Log inSign up
Log inSign up
Ismail Abdelkrim
14 posts
Ismail Abdelkrim profile banner
@ismailabdlkrim

Ismail Abdelkrim

@ismailabdlkrim
Cloud Engineering & Systems Design. Bridging the gap between theory and implementation. Commitment to architectural excellence.
Morocco
linktr.ee/ismail_abdelkr…
Joined May 2022
44 Following
1 Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @ismailabdlkrim
    Ismail Abdelkrim
    @ismailabdlkrim
    Dec 25, 2025
    Hi, I’m starting my preparation for the AWS Solutions Architect Associate. ​Coming from a Linux background, I want to see how those fundamentals translate to cloud infrastructure. ​I will be posting my technical notes, diagrams, and labs here to keep track of my progress.
  • @ismailabdlkrim
    Ismail Abdelkrim
    @ismailabdlkrim
    Feb 27
    If you open an inbound port in a NACL and forget the outbound return path, your traffic is going nowhere. Security Groups remember the "state" of a connection; NACLs don't care. ​Don't confuse "instance-level" filtering with "subnet-level" routing. Know your flow.
  • @ismailabdlkrim
    Ismail Abdelkrim
    @ismailabdlkrim
    Feb 4
    The first rule of AWS: Delete your Root access keys. ​Using Root for daily tasks isn't "convenient"; it’s a single point of failure for your entire business. Create an IAM Admin user, enable MFA on Root, and forget the password exists. Identity is the new perimeter.
  • @ismailabdlkrim
    Ismail Abdelkrim
    @ismailabdlkrim
    Jan 29
    DNS is eventual consistency. ​If you migrate without lowering TTLs to 60s first, you aren't doing a cutover; you are gambling with traffic. You cannot force the internet to clear its cache. Plan your TTL strategy before touching the records.
  • @ismailabdlkrim
    Ismail Abdelkrim
    @ismailabdlkrim
    Jan 10
    HTTP is plaintext. If your application serves traffic on Port 80, you aren't just hosting data; you are broadcasting it to the network. TLS certificates are free and automated now. There is absolutely no architectural excuse for unencrypted traffic. Port 80 is a vulnerability.