#aws (2022-08)
Discussion related to Amazon Web Services (AWS)
Discussion related to Amazon Web Services (AWS)
Archive: https://archive.sweetops.com/aws/
2022-08-02
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
I have an unusual situation with a client. They manage many remote sites and have physical devices (up to 20) at each location. Each device needs to send metrics to cloudwatch and upload files to S3 and they currently use static aws credentials (~~~/.aws/credentials). I would like to move them to IAM anywhere to use temporary credentials. The ask is if a device gets compromised how can we disable access to AWS from that particular device. I was thinking to use an IAM Role per device however they are expecting to have ~~~k devices online by the end of the year. I’d use Terraform to manage the roles and AWS organizations to use multiple accounts since there’s a 5k IAM role quota per account. Does this sound manageable? or is there a better approach?
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
I’m thinking a role per device is not the best approach. Maybe you can have fewer roles that are based on the device class/location/etc. That way you can have one role for “Ohio” devices and another for “Utah” devices (just giving examples). The roles would be tightly locked down to only allow writes to CloudWatch and S3 based on their class/location/etc. I would also limit access to CloudWatch and S3 by the class as well…no need to give any more permissions if you are worried about compromise of the device.
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
If we used a role per location like “Ohio” for example and a single device is compromised how would we just deny access to that device instead of all of Ohio since they’ll be using the same role?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Isn’t this what you want? https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html
Immediately revoke permissions from a console session or a role whose credentials have been compromised or are suspected of being compromised.
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
I guess I’m not sure what sort of compromise you’re trying to mitigate.
Indeed if you had long-lived AWS cred sitting on disk for each device, some gets those and you have to reset everything everywhere.
With IAM creds they expire regularly and are regenerated. So if someone grabs those creds (and the associated session token) they are only good for a short time.
However, if someone is camped on your device, yes, they could likely use the role creds.
Is it the case that someone could sit on your device undetected? How would they connect? If its via SSH, have you considered removing SSH access altogether and using an SSM agent?
I have lots of questions!
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
If these are IOT devices (vs server devices) perhaps there are managed IOT services that you can use in AWS for the same purpose (CloudWatch logging and uploads).
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
The idea is to brick them, not necessarily to brick the OS but the running application
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
got it
data:image/s3,"s3://crabby-images/0e28a/0e28a0ab316a876deab5cdfca471a810d2bcaef7" alt="Joe Niland avatar"
Does each device have its own log group?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
@Joe Niland - Yes they do. The cloudwatch agent is sending logs to their respective log groups
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
@Erik Osterman (Cloud Posse) - Thanks for posting the link. It looks like the only option is to revoke ALL sessions for a particular role. I’m looking to revoke or deny a device session without affecting the rest of the devices.
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
I’m wondering if the IoT services have any faculty for helping with that. I’m thinking of the TF plans you’ll have to run to manage all those roles and its giving me chills
But seriously, at that scale, I’m thinking there should be a better approach than having to manage 10k roles across multiple accounts
data:image/s3,"s3://crabby-images/0e28a/0e28a0ab316a876deab5cdfca471a810d2bcaef7" alt="Joe Niland avatar"
@Patrick McDonald and they each have their own IAM user right?
data:image/s3,"s3://crabby-images/4b79c/4b79cb3ac4d33ded2b752b1679ba680cf5687cb9" alt="Jeremy (UnderGrid Network Services) avatar"
I’ve just recently taken a look at IAM Roles Anywhere… From what I’ve understood so far, you need a CA to serve as trust anchor. In my case I’m using Hashicorp Vault for my POC testing. If you issued unique certificates for each device under the CA then if one were to become compromised you should be able to revoke the certificate of that device. The CRL URL should be part of the CA certificate and I would assume it would be queried to check if the certificate was validate besides just being signed by the CA. This would allow to use the same role if the devices didn’t require unique IAM permissions but still have unique device authentication.
