AWS CLOUD ARCHITECTURE

AWS cloud architecture from an engineer who's actually done it.

BlueLake IT is led by Liam Curran, an AWS-certified Lead Cloud Architect with 9+ years of hands-on AWS experience and 25+ years in enterprise IT — designing secure, cost-efficient cloud environments for financial services, utilities, manufacturing, and public sector clients.

AWS Certified: Solutions Architect · Developer · SysOps Administrator · AI Practitioner
LC
ABOUT

I specialise in designing, implementing, and optimising AWS solutions for enterprise clients — from multi-account security governance to Well-Architected reviews to hands-on delivery with Terraform and CloudFormation. I've delivered AWS cost optimizations exceeding £500k per year for individual clients, and I'm equally comfortable advising at C-level on cloud strategy as I am in the console or the codebase.

More recently, I've been building AI-assisted application development into how I work — using Amazon Kiro's spec-driven, agentic approach to build production tools in Python and Go, including an automated Windows Server fleet upgrade tool and an AWS network diagramming tool that auto-generates HLD/LLD diagrams from live VPC and Transit Gateway topology.

AWS Certified AI Practitioner AWS Solutions Architect — Associate AWS Developer — Associate AWS SysOps Administrator — Associate Microsoft Azure Fundamentals (AZ-900)
WHAT I DO

Practical AWS delivery, not just slide decks

Architecture, cost, security, and code — the same person from design through to delivery.

Cloud Architecture & Migration

HLD/LLD design and delivery aligned to the AWS Well-Architected Framework, including multi-account environments.

Cost Optimization (FinOps)

Rightsizing, Reserved Instances, Savings Plans, and architectural redesign — with a track record of £500k+/year in savings.

Security & Governance

Multi-account governance with IAM, SCPs, Security Hub, AWS Config, and GuardDuty to enforce compliance posture.

Infrastructure as Code & DevOps

Terraform and CloudFormation delivery, container platforms on EKS/ECS, and CodePipeline automation.

AI-Assisted Application Development

Spec-driven, agentic development with Amazon Kiro to build governed, production-ready Python and Go tooling.

Hybrid & Enterprise Identity

Hybrid Active Directory, AWS Directory Service, and Route53 Resolver for seamless on-prem-to-cloud integration.

SELECTED WORK

A sample of past delivery

Drawn from 25+ years across enterprise IT and cloud architecture.

  • Managed
    Services

    £500k+/year AWS cost optimization

    Delivered cost optimizations for enterprise clients through rightsizing, Reserved Instance strategy, and architectural redesign, as named AWS consultant across a multi-million-pound client portfolio.

  • Energy &
    Utilities

    Greenfield IL3-accredited infrastructure

    Designed and delivered government-regulated server infrastructure for a major new-build programme in the energy sector — VMware, Citrix, multi-site PKI, SQL clusters, and secure remote access.

  • Automotive
    Manufacturing

    Secure UK-to-China application platform

    Architected a critical application access platform enabling Chinese market sales for a global automotive manufacturer, publishing UK line-of-business applications securely across borders as part of an international joint venture.

  • Retail &
    E-commerce

    Fully Terraform-managed e-commerce platform

    Built and maintain an AWS e-commerce platform for a cosmetics retailer with end-to-end IaC ownership across VPC, EC2, RDS, ELB, Auto Scaling, and Route53.

INSIGHTS

Tracking AWS's new agentic security tooling

As someone building with Amazon Kiro day to day, I've been following AWS's agentic security tooling closely. Here's a full breakdown of AWS Security Agent — what it does, the problems it solves, and how to roll it out.

Guide · 11 min read

AWS Security Agent: What It Is, What It Solves, and How to Implement It

Design review, threat modeling, code review, and on-demand penetration testing — and a 10-step guide to implementing it.

Designing Transit Gateway for security, not just connectivity

Transit Gateway is easy to stand up but easy to get wrong at the routing layer. Here's a walkthrough of three proven TGW patterns — from simple hub-and-spoke through to fully segmented, inspected traffic flows.

Architecture · 9 min read

AWS Transit Gateway: Three Best-Practice Architecture Patterns

Hub-and-spoke, segmented isolation, and centralized inspection — how to design TGW route tables for connectivity, environment separation, or forced traffic inspection.

GET IN TOUCH

Let's talk about your AWS environment

Whether it's a cost review, a security posture check, or a full migration — happy to have a straightforward conversation about what's actually going on in your account.