2025-07-05
aws, serverless, genai
🇺🇸 🇩🇪 🇪🇸 🇫🇷 🇮🇹 🇵🇹
Escrever conteúdo técnico como falante não nativo de inglês frequentemente significa gastar tempo significativo revisando erros ortográficos e gramaticais. Neste post, exploro como estendi minha pipeline CI/CD de blog event-driven existente com revisão automatizada usando Amazon Nova e Amazon Bedrock, integrando perfeitamente correção de texto alimentada por IA.
Scrivere contenuti tecnici come parlante non nativo inglese spesso significa dedicare molto tempo alla correzione di errori ortografici e grammaticali. In questo post, esploro come ho esteso la mia pipeline CI/CD del blog event-driven esistente con la correzione automatica di bozze usando Amazon Nova e Amazon Bedrock, integrando perfettamente la correzione di testo basata sull'IA.
Écrire du contenu technique en tant que locuteur non natif anglais signifie souvent passer beaucoup de temps à relire pour corriger les erreurs d'orthographe et de grammaire. Dans ce post, j'explore comment j'ai étendu mon pipeline CI/CD de blog event-driven existant avec une relecture automatisée utilisant Amazon Nova et Amazon Bedrock, intégrant de manière transparente la correction de texte alimentée par l'IA.
Escribir contenido técnico como hablante no nativo de inglés a menudo significa pasar mucho tiempo corrigiendo errores ortográficos y gramaticales. En esta publicación, exploro cómo extendí mi pipeline de CI/CD de blog basado en eventos existente con corrección automatizada de texto usando Amazon Nova y Amazon Bedrock, integrando sin problemas la corrección de texto con IA.
Das Schreiben technischer Inhalte als Nicht-Muttersprachler bedeutet oft, viel Zeit mit dem Korrekturlesen von Rechtschreib- und Grammatikfehlern zu verbringen. In diesem Post erkunde ich, wie ich meine bestehende event-driven Blog CI/CD-Pipeline mit automatisiertem Korrekturlesen unter Verwendung von Amazon Nova und Amazon Bedrock erweitert habe, um AI-gestützte Textkorrektur nahtlos zu integrieren.
Writing technical content as a non-native English speaker often means spending significant time proofreading for spelling and grammatical errors. In this post, I explore how I extended my existing event-driven blog CI/CD pipeline with automated proofreading using Amazon Nova and Amazon Bedrock, seamlessly integrating AI-powered text correction.
2025-05-06
aws, authz, serverless
Levando nosso sistema de autorização para o próximo nível! Nesta terceira parte de nossa série, estamos aprimorando nossa solução Amazon Verified Permissions (AVP) com Controle de Acesso Baseado em Atributos (ABAC). Ao combinar RBAC e ABAC, obtemos um sistema de autorização poderoso que pode impor acesso refinado com base em atributos de usuário e contexto - perfeito para aplicações multi-tenant onde o controle de acesso precisa considerar mais do que apenas funções.
Faites passer notre système d'autorisation au niveau supérieur ! Dans cette troisième partie de notre série, nous améliorons notre solution Amazon Verified Permissions (AVP) avec le contrôle d'accès basé sur les attributs (ABAC). En combinant RBAC et ABAC, nous obtenons un système d'autorisation puissant qui peut appliquer un accès finement granulaire basé sur les attributs des utilisateurs et le contexte - parfait pour les applications multi-locataires où le contrôle d'accès doit tenir compte de plus que de simples rôles.
¡Llevando nuestro sistema de autorización al siguiente nivel! En esta tercera parte de nuestra serie, estamos mejorando nuestra solución de Amazon Verified Permissions (AVP) con Control de Acceso Basado en Atributos (ABAC). Al combinar RBAC y ABAC, obtenemos un poderoso sistema de autorización que puede aplicar un acceso detallado basado en atributos de usuario y contexto, perfecto para aplicaciones multi-inquilino donde el control de acceso necesita considerar más que solo roles.
Wir bringen unser Autorisierungssystem auf die nächste Stufe! In diesem dritten Teil unserer Serie erweitern wir unsere Amazon Verified Permissions (AVP) Lösung um Attribute-Based Access Control (ABAC). Durch die Kombination von RBAC und ABAC erhalten wir ein leistungsfähiges Autorisierungssystem, das feinkörnige Zugriffskontrollen basierend auf Benutzerattributen und Kontext durchsetzen kann - perfekt für Multi-Tenant-Anwendungen, bei denen die Zugriffskontrolle mehr als nur Rollen berücksichtigen muss.
