Skip to main content

GitHub Access Control at Scale: Why IaC Beats Entra Groups and Manual Grants

· 17 min read
Abdulmalik
AppSec Engineer

A Reddit thread on r/devops stuck with me: someone at a 600-developer org with 2,000 repositories, Okta pushing users via SCIM, was redesigning RBAC and asking whether GitHub teams could realistically be managed with IaC. The replies split fast: Entra groups, access-request tickets, safe-settings, Terraform, and one blunt take: "Don't. Unless you have a full team of Terraform experts."

Reddit r/devops thread: IaC for GitHub teams - Need advice

AWS Cloud Costs Nightmare, Cutting It To Elongate That Startup Runway

· 6 min read
Abdulmalik
AppSec Engineer

Cloud costs at early stage startups rarely spiral because of recklessness.

They spiral because the team was moving fast, the architecture made sense at the time, and nobody had the bandwidth to revisit it.

By the time the bill becomes a problem, the decisions are already baked in.

I have been on both sides of this, burning through it personally, and leading teams trying to unwind it before the runway ran out. Here is what has actually worked.