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
Jeremy, that’s an interesting approach which makes total sense. I’m going to look into that! Thank you.
data:image/s3,"s3://crabby-images/dfed7/dfed7bb76ce83f846564d41c35c2d88fde33f841" alt="Warren Parad avatar"
IAM isn’t really designed to be supported at scale in an account for your users like that. The solution that we usually help our customers implement is using our platform to generate private/public keys per device, and then verifying those keys on your service side. Exposing all of these clients direct access to your cloudwatch and S3, is a huge risk. Throwing a CF + lambda@edge plus service client authentication goes a long way. If you really want to allow direct access, because you consider the huge risk to be worth the small decrease in cost, you could proxy the requests through CF/APIGW directly to the service API.
Alternatively, you could take the private/public key signed JWT that you have (either custom built or using our platform) and use cognito identity pool to vend temporary AWS tokens.
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
Another question i have is the network access. That is, is the device using a private network when in service? That could be another way to lock down access by limiting access to devices on the private network. That assumes if the device is compromised/stolen and then connects to a different network, access to AWS resources would be blocked.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
check out today’s office hours recording for some good suggestions
data:image/s3,"s3://crabby-images/8a801/8a8015f91eff43ac708f3222ffa2867df37bb811" alt="Patrick McDonald avatar"
is the recording already published?
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
@Patrick McDonald https://www.youtube.com/watch?v=zANiSr_PzcQ&ab_channel=CloudPosse
2022-08-03
2022-08-04
data:image/s3,"s3://crabby-images/5860e/5860e9e171dc7f4e147c8a262126a653ed93ed9c" alt="Jonathan Backhaus avatar"
Hey everyone! Does anyone have an example of a CloudWatch Agent config. with a multi_line_start_pattern
and/or filter.expression
that includes RE2 escaped characters? I’m having a devil of a time getting this to work as expected. I’ve tried single escapes (e.g. \]
for the literal ]
character) and double-escapes (e.g. \\]
for the same literal) and neither seems to be working right. For what it’s worth, the configuration is deployed with Ansible, so the inputs are YAML and converted to JSON on the fly when the values are interpolated in the template file.
For example, any filters that I specify get translated as follows (snippet from a Jinja2 template file for the agent config):
"filters": {{ __log_file.filters | to_json }},
The templating is working as-expected; I’m just not sure the final syntax is right. I’ve been checking against the RE2 syntax but I can’t find a good example with escaped characters. Thanks for any help!
2022-08-08
data:image/s3,"s3://crabby-images/f1fac/f1facfa35ad2ccd627c37d58577d47bc1ba7a3cb" alt="Adarsh Hiwrale avatar"
Hey everyone! Is it possible to attach multiple load balancers to ECS service like ALB for internal user and NLB for external use ?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Yes
data:image/s3,"s3://crabby-images/f1fac/f1facfa35ad2ccd627c37d58577d47bc1ba7a3cb" alt="Adarsh Hiwrale avatar"
i ahve added nlb and lab both but when i add nlb target group to the ecs service it says InvalidParameterException: loadBalancerName and targetGroupArn cannot both be specified. You must specify either a loadBalancerName or a targetGroupArn.
data:image/s3,"s3://crabby-images/f1fac/f1facfa35ad2ccd627c37d58577d47bc1ba7a3cb" alt="Adarsh Hiwrale avatar"
i am using cloudposse ecs-alb-service-task
ecs-container-definition`
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
You have to set the load balancer name to null and give it multiple target groups that are attached as listener rules to the same load balancer
data:image/s3,"s3://crabby-images/f1fac/f1facfa35ad2ccd627c37d58577d47bc1ba7a3cb" alt="Adarsh Hiwrale avatar"
@RB Thanks man I did that it worked thanks but the target container are not getting registered. Registration and deregistration in loop
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
I’d look into why that’s happening. Are the health checks failing?
data:image/s3,"s3://crabby-images/f1fac/f1facfa35ad2ccd627c37d58577d47bc1ba7a3cb" alt="Adarsh Hiwrale avatar"
yes i think with helath checks 401 in logs
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
Sharing an approach I used for a similar situation with ECS serving two LBs (internal ALB and external NLB)…
Instead of having two sets of target groups, I configured the ECS to use the target group associated with the internal ALB. That way, deployments are only updated in one place.
Then I created an externally available NLB that uses the internal ALB as its target.
