← Architect · Learner

Knowledge material · ~6 min read

Architect · Learner

Detection, IaC, K8s, and the cost lens.

Overview

Architects don't build features — they shape how systems detect attacks, get described as code, scale, and stay affordable. At Learner you're absorbing the four levers that separate hobby clouds from production: SIEM (Security Information and Event Management), IaC, Kubernetes, and FinOps.

SIEM & the SOC (Security Operations Center) mindset

  • ▸Collect logs (identity, endpoint, network, cloud) → normalize → correlate → alert.
  • ▸Detection engineering: write rules from real TTPs (MITRE ATT&CK), not vendor defaults.
  • ▸Alert fatigue is the enemy — every alert needs an owner and a runbook.
  • ▸Mean Time To Detect (MTTD (Mean Time To Detect)) + Mean Time To Respond (MTTR (Mean Time To Resolve)) are the scorecards.

Infrastructure as Code

  • ▸Declarative > imperative — describe the end state.
  • ▸Terraform (multi-cloud), Bicep/ARM (Azure), CloudFormation/CDK (AWS (Amazon Web Services)).
  • ▸State file is sacred — store remote, lock, encrypt.
  • ▸Modules + variables + environments; never copy-paste.

Kubernetes — just enough

  • ▸Pod = group of containers, scheduled together.
  • ▸Deployment = desired state for pods; ReplicaSet maintains count.
  • ▸Service = stable network endpoint; Ingress = HTTP (Hypertext Transfer Protocol) routing.
  • ▸Use managed (AKS (Azure Kubernetes Service)/EKS/GKE) before self-hosting control plane.

Designing for cost

  • ▸Right-size before discounting; reserved/savings plans only on steady load.
  • ▸Egress, storage tiers, idle resources — the silent killers.
  • ▸Showback / chargeback by tag forces ownership.
  • ▸Architecture decisions made on bills, not theory.

Glossary

SIEM
Security Information & Event Management — log + alert platform.
TTP
Tactic, Technique, Procedure — how attackers operate.
IaC drift
Real state diverging from declared state.
FinOps
Practice of running cloud spend like a product.

Common pitfalls

Practice drills