<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Keenen Wilkins</title>
    <description>The latest articles on DEV Community by Keenen Wilkins (@keenenwilkins).</description>
    <link>https://dev.to/keenenwilkins</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4104968%2Fc66b5714-f6a9-48c9-be9f-3a67425354b7.png</url>
      <title>DEV Community: Keenen Wilkins</title>
      <link>https://dev.to/keenenwilkins</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/keenenwilkins"/>
    <language>en</language>
    <item>
      <title>I Am a Single Point of Failure</title>
      <dc:creator>Keenen Wilkins</dc:creator>
      <pubDate>Mon, 21 Sep 2026 14:32:47 +0000</pubDate>
      <link>https://dev.to/keenenwilkins/i-am-a-single-point-of-failure-950</link>
      <guid>https://dev.to/keenenwilkins/i-am-a-single-point-of-failure-950</guid>
      <description>&lt;p&gt;&lt;strong&gt;If someone can't follow it without you, it's a memory, not documentation.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I heard that on a Monday, in a session about writing standard operating procedures. I wrote it down thinking it was about documentation.&lt;/p&gt;

&lt;p&gt;By Friday it had described two different failures of mine, and the second one had nothing to do with writing anything down.&lt;/p&gt;

&lt;h2&gt;
  
  
  The obvious version
&lt;/h2&gt;

&lt;p&gt;Last week I mapped my default work habit as a flowchart and the left branch looped back on itself. I take the work because I already know how to do it, nobody else learns it, and next week I am still the only one who knows.&lt;/p&gt;

&lt;p&gt;That line is the same loop in one sentence.&lt;/p&gt;

&lt;p&gt;Everything I take on because I already know how to do it lives in my head. It feels like productivity while I am doing it. What it produces is a memory, and a memory leaves the building when I do. The loop was never that I work too hard. The loop is that I keep generating knowledge that has exactly one copy.&lt;/p&gt;

&lt;p&gt;The session's worked example was deliberately stupid: how to log into your laptop, written out to the level of which button is the power button and where it sits on the keyboard.&lt;/p&gt;

&lt;p&gt;My first reaction was that this is over-explained. That reaction is the problem. "Everybody knows that" holds up right until the person who knows it is out sick.&lt;/p&gt;

&lt;h2&gt;
  
  
  The same idea pointed at a team
&lt;/h2&gt;

&lt;p&gt;The other framework this week was &lt;strong&gt;Role, Signal, Handoff&lt;/strong&gt;.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Role.&lt;/strong&gt; What you are specifically responsible for.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Signal.&lt;/strong&gt; How anyone else knows it is done.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Handoff.&lt;/strong&gt; How the next person receives it and confirms they got it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Weak version: "I handle research." "I finished my part."&lt;/p&gt;

&lt;p&gt;Strong version: find three credible sources, put the key points on slide 2 by 1 PM, upload it and tag the person who needs it next.&lt;/p&gt;

&lt;p&gt;The difference is not effort. It is whether the work is visible from outside your own head.&lt;/p&gt;

&lt;p&gt;We have our roles set and our signals defined. Handoff is the part we are still building, which is predictable, because handoff is the only one of the three that requires somebody else to confirm they got it. The first two you can do alone.&lt;/p&gt;

&lt;h2&gt;
  
  
  The same failure at company size
&lt;/h2&gt;

&lt;p&gt;Friday was the i.c.stars iOpener Innovation Conference. The theme was "KC's AI Boom: Billions Invested, What Comes Next?" Banks, engineering firms, law firms, a school district.&lt;/p&gt;

&lt;p&gt;I went in expecting infrastructure and models. Most of what I heard was about documentation.&lt;/p&gt;

&lt;p&gt;Traci Wills, who runs enterprise portfolio management and strategy execution at NAIC, put it plainly: the barrier is not access to AI. The access is there. The barrier is organizational readiness. Companies pilot fine and then cannot scale, because there is no clear problem statement, no trusted data, and governance that exists on paper without changing what anyone actually does on a Tuesday.&lt;/p&gt;

