Sign in

Sandro Volpicella

@sandrovolpicella.com
824 followers 100 following 551 posts

I teach developers about the cloud ⛅ 👨🏽‍💻 Platform Lead @hashnode 📕 New Book: cloudwatchbook.com ⛅ AWS Fundamentals Book: awsfundamentals.com 😼 Builds kitlytics.com 🤗 AWS Community Builder

PostsRepliesMedia
Sandro Volpicella @sandrovolpicella.com · 13/05/2026
I've been running centralized logging for our AWS accounts. CloudWatch log centralization has two gotchas that caught me off guard. Gotcha #1: Settings Don't Transfer 🚨 Log Group settings get stripped during the copy. Retention policies? Gone. Data protection policies? Gone.
100
Sandro Volpicella @sandrovolpicella.com · 13/03/2026
Stop using 𝐒𝟑 𝐒𝐭𝐚𝐧𝐝𝐚𝐫𝐝 as your default storage class. Unless you know exactly how your data will be accessed, you are likely overpaying. I used to default to Standard for everything. Then I looked at our bill.
100
Sandro Volpicella @sandrovolpicella.com · 09/03/2026
Everyone tells you to move old data to Glacier to save money. But they usually forget to mention the pain. • Retrieval fees hurt. • Waiting 5-12 hours for data sucks. That is why I prefer 𝐒𝟑 𝐈𝐧𝐭𝐞𝐥𝐥𝐢𝐠𝐞𝐧𝐭-𝐓𝐢𝐞𝐫𝐢𝐧𝐠. It solves the biggest problem with archiving:
100
Sandro Volpicella @sandrovolpicella.com · 24/02/2026
I see Opus is debugging in the same way I do: make the background red and figure out why there is so much fricking space at the top 😬
000
Sandro Volpicella @sandrovolpicella.com · 20/02/2026
One nugget I really took from the podcast of Steinberger & Friedman is this prompt: With everything you have seen right now, is there anything to improve. In the image is the exact prompt I'm using and I really like the results.
110
Sandro Volpicella @sandrovolpicella.com · 19/02/2026
This is my OpenClaw Setup. I actually let it run on my RaspberryPi locally. Not a huge benefit compared to a VM on AWS but I had it already at home. Let's go through some of the components: 𝐇𝐚𝐫𝐝𝐰𝐚𝐫𝐞: Raspberry Pi 5 8 GB. 𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐢𝐧𝐠:
111
Sandro Volpicella @sandrovolpicella.com · 18/02/2026
Next Milestone reached 👑 Both our Shopify apps now have Built for Shopify. What that means for non-shopify folks: - You can target ads better for specific store plans - Better organic reach - You prove that you meet a high-bar of UX/functional standards
100
Sandro Volpicella @sandrovolpicella.com · 18/02/2026
With just seven lines of code (and a small script 👀), you can connect your Claude code to your privately deployed database in RDS! This gives your AI assistant access to: - database schema - example data - changes after actions (e.g., it clicks in the UI and sees what happened in the DB)
100
Sandro Volpicella @sandrovolpicella.com · 18/02/2026
I LOVE seeing content like that. If you're interested in: - bootstrapping - open source - tech check it out! I followed David Boyne since he was at AWS and I really love his implementations, graphics, and talks. Thanks for the share Jeremy! 😊
000
Sandro Volpicella @sandrovolpicella.com · 17/02/2026
AI writes amazing code. But it has a huge blind spot. Most models are trained on data that is 6-12 months old. That means they could suggest packages with known vulnerabilities, outdated versions and versions that don’t even exist I hate this feedback loop:
100
Sandro Volpicella @sandrovolpicella.com · 17/02/2026
I love seeing open-source projects like that. Actionlint became the de-facto standard for GitHub actions linting. And it is open-source developed by Linda_pp (apparently a 🐶) You can simply lint your GitHub actions workflows like that.
