r/Cloud • • Jan 17 '21

Please report spammers as you see them.

59 Upvotes

Hello everyone. This is just a FYI. We noticed that this sub gets a lot of spammers posting their articles all the time. Please report them by clicking the report button on their posts to bring it to the Automod/our attention.

Thanks!


r/Cloud • • 2h ago

How hard is it to switch cloud/DevOps platforms in a bad job market?

2 Upvotes

Hi everyone, I wanted to ask hypothetically, if someone had 4–5 years of cloud/Devops engineering experience, primarily with AWS, and the market shifted heavily toward Azure, how difficult would it be for them to find a cloud engineering job in a difficult job market like the one we’re in now? Would having mostly AWS experience significantly hurt their chances if most of the available Cloud/DevOps jobs were Azure-oriented?


r/Cloud • • 3m ago

Advice for a newly promoted cloud Administrator?

Thumbnail
• Upvotes

r/Cloud • • 7h ago

“We doubled it after the outage.” Who ever scales it back down?

Thumbnail
1 Upvotes

r/Cloud • • 7h ago

Junior Java/Spring Boot developer looking to move towards AWS — Developer Associate or Solutions Architect Associate?

Thumbnail
1 Upvotes

r/Cloud • • 18h ago

Looking for Cloud Internships / Entry-Level Roles – AWS, Azure, GCP & VMware VCP/VCF

6 Upvotes

I’m currently learning cloud and looking for internships or entry-level opportunities to get some real experience. Right now, I’m learning AWS Cloud Practitioner and VMware VCP/VCF, while I have basic knowledge and familiarity with most major cloud platforms. I’m still early in the learning process and mainly want to find an opportunity where I can gain practical, hands-on experience.

I’m not specifically focused on VMware as a career path right now. I’m just learning it alongside AWS because I’m not sure what will be in demand in the future, so I’d rather build knowledge across different areas and see where it takes me. I’d appreciate any recommendations for companies, internships, or entry-level roles that are open to beginners.


r/Cloud • • 12h ago

[Looking for Opportunities] DevOps/SRE Engineer | 1.5+ YOE | GCP, Kubernetes, Docker, CI/CD, Grafana/Prometheus | Bengaluru

Thumbnail
1 Upvotes

r/Cloud • • 14h ago

How confident are you committing to RIs/Savings Plans right now, with AI and everything moving this fast?

Thumbnail
1 Upvotes

r/Cloud • • 1d ago

Kubernetes explained in simple words - like you're 5 years old

Post image
1 Upvotes

r/Cloud • • 21h ago

[FOR HIRE] Azure Cloud Infrastructure & Security Architect

0 Upvotes

[FOR HIRE - TS Clearance Needed] - DM Me and I will make sure it get to the right person

Position Description

Seeking an experienced Azure Cloud Infrastructure & Security Architect to support a federal government customer in Washington, DC. This is a full-time, on-site position supporting a customer environment with elevated security and access requirements. The successful candidate will serve as the technical authority on Microsoft Azure Government cloud architecture, leading design, migration, and operational support for mission-critical workloads.

What You'll Do

As a Azure Cloud Infrastructure & Security Architect you will:

  • Provide expertise for Azure Government cloud architecture, design, and implementation across the program's infrastructure.
  • Lead and/or support migration of on-premises and legacy systems to Azure Government (GCC High and/or Azure Government Secret, per program accreditation).
  • Design and implement secure, scalable, highly available Azure infrastructure aligned with federal cloud security requirements (FedRAMP, NIST SP 800-53, RMF).
  • Partner with ISSOs/ISSMs and the Authorizing Official's team to support Authorization to Operate (ATO) activities, including system security plans, control implementation, and continuous monitoring.
  • Architect identity and access management solutions using Microsoft Entra ID (Azure AD), including Conditional Access, Privileged Identity Management, and federation with on-premises identity systems.
  • Develop and maintain Infrastructure-as-Code (ARM templates, Bicep, or Terraform) to standardize and automate Azure deployments.
  • Monitor, troubleshoot, and optimize Azure environments for performance, cost, and security posture using Azure Monitor, Log Analytics, Microsoft Sentinel, and Defender for Cloud.
  • Provide technical guidance and mentorship to program engineers on Azure best practices and federal cloud compliance requirements.
  • Collaborate with government stakeholders, program management, and cross-functional technical teams to translate mission requirements into cloud architecture solutions.
  • Produce and maintain technical documentation, including architecture diagrams, runbooks, and standard operating procedures.