&lt;p&gt;Then Craig Moore II of Endeavor Heartland said the thing that made me put my pen down:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;If you can't do it manually, you're not going to be able to automate it. If you don't have SOPs, if multiple people in your organization cannot speak to the same process the same way, AI is going to be hard for you.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is Monday's session with a budget attached. A company where one person can describe a process is a company running on memory instead of documentation. Same failure as mine. More zeroes.&lt;/p&gt;

&lt;p&gt;Dianna Keen, Managing Director of Technology at VML Enterprise Solutions, gave the version that stuck:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Whatever is true about that system at the time is what you're scaling. If it's bad, you're scaling bad.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Scale is not a fix. Scale is a multiplier on whatever shape is already there.&lt;/p&gt;

&lt;h2&gt;
  
  
  One shape, three sizes
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0z07hllayyg56wggnnkc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0z07hllayyg56wggnnkc.png" alt="The same failure at three scales" width="800" height="486"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;By Friday afternoon I had seen the same diagram three times in five days.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One person.&lt;/strong&gt; I already know how to do it, so it never gets written down, so next week I am still the only one who knows.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A team.&lt;/strong&gt; Roles that sound like "I handle research," so nobody says what done looks like, so the work stalls between people.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;An organization.&lt;/strong&gt; A process only one person can describe, so the pilot works and production never ships.&lt;/p&gt;

&lt;p&gt;Something valuable exists, it has exactly one copy, and the fastest path today guarantees you make the same decision again next week.&lt;/p&gt;

&lt;p&gt;At every one of those scales, the problem is rarely that the knowledge does not exist. It exists and cannot be reached. Somebody absorbs that friction either way. The only question is whether it lands on the one person who knows or the however-many people who have to go ask them.&lt;/p&gt;

&lt;p&gt;The fix is the same at every size and it is boring. Write it down so it survives without you.&lt;/p&gt;

&lt;h2&gt;
  
  
  The fourth size
&lt;/h2&gt;

&lt;p&gt;Here is the one I did not see coming, and it is smaller than all three.&lt;/p&gt;

&lt;p&gt;On Thursday we had a roundtable Q&amp;amp;A with our client. Every team got to ask. I asked one.&lt;/p&gt;

&lt;p&gt;Not a throwaway. I am the solutions analyst on my team and I could not tell where this project was supposed to end. The only people who could answer that were sitting right there, so I asked them.&lt;/p&gt;

&lt;p&gt;That is the exact thing I told you all I would start doing. I did it inside of a week.&lt;/p&gt;

&lt;p&gt;It was also the easiest possible version of it. Clear role, specific gap, question written down in advance. If speaking up were always that structured I would not have a problem.&lt;/p&gt;

&lt;p&gt;Friday was not structured.&lt;/p&gt;

&lt;p&gt;The table exercise: your table gets a symbolic one billion dollars. Allocate all of it to one of six AI priority areas. Then imagine it is 2031 and it worked. Write the headline.&lt;/p&gt;

&lt;p&gt;I contributed. I also choked.&lt;/p&gt;

&lt;p&gt;Both are true and the difference between them is the useful part. I said things at my table. They were not the things I was actually thinking. The gap between what I had in my head and what came out of my mouth was wider than it has been in any session so far, and the only variable that changed was who was sitting there.&lt;/p&gt;

&lt;p&gt;Then I walked away from the table and networked for the rest of the event with none of that friction. Real conversations. People I want to talk to again.&lt;/p&gt;

&lt;p&gt;So I am not quiet. One on one I am fine. What shuts me down is a group of people I have not earned anything with yet, talking about something I have an opinion on.&lt;/p&gt;

&lt;p&gt;Which brings it back around to Monday.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;An opinion I do not say out loud is knowledge with exactly one copy.&lt;/strong&gt; It exists. It is in one head. Nobody else can act on it, build on it, or tell me I am wrong about it. Next week I am in another room with the same thought, having the same internal argument, and nothing about the situation has changed.&lt;/p&gt;

&lt;p&gt;That is not a personality trait. That is the same loop I drew last week, running at the smallest scale there is.&lt;/p&gt;

&lt;p&gt;A memory, not documentation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Looking ahead to week four
&lt;/h2&gt;

&lt;p&gt;Finish the handoff half of Role, Signal, Handoff, which means actually confirming receipt instead of assuming the work landed.&lt;/p&gt;

