@tom_doerr You may also enjoy Powerpipe for hundreds of pre-built benchmarks, visualizations etc that build on Steampipe - https://t.co/gsxZIA5sgk
Or Tailpipe, a CLI-first system to collect and query logs built on DuckDB - https://t.co/dS4mqBwCV5
It's all open source!
Cloud Governance and GRC aren't the same thing.
GRC documents what should happen and proves what did happen. Risk registers, control libraries, audit trails — it's a lagging indicator. The business already made its choices.
Cloud Governance is different. It's not just describing rules — it's deploying them.
Setting guardrails, enforcing policies, nudging teams, blocking risks. It's proactive. It changes the path before the train leaves the station.
The best Cloud Directors aren’t empire-builders. They’re influence operators. Power by presence. Clout through clarity. They earn trust across engineering, security, finance, and the exec team. And they use that trust to make change happen. Quietly, but decisively.
The Head of Cloud isn’t really in charge. They’re not the President. They’re the Chief of Staff. No final say, no official control. But somehow, they’re still responsible for everything running smoothly.
They don’t own the budget. They don’t own the teams. They don’t get to make a decision and slam the table. But they shape the agenda. Build coalitions. Keep the big wheels turning while the chaos swirls. They know where the risk is hiding and who’s pretending it’s not.
You can have the right intentions: secure the cloud, reduce cost, move fast.
But without governance, things drift. Exceptions pile up. Good ideas go rogue.
If you're on the cloud team, you own the bill. You're expected to explain every charge. You're responsible for every $ — because it’s easier.
Until you have a system to track and allocate spend, every cost is yours.
Tags. Accounts. Metadata. Good governance is the only way out.
The best governance ideas don’t fail because they’re flawed.
They fail because they’re abandoned.
Focus on function, not form. Build things that get used.
(Inspired by an early morning walk across the abandoned Memphis monorail bridge.)
LLM results depend on two things:
🧠 How smart the model is
📚 How well you brief it
Model quality? That’s up to OpenAI and friends.
Context? That’s your job.
Want Jedi-level performance?
Be like Luke: bring the force and the facts.
To make security move faster, shift the perspective. Talk about their data, their systems, their risk. The moment it feels personal, it becomes a priority — just like budget.
FinOps changes happen faster than security. Why? Incentives.
Budget is your problem and opportunity.
But, security is everyone’s problem — which often means it's no one's.
Blow the budget? It hits your team, your goals, your bonus. Fix it and you see the win.
Fix a security issue? Best case: nothing happens. Worst case: someone else deals with the fallout.
The toughest Cloud Governance problems aren’t technical - they’re human. Our new book How to Herd Clouds and Influence People follows Gary, a cloud architect navigating chaos, silos & shifting priorities. Feel his pain, and joy, of driving real change 👇
https://t.co/ldd3V3FqPO