GKE Workload Identity Federation: The Complete Guide (Direct Access and Legacy Modes, Tested on Autopilot 1.35)
Complete tested guide to Workload Identity Federation for GKE on Autopilot 1.35. Direct resource access, legacy GSA impersonation,…
Complete tested guide to Workload Identity Federation for GKE on Autopilot 1.35. Direct resource access, legacy GSA impersonation,…
You deployed to EKS with kubectl apply, then shell scripts, then a CI job that ran helm upgrade…
We just spent a week testing EKS Pod Identity. If we were paying full price instead of using…
Hardcoded database passwords in a .env file committed to Git is still how a surprising number of teams…
If you landed here after reading our IAM Roles for Service Accounts (IRSA) guide, welcome to the sequel.…
Baking AWS access keys into container images was acceptable in 2017. In 2026 it is career-ending. One leaked…
Tested April 2026 on Debian 13, Amazon Linux 2023, and macOS 26.3 with AWS CLI 2.34.27 AWS CLI…
S3 Files pricing trips people up because it layers three separate cost components on top of each other.…
There are now three distinct ways to mount an S3 bucket as a file system on Linux: S3…
Setting up S3 Files involves IAM roles, security groups, mount targets, and NFS configuration. Each piece can fail…
Twenty years of S3, and the answer to “can I just mount it like a normal file system?”…
AWS finally shipped a proper way to mount S3 buckets as file systems. Amazon S3 Files, which went…