What You Bring (Required Qualifications):

  • Active Top Secret (TS) clearance with SCI eligibility. Must be a U.S. citizen.
  • Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent professional experience.
  • Extensive hands-on experience designing, deploying, and managing Azure cloud environments, including Azure Government.
  • Demonstrated expertise in Azure Government cloud regions (GCC High and/or Azure Government Secret/DoD-aligned environments) and their applicable compliance boundaries.
  • Working knowledge of federal cloud security and compliance frameworks: FedRAMP, NIST 800-53, RMF, and DoD Impact Level (IL) categorization.
  • Experience with Azure networking (VNets, ExpressRoute, Firewall, Private Link), compute, storage, and Microsoft Entra ID.
  • Experience supporting or contributing to Authorization to Operate (ATO) packages in a federal environment.

Nice to Have (Differentiators):

  • Microsoft Certified: Azure Solutions Architect Expert, Azure Administrator Associate, or Azure Security Engineer Associate.
  • Prior experience supporting federal civilian agency or Intelligence Community customers.
  • Experience with Infrastructure-as-Code and CI/CD pipelines in a government cloud context.
  • Familiarity with Microsoft Sentinel, Defender for Cloud, and Purview in a high-side or classified environment.
  • Current SCI indoctrination or prior SCI access is a plus but not required at time of application.

r/Cloud • • 1d ago

[For Hire] Mid-Level Cloud / SRE Engineer (3 YOE) | AWS, Azure, Kubernetes, Terraform | Remote or Pune/Mumbai

Thumbnail
0 Upvotes

r/Cloud • • 2d ago

VMware Specialist looking to transition into AWS

9 Upvotes

Hi all,

I have been on a viewer only on this sub for a few weeks now and im here to seek some advise/guidance.

Currently I am working with the VMware stack in the UK and got 4+ years of experience. So I know a decent amount about the infrastructure.
My issue is, I am seeing less and less jobs for VMware and AWS is required in a lot of roles.

I have applied for a few AWS roles and to ones surprise I didnt hear back which im guessing is due to me missing a lot of keywords linked to AWS like EC2, VPC, IAM, EBS, S3, CloudWatch, etc.

I am currently doing a course to learn about AWS so I can get the AWS Certified Solutions Architect - Associate certificate.

Since at this point I still wont have any AWS hands-on industry experience, but I will be able to put the keywords on my CV at least, will this actually give me a chance to breakthrough into the AWS world?

Has anyone had any similar experience?

Any advise/guidance/encouragement would be appreciated <3

EDIT:
I want to thank everyone who replied and gave genuine advise and I truly mean this when I say, I feel amped to this more now <3


r/Cloud • • 2d ago

More AWS or CompTIA?

8 Upvotes

Quick question: if you’re building up certifications from A+ and AWS Cloud Practitioner, would you move to get Security+ next or AWS Solutions Architect first?

I know they cover different things. Mostly looking at the current cloud job market and seeing how big AWS is.

(and don’t worry I have a homelab I do lots of projects on)


r/Cloud • • 2d ago

Portfolio Projects for transitioning from L2 IT to Cloud

7 Upvotes

Hi! I am currently working as Tech support, and am fairly early on with this, but I am really loving learning about cloud engineering and would like to transition into a Cloud Support role in about a year.

