Platform engineering · DevSecOps · Cloud-native systems

Production-shaped notes from the cloud-native workshop.

Cloud Sandbox is a technical field journal about platform engineering, secure systems, observability, Kubernetes, and making software less fragile.

Cloud Sandbox editorial card illustration.
Technical field notes from the cloud-native workshop.

Recent writing

Essays and field notes

Field note

Centralised AWS networking: what belongs in the network account?

A central AWS network account should own shared address planning, transit routing, central egress, inspection, hybrid connectivity and selected DNS infrastructure. Workload VPCs, application ingress and service-level network controls should normally remain with the accounts that operate those workloads.

27 Jul 2026 · about 27 minutes min read ·

Field note

AWS Control Tower: what it solves and why I chose not to use it

AWS Control Tower can establish and govern a multi-account landing zone using AWS Organizations, IAM Identity Center, CloudTrail, Config, Service Catalog and managed controls. bfstore chose a manually engineered landing zone to preserve explicit ownership, learning depth and a custom policy-testing workflow.

23 Jul 2026 · about 25 minutes min read ·

Field note

Getting AWS telemetry into a self-hosted observability platform

AWS telemetry does not emerge through one universal export path. Application signals can travel through OpenTelemetry, while CloudWatch metrics, managed-service logs, flow logs, CloudTrail and configuration evidence require different streaming, polling and durable-ingestion patterns.

18 Jul 2026 · about 30 minutes min read ·