&lt;p&gt;And find the smaller version of Friday. Not a keynote. A room of eight or ten people where I have an opinion and no assigned role that requires me to speak. That is the rep I am missing, and asking a prepared question at a structured Q&amp;amp;A does not count as having done it.&lt;/p&gt;

&lt;p&gt;What is the thing you know how to do that nobody else on your team could run without you?&lt;/p&gt;

&lt;p&gt;That is not a skill. That is a single point of failure with your name on it.&lt;/p&gt;

&lt;p&gt;Week four goes up Friday.&lt;/p&gt;

</description>
      <category>career</category>
      <category>beginners</category>
      <category>devjournal</category>
      <category>discuss</category>
    </item>
    <item>
      <title>I Drew My Worst Work Habit as a Flowchart. It Was a Loop.</title>
      <dc:creator>Keenen Wilkins</dc:creator>
      <pubDate>Sun, 13 Sep 2026 18:20:08 +0000</pubDate>
      <link>https://dev.to/keenenwilkins/week-two-i-take-over-the-work-and-i-hold-back-my-voice-1598</link>
      <guid>https://dev.to/keenenwilkins/week-two-i-take-over-the-work-and-i-hold-back-my-voice-1598</guid>
      <description>&lt;p&gt;Last week I wrote that when a project gets hard and progress feels slow, I take on more work instead of asking for help. I put that in public on a Friday.&lt;/p&gt;

&lt;p&gt;By Tuesday the structure of my week was handing me every reason to do it again. By Friday I was sitting in a one on one hearing about a second problem I did not know I had.&lt;/p&gt;

&lt;h2&gt;
  
  
  The math
&lt;/h2&gt;

&lt;p&gt;Project teams here are built for four or five people. Mine has three.&lt;/p&gt;

&lt;p&gt;When a team is short a person, that work does not evenly redistribute. It falls on whoever knows the most about the thing in front of you. On our project right now, for a few pieces, that is me.&lt;/p&gt;

&lt;p&gt;So the path of least resistance was obvious. Absorb the extra, move faster in the short term, look productive. It is the exact behavior I had just finished admitting was a weakness, and the situation was practically arguing for it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I tried
&lt;/h2&gt;

&lt;p&gt;Load balancing. Deliberately letting my teammates learn the work instead of handling it myself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I told them what I needed.&lt;/strong&gt; Not vaguely. I said what support actually looks like for me and why it would help us hit the deliverable. That is harder than it sounds when your instinct is to go do the thing quietly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I stopped handing over answers.&lt;/strong&gt; When we got to the core concept behind our solution, I had a head start on it. The old version of me writes it up and presents it finished. Instead I asked them to go learn the base concept so we could build on it together.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;We wrote down how we work.&lt;/strong&gt; A session on trust and team agreements turned what I had been doing informally into something structural. Last week I wrote about trust as an equation. This was the operational version. On a three person team those agreements are not bureaucracy. They are how we hold each other accountable so all three of us grow, and how we cover a role we do not have a person for.&lt;/p&gt;

&lt;p&gt;Something did change. They are actively understanding the solution instead of receiving it. When we talk about it now, it is a conversation rather than a briefing.&lt;/p&gt;

&lt;h2&gt;
  
  
  My week as a flowchart
&lt;/h2&gt;

&lt;p&gt;We covered flowcharts, swimlanes, and UML this week. Mapping a process, showing who owns what, making the handoffs visible.&lt;/p&gt;

&lt;p&gt;The whole time I kept thinking that if I diagrammed my own default behavior, it would not look like a line. It would look like a loop.&lt;br&gt;
&lt;/p&gt;

&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart TD
    A["Work lands on the team"] --&amp;gt; B{"Am I the one&amp;lt;br/&amp;gt;who knows it best?"}

    B --&amp;gt;|"take it"| C["I do it myself.&amp;lt;br/&amp;gt;Fastest path today."]
    C --&amp;gt; D["Nobody else learns it"]
    D --&amp;gt; E["Next time I am still&amp;lt;br/&amp;gt;the only one who knows"]
    E --&amp;gt; A

