The situation
Each of twenty AWS accounts had grown its own Route 53 resolver endpoints and rules, one account at a time, as teams solved the same problem independently. Nobody had set out to build twenty copies of the same thing. It had just happened.
What I did
- Mapped every resolver endpoint and rule across all twenty accounts and traced what was actually resolving what.
- Designed a shared resolver model in a central networking account, with rules shared via Resource Access Manager.
- Migrated accounts over in batches, verifying resolution before decommissioning each redundant endpoint.
The outcome
Roughly $60,000 a year in resolver costs recovered, and a network that is simpler to reason about than it was before. Not every job is a dramatic rebuild. Some of the best ones are this.