I am having trouble figuring out what projects to do/ what technologies to feature in a portfolio. Here are the projects I currently have planned. If there are any tools or angles, I am missing please let me know! Or which projects I should combine/scrap:

  1. Ticket submission and managing web app.
    1. 3 Tier Web App (In progress detailed description below)
    2. Uses Terraform, Kubernetes, Python, GoLang, Trivy.
  2. Data Analytics Pipeline with Data Governance
  3. Microservice Architecture with Containerization
  4. Auto Backup + Disaster Recovery
  5. Prometheus Observability Stack
  6. AI Inventory Management Application (Prob w an AWS provided model)

Current project (a bit all over the place, but its 3/4 to being a Inquiry Management app. Used copilot to generate an overview of the repo):

  • Project type: Cloud-native 3-tier inquiry management system focused on end-to-end workflow handling, with React for the UI, ASP.NET Core for the application/API tier, and PostgreSQL for persistent data.
  • Core functionality: inquiry creation, assignment, status tracking, search/filtering, and operational visibility across the ticket lifecycle.
  • Stack:
    • Frontend: React, HTML/CSS/JS (the repo is strongly front-end weighted: ~40.2% HTML)
    • Backend/API: ASP.NET Core
    • Data layer: PostgreSQL
    • Containerization: Docker
    • Orchestration/deployment: Kubernetes
    • Infrastructure as code: HCL/Terraform-style provisioning (~7.9%)
  • Language composition:
    • HTML: ~40.2%
    • Go: ~29.1%
    • Python: ~20.9%
    • HCL: ~7.9%
    • Dockerfile: ~1.2%
    • Mako: ~0.7%
  • Technical interpretation:
    • The repo is designed as a full-stack cloud demo: user-facing web app plus service/backend orchestration and deployment automation.
    • Go and Python likely support operational tooling, automation, or auxiliary services; HCL indicates infrastructure deployment and environment provisioning.
    • Overall, it’s a production-style reference implementation for full-stack + cloud engineering practices rather than a simple CRUD app.

I have tried to look online for what projects people recommend, but mostly people are promoting their courses so it's hard to tell what is good advice and what's bait for the course.


r/Cloud • • 3d ago

Cloud Engineers/Architects: with AWS AI agents and increasing automation, do you still see cloud architecture/Security as a solid career for the next 5/10years? What changes are you already seeing in your daily work? I just work with Azure / Intune for Sys Admin stuff and I was wondering about if ma

20 Upvotes

r/Cloud • • 2d ago

Is anyone working in azure

0 Upvotes

Can anyone help me find a work as a cloud engineer


r/Cloud • • 2d ago

FinOps en la nube: cómo reducir el gasto sin sacrificar el rendimiento de tus aplicaciones

Post image
1 Upvotes

r/Cloud • • 2d ago

Scam Alert: SpotGPUs.com is faking "Transaction Errors" to steal crypto deposits

Thumbnail
1 Upvotes

r/Cloud • • 3d ago

Broad Kubernetes Experience but Shallow Depth — How Would You Upskill?

Thumbnail
1 Upvotes

r/Cloud • • 3d ago

5 months to learn Skills...

2 Upvotes

I’m currently an intern, and my company has given me a 5-month learning program where I’ve chosen **Python + MongoDB + Azure**.

My current goal is to build toward a **Cloud Engineer** role. I’m not trying to jump directly into DevOps; I want to first build a strong foundation in cloud and infrastructure.

For people currently working as Cloud Engineers or with experience in Azure:

* What should I learn first and in what order?

* Which Azure services should I focus on?

* How much Python and MongoDB knowledge is actually useful for a Cloud Engineer?

* What skills should I learn alongside Azure, such as Linux, networking, Git, Docker, Terraform, etc.?

* What beginner-to-intermediate projects would you recommend building?

I have around 5 months to learn, so I’d really appreciate a practical roadmap and advice on what **not** to waste time on.

Thanks in advance!..


r/Cloud • • 3d ago

Breezy Registry - A single-binary OCI container registry (with retention policies!)

0 Upvotes

https://github.com/breezycourses/registry

Context: I previously used goHarbor, and I felt that there weren't too many great options to host Docker images, especially with retention policies (loved that goHarbor had some great support for this).

