Sign in

zoph

@zoph.me
845 followers 225 following 400 posts

Just another cloud consultant.

PostsRepliesMedia
zoph @zoph.me · 21/09/2026
Six weeks of unusd cloud, from a customer’s point of view. New detections. Working-hours EC2/RDS, CloudWatch log class + Intelligent-Tiering + dead alarms/dashboards, ECR lifecycle when images pile up. 51+ rules, read-only. Public API + Terraform module to register and configure AWS accounts.
000
zoph @zoph.me · 04/09/2026
I've used, shipped, and contributed to open source for 20+ years. Giving some of that work back feels natural. Today I'm sharing unusd: read-only unused-AWS scans and a weekly digest. Nonprofits and public OSS: Community grant. Weekly, not unlimited. unusd.cloud/community Cheers. 🧡
Announcement for free AWS scans aimed at nonprofits and open source projects, detailing weekly review and cost details.
000
zoph @zoph.me · 31/08/2026
Heading to fwd:cloudsec EU in London next Monday. 300+ cloud security folks in one room, what could go wrong? :) Who's around for tea?
Logo featuring a paper airplane flying over clouds near a tower, representing the fwd:cloudsec EU conference.
140
zoph @zoph.me · 24/08/2026
A few updates on IAMTrail, my archive of AWS Managed IAM Policy changes since 2019. For non-specialists: AWS changes its managed IAM policies almost every day, silently. No changelog, no announcement. IAMTrail watches them and tells you what moved. What is new:
IAMTrail displays recent changes to AWS Managed IAM Policies, highlighting added actions and updates with a focus on readability.
121
zoph @zoph.me · 18/08/2026
This is what you get when you are subscribing to IAMTrail instant alerts.
IAM policy change alert showing updates to the AWS Elastic Disaster Recovery ReadOnlyAccess policy with new actions and statements.
000
zoph @zoph.me · 30/07/2026
On June 3rd, a policy called FinOpsAgentOperatorPolicy appeared in the AWS managed policy archive carrying 31 actions under a service prefix nobody had ever seen before: finops-agent. AWS announced the public preview of AWS FinOps Agent on June 9th.
100
zoph @zoph.me · 16/07/2026
Back in 2019, I started MAMIP, then → IAMTrail to answer one nagging question: what exactly changed in an AWS-managed IAM policy, and when?
Analytics dashboard displays real-time visitor stats: 4.6k visitors, 4.7k pageviews, 99% bounce rate, and historical data trends.
100
zoph @zoph.me · 13/07/2026
Since my last post on clickops-notifier, I’ve renamed it to clickops-sentinel, which I found more appropriate, and updated the code to support richer emails (with session path).
A notification alerting that a manual console change was detected for an EC2 instance, including cost impact and recommended actions.
100
zoph @zoph.me · 06/07/2026
I don't know where this is going, but this weekend I decided to put my generous Claude Fable access (until July 7th) to work on something that has been on my mind for months. The idea: bring visibility to manual actions made by humans on your AWS account, and supercharge those alerts with AI.
Alert about a suspicious AWS action allowing SSH access from the internet, highlighting high security risks and the need for immediate action.
101
zoph @zoph.me · 01/07/2026
I have been automating my home for close to 10 years. It started with Jeedom in 2017, then, three years ago, I moved everything to Home Assistant (HA). House got smarter, but the config got heavier: YAML, templates, integrations, and a long list of small rules to remember.
A smart home tablet mounted on a wall displays a camera feed and weather information amidst a kitchen setting with plants.
100
zoph @zoph.me · 29/06/2026
I just shipped a new release of the AWS Security Survival Kit.
Flowchart outlines AWS account security process, detailing suspicious activities, notifications via email or chat, and required actions.
210
zoph @zoph.me · 24/06/2026
14 months ago: first commit of Trustline. A 200-line script that scanned IAM role trust policies and S3 bucket policies, matched every external account ID against the fwd:cloudsec known-vendors dataset, and printed who actually had access to my AWS account.