    B --&amp;gt;|"balance it"| P["Say out loud&amp;lt;br/&amp;gt;what I need"]
    P --&amp;gt; G["Hand over the concept,&amp;lt;br/&amp;gt;not the answer"]
    G --&amp;gt; H["They learn it with me"]
    H --&amp;gt; I["Next time three people&amp;lt;br/&amp;gt;can carry it"]&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;The left path loops back to where it started. That is the part I had not seen before I drew it. Taking the work myself is not a one time cost I pay to move faster today. It is a cycle that guarantees I face the same decision again next week, with the same answer waiting, because nothing about the situation changed.&lt;/p&gt;

&lt;p&gt;The right path ends.&lt;/p&gt;

&lt;h2&gt;
  
  
  Then I had my one on one
&lt;/h2&gt;

&lt;p&gt;I went in with my own report ready. Here is the thing I wrote about last week, here is what I have been doing about it, here is where I think I stand. On the development rubric I put myself at proficient with room to grow on emotional intelligence and self-awareness. Patience, and meeting my teammates where they are instead of jumping in with &lt;em&gt;I will just do it&lt;/em&gt;, went on my own list as the thing I am actively working on.&lt;/p&gt;

&lt;p&gt;I was prepared to talk about all of that.&lt;/p&gt;

&lt;p&gt;My program director wanted to talk about something I had not put on the list.&lt;/p&gt;

&lt;h2&gt;
  
  
  The thing I did not bring up
&lt;/h2&gt;

&lt;p&gt;The growth area she flagged was not the work. It was my voice.&lt;/p&gt;

&lt;p&gt;Observant, thoughtful, and tends to hold back. Other people in the room would benefit from hearing more from me, and they are not, because I do not say it.&lt;/p&gt;

&lt;p&gt;I sat with that one, because at first it sounds like the opposite of the problem I walked in ready to discuss. How can I be the guy who takes over everything and also the guy who does not speak up?&lt;/p&gt;

&lt;p&gt;They are the same thing.&lt;/p&gt;

&lt;p&gt;Doing the work quietly and staying quiet in the room are both ways of skipping the exposed part. If I take the task, I never have to say I think we are heading the wrong direction. If I sit on a thought in a session, I never have to find out whether anyone disagrees with it. Both look like humility from the outside. Both are me picking the version of the situation where I cannot be wrong out loud.&lt;/p&gt;

&lt;p&gt;Taking over is not confidence. It is the quiet option that happens to produce output.&lt;/p&gt;




&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Seek first to understand, then to be understood.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Stephen Covey, &lt;em&gt;The 7 Habits of Highly Effective People&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;I had heard that line before. It landed differently this week, and not on the half I expected.&lt;/p&gt;

&lt;p&gt;I have been working on the first half all week. Understand first, do not arrive with the answer already formed, let people get there with you.&lt;/p&gt;

&lt;p&gt;The second half is the one I keep skipping. Being understood requires actually saying the thing.&lt;/p&gt;

&lt;h2&gt;
  
  
  The tea
&lt;/h2&gt;

&lt;p&gt;High Tea started this week, which means the job I described last week as something I did not understand yet is now something I have actually done.&lt;/p&gt;

&lt;p&gt;It turned out to be less about the guest than I expected.&lt;/p&gt;

&lt;p&gt;It is a roundtable. Everybody sits at one table, and you introduce the person next to you and pour their tea. Literally pour it, into their cup. The host opens with the guest, it moves around the table, and the last seat comes back around to introduce the host.&lt;/p&gt;

&lt;p&gt;Which means you cannot phone in your introduction. To introduce somebody you have to have asked them something first. The format quietly requires you to go learn a little about the person sitting beside you before you ever sit down.&lt;/p&gt;

&lt;p&gt;We sign up and work out as a team who sits where. I keep the document that holds all of it, which this week meant building in a spot for the guest of the day and a sign-up for who helps set up.&lt;/p&gt;

&lt;p&gt;Here is the part I did not expect. &lt;strong&gt;A format where every single person is handed a turn to talk still does not guarantee everybody gets heard.&lt;/strong&gt; Making sure each person gets a fair shot, or lands a real question during the session, is an open problem we are still working on.&lt;/p&gt;

&lt;p&gt;So I got told Friday morning that I hold back my voice, and then spent Friday afternoon inside a structure purpose built to give everyone one, watching it not entirely solve the problem either.&lt;/p&gt;