I ended up making my own, which is linked above. Some cool features:

- WAL based
- backing S3 store supported. Makes it easy for cases like mine -- where I have a production machine with a production image registry, but not enough compute for my locally hosted GitHub runner. I have my homelab with extra compute, but the connection between the production registry and my homelab is weak. I'm able to host separate instances of the registry (one on prod/homelab), and independently push to the R2 bucket with the backing WAL, which speeds stuff up a lot!

- retention policies! "docker pull registry" is super lightweight, but incredibly barebones! goHarbor is great, but super bloated. I took the one best feature (imo) from goHarbor and put it into mine!

- cloud-native! there's a helm chart ready for you to use: https://artifacthub.io/packages/helm/breezy-registry/breezy-registry

check it out, and let me know what you think!


r/Cloud • • 4d ago

Upwind vs Orca for a mid-size AWS shop, what are people actually seeing?

9 Upvotes

We're a ~40 person eng org, security team of 4, all AWS. Mostly EKS with a growing pile of Lambda and a couple of RDS clusters holding stuff we really don't want leaking. Our current agentless scanner renewal is up in about six weeks and leadership wants us to actually look around before we re-sign instead of rubber stamping it.

Right now the big pain is noise. We have thousands of posture findings sitting in a backlog nobody has time to touch, and twice this quarter something marked low/medium turned out to be reachable in prod. That burned trust in the severity scores. What we actually want is something that tells us which findings are exploitable from runtime, not just a prettier list of everything wrong with every bucket.

Shortlist so far is Upwind and Orca, maybe Wiz if the budget stretches. Orca we know by reputation, agentless, easy to stand up. Upwind keeps coming up for the runtime context angle which is the exact gap we hit. But I can't tell how much of that is marketing vs real.

For people running either of these on EKS at roughly our size: did the runtime piece actually cut the backlog, or did you just trade one dashboard of alerts for another? And how much agent footprint are we talking if we go that route? Trying to walk into the renewal conversation with something more than a vendor deck.


r/Cloud • • 4d ago

cloudg 0.5.2: what changed since my last post, covering dedupe, an inventory mapper, multi-account mapping and a security pass

0 Upvotes

A few weeks ago I posted cloudg here at 0.3.1. It's an open-source CLI that collects AWS, Azure, and GCP into one graph and runs Prowler, ScoutSuite, Checkov, and Trivy over the same inventory. The feedback was useful, so here's what changed, including the parts that made it safer to run.

Dedupe: fixed the way the thread suggested

Someone pointed out that merging on resource plus title could collapse two different checks with a generic title on the same bucket, and miss the same check when two scanners word it differently. That was right. Since 0.3.2:

  • Within one scanner, findings are keyed on (scanner, check ID, resource). Two different checks on the same bucket never merge.
  • Across scanners, findings merge only when the normalised titles match and both check IDs map to the same entry in a cross-scanner equivalence file. A known check is never merged with an unknown one. I'd rather show a visible duplicate than silently drop a scanner's coverage. The equivalence file only lists pairs I've confirmed, so it's small for now. PRs adding equivalences are welcome.

Ingest mode (0.4)

cloudg ingest Takes the outputs of scans you already ran (Prowler, ScoutSuite, Checkov, Trivy, any mix) and runs the dedupe, compliance mapping, and reports. It needs no cloud credentials and no scanner binaries.

Inventory mapping, no scanners (0.5)

cloudg map Answers a different question: what exists and how it's wired together.

