Term Kind Topic What it is
Account Vending practice Landing Zones Automated creation of new cloud accounts pre-configured with the organisation's networking, identity, logging, guardrails and cost allocation.
Active-Active vs Active-Passive concept Multi-Region Architecture Whether all regions serve traffic simultaneously, or one serves while another waits to take over — a choice about which failure mode you would rather have.
Application Discovery practice Cloud Migration Establishing what applications exist, what they depend on, who owns them and whether anyone uses them — the step whose absence makes every later step a guess.
Autoscaling pattern Cloud Architecture Adding and removing capacity automatically in response to a demand signal, to track load without paying for peak all the time.
Availability Zone AZ concept Cloud Architecture One or more physically separate data centres inside a cloud region, with independent power, cooling and network, connected by low-latency links.
Availability Zone Independence concept Availability Zones The property that a failure in one zone does not propagate to another, and the design work needed to actually benefit from it.
Backup Restore Testing practice Backup Strategies Periodically performing a full restore and measuring it, on the basis that an untested backup is a hypothesis rather than a capability.
Backup Strategy 3-2-1 Rule practice Cloud Architecture A plan for what is copied, how often, where to, how long it is kept, and — the part that decides whether it is real — how the restore is verified.
Blast Radius concept Cloud Architecture The set of things that break, or become reachable, when one component fails or is compromised.
Blast Radius Reduction practice Cloud Architecture The set of deliberate partitions — accounts, regions, zones, cells, tenants, deployment stages — that bound how far any single failure or compromise can reach.
Block Storage Persistent Disk, EBS concept Cloud Storage A virtual disk attached to one instance at a time, presented as raw blocks and formatted with a filesystem — the storage databases and stateful workloads run on.
Burst Capacity Cloud Bursting, Overflow Capacity concept Cloud Architecture Capacity acquired quickly for short-lived demand above the baseline, deliberately priced higher than owned capacity in exchange for immediate availability.
Burstable Instance T-series, B-series concept Compute Models An instance that provides a low baseline CPU allocation and accrues credits while idle, spendable for short periods of full performance.
Cloud Databases concept Cloud Databases Managed and cloud-native database services — where the operational relief is real, and where the abstraction leaks.
Cloud Disaster Recovery practice Disaster Recovery Designing and rehearsing recovery from the loss of a zone, a region or a provider — where the plan is worth exactly as much as its last test.
Cloud Exit Plan practice Multi-Cloud A documented, costed assessment of what leaving a provider or service would require — increasingly a regulatory expectation and a better lock-in control than portability itself.
Cloud Governance practice Cloud Governance The account structure, identity model, guardrails and cost attribution that make a cloud estate operable by many teams without becoming ungovernable.
Cloud Migration practice Cloud Migration Moving workloads to the cloud — where the strategy per workload matters more than the programme, and where lift-and-shift produces the bill that discredits the whole effort.
Cloud Storage concept Cloud Storage Object, block and file storage — with different durability, latency and cost models, and an egress bill that shapes architecture more than most designs admit.
Cold-Start Amortisation Warm Affinity, Startup Cost Reduction practice Serverless Attacking the startup cost itself - through snapshots, lazy image pulls, local artefact caches and affinity routing - rather than choosing between scaling strategies that all suffer from it.
Compute Models concept Compute Models Virtual machines, containers, serverless functions and dedicated hardware — chosen by workload shape rather than by modernity.
Connection Draining Deregistration Delay, Graceful Shutdown practice Load Balancing Allowing in-flight requests on an instance to complete before it is removed from service, rather than terminating them at cutover.
Connection Proxy RDS Proxy, PgBouncer tool Cloud Databases A pooling layer between applications and a managed database that multiplexes many client connections onto a small number of database connections.
Container Image concept Containers A layered, content-addressed filesystem bundle plus metadata, from which containers are instantiated — immutable by construction and identified by digest.
Containers tool Containers Packaging an application with its dependencies into an immutable image, and the orchestration layer that schedules those images across a fleet.
Control Plane and Data Plane concept Cloud Architecture The separation between the machinery that makes changes to a system and the machinery that serves its traffic.
Control Plane vs Data Plane concept Cloud Architecture The separation between the system that manages configuration and the system that serves requests, which have very different reliability requirements.
Cross-Zone Data Transfer concept Availability Zones Charges incurred when data moves between availability zones within a region — invisible on architecture diagrams and a recurring surprise on cloud bills.
Cross-Zone Load Balancing concept Load Balancing Whether a load balancer node distributes traffic to targets in all zones or only its own — a setting that affects both balance and data transfer cost.
Drift Reconciliation Post-Incident Codification, Managed Divergence practice Infrastructure as Code Treating divergence between declared and actual infrastructure as an expected condition with an owned resolution path, rather than as a violation to be automatically reverted.
Durability vs Availability concept Cloud Storage Two different storage guarantees — whether data survives, and whether it can be reached right now — routinely conflated because both are quoted in nines.
