Automated Windows AMI Patching & AWS Infrastructure Automation I built an automated AWS pipeline ...Automated Windows AMI Patching & AWS Infrastructure Automation I built an automated AWS pipeline ...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Automated Windows AMI Patching & AWS Infrastructure Automation
I built an automated AWS pipeline to eliminate the manual process of patching Windows servers and updating the AMI used by an Auto Scaling Group.
The solution uses AWS Image Builder, SSM Patch Manager, CloudWatch, EventBridge, Lambda, and CloudFormation to automate the complete patching lifecycle.
Automated Windows patch scanning and installation
Automated Sysprep and patched AMI creation
CloudWatch logging for patching and audit visibility
Automatic Launch Template and ASG updates
Preserved existing production configuration
The infrastructure is deployed through a single CloudFormation template, creating a repeatable and auditable workflow with minimal manual intervention.
My Role: AWS DevOps / Cloud Automation Engineer
Technologies: AWS Image Builder, SSM Patch Manager, EC2, Auto Scaling, Lambda, EventBridge, CloudWatch, CloudFormation, IAM, Windows Server, PowerShell
The question I ask before automating anything: "What does this look like on a Tuesday in month four?"
Not the demo. Not launch day. Month four, when the person who championed it has moved on, the data has drifted, and the model has quietly started doing something slightly different.
The automations that survive month four have three things: a human somewhere in the loop, a log a non-engineer can read, and a kill switch that doesn't need me. The PO intake agent I posted last week is built that way on purpose. It registers and notifies, people decide, and every email in and out is logged.
If yours has all three, you're fine. If it has none, I'd love to hear how it's going. I collect these stories.
What if anyone on your team could ask your data a question and get a live dashboard back in under a minute?
That was the brief. Business users were locked out of their own data. Every question waited on someone who could write SQL, data sat across disconnected systems, and security teams refused to send sensitive records to third-party AI tools.
So we flipped the model. Instead of moving enterprise data to an AI product, we moved the AI analytics product into the customer's AWS account.
What we built:
• Natural-language querying that turns plain-English questions into governed dashboards in under 60 seconds
• Federated queries across SQL and NoSQL sources through Trino
• AI query generation on AWS Bedrock Agents, with Bedrock Guardrails keeping model output in bounds
• Dashboards generated with Apache Superset, plus proactive anomaly and trend alerts
• A white-label React widget that embeds in any product
• Role-based access, row-level security and enterprise SSO enforced at every layer
The result:
Zero data egress. The whole platform deploys inside the customer's VPC and is live on AWS Marketplace.
Building AI features for a data-heavy or regulated product? Let's talk about doing it without your data leaving your cloud.