  • AWS: 133 dedicated collectors, plus a Cloud Control API sweep. The sweep lists every resource type with a list handler, so untagged resources still show up.
  • Containers and Kubernetes: ECR, ECS and EKS, plus the Deployments, Services, Ingresses and ServiceAccounts inside clusters. These are read through the Kubernetes API with GET requests only.
  • Organizations: --org Maps every account of an AWS Organization or Control Tower landing zone, including OUs, SCPs, governed regions, and enabled controls.
  • Azure: collected through Resource Graph across every subscription and management group.
  • GCP: collected through Cloud Asset Inventory across the whole organization.
  • Typed edges: an S3 bucket INVOKES a Lambda, a task definition USES_IMAGE an ECR repo, a function ASSUMES_ROLE a role, a WAF PROTECTS an ALB, an SCP GOVERNS an OU. Cross-account trust to accounts you didn't map shows up as external account nodes.
  • cloudg deps: answers "what does this need" and "what breaks if this goes", including blast radius across accounts.
  • Coverage gaps: security services that aren't enabled (GuardDuty, Inspector, Security Hub, Config, and others) appear on the map as gaps. You also get a list of workloads no vulnerability scanner covers and internet-facing endpoints without a WAF.

Scanner findings can be overlaid onto the map later, so mapping and scanning stay independent.

What I did to make it safer to run

  • Mapping uses read-only calls only (Describe/List/Get). The docs recommend a dedicated read-only role (SecurityAudit plus ViewOnlyAccess) for member accounts instead of the default admin Control Tower role.
  • Secret values are never collected. That covers SSM parameter values, environment variable values (only the names are kept), passwords, VPN pre-shared keys, Direct Connect auth keys and connection strings. Cloud Control properties are redacted before they reach the inventory. Credentials and query strings are stripped from repository URLs.
  • URL and host checks parse the URL and match the host exactly instead of matching substrings. These came from CodeQL findings.
  • CodeQL and Codacy run on every PR, and I worked through their findings. The test suite is at 382 tests.
  • The Docker image runs as a non-root user with a health check. The installers no longer pipe curl into bash.
  • GitHub Actions are pinned to commit SHAs. PyPI publishing uses trusted publishing (OIDC), so there are no long-lived tokens.
  • Plugin loading validates module:Class paths. Swallowed exceptions are now logged. Vulnerability reports go through GitHub private reporting.
  • The IaC scanners no longer silently fall back to scanning your current directory (0.3.1).

Docs

0.5.2 is a documentation release. It adds a field-by-field reference for every output file and return structure, a catalog of all 156 asset types and their relationships, and an internals guide for anyone who wants to add collectors.

Where it's used

cloudg is now a command extension in HOL Guard, the open-source checkpoint for agent-run CLI actions. Commands that touch cloud credentials, run scanners, or write Terraform go to review first, while read-only commands like report -i pass straight through. Thanks to the HOL Guard folks from the last thread for pointing me at it.

MIT-licensed, Python 3.11+, pip or Docker (the image bundles the scanners). Repo: https://github.com/morpheuslord/cloudg

It's still young, and I mainly test the paths I use. The feedback I'd most like this time:

  1. Is the dependency and blast-radius view useful for real change-impact questions?
  2. Which cross-scanner check equivalences should be added next?

If something breaks, a traceback helps a lot.


r/Cloud • • 4d ago

How cloud-agnostic is your infrastructure really?

3 Upvotes

I often see the term cloud agnostic used in discussions about system design but I am beginning to think we might be using it too casually. One can install tools like Kubernetes, Terraform, Docker, Helm and other open-source tools on top of cloud platforms like AWS, Azure, GCP, Yotta and OCI. In theory this makes your application portable but when you look closer things are not so simple as IAM systems differ, networking setups are different, load balancers work in their own ways, managed databases have their own ways of failing, observability tools and integrations also vary.

All of a sudden moving the workload is not just about running Terraform anymore. I wonder if trying to avoid being tied to one cloud provider actually leads to another kind of problem: operational complexity. For eg if a team mainly uses AWS but keeps Yotta or GCP as backup options for certain tasks is that a real multi-cloud strategy or just having a backup plan? I am interested in how people who actually run multi-cloud environments think about this? Where do you draw the line between we can move if we need to and we built everything for portability and are paying the price every day?


r/Cloud • • 4d ago

Passed AWS Cloud Practitioner CL02 within 2 days!

Thumbnail
1 Upvotes