<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CloudTrail on Samuel Tillman</title><link>https://samueltillman.com/tags/cloudtrail/</link><description>Recent content in CloudTrail on Samuel Tillman</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 04 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://samueltillman.com/tags/cloudtrail/index.xml" rel="self" type="application/rss+xml"/><item><title>Layer 1: The Landing Zone, and the Org-Service Enablement That Terraform Won't Do For You</title><link>https://samueltillman.com/posts/refplatform/layer-1-the-landing-zone/</link><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><guid>https://samueltillman.com/posts/refplatform/layer-1-the-landing-zone/</guid><description>&lt;p>Last week I walked through &lt;a href="https://samueltillman.com/posts/refplatform/layer-0-bootstrapping-an-aws-org/">Layer 0&lt;/a>
: the organization itself, OUs, four member
accounts, guardrail SCPs, a Terraform state backend, and GitHub OIDC, all managed
from the management account and nothing else. That layer was deliberately inward:
everything it touched lived in one account.&lt;/p>
&lt;p>Layer 1 is where the platform stops being a skeleton and grows a nervous system.
This is the &lt;em>landing zone&lt;/em>, the shared identity, audit, and security backbone
that every layer above it, including the EKS platform in Layer 2, quietly depends
on. And it&amp;rsquo;s the first time Terraform reaches &lt;strong>across account boundaries&lt;/strong> and
leans on &lt;strong>organization-wide services with delegated administration&lt;/strong>. Those two
facts drive almost every interesting decision, and every single one of the
gotchas, in this post.&lt;/p></description></item></channel></rss>