Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not that unusual to use separate AWS accounts as blast-barriers. I.e. they contain the damage that might occur due to a leak etc. I typically use 2 (prod & non-prod) for each major product/offering, plus a centralised one to manage policies, billing etc for all the sub accounts. They add up pretty quickly.


I use an account for $service-$stage-$region-<$function> then I run most services in every available region

so:

main-service_prod_us-east-1_dataStore

main-service_prod_us-east-1

main-service_test_us-east-1_dataStore

main-service_test_us-east-1

main-service_beta_us-east-1_dataStore

main-service_beta_us-east-1

* regions

Adds up pretty quickly.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: