<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>ShahriarLabs Simulators</title><link>https://sim.shahriarlabs.com/</link><description>Free problem guides and interactive comparisons</description><item><title>EC2 SSH connection timed out: trace the broken hop</title><link>https://sim.shahriarlabs.com/guides/ec2-ssh-connection-timed-out/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/guides/ec2-ssh-connection-timed-out/</guid><description>A timeout means the connection did not complete. Check the instance, public address, subnet route, security group and both NACL directions before changing credentials.</description></item><item><title>Private subnet has no internet: check the NAT path</title><link>https://sim.shahriarlabs.com/guides/private-subnet-no-internet/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/guides/private-subnet-no-internet/</guid><description>A private instance needs a usable outbound path. For public NAT, verify the private route to NAT, NAT state and VPC, its public subnet route to an attached internet gateway, and both subnet ACLs.</description></item><item><title>S3 AccessDenied: identify the permission boundary</title><link>https://sim.shahriarlabs.com/guides/s3-access-denied/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/guides/s3-access-denied/</guid><description>A 403 is an access decision, not proof that the object is missing. Identify the caller, action and resource; then check matching allows, explicit denies and the applicable public-access or encryption controls.</description></item><item><title>IAM explicit deny: why another allow cannot fix it</title><link>https://sim.shahriarlabs.com/guides/iam-explicit-deny/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/guides/iam-explicit-deny/</guid><description>A matching explicit deny overrides an allow. First identify which statement applies to the exact action, resource and principal; adding a broader allow cannot cancel that deny.</description></item><item><title>SQS backlog keeps growing: compare arrival and drain rates</title><link>https://sim.shahriarlabs.com/guides/sqs-backlog-keeps-growing/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/guides/sqs-backlog-keeps-growing/</guid><description>A queue grows when incoming work exceeds completed work over time. Separate arrival rate, worker capacity and retries before increasing concurrency or changing visibility timeout.</description></item><item><title>Retry storms: when recovery logic multiplies the outage</title><link>https://sim.shahriarlabs.com/guides/retry-storm/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/guides/retry-storm/</guid><description>Retries consume capacity too. Bound attempts, use backoff and jitter, and make side effects idempotent so failure recovery does not amplify load or duplicate work.</description></item><item><title>Security groups vs NACLs: follow the request and reply</title><link>https://sim.shahriarlabs.com/compare/security-groups-vs-nacls/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/compare/security-groups-vs-nacls/</guid><description>Security groups apply to associated resources and are stateful. NACLs filter subnet-boundary traffic, support allow and deny rules, and require separate permission for return traffic.</description></item><item><title>NAT gateway vs internet gateway: two different paths</title><link>https://sim.shahriarlabs.com/compare/nat-gateway-vs-internet-gateway/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/compare/nat-gateway-vs-internet-gateway/</guid><description>An internet gateway provides a VPC internet path for appropriately addressed resources. Public NAT lets private IPv4 resources initiate internet connections through a translated public address.</description></item><item><title>IAM users vs roles: choose credentials for the workload</title><link>https://sim.shahriarlabs.com/compare/iam-users-vs-roles/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/compare/iam-users-vs-roles/</guid><description>IAM users identify account identities that can have long-lived credentials. Roles are assumed to obtain temporary credentials. Prefer suitable federation for people and roles for workloads.</description></item><item><title>SQS vs SNS vs EventBridge: queue, publish or route?</title><link>https://sim.shahriarlabs.com/compare/sqs-vs-sns-vs-eventbridge/</link><guid isPermaLink="true">https://sim.shahriarlabs.com/compare/sqs-vs-sns-vs-eventbridge/</guid><description>Use SQS to buffer work for consumers, SNS to publish to subscribers, and EventBridge to route events using rules. They can be combined when a system needs both routing and durable buffering.</description></item></channel></rss>
