Hardened OpenClaw on AWS with Terraform
Replaces curl-pipe-sh defaults with Cognito MFA and proper AWS security patterns.

Lambda reconciliation loop scales NAT to zero, saving costs versus NAT Gateway for sporadic workloads.
DevOps engineers, AWS users with sporadic workloads, cost-conscious infra teams
fck-nat · AWS NAT Gateway · VPC NAT instances
Replaces curl-pipe-sh defaults with Cognito MFA and proper AWS security patterns.
Reverse-engineered CloudShell API to build free global storage with erasure coding and hole-punching.
Terraform-native ISO controls are table stakes; unclear if reports actually satisfy auditors.
Turns docker-compose into real Terraform modules you actually own and can edit.
Cross-cloud spot pricing API saves 80% on ML training where Spotinst charges premiums.
MCP integration with Cursor and Claude Code sets this apart from generic RAG tools.