MGMario Gongorainblog.leastprivilege.cloud·5d ago · 4 min readAWS Well-Architected Agent: Don't Leave the Context EmptyI created a Well-Architected Agent profile from the console. Three accounts, four pillars, one goal per pillar. The API said the profile was eligible for recommendations. Everything looked fine. Then 01I
MGMario Gongorainblog.leastprivilege.cloud·Sep 16 · 10 min readDeye Cloud API to a Daily Solar Report With BedrockI have a 15.12 kWp array on the roof and a dashboard that shows me every number about it, live. What I wanted was different: one message, once a day, that already answered the questions I actually ask10
MGMario Gongorainblog.leastprivilege.cloud·Sep 16 · 10 min readDeye Cloud API to a Daily Solar Report With BedrockI have a 15.12 kWp array on the roof and a dashboard that shows me every number about it, live. What I wanted was different: one message, once a day, that already answered the questions I actually ask00
MGMario Gongorainblog.leastprivilege.cloud·Aug 15 · 11 min readWriting an IAM Policy That's Actually Least PrivilegeI wrote the IAM policy for my solar agent myself, on the first try, thinking I had done it right. I had not, entirely. The agent behind the last article does two things: it reads one secret from Secre00
MGMario Gongorainblog.leastprivilege.cloud·Aug 13 · 8 min readIAM Roles Anywhere: AWS Access With Zero Static KeysEvery environment I have audited has the same ghost. An IAM user with an access key and a secret key. Created for a script, a cron job, a device that needed to reach AWS. It worked, so nobody touched 00