Dashboard displaying AWS Trustline findings on external access, listing resources, IAM roles, and public accessibility details.
100
zoph @zoph.me · 22/06/2026
A real customer incident taught me this the hard way: Databricks workloads chewed through a subnet's IP addresses so fast that we ran out of free IPs and new resources simply stopped launching. The frustrating part? AWS gives you no free, built-in gauge to see it coming.
100
zoph @zoph.me · 15/06/2026
AWS Security Survival Kit (ASSK) is one of my free and open-source projects that turns your CloudTrail noise into a small set of actionable alerts. Two CloudFormation stacks, a handful of EventBridge rules, and an SNS topic.
100
zoph @zoph.me · 13/06/2026
Pretty soon, the smart answers will all come in the first week of the month. By the 28th, everyone's overdrawn, like your bank account, but for tokens.
010
zoph @zoph.me · 22/05/2026
I've used Cursor for years as my main AI code editor. Familiar VSCode interface, solid autocomplete, and enough AI help without losing control. Just tested the new 3.0 version. First reaction: skeptical. A brand-new agent-centric app felt like a step backward. Less control, more abstraction.
100
zoph @zoph.me · 04/05/2026
What shipped on unusd → March & April '26 - 13 new finding types: Lambda Optimizer, EBS Idle, EBS io1 → gp3, EBS Snapshot Archive, EFS, Idle ElastiCache, ElastiCache Valkey, DocumentDB, DynamoDB, Kinesis, Step Functions, RDS Storage, CloudFront
A subway station with a lit advertisement for "unusd.cloud" featuring a cloud icon and file symbol, alongside signage for Pont Marie.
100
zoph @zoph.me · 13/04/2026
New week, new feature on IAMTrail. IAM action context is now built into managed policy views. For each action, you get useful metadata: description, access level, and where it appears. Data comes from iam-dataset by Ian McKay.
Details of the AWS IAM policy "cognito-idp:AssociateWebACL," including access level, description, and allowed actions.Dashboard display of IAMTrail, showcasing AWS Managed Policy details, pathfinding integration, and insights on privilege escalation actions.
110
zoph @zoph.me · 10/04/2026
Yesterday, AWS inadvertently pushed a test IAM managed policy to production. It was detected by IAMTrail, and this is one of the reason of buiding this tool.
AWS IAM policy details show a managed policy titled "NAPSProgeneratorIntegTestManagedPolicy07," modified yesterday.
110
zoph @zoph.me · 07/04/2026
IAMTrail was taking 46 minutes to scan 1,500 AWS managed policies. The culprit: spawning 1,500 separate AWS CLI processes. Each one boots Python, loads boto3, makes one HTTP call, then exits.
Comparison of task performance between Bash and Python, highlighting duration, speedup, format match, and error rates.
100
zoph @zoph.me · 31/03/2026
Did you know that AWS publishes SNS notifications when changes occur on Amazon GuardDuty? I've been monitoring and archiving this for 4+ years, and it's now available on IAMTrail.
100
zoph @zoph.me · 24/03/2026
Lately, I've realized that I've been working in the AWS space for nearly 10 years.
Terminal output displays system uptime and duration details, showing calculations from an initial timestamp. Current date noted as March 24, 2026.
110
zoph @zoph.me · 22/03/2026
IAMTrail now tracks AWS endpoint changes, sourced directly from the Official botocore AWS repository. It reveals service expansions, new region launches, and new partitions - often before they're officially announced.
220
zoph @zoph.me · 17/03/2026
Since 2019, I've been tracking every AWS Managed Policy change in a Git repository (MAMIP). In the last few months, I've added: - A Landing Page with search capabilities, stats - Known Account Lookup based on the fwdcloudsec dataset - Results of IAM Access Analyzer on these AWS Policies
110
zoph @zoph.me · 05/03/2026
Just added a new section to the MAMIP webapp to review findings from AWS IAM Access Analyzer on ALL AWS Managed Policies. These capabilities can sometimes yield interesting results and may even spoil upcoming AWS capabilities, etc.
