Stop Using Long-Lived AWS Credentials in CI/CD: A Guide to GitHub OIDC
Long-lived credentials are a ticking time bomb. Here’s how to defuse them.
Long-lived credentials are a ticking time bomb. Here’s how to defuse them.
The first time I saw the sea I was five years old. My dad took my brother and me walking along the breakwater, all the way to the end. Later he told me that his idea was for us to feel like we were entering the sea, to feel the force with which the waves crashed against the rocks. And that’s how it felt.
The goal: set up CMK encryption for our web apps’ S3 buckets. Simple, right? Not quite.
Sometimes the best adventures are the ones you decide to do when it’s already “a bit late.” And that’s exactly what I did that day: set out at noon toward Laguna de Normandía.
AI, AI, AI. Another story? Yes, but this one’s personal.
Sometimes the best solution to a problem creates a new problem you didn’t expect. This is a story about fixing one Terraform error, only to discover that the fix itself introduces a whole new class of deployment challenges.