&lt;p&gt;If a format designed specifically for this still has to be worked at, my own quiet is not going to fix itself by accident.&lt;/p&gt;

&lt;p&gt;Nobody asked for the recap one sheeter. I started making them after a session because of what I want them to be good for later. My hope is that six weeks from now somebody in my cycle hits a situation, remembers a guest who talked about exactly that, and can pull up the profile I built instead of trying to remember a conversation from a Thursday in September.&lt;/p&gt;

&lt;p&gt;My program director read it as something that could become a running record people come back to, for reference or for motivation. That is close enough to what I was going for that I am going to keep making them.&lt;/p&gt;

&lt;p&gt;The hard part is not the writing. It is staying present. I have to catch everything with weight to it while also actually being in the room getting something out of it myself. Those two modes fight each other.&lt;/p&gt;

&lt;p&gt;Thursday guest was &lt;strong&gt;Dominic Barrett&lt;/strong&gt;, a Cycle 5 graduate who works as a photographer and a software engineer.&lt;/p&gt;

&lt;p&gt;Friday was &lt;strong&gt;Shanda McConnell&lt;/strong&gt;, who runs corporate relations here. Twenty-one years at one firm, then fourteen months of getting to this one. She organizes what she says yes to around an acronym she has been carrying for about a decade: BEE. Build, equip, empower. If something does not fit, she has learned to decline it, even for a season.&lt;/p&gt;

&lt;p&gt;The line I wrote down came out of a stretch when she was working sixty and seventy hour weeks and could not physically be everywhere she needed to be. She had to start asking her community for help, and she was honest that it was hard at the time.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Asking for help is a sign of wisdom, not weakness.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I have spent two weeks now writing publicly about a pattern where I take on more work instead of asking for help. On Friday morning I got told I also do not speak up enough. On Friday afternoon a guest sat down and said that.&lt;/p&gt;

&lt;p&gt;I did not go looking for it. I just happened to be the one taking notes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Looking ahead to week three
&lt;/h2&gt;

&lt;p&gt;Two things to carry forward, and only one of them is new.&lt;/p&gt;

&lt;p&gt;Keep load balancing, and find out whether it holds when a deadline gets close and the fastest path is to take the work back. Look at the flowchart again. The left branch is not there because I am careless. It is there because it works, right up until it does not.&lt;/p&gt;

&lt;p&gt;And start talking. Not more words, just the ones I am currently swallowing. If I have a read on something in a session, say it in the session.&lt;/p&gt;

&lt;p&gt;I do not know how either goes. I will report back.&lt;/p&gt;

&lt;p&gt;If someone told you that you both take over too much and speak up too little, would you have seen those as the same problem? I did not, until this week.&lt;/p&gt;

&lt;p&gt;Week three goes up next Friday.&lt;/p&gt;

</description>
      <category>career</category>
      <category>beginners</category>
      <category>devjournal</category>
      <category>discuss</category>
    </item>
    <item>
      <title>I Put a Database on the Public Internet. My Flow Logs Knew Before I Did.</title>
      <dc:creator>Keenen Wilkins</dc:creator>
      <pubDate>Tue, 08 Sep 2026 17:41:37 +0000</pubDate>
      <link>https://dev.to/keenenwilkins/i-put-a-database-on-the-public-internet-my-flow-logs-knew-before-i-did-510k</link>
      <guid>https://dev.to/keenenwilkins/i-put-a-database-on-the-public-internet-my-flow-logs-knew-before-i-did-510k</guid>
      <description>&lt;p&gt;I built a lab in AWS to watch an attack happen. Terraform provisioned a VPC, I put a PostgreSQL database on the public internet on purpose, pointed a script at it, and piped VPC Flow Logs into Splunk so my partner could watch from the SOC side.&lt;/p&gt;

&lt;p&gt;Then I wrote an incident report describing a single external threat actor conducting a systematic port scan.&lt;/p&gt;

&lt;p&gt;Months later I went back and read my own flow logs line by line. There were twenty-eight source addresses in the sample. I had written about one of them, and it was the wrong one.&lt;/p&gt;

&lt;h2&gt;
  
  
  The setup
&lt;/h2&gt;