Edge Computing concept Edge Computing Running computation at points of presence near users rather than in a central region, trading capability for round-trip latency.
Edge Function concept Edge Computing Code executed at a CDN point of presence close to the user, in a constrained, fast-starting runtime, typically to modify or route a request before it reaches an origin.
Egress-First Cost Modelling Bandwidth-Dominant Costing, Cost Order of Magnitude practice Cloud Architecture Establishing which cost category actually dominates before optimising anything - because in media-heavy consumer platforms the order is usually bandwidth, then storage, then compute, which is the inverse of wh…
Entity Homing Home Region, Per-Entity Primary pattern Multi-Region Architecture Assigning each entity - customer, account, tenant - a single home region that owns its writes, so a regional outage affects a subset of entities rather than every write in the system.
Failback practice Disaster Recovery Returning to the primary region after a failover, including reconciling the data written while it was unavailable — the half of DR that is usually unplanned.
Fragmentation Cost Bin-Packing Loss, Scheduling Fragmentation concept Compute Models The capacity that exists in aggregate but cannot be used because it is scattered across nodes in pieces too small for the jobs that need it - the dominant inefficiency in indivisible-resource scheduling.
Gang Scheduling Co-scheduling, All-or-Nothing Allocation concept Compute Models Allocating every resource a job needs simultaneously or not at all, so tightly-coupled distributed work cannot deadlock holding a partial allocation.
Global Traffic Management GSLB, Global Load Balancing tool Multi-Region Architecture The layer that decides which region a given user reaches, using DNS, anycast or an edge network, and that performs regional failover.
Google Borg to Kubernetes: Learning From an Internal System Borg, Omega case-study Containers Kubernetes was designed with a decade of Borg experience behind it, and its authors have been explicit about which Borg decisions they deliberately did not repeat.
Image Registry tool Containers The store from which container images are pulled, and an under-appreciated availability and security dependency of every deployment and every autoscale event.
Immutable Backup Object Lock, WORM pattern Backup Strategies A backup that cannot be modified or deleted for a defined retention period, even by an administrator — the control that makes backups survive ransomware and insider error.
Infrastructure as Code IaC practice Cloud Architecture Defining infrastructure in version-controlled declarative files that a tool reconciles against the real environment.
Infrastructure as Code in Practice IaC practice Infrastructure as Code Defining infrastructure declaratively in version-controlled code so environments are reproducible, reviewable and auditable.
Instance Family concept Compute Models A group of instance types sharing a resource profile — general purpose, compute optimised, memory optimised, storage optimised, accelerated — chosen by which resource the workload actually exhausts first.
Kubernetes K8s tool Cloud Architecture A container orchestrator that continuously reconciles the running state of a cluster towards a declared desired state.
Kubernetes Operator pattern Kubernetes A custom controller that encodes operational knowledge for a specific application, reconciling a custom resource towards a desired state the same way built-in controllers do.
Kubernetes Resource Requests and Limits concept Kubernetes The declared minimum a container is guaranteed and the maximum it may consume, which drive scheduling, eviction and throttling in ways that are easy to get wrong.
Landing Zone pattern Landing Zones The pre-built, policy-governed cloud foundation into which workloads are deployed — account structure, networking, identity, logging and guardrails.
Maersk and NotPetya: Recovery from a Single Surviving Copy NotPetya 2017 case-study Backup Strategies A destructive malware outbreak encrypted Maersk's estate globally, and the domain controllers were recovered only because one office had been offline during the attack.
Managed Service concept Cloud Architecture A capability the provider operates — provisioning, patching, backup, scaling and failover — leaving you the configuration and the data.
Managed Service Upgrade Window concept Managed Services The period during which a provider may apply patches or version upgrades to a managed service, usually involving a failover or brief unavailability.
Managed Services concept Managed Services Paying a provider to operate a component — usually the right default, with a small number of genuine reasons to self-manage.
Migration Wave practice Cloud Migration A batch of applications migrated together, sequenced so that dependencies move in a workable order and each wave delivers learning for the next.
Multi-Cloud concept Cloud Architecture Deliberately running across more than one cloud provider — a decision with a much higher cost than the lock-in it is usually adopted to avoid.
Multi-Region Active-Active pattern Multi-Region Architecture Serving live traffic from two or more regions simultaneously, which removes failover time and introduces distributed data problems permanently.
Netflix: Regional Evacuation Chaos Kong, Region Failover case-study Multi-Region Architecture Netflix rehearses shifting all traffic out of an entire AWS region, which is what makes the capability real rather than documented.
Object Storage concept Cloud Architecture Flat, HTTP-addressable storage for immutable blobs with rich metadata — effectively unlimited, cheap, and not a filesystem.
Pilot Light pattern Disaster Recovery A disaster recovery posture where core data is continuously replicated and minimal infrastructure runs, with the rest provisioned only on failover.
Pod concept Kubernetes The smallest deployable unit in Kubernetes — one or more containers that share a network namespace, storage volumes and a lifecycle, scheduled together on one node.