLMjacking works, the AWS account-management essentials, Bedrock key management, and the guardrails that cap the blast radius.→
Common cloud cost and security questions
Why can an AWS bill rise when compute usage looks stable?+
Should cost optimization start with Savings Plans?+
Why is LLMjacking both a security and a cost incident?+
Explore Cloud & Infrastructure for work spanning bill analysis, AWS architecture, multi-account governance, GPU and Kubernetes platforms, and IaC operations.
Explore Cloud & Infrastructure →Put this work into practice.
An engineer reviews your environment and constraints first, then uses a 30-minute technical conversation when it helps define the execution scope.