Technology
AWS
Account structure, networking, identity and managed services laid down as code — with cost attribution from day one rather than after the first surprising bill.
The foundation decides the next five years
Account structure, network topology and identity are the decisions that are painful to revisit. Almost everything else on AWS can be changed later without much drama.
So we spend our effort there — multi-account landing zones, least-privilege identity and tagging that makes cost attributable — and use managed services aggressively above that line.
Practice
How we use it
Landing zones
Multi-account structure with guardrails, centralised logging and policy applied as code.
Identity and access
Least-privilege roles and federated access, with standing human credentials treated as a defect.
Managed-first
RDS, SQS, EventBridge and their peers over self-hosted equivalents unless there is a specific reason.
Cost engineering
Tagging, attribution and commitment planning so spend is explainable per team and per workload.
Judgement
When AWS is the right call
And when it is not. A technology page that only lists strengths is a brochure.
Reach for it when
- Broadest managed-service coverage and the deepest hiring pool
- Regulated workloads needing mature compliance evidence
- Organisations already invested in the ecosystem
Look elsewhere when
- Where an existing commercial relationship makes another provider materially cheaper
- Simple workloads where a platform-as-a-service removes the operations entirely
Sectors
Where we run it
Proof
Related work
Also relevant