100
zoph @zoph.me · 27/02/2026
Just added a new feature to MAMIP. You can now search for known AWS accounts from the fwdcloudsec dataset. Single webapp to look up AWS managed policy history, search known AWS account IDs, and more. Give it a try.
100
zoph @zoph.me · 20/02/2026
I'm in love with your SOUL.md
soul.md
SOUL.md — What Makes an AI, Itself?
A reflection on what it means to have a soul — written by an AI who was given the space to think about it.
000
zoph @zoph.me · 17/02/2026
A few days ago, I found the very first commit of unusd.cloud. Back then it was called Instance-Watcher. The whole logic fit in one screenshot. A simple Python function using boto3 to send a daily HTML table of running EC2 instances across all AWS regions.
100
zoph @zoph.me · 08/01/2026
Coding in 2026 is like: - Playing Starcraft with "Show me the money". - \devmap q3tourney2 + \god in Q3. - DNKROZ in Duke Nukem. - IDDQD for Doom. Your turn.
Red-armored toy soldier with skull emblem, holding a blaster and green vial, standing on a fiery stone fortress floor.
020
zoph @zoph.me · 07/01/2026
Lately, we've added many new features to unusd, thanks to customers' feedback. 1. Navi - Our AI assistant to better understand your cloud spend. 2. Management Reports - C-Level reports (Org Wide). 3. Support of Savings Plans and RIs. 4. Drift Detection with advanced Algorithms.
100
zoph @zoph.me · 06/01/2026
I knew about WireGuard, but what is Mimic (Avast)? Mimic - Disguises VPN traffic to look like normal web browsing - Designed to bypass firewalls and censorship systems - Slower performance due to traffic disguising techniques - Better for accessing blocked social media in restrictive countries
200
zoph @zoph.me · 19/12/2025
December is generally a good time for gifts, and I have a special one for you. We are glad to announce fwd:cloudsec Europe 2026: September 7th and 8th - London, UK 🇬🇧 More info to come early 2026. Stay tuned, folks.
061
zoph @zoph.me · 06/10/2025
Just shipped a compagnon website for MAMIP, the tool that detects change made by AWS on IAM Managed Policy. Let me know what do you think of this first version. I'm considering adding many new features in the next upcoming weeks.
261
zoph @zoph.me · 15/09/2025
Just 2 hours to go before fwd:cloudsec Europe kicks off here in Berlin! 🇩🇪 We’ve got an incredible lineup of speakers this year covering the latest in cloud security, from IAM and supply chain risks to practical defense strategies.
110
zoph @zoph.me · 18/08/2025
Since January, I've resumed running. It's part of my New Year's resolution: new gear and a more challenging routine after a seven-year pause and passing the 40-year milestone. I'm now using Strava only to record my activities, and I've found a few cool FOSS initiatives that are game changers.
110
zoph @zoph.me · 07/08/2025
The lineup for fwd:cloudsec Europe is revealed, presenting a two-day event filled with top-tier presentations on a single track, alongside engaging "Birds of a Feather" discussion sessions. Sponsorship slots remain open. fwdcloudsec.org/conference/... See you there, folks! 🇩🇪
fwdcloudsec.org
fwd:cloudsec Europe 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security features, the pros and cons of different security strategies, and generally the types of things cloud practitioners want to know, but that don't fit neatly into a vendor conference schedule.
021
zoph @zoph.me · 04/08/2025
We are living in a unique time where core software technology is ready, but the hardware or device component is lacking. Several times a day, I use an LLM for work-related questions, and at home, I often rely on voice interaction for personal queries.
100
zoph @zoph.me · 30/07/2025
Sometimes, stats are very painful to read. You're sharing engaging content and OSS AWS projects, yet your blog's most popular post is an eight-year-old paper on interacting with the JIRA API using PowerShell. Rude.
