<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Shane Law — writing</title><description>Shane Law, cloud engineer in Jakarta. AWS architecture, identity and access design, and the Terraform that puts it in place.</description><link>https://shanelaw.tech/</link><item><title>Dependency order is the real EKS deployment problem</title><link>https://shanelaw.tech/blog/eks-deployment-sequencing/</link><guid isPermaLink="true">https://shanelaw.tech/blog/eks-deployment-sequencing/</guid><description>Most failed Kubernetes platform rollouts aren&apos;t a tooling problem — they&apos;re a sequencing problem. A tool-agnostic way to think about what has to exist before what.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The cloud comparison chart lied to you (a little).</title><link>https://shanelaw.tech/blog/cloud-comparison-reality/</link><guid isPermaLink="true">https://shanelaw.tech/blog/cloud-comparison-reality/</guid><description>Every &apos;AWS to Azure to GCP&apos; cheat sheet does the same thing: it gives you a table. S3 equals Blob Storage. EC2 equals Compute Engine. Done, ship it.
Except it&apos;s not done. The table tells you where to start, not where you&apos;ll get burned.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Decoupling &amp; Securing Web App Storage: Building a Zero-Trust S3 Perimeter with Terraform</title><link>https://shanelaw.tech/blog/decoupling-and-securing-web-app-storage/</link><guid isPermaLink="true">https://shanelaw.tech/blog/decoupling-and-securing-web-app-storage/</guid><description>When hosting a scalable, multi-AZ 3-tier web application (like WordPress), storing media files locally on the EC2 instances is an architectural dead end. The moment your auto-scaler destroys an instance, your user uploads vanish.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Least privilege is a design problem, not an audit finding</title><link>https://shanelaw.tech/blog/least-privilege-is-a-design-problem/</link><guid isPermaLink="true">https://shanelaw.tech/blog/least-privilege-is-a-design-problem/</guid><description>IAM policies get written last and reviewed never. Treating blast radius as an architecture constraint changes what you build, not just what you document.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>