100
Sandro Volpicella @sandrovolpicella.com · 17/02/2026
Everyone says more context makes Claude worse. You are just giving it the WRONG context. The correct context for me? Database connection. Now there is an issue with connecting it to your database. Your database is typically not connected to the public internet, and it shouldn't be anyway.
200
Sandro Volpicella @sandrovolpicella.com · 13/02/2026
Most people set up AWS Config and think they're covered. But until this week, 30+ resource types were flying completely under the radar. 🫣 AWS just added support for 𝟑𝟎 𝐧𝐞𝐰 𝐫𝐞𝐬𝐨𝐮𝐫𝐜𝐞 𝐭𝐲𝐩𝐞𝐬 to AWS Config.
100
Sandro Volpicella @sandrovolpicella.com · 10/02/2026
Amazon API Gateway is much more than a simple integration into you Lambda function. It isn't just a door to your backend. It is a superpower for your serverless applications. We see this pattern all the time. Developers treat API Gateway as a "dumb pipe" that just forwards traffic.
100
Sandro Volpicella @sandrovolpicella.com · 27/01/2026
> 1,000 subscribers in under 4 weeks I think there is great value in teaching AWS & FullStack AWS Content in Video Format. If you haven't seen it yet, we started a YouTube Channel with AWS Fundamentals: www.youtube.com/@aws-fundam... Hop over & check it out. Videos so far:
120
Sandro Volpicella @sandrovolpicella.com · 26/01/2026
Gateway Endpoint: - Free - Only S3 & DynamoDB - Secure with VPC Policies - Can be accessed only from within the VPC - Doesn't use PrivateLink Interface Endpoint - Charged per hour and GB - Can be accessed outside of the VPC (ENI / IP. Still not public internet) - Uses PrivateLink
110
Sandro Volpicella @sandrovolpicella.com · 23/01/2026
I love using monorepos. Typically I have the following structure: - apps: Different applications with full infrastructure attached - packages: Shared constructs, libraries, frameworks
120
Sandro Volpicella @sandrovolpicella.com · 21/01/2026
We lie to ourselves about IAM access. "I will revoke this Admin permission later." No, you won't. We've all been there. You need access to a production database or an EC2 instance. You create a long-lived access key or add a user to the Admin group. And then it stays there. Forever.
100
Sandro Volpicella @sandrovolpicella.com · 19/01/2026
I am generating more code than ever before. And honestly, most of it is throwaway. I use Claude Code daily now. Quick scripts, data transformations, prototypes. Charity Majors from Honeycomb calls this "disposable code" and she is absolutely right.
100
Sandro Volpicella @sandrovolpicella.com · 16/01/2026
Most people don't know this resource exists. AWS has a massive library of workshops they use to train Fortune 500 engineering teams. You can do them for free. They are currently moving all content to the new Builder Center here builder.aws.com/build/works...
110
Sandro Volpicella @sandrovolpicella.com · 15/01/2026
Your Lambda bill might have just dropped. And you didn't even notice. AWS introduced tiered pricing for Lambda logs. This is huge for high-volume applications. Here is what changed: • Standard logs are cheaper • Infrequent access storage saves even more
100
Sandro Volpicella @sandrovolpicella.com · 09/01/2026
We are live on YouTube now! 🎥 We thought about that a lot in the past. After doing our video course for the CloudWatch Book, we first saw that teaching programming & cloud content is much easier via video. But we still didn't take the leap.
