Jump to: Pinned repos • All repos ↗ • Contribution graph
- Secure private network
- Editable application configuration
- Automatic, no-edit transformations
- Strict, reciprocal security group egress and ingress rules (only known hosts can talk; no private IP address ranges)
- Secure, small, but still simple container definition
- Require encryption with KMS keys specified in S3 bucket tags
- Central resource control policy covers buckets in many accounts
- Self-service documentation helps developers
- Templated test buckets support thorough, realistic, automated tests
- Keywords communicate properties of test buckets (avoids duplication, inconsistencies)
- Require a storage class specified in an S3 bucket tag
- Architectural decision record: history of S3, IAM, and AWS Organizations feature releases
- Safe permissions delegation trick ("Detailed semantics", Item 4)
[More examples coming...]

