Hacker News new | ask | show | jobs
by mtippett 1818 days ago
+1 on the private subnet.

You want to design your system so that if a network a critical misconfiguration occurs you don't open yourself up - you simply stop working.

(Too many years chasing EMR clusters getting dropped onto the internet by users with AWS console access).