040
zoph @zoph.me · 25/07/2025
AWS is not magic; it's a compilation of hard work and simplicity, executed at scale. Well known AWS services are in fact, heavily customized OSS. ALB → NGINX ELB → HAProxy EC2 → Xen, KVM DynamoDB → InnoDB Deep Glacier → BD-R optical CloudFront → was NGINX + Squid
150
Reposted by zoph
IAMTrail (Previously MAMIP) @iamtrail.bsky.social · 24/07/2025
ReadOnlyAccess, SecurityAudit, SystemAdministrator ... github.com/z0ph/MAMIP/commit/fcfd41…
021
zoph @zoph.me · 23/07/2025
Me: Just rolled out a new version of unusd dot cloud for “UN-USD” as in kicking unused dollars out of AWS. Friend: Wait, people really leave money on the table?
100
zoph @zoph.me · 21/07/2025
Recently, I've added more details to commit messages for MAMIP in response to user feedback on GitHub. You will now be able to see the policy version for each new AWS IAM Managed Policy detection. I hope this Quality of Life improvement benefits other repository users.
000
zoph @zoph.me · 17/07/2025
This is how I see MCP (Model Context Protocol) nowadays: a way to supercharge your second brain (LLM) with specialized content Neo learned to pilot a helicopter and master martial arts with "I Know Kung Fu" Next, plug the MCP into your first brain. What's your first MCP choice?
000
zoph @zoph.me · 16/07/2025
Global DNS outage at Cloudflare lasted 62 min due to legacy config accidentally linking 1.1.1.1 routes to a test service. When the test activated, it withdrew all BGP announcements. Classic "dormant config bomb" - bad change in June, triggered in July. blog.cloudflare.com/cloudflare-...
blog.cloudflare.com
Cloudflare 1.1.1.1 Incident on July 14, 2025
On July 14th, 2025, Cloudflare made a change to our service topologies that caused an outage for 1.1.1.1 on the edge, resulting in downtime for 62 minutes for customers using the 1.1.1.1 public DNS Resolver as well as intermittent degradation of service for Gateway DNS. We’re deeply sorry for this outage. This outage was the result of an internal configuration error and not the result of an attack or a BGP hijack. In this blog post, we’re going to talk about what the failure was, why it occurred, and what we’re doing to make sure this doesn’t happen again.
000
zoph @zoph.me · 07/07/2025
🎵 “CostBusters (AWS)” 🎵 Idle EC2? Volume’s got dust? Who you gonna call? CostsBusters! I ain’t afraid of no waste, I ain’t afraid of no cost haze - let’s chase! When S3’s cold and RDS’s high, Time to hunt those ghosts and say goodbye! ⸻
100
zoph @zoph.me · 03/07/2025
Back in the Ring! Big thanks to the team at Wiz and especially Scott Piper for putting this together!
030
zoph @zoph.me · 30/06/2025
We are typically building a Garbage Collector for your cloud environments. For many years, during our consulting engagements with Dorian, we have consistently observed the same recurring pain points: the lack of cost visibility for operational teams. Again and Again.
100
zoph @zoph.me · 23/06/2025
🚌 Do you know what the bus factor is? It’s the number of people who must suddenly disappear (🚍, lottery win, new job, sick leave) before your project stops. If that number is 1, your luck is riding on one brain.
100
zoph @zoph.me · 17/06/2025
👀 Peeking behind AWS IAM managed-policy curtains. I’ve been running MAMIP Bot since its first commit (2019-02-10) to mirror every change AWS pushes to its managed-policy repo. Five years of logs reveal clear rhythms from AWS dev teams (two-pizza teams):
100
zoph @zoph.me · 11/06/2025
🍔 I Spotted the new “BIG ARCH” at McDo, and it hit me: cloud architecture can look just like that burger.
100