&lt;p&gt;One VPC at &lt;code&gt;10.0.0.0/16&lt;/code&gt;, two subnets across two availability zones, both public. An RDS PostgreSQL instance with the line that makes security people wince:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight hcl"&gt;&lt;code&gt;&lt;span class="nx"&gt;publicly_accessible&lt;/span&gt; &lt;span class="err"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;and a security group allowing &lt;code&gt;0.0.0.0/0&lt;/code&gt; inbound on 5432, 22, and 80. Deliberately wrong, in the specific way production gets it wrong.&lt;/p&gt;

&lt;p&gt;Flow logs to S3, S3 into Splunk. A Node script ran a dictionary attack against &lt;code&gt;db_admin&lt;/code&gt; on 5432, knocked on 22 and 80, and mixed in successful logins with the real password so the SOC side had to separate authorized traffic from attacks. Three different jitter ranges so none of it looked like a metronome.&lt;/p&gt;

&lt;h2&gt;
  
  
  What was actually in the logs
&lt;/h2&gt;

&lt;p&gt;A 1,000-line sample from that capture:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;th&gt;Lines&lt;/th&gt;
&lt;th&gt;What it was&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;10.0.1.149&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;445&lt;/td&gt;
&lt;td&gt;My own traffic, inside the VPC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;194.87.190.127&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;245&lt;/td&gt;
&lt;td&gt;The simulated bot&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;136.35.186.87&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;183&lt;/td&gt;
&lt;td&gt;A real internet actor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;25 other addresses&lt;/td&gt;
&lt;td&gt;1 to 3 each&lt;/td&gt;
&lt;td&gt;Internet background radiation&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;876 ACCEPT, 124 REJECT.&lt;/p&gt;

&lt;p&gt;The three noisy sources are the ones I designed. &lt;strong&gt;The twenty-five quiet ones are the story&lt;/strong&gt;, and I never looked at them.&lt;/p&gt;

&lt;h2&gt;
  
  
  The quiet ones were not mine
&lt;/h2&gt;

&lt;p&gt;Here are destination ports that appear in the REJECT lines:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;6379   Redis
5902, 5931, 5937, 5959   VNC
10250, 10255   Kubernetes kubelet
137   NetBIOS
8008, 8022, 8081, 8088, 8090, 8103, 8389   assorted alt-HTTP
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Nothing in my lab ran Redis. Nothing ran VNC. There was no Kubernetes cluster and no NetBIOS. My script targeted exactly three ports.&lt;/p&gt;

&lt;p&gt;Twenty-nine distinct ports show up in the rejections. That is not one attacker sweeping a host. That is the internet's ambient scanning layer finding a fresh public IP and checking whether anything soft is listening. The source addresses back it up: several sequential hosts in one cloud range, a scattering of others across hosting providers known for this.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Every one of those lines arrived because I set one boolean to &lt;code&gt;true&lt;/code&gt;.&lt;/strong&gt; Not one of them appears in the incident report I wrote.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I put in the ticket instead
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Threat Actor IP Address:&lt;/strong&gt; 10.0.1.179&lt;br&gt;
... an external threat actor is systematically scanning for open database and secure shell ports.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;code&gt;10.0.1.179&lt;/code&gt; sits inside &lt;code&gt;10.0.1.0/24&lt;/code&gt;, one of the two subnets I had defined twelve lines earlier in my own Terraform. RFC 1918 reserves &lt;code&gt;10.0.0.0/8&lt;/code&gt;, &lt;code&gt;172.16.0.0/12&lt;/code&gt;, and &lt;code&gt;192.168.0.0/16&lt;/code&gt; for private use, and none of it routes on the public internet. If a private address is in your &lt;code&gt;srcaddr&lt;/code&gt; field, whatever produced it was already inside your network.&lt;/p&gt;

