Notes from AWS Practice.

Deep-dives from ongoing AWS projects — no vendor slides, no hype cycles. What works, what it costs, what I wouldn't do again.

Two Systems, One Sales Motion: An AWS Partner Agent on Amazon AgentCore Harness
Featured

Two Systems, One Sales Motion: An AWS Partner Agent on Amazon AgentCore Harness

Part 1 of the series "Building a Partner Sales Agent on Amazon Bedrock AgentCore", built around one real project: a conversational agent that connects HubSpot CRM and AWS Partner Central for an AWS Partner's sales team.

#aws#agentic-ai#demo#agentcore#identity#bedrock
22 min read
3 min read

AWS Certification: How to Get 30 Extra Minutes on Your Exam (DaZ +30)

AWS doesn't offer its certification exams in German, so native German speakers have to test in English. With \"DaZ +30\" you can request a one-time 30-minute extension to make up for that. Here's how to set it up.

#certification#training
AWS European Sovereign Cloud: What Six Months and One Live Test Actually Show
Security
12 min read
LinkedIn Article

AWS European Sovereign Cloud: What Six Months and One Live Test Actually Show

A reality check from a live account: what the sovereign AWS cloud can do today, where it hits its limits, and what that means for CIOs and CISOs in the DACH market.

#aws#cloud-security#compliance#sovereignty#ciso
Shadow Code: The Security Risks German Companies Are Buying Unnoticed in 2026
Security
7 min read
LinkedIn Article

Shadow Code: The Security Risks German Companies Are Buying Unnoticed in 2026

We knew shadow IT. Now comes shadow code: production code that AI agents write past IT, security, and compliance. 79 percent of organisations have no overview of the agents running in their environment. Four risks that get bought along unnoticed, and an audit in three steps.

#cloud-security#shadow-code#bsi-c5#nis2#agentic-ai
From Pilot to Production: Why Most AI Projects Get Stuck, and What the Exceptions Do Differently
Agentic AI
6 min read
LinkedIn Article

From Pilot to Production: Why Most AI Projects Get Stuck, and What the Exceptions Do Differently

Around 95 percent of enterprise GenAI pilots show no measurable impact. Why the step from pilot to production is the hardest one of all — and what the few exceptions do differently. From my own experience building a product with AI agents over five months.

#agentic-ai#ai-transformation#cloud-security#governance#aws
Set the AWS Security Agent Loose on Our Production Site. Here is What 10 Hours Got Us.
Security
5 min read
LinkedIn Article

Set the AWS Security Agent Loose on Our Production Site. Here is What 10 Hours Got Us.

A field report from one of AWS’ newest AI-driven security services - from setup to findings to verdict.

#aws#agentic-ai#cloud-security#pentest
When Agents Pay: AWS AgentCore Payments and the Next Identity Problem
Security
6 min read
LinkedIn Article

When Agents Pay: AWS AgentCore Payments and the Next Identity Problem

AWS launched Amazon Bedrock AgentCore Payments with Coinbase and Stripe. This is not just a feature update. It is the moment agents move from planners to actors with financial impact. What that means for architects and CISOs.

#aws#agentic-ai#cloud-security#agentcore#bsi-c5#identity
Security
6 min read

Shadow Agents: The New Blind Spot for CISOs

67 percent of security leaders do not know which AI models and agents are running in their organisation. That is the core finding of the Pentera 2026 Report. And while Gartner projects that 40 percent of all enterprise apps will have AI agents built in by end of 2026, both curves are moving in the wrong direction.

#agentic-ai#cloud-security#identity#ciso#aws#governance
Architecture
6 min read

Brownfield Cloud: Why Remediation Matters More Than Innovation

Greenfield cloud projects are the exception in 2026. The rest of us live in brownfield. And very few have a strategy for it. Three patterns I see repeatedly in AWS assessments - and why the next major discipline in cloud work is not innovation, but remediation.

#aws#cloud-security#brownfield#cloud-architecture#iam#governance
What a Cloud Security Architect Actually Does All Day
Security
6 min read

What a Cloud Security Architect Actually Does All Day

When people hear Cloud Security Architect, most imagine someone who writes firewall rules all day. In practice, the majority of the work is something entirely different. An honest description of the job, for everyone who looks at it from the outside.

#cloud-security#aws#architecture#career#employer-branding
Agentic AI Governance Gap: Why 79 Percent Deploy But Only 21 Percent Are Ready
Security
6 min read

Agentic AI Governance Gap: Why 79 Percent Deploy But Only 21 Percent Are Ready

79 percent of organisations are deploying or testing Agentic AI. Only 21 percent have a mature governance model for it. That is not a surprise - it is the consequence of governance always lagging behind technology. Three core questions every CISO team needs to answer now.

#agentic-ai#cloud-security#governance#ciso#aws#identity
BSI C5:2026: What Cloud Users Need to Know Now
Security
6 min read

BSI C5:2026: What Cloud Users Need to Know Now

The BSI has published C5:2026. 168 criteria instead of 121, new mandatory areas, machine-readable for the first time. Anyone who considered C5:2025-readiness sufficient is starting over. Here is what changes and what organisations need to do now.

#aws#bsi-c5#cloud-security#compliance#nis2
Your AI-Generated Tests Are Lying to You
Architecture
6 min read
LinkedIn Article

Your AI-Generated Tests Are Lying to You

393 test files, all green. Then a colleague sat down with me. What he showed was systematic: AI-generated tests fail in predictable patterns. The seven anti-patterns I documented in my codebase - and how a Kiro Skill fixes them.

#aws#kiro#agentic-ai#testing#spec-driven-development
Kiro vs. Vibe Coding: Why Spec-Driven Development Is the Key to Sustainable Enterprise Code
Architecture
8 min read
LinkedIn Article

Kiro vs. Vibe Coding: Why Spec-Driven Development Is the Key to Sustainable Enterprise Code

Vibe coding may work for prototypes. For enterprise code with security requirements, it is an architectural dead end. How AWS Kiro charts a radically different path with spec-driven development - and what 175,000 lines of code in 19 days says about that path.

#aws#kiro#agentic-ai#spec-driven-development#cloud-architecture