Articles by Andrew Ghobrial

Stop Reusing the Same CIDR Everywhere: VPC Peering Will Bite You

Stop Reusing the Same CIDR Everywhere: VPC Peering Will Bite You

Overlapping CIDRs block VPC peering and make growth painful. Here’s a practical plan for org-wide CIDR design, Terraform guardrails, and zero-downtime migration.

2 min read
🧠 Cognito in Multi-Region AWS Architectures β€” What’s the Right Approach?

🧠 Cognito in Multi-Region AWS Architectures β€” What’s the Right Approach?

Cognito is AWS’s managed authentication service, but it comes with a critical limitation: user pools are region-bound. In this post, I explore why this matters in multi-region designs and the approaches you can take to solve it.

3 min read
πŸš€ Ways to Access Your Database in a Private Subnet in AWS VPC

πŸš€ Ways to Access Your Database in a Private Subnet in AWS VPC

Databases should live in private subnets for security β€” but how do you access them when they’re not exposed to the internet? In this post, I cover bastion hosts, Session Manager, VPC peering, VPN/Direct Connect, and PrivateLink.

3 min read
🌟 How I Decreased Docker Image Size by Half with Distroless Images

🌟 How I Decreased Docker Image Size by Half with Distroless Images

Discover how switching to distroless images can drastically reduce Docker image size, improve security, and accelerate deployments.

2 min read
🚨 Docker on ECR Costs Alert! 🚨 Managing Hidden Storage Charges

🚨 Docker on ECR Costs Alert! 🚨 Managing Hidden Storage Charges

ECR charges $0.10 per GB/month for stored Docker images. Learn how lifecycle policies can keep your costs under control and prevent runaway storage bills.

2 min read
🚨 AWS Lambda Costs ALERT! 🚨 Optimizing Memory and Node.js Garbage Collection

🚨 AWS Lambda Costs ALERT! 🚨 Optimizing Memory and Node.js Garbage Collection

Learn how improper memory allocation in AWS Lambda with Node.js can lead to crashes and inflated costs, and how tuning memory with NODE_OPTIONS can save you money.

3 min read
πŸ’Έ When AWS NAT Gateway Costs Spike Out of Control (and How to Be Prepared)

πŸ’Έ When AWS NAT Gateway Costs Spike Out of Control (and How to Be Prepared)

A sudden spike in AWS NAT Gateway costs can be painful β€” and without VPC Flow Logs, you’re left in the dark. Here’s why it happens, how to investigate, and what to do next.

3 min read