&lt;p&gt;I had a genuine external actor in the same dataset, &lt;code&gt;136.35.186.87&lt;/code&gt;, doing a real multi-port scan. I escalated the wrong IP and labeled my own traffic as the threat.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three things flow logs will not tell you
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Not who authenticated.&lt;/strong&gt; A flow log record carries source and destination address, ports, protocol, packet and byte counts, timestamps, and ACCEPT or REJECT. No payload, no usernames, no auth result. My script really was throwing bad passwords, and my analyst notes really did say credential stuffing, but the flow logs were never the evidence for that. A backup job with a broken retry loop looks identical at that layer. Authentication failures live in the RDS PostgreSQL error log, which is an entirely separate pipeline.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Not what a big number means.&lt;/strong&gt; My ticket led with 15,025 blocked events because it was the largest number on the dashboard. I never worked out which rows produced it. Looking at the sample now, rejections are spread across twenty-nine ports, most of which nothing in my lab ever touched, so that headline figure was mostly counting strangers rather than my simulation. I could have known that in five minutes by grouping by port. Instead I put it in a SEV-1 and moved on, and by the time I thought to check, the account was closed and the data was gone.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Not intent.&lt;/strong&gt; ACCEPT means the packet passed your security group. It does not mean something answered, and REJECT does not mean you blocked an attack. Both are network-layer facts about your own configuration, not judgments about the traffic.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part that held up
&lt;/h2&gt;

&lt;p&gt;One line:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight hcl"&gt;&lt;code&gt;&lt;span class="nx"&gt;publicly_accessible&lt;/span&gt; &lt;span class="err"&gt;=&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;terraform apply&lt;/code&gt;, then re-run the simulator:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;$ node attack_sim.js
[+] Initiating connection to database...
[-] Error: Connection Timeout. Network unreachable.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Worth being precise about what that flag does, because I got this wrong too. It stops RDS from handing out a publicly resolvable endpoint. It does &lt;strong&gt;not&lt;/strong&gt; move the instance to a different subnet, and my DB subnet group still contained the same two public subnets it always had. My report claimed the database was migrated into a private subnet. The code does no such thing.&lt;/p&gt;

&lt;p&gt;The narrower claim is the true one, and it is still worth something: the database is no longer reachable from outside the VPC, the change is version controlled, and anyone can clone the repo and reproduce the before and after.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I would tell someone building this
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Read the long tail.&lt;/strong&gt; I spent all my attention on the three sources generating volume, because volume is what dashboards are built to show. The twenty-five sources with one line each were the only unplanned thing in the entire dataset, and they were the answer to the question the lab was supposed to ask.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Check whether your attacker is actually external.&lt;/strong&gt; Look at &lt;code&gt;srcaddr&lt;/code&gt;, compare it to your own CIDR blocks. It takes ten seconds and it is embarrassing in a very specific way to skip.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Work out what a number counts before you escalate it.&lt;/strong&gt; If you cannot say which rows produced a figure, it does not belong in a ticket.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Know what each log source can prove.&lt;/strong&gt; Flow logs answer who talked to what, on which port, and whether the packet landed. They cannot answer whether someone tried to log in. Different question, different log, different pipeline.&lt;/p&gt;

&lt;p&gt;The lab was supposed to demonstrate that exposing a database to the internet gets you found. It did that on day one, in writing, in my own S3 bucket. I just described the wrong attacker.&lt;/p&gt;

&lt;p&gt;Terraform, the attack script, and the flow log sample are all here if you want to check my work: &lt;a href="https://github.com/cruisethecity/aws-incident-response-honeypot" rel="noopener noreferrer"&gt;aws-incident-response-honeypot&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Detection and dashboards by &lt;a href="https://github.com/KennySBarr" rel="noopener noreferrer"&gt;Kenny Barr&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;If you have run something like this, what was in your long tail?&lt;/p&gt;

