Skip to content
BinaryScaler

Technology

AWS

Account structure, networking, identity and managed services laid down as code — with cost attribution from day one rather than after the first surprising bill.

The foundation decides the next five years

Account structure, network topology and identity are the decisions that are painful to revisit. Almost everything else on AWS can be changed later without much drama.

So we spend our effort there — multi-account landing zones, least-privilege identity and tagging that makes cost attributable — and use managed services aggressively above that line.

Practice

How we use it

Landing zones

Multi-account structure with guardrails, centralised logging and policy applied as code.

Identity and access

Least-privilege roles and federated access, with standing human credentials treated as a defect.

Managed-first

RDS, SQS, EventBridge and their peers over self-hosted equivalents unless there is a specific reason.

Cost engineering

Tagging, attribution and commitment planning so spend is explainable per team and per workload.

Judgement

When AWS is the right call

And when it is not. A technology page that only lists strengths is a brochure.

Reach for it when

  • Broadest managed-service coverage and the deepest hiring pool
  • Regulated workloads needing mature compliance evidence
  • Organisations already invested in the ecosystem

Look elsewhere when

  • Where an existing commercial relationship makes another provider materially cheaper
  • Simple workloads where a platform-as-a-service removes the operations entirely