120
Sandro Volpicella @sandrovolpicella.com · 08/01/2026
The journey of a CloudWatch Alarm in a multi-account setup. We wanted to visualize exactly how an alert travels from a production database all the way to our Discord channel. It is a game of "pass the parcel" between accounts. Here is the flow: 1. The Trigger
100
Sandro Volpicella @sandrovolpicella.com · 07/01/2026
Typically, one of the first issues you will encounter in bad architected systems: 𝐓𝐢𝐦𝐞 𝐂𝐨𝐮𝐩𝐥𝐢𝐧𝐠 Imagine building a blogging platform. Your `create-post` API started out with just publishing a post. But after a few more cool ideas this API is now responsible for:
110
Sandro Volpicella @sandrovolpicella.com · 05/01/2026
Giving developers permanent Admin access is a bad idea. But sometimes they really need it to fix things. I discovered TEAM (Temporary Elevated Access Management) some time back. It's a serverless React app from AWS that handles this perfectly: • Request temporary admin access
100
Sandro Volpicella @sandrovolpicella.com · 31/12/2025
Managing alerts in one AWS account is easy. Managing alerts across an entire organization? That is where the chaos starts. We recently moved to a centralized alerting architecture to make the setup of alarm actions simpler. Here is the 3-part architecture we built using CDK and EventBridge:
130
Sandro Volpicella @sandrovolpicella.com · 30/12/2025
I love Logs Insights. But it fails at one specific thing: High-cardinality data. You need to find the top-N IPs accessing your API? Don't write a query. Typically, my first step is always going to Logs Insights. And in 90% of the times I'm at the right place.
110
Sandro Volpicella @sandrovolpicella.com · 26/12/2025
One external SQS producer crashed our entire production API. Reserved concurrency could have safeguarded us at no cost. Here's how it works. ⚠️ Let's say you have one production AWS account. In your AWS account, there are two different kinds of resources:
100
Sandro Volpicella @sandrovolpicella.com · 25/12/2025
I often work with clients on different operating systems. I need to verify that tools I offer them also work on Windows (I am on Mac) To test this quickly, I typically do the following: - set up an EC2 with the correct OS (Windows Server xx) - Connect via RDP and test it out
100
Sandro Volpicella @sandrovolpicella.com · 24/12/2025
The most important command in the AWS CDK CLI isn't "deploy". It's "diff". I know this sounds obvious. But I see so many developers skipping this step. In a small side project, you might get away with it. You change a Lambda function, deploy it, and everything is fine.
122
Sandro Volpicella @sandrovolpicella.com · 23/12/2025
AWS just invented a new pricing unit for Aurora DSQL. It’s called the DPU (Distributed Processing Unit). If you want to estimate your database costs, you need to understand this. Here is what we know so far: • It covers all request activities (reads, writes, queries)
100
Sandro Volpicella @sandrovolpicella.com · 22/12/2025
Your developers are wasting 2 hours per service setting up alerts. You have 10 services. That's 20 hours solving the same problem. And you still don't know where half your alerts actually go. Your developers shouldn't be thinking about alert routing.
110
Sandro Volpicella @sandrovolpicella.com · 19/12/2025
Giving developers permanent Admin access is a bad idea. But sometimes they really need it to fix things. I discovered TEAM (Temporary Elevated Access Management) some time back. It's a serverless React app from AWS that handles this perfectly: • Request temporary admin access
120
Sandro Volpicella @sandrovolpicella.com · 18/12/2025
Your alert chaos isn't a configuration problem. It's an architecture problem. Different Slack apps per team. Email alerts nobody reads. Webhooks pointing to servers that don't exist anymore. PagerDuty configured by someone who left 2 years ago.
120
Sandro Volpicella @sandrovolpicella.com · 16/12/2025
Lambda Durable Functions are here! Step Functions, just in code without ASL - seems interesting! I think it adds a bit to the complexity of "which service should I actually take" in Step Function vs. Lambda But in the end, you just get more opportunities to choose your favourite ones.
120
Sandro Volpicella @sandrovolpicella.com · 15/12/2025
The CloudWatch Logs Insights Console got an upgrade 💅🏽 You can now: - Query log log groups directly from the scope - Access facets & fields (I think they renamed it from indexed fields to facets 🤔) - Look at saved queries in a different pane (not mixed anymore with fields, samples, etc.)