</description>
      <category>aws</category>
      <category>terraform</category>
      <category>security</category>
      <category>devops</category>
    </item>
    <item>
      <title>The Tea on Teamwork: Week One of My i.c.stars Tech Internship</title>
      <dc:creator>Keenen Wilkins</dc:creator>
      <pubDate>Sat, 05 Sep 2026 19:13:10 +0000</pubDate>
      <link>https://dev.to/keenenwilkins/the-tea-on-teamwork-week-one-of-my-icstars-tech-internship-k3o</link>
      <guid>https://dev.to/keenenwilkins/the-tea-on-teamwork-week-one-of-my-icstars-tech-internship-k3o</guid>
      <description>&lt;p&gt;I went into my first week at &lt;a href="https://www.icstars.org/" rel="noopener noreferrer"&gt;i.c.stars&lt;/a&gt; thinking about technology, code, and systems. The week turned out to be about the human layer instead, and the most useful thing I learned was about myself: when a project gets hard and progress feels slow, I take on more work instead of asking for help.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbn5o5pgurelr8li96mza.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbn5o5pgurelr8li96mza.png" width="800" alt="A letterboard sign reading Welcome Cycle 7 Interns, Excited You're Here" height="1055"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;While Team Week was very involved and we spent a lot of time learning about our team dynamic and reflecting on it, I feel like I genuinely got to know my teammates and their approaches to teamwork and collaboration. I realized going into the program that I am a very collaborative person and tend to value my interpersonal relationships more than the task at hand.&lt;/p&gt;

&lt;p&gt;Still, some of the self-assessment tools we used really highlighted that blind spot. In many situations taking on more work is a positive attribute. In a team setup it is a major weakness.&lt;/p&gt;

&lt;h2&gt;
  
  
  Rethinking True Collaboration
&lt;/h2&gt;

&lt;p&gt;We ran through a few workshops during the week that really spoke to me on this topic. One of them was a consulting agency case study. My partner drew a scenario where he was the more experienced colleague doing all the work, because his coworker was resistant to change. The natural impulse there is to take over and do the work for the person who is not prepared.&lt;/p&gt;

&lt;p&gt;But in reality, collaboration means setting the expectations, making a plan, and providing the tools for the teammate to bring themselves up to speed.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Mathematics of Trust
&lt;/h2&gt;

&lt;p&gt;We also had a discussion about trust that came with actual math. Trust is a broad concept, but it comes down to four things. Your credibility, your reliability, and your intimacy, which is the willingness to make other people feel safe with you. Those three stack on top. Underneath all of them sits self-orientation, which is how much of this is really about you.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fd8sntd0rbimu0g6xuont.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fd8sntd0rbimu0g6xuont.png" alt="Trustworthiness equals credibility plus reliability plus intimacy, divided by self-orientation" width="800" height="138"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The single best piece of advice I got that week was that everything above the line is irrelevant if what is below it is not genuine.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;In other words, if your primary goal is to get things done by any means necessary, it will come across, and no amount of effort will convince people otherwise that you are trustworthy.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Tackling the Unknowns
&lt;/h2&gt;

&lt;p&gt;We also spent about twenty minutes on the fundamentals of technology transformation: cybersecurity, data analytics, and AI. Twenty minutes is nowhere near enough to learn any of that, which was the point. The workshop was not about the tech. It was about how you handle information you do not have yet.&lt;/p&gt;

&lt;p&gt;When trying to absorb a lot of information about a particular topic, it is easy to get overwhelmed and attempt to consume everything at once. Still, realistically, it is better to focus on the knowns and the unknowns, then tackle the unknowns one at a time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Looking Ahead to Week Two
&lt;/h2&gt;

&lt;p&gt;I also picked up a role this week: tea documentarian. That needs some context if you have not been through this program. High Tea is a daily afternoon session where a business or technology executive sits down with the cohort. They walk through how they actually got where they are, what they are wrestling with right now, and a book that shaped them, and then the floor opens for questions. It is the part of the program that puts nontraditional candidates in a room with people whose calendars are usually closed to us.&lt;/p&gt;

&lt;p&gt;My job is to track who comes through and what each visit does for the cycle. We have not had one yet, so I am writing this before I know what I am in for. It is going to test the exact thing I just admitted is my weak spot, because documenting it well means paying attention to everyone else in the room instead of quietly grinding on my own work.&lt;/p&gt;

&lt;p&gt;The first week has been exciting and busy, and it has already given me more to think about on the human layer of this program than I expected. I am really looking forward to seeing what else week two has in store.&lt;/p&gt;

&lt;p&gt;If you have been the teammate who quietly takes on more work instead of asking for help, what actually got you to stop? I am asking selfishly.&lt;/p&gt;

&lt;p&gt;Week two goes up next Friday.&lt;/p&gt;

</description>
      <category>career</category>
      <category>beginners</category>
      <category>devjournal</category>
      <category>discuss</category>
    </item>
  </channel>
</rss>