Taking our authorization system to the next level! In this third part of our series, we're enhancing our Amazon Verified Permissions (AVP) solution with Attribute-Based Access Control (ABAC). By combining RBAC and ABAC, we get a powerful authorization system that can enforce fine-grained access based on user attributes and context - perfect for multi-tenant applications where access control needs to account for more than just roles.
2025-02-20
As authorization needs evolve, managing access efficiently becomes even more crucial. In this follow-up post, we extend our Policy Decision Point (PDP) and Policy Enforcement Point (PEP) solution by introducing Amazon Verified Permissions (AVP) for fine-grained authorization. Instead of storing permissions in DynamoDB, we leverage AVP’s centralized policy engine and Cedar policy language to define and enforce access control dynamically.
2025-01-30
Authorization is a critical part of securing cloud applications, and understanding the best practices for implementing it can make all the difference. In this post, we dig deep on the concepts of Policy Decision Points (PDPs) and Policy Enforcement Points (PEPs), and how they work together to manage user access efficiently. We dive into a serverless solution using AWS Lambda and API Gateway, implementing Role-Based Access Control (RBAC) for fine-grained access control based on Cognito User Groups. This solution ensures scalability, low latency, and efficient authorization in serverless environments.
2024-12-22
aws, iot, security, serverless
Secure communication is a important in IoT systems, where certificates and trust play a vital role. In this post we extend the API introduced in part 1, we will add functionality to create device certificates, introduce an inventory, add some event-driven parts, and the possibility to list and get certificates. This hands-on approach is great for learning purposes and development environments, production setups however require robust managed solutions.
2024-11-27
Secure communication is a important in IoT systems, where certificates and trust play a vital role. In this post, I explore the foundations of certificate management, including PKI, certificate chains, and trust. Also I introduce a serverless self-service API using Amazon API Gateway and Lambda for an easy way to create certificates. This hands-on approach is great for learning purposes and development environments, production setups however require robust managed solutions.
2024-10-31
aws, ai, security, serverless
In this post, I extend the File Manager service I built previously by adding content moderation capabilities. The original service stores files in S3 and records them in a DynamoDB table, using a serverless, event-driven approach. Now, with AWS GuardDuty and Rekognition, I’ve enhanced the service with malware scanning and image moderation.
2024-09-25
aws, re:Invent
A re:Invent é uma das maiores, se não a maior, conferências de tecnologia do mundo. Participar da re:Invent pela primeira vez pode ser avassalador. Neste post, tento dar alguns conselhos sobre como sobreviver não apenas à re:Invent, mas também a Las Vegas como um participante de primeira viagem.
re:Invent is one of, if not the biggest, tech conferences in the world. Attending re:Invent for the first time can be overwhelming. In this post, I try to give you some advice on how to survive not only re:Invent but also Las Vegas as a first-time attendee.
re:Invent est l'une des plus grandes conférences technologiques au monde, sinon la plus grande. Assister à re:Invent pour la première fois peut être accablant. Dans cet article, j'essaie de vous donner quelques conseils pour survivre non seulement à re:Invent mais aussi à Las Vegas en tant que participant pour la première fois.
re:Invent es una de las conferencias tecnológicas más grandes del mundo, si no la más grande. Asistir a re:Invent por primera vez puede ser abrumador. En esta publicación, intento darte algunos consejos sobre cómo sobrevivir no solo a re:Invent sino también a Las Vegas como asistente por primera vez.
re:Invent ist eine der größten, wenn nicht sogar die größte Tech-Konferenz der Welt. Der erste Besuch bei re:Invent kann überwältigend sein. In diesem Beitrag versuche ich, Ihnen einige Ratschläge zu geben, wie Sie nicht nur re:Invent, sondern auch Las Vegas als Erstbesucher überleben können.
re:Invent is one of, if not the biggest, tech conferences in the world. Attending re:Invent for the first time can be overwhelming. In this post I try give you some advice how to survive not only re:Invent but also Las Vegas as a first time attendee.
2024-09-20
serverless, aws, saas, IoT
In part four of the series about the world of BBQ, where tradition and technology rarely cross paths. The future of grilling is here, and it’s connected, smart, and runs on the cloud! We look at the key difference between Authentication and Authorization in a SaaS solution. We introduce a new authorization architecture with a centralized Policy Decision Point (PDP) and distributed Policy Enforcement Points (PEPs) implemented serverless with API Gateway and Lambda.