100
Sandro Volpicella @sandrovolpicella.com · 11/12/2025
CDK 4 TF is deprecated 🪦 It was a great idea, I liked the concepts. But tbh this is why I'm often afraid of using non-official IAC tools. (saying that as an avid sst user)
020
Sandro Volpicella @sandrovolpicella.com · 04/12/2025
I've had my third (irl) conference talk in my life and I've got some feedback. I appreciate that! The talk was about "EDA for the real world". Let's look at the feedback: Quality of the session: 4.6 (n=14) What was liked most: Presentation style / Practical examples (n=13) Any Improvements:
100
Sandro Volpicella @sandrovolpicella.com · 03/12/2025
I've been running centralized logging for our AWS accounts. CloudWatch log centralization has two gotchas that caught me off guard. Gotcha #1: Settings Don't Transfer 🚨 Log Group settings get stripped during the copy. Retention policies? Gone. Data protection policies? Gone.
100
Sandro Volpicella @sandrovolpicella.com · 02/12/2025
AWS trains Fortune 500 companies with these workshops. You can access them for free. They're migrating from workshops.aws to the builder center: builder.aws.com/build/works... These are the same workshops used in official AWS Immersion Days at companies.
240
Sandro Volpicella @sandrovolpicella.com · 27/11/2025
Most RAG implementations suck because everyone skips the boring parts. We just shipped a related posts feature with Bedrock. - Total queries: 244 (against our knowledge base) - Average related posts: 1.4 - Posts with zero results: 30 That's not too good.
110
Sandro Volpicella @sandrovolpicella.com · 26/11/2025
Honeycomb published a blog post called "The End of Observability as We Know It." I've been using observability tools for years now. Heck, I wrote a book about CloudWatch ⛅ And honestly? I like the take of this post. Let's see a typical daily observability issue: - You have 5 AWS accounts.
120
Sandro Volpicella @sandrovolpicella.com · 26/11/2025
You can now stream AI responses through API Gateway natively! The main changes: - Integration timeout extended to 15 minutes - Larger payloads possible You can even stream your whole documents & media files from S3 without pre-signed links now 🤯
110
Sandro Volpicella @sandrovolpicella.com · 26/11/2025
Public Lambda Roadmap is live 🔥 And OTEL is already in the researching state 👀 🔗 github.com/orgs/aws/pr...
010
Sandro Volpicella @sandrovolpicella.com · 25/11/2025
We added semantic search to our blog in one afternoon. No vector database. No extra infrastructure. Just S3 and Bedrock. 100+ posts now have intelligent related content suggestions. The setup was surprisingly simple: 1️⃣ Upload Content to S3 Store your markdown files in S3.
130
Sandro Volpicella @sandrovolpicella.com · 25/11/2025
"Based on this feedback, CodeCommit is returning to full General Availability, effective immediately." - that is a new one! Welcome Back CodeCommit 👨🏽‍💻
000
Sandro Volpicella @sandrovolpicella.com · 24/11/2025
CloudWatch log centralization takes 3 steps. 𝗦𝘁𝗲𝗽 𝟭: 𝗗𝗲𝗹𝗲𝗴𝗮𝘁𝗲 𝗮𝗻 𝗔𝗱𝗺𝗶𝗻𝗶𝘀𝘁𝗿𝗮𝘁𝗼𝗿 Go to your management account. CloudWatch → Settings → Organization. Assign one delegated administrator. I recommend using your dedicated logging account.
210
Sandro Volpicella @sandrovolpicella.com · 19/11/2025
AWS finally made centralized logging simple 🎉 Everybody says "you need a central logging account" but creating it was quite a hassle. Your options before: 🔹 Observability Access Manager (OAM) Works, but complicated setup. Requires understanding sinks, sources, and links.
100
Sandro Volpicella @sandrovolpicella.com · 19/11/2025
Nice new launch - I think that means no more: - "Bucket with this name already exists" - "Couldn't delete bucket because it is not empty" The feedback loop is faster to have it BEFORE it actually starts deploying. So far it works on:
120
Sandro Volpicella @sandrovolpicella.com · 18/11/2025
TIL: Step Functions Tasks can assume roles for cross-account access 🤯
030