Posts

AWS: Custom Config Rule

Image
-- Explain Custom config with an example? -- Custom config rules in AWS Config allow you to define your own rules to evaluate the configuration settings of your AWS resources. These rules help ensure that your resources are compliant with your organization's requirements and best practices. A custom config rule is created using AWS Lambda functions that evaluate the resource configurations and return a compliance status. {   "ConfigRuleName": "Sumodh c Sabu",   "Description": "Checks if S3 buckets have server-side encryption enabled.",   "InputParameters": {},   "Scope": {     "ComplianceResourceTypes": [       "AWS::S3::Bucket"     ]   },   "Source": {     "Owner": "CUSTOM_LAMBDA",     "SourceIdentifier": <<arn name>>   } } -- In this example , the custom config rule is named "Sumodh c Sabu" and its purpose is to verify if S3 buckets have se...

AWS: Automatic Remediation

Image
What is Automatic Remediation in AWS? -- Auto-remediation in AWS refers to the process of automatically fixing problems that occur within an environment, without the need for human intervention. Auto-remediation can help reduce downtime and ensure that critical systems and applications are always available. In AWS, we can use services like AWS CloudWatch and AWS Lambda to set up auto-remediation processes that can detect and fix issues in real-time, enabling you to maintain optimal performance and availability for our critical workloads. -- Amazon CloudWatch is a monitoring service provided by Amazon Web Services (AWS) that enables us to monitor our AWS resources, applications, and services in real-time. CloudWatch provides metrics, logs, and alarms to monitor and troubleshoot your AWS environment. We can use CloudWatch to collect and track metrics, collect and monitor log files, and set alarms. -- With CloudWatch, we can monitor and visualize metrics such as CPU usage, network traffic...

AWS: Lambda function & Boto3

Image
What is AWS Lambda? -- AWS Lambda is a serverless computing service that allows developers to run code without having to worry about server management. With AWS Lambda, developers can build and deploy applications quickly and easily, while only paying for the compute time that they use. We can say while exploring AWS Lambda functions it also provides an example of how to create a Python-based Lambda function also. Functionalities of AWS Lambda -- Lambda functions are small pieces of code that can be triggered by events such as changes in data or user activity. The functions are stored in the cloud and run on demand, which means that developers don't have to worry about provisioning or managing servers. AWS Lambda supports several programming languages, including Python, Java etc. Case study : To get description  of an EC2 instance ( example Configuration ) -- Here's an example Python AWS Lambda function that retrieves the description of an EC2 instance using the Boto3 library: ...

AWS: Config Rule & Compliance Check

Image
What is Config Rule? -- A config rule, also known as an AWS Config rule, is a customizable, automated process that evaluates the configuration of resources within an Amazon Web Services (AWS) account. The rule checks whether the resources conform to the desired configuration, and reports back on any discrepancies. Config rules can be used to ensure compliance with industry standards, security best practices, and company policies. -- To create a config rule, the user defines a set of conditions or constraints that must be met for the resource to be considered compliant. These conditions are specified using AWS Lambda functions, which can be written in Python. -- The Lambda function is triggered by the AWS Config service, which calls the function whenever a new resource is created, modified, or deleted. The function then performs the necessary checks, and returns a response indicating whether the resource is compliant or not. What are the functionality of the Config Rule? -- Config rules...

AWS: Security groups boto3 Reference

Image
-- A security bunch controls the traffic that is permitted to reach and leave the assets it is related with. For instance, after a security bunch with an EC2 occurrence, it controls inbound and outbound traffic for that case. We can relate a security bunch just with the assets in the VPC for which it was made. -- At the point when we make a VPC, it accompanies a default security bunch. We can make extra security bunches for each VPC. -- There is no extra charge for utilizing security gatherings. -- The accompanying outline a VPC with subnets in two Accessibility Zones, a Web Passage, and an Application Burden Balancer. Every accessibility zone has a public subnet for web servers and a private subnet for data set servers. There are isolated security bunches for the heap balancer, web servers, and information base servers. We can add rules to the heap balancer security gathering to permit HTTP and HTTPS traffic from the Web. We can add rules to a security bunch for web servers to permit ...

AWS: Resource Identification

Image
Tags are used in every AWS resource we use it for the proper identification. To identify the resources which are only used in some particular environment for that we use environment tag. These tags can give us the information about the resource for example whether it is in production environment or test environment. We can identify that by environment tags. Boto3 is a module which is used for the API references of the AWS services. We can implement it using python as it is a faster and less complex way to handle but this module is also available across programmatic languages. There are two or three ways we implement Boto3.  By client, resources or paginator. We can use used clients but to take individual resources we can use the Boto3 resource object.  We can find boto3 documentation in this link. Link - https://boto3.amazonaws.com/v1/documentation/api/latest/index.html Let's take an example of boto3 scripting. Case: to print the EC2 instance present in roles accounts–...

AWS: Boto3 & Documentions

Image
There are more than 200 services provided by AWS and they have very user friendly interface. Due to this reason the outreach of these technologies were increasing Day by day. AWS works on a shared responsibility model . As the name suggests that both AWS and the customer or client are responsible for the service they use in organization or individual or enterprise accounts. While initiating the service they ask the customer for the configuration changes and any third party involvement. Let me clear up what this means AWS is responsible for the physical and also environmental status of their data center where our data is stored and the various services around the world. And the customers are responsible for the configuration of the service which they are using. --Hence the security within the cloud infrastructure is customer or client responsibility and outside the cloud infrastructure like servers, data center they AWS's responsible for AWS. --While enabling...