This has been working great.
data:image/s3,"s3://crabby-images/f1fac/f1facfa35ad2ccd627c37d58577d47bc1ba7a3cb" alt="Adarsh Hiwrale avatar"
But in my infra the container has two ports one for internal use and one for external which will be connected to NLB and internal to alb so two separate target groups are needed
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
That’s interesting! I’m curious why you would need two ports on the container if its providing the same service internally or externally… does the app/service/container do any sort of processing based on where the client is connecting from?
In my experience, the only need for internal vs external access if the DNS. on VPN, clients use an internal address. On internet, they use the external address. Once they hit the application, the app forwards it to an IAM service for authentication, then they get redirected back to the app.
if possible, is there a way for you to only use one target group? Asking because, if i recall correctly, i started to go down the multiple target group route and it looked like I would need two deployments of the same application, one for the internal ALB TGs and one for what would have been an external ALB TG.
If all else fails, and you have to keep the applicaiton configured as is (with two ports), it might just be easier to consider it as two seperate services in the same cluster. One service for internal ALB with its own TG and another server for external ALB and TG (i would def use ALB with this approach and not NLB). When you deploy, just deploy to both services at the same time.
data:image/s3,"s3://crabby-images/2efb7/2efb729d31057594f332f9910b29bb3a356285a6" alt="Balazs Varga avatar"
hello all, We are using aurora serverless v1 and few of them has a strange issue. Sometimes it dropts all connections. In error log around that time I see the db restarted. but did not see anything before that. any idea ?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Sounds like the db is stopping, as it does. You can try v2
data:image/s3,"s3://crabby-images/2efb7/2efb729d31057594f332f9910b29bb3a356285a6" alt="Balazs Varga avatar"
yes, i see it is stopping and starting, but why only on few clusters and not on all with same usage?
data:image/s3,"s3://crabby-images/2efb7/2efb729d31057594f332f9910b29bb3a356285a6" alt="Balazs Varga avatar"
it started few days ago and happens in every 4 hours
data:image/s3,"s3://crabby-images/2efb7/2efb729d31057594f332f9910b29bb3a356285a6" alt="Balazs Varga avatar"
I cannot try the v2 because of the price and it is production traffic. Is there any zero downtime upgrade ?
2022-08-09
2022-08-10
data:image/s3,"s3://crabby-images/c4e19/c4e19a632a33969e29cdd592c3354f1c84510f67" alt="Soren Jensen avatar"
Hi All, anyone who got experience with https://vantage.sh/ or other cost analyser?
data:image/s3,"s3://crabby-images/1a1ae/1a1ae40120c116b2a22f957908cc46e8b755dcb2" alt="attachment image"
Vantage is a self-service cloud cost platform that gives developers the tools they need to analyze, report on and optimize AWS and GCP costs.
data:image/s3,"s3://crabby-images/81d28/81d28ba8905ad1587b6f924945c3f9b6fa43c721" alt="Darren Cunningham avatar"
A friend of mine is the CEO of this early-stage startup and asked that I share it around, in case anyone finds it interesting: https://www.usage.ai/
data:image/s3,"s3://crabby-images/2efb7/2efb729d31057594f332f9910b29bb3a356285a6" alt="Balazs Varga avatar"
We are testing v2 aurora… is that possible that v2 is slower than v1 on same size?
data:image/s3,"s3://crabby-images/0c2a3/0c2a39176cfaf6b69c6c0f18c7e39c948273dfc2" alt="MrAtheist avatar"
Need some help with kinesis agent not spamming to kinesis… i can see stuff happening in /var/log/aws-kinesis-agent/aws-kinesis-agent.log
to the right kinesis, but i just dont see any blip from kinesis monitoring, anything else im missing?
2022-08-11
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
Not sure where else to post ist so I’ll try it here.
I have a bucket with CORS configuration allowing only certain domains as origins.
I am trying to use Cloudflare image resizing /cdn-cgi/image
proxy but I get CORS errors when accessing something like:
<https://www.example.com/cdn-cgi/image/https://my-bucket.s3-eu-central-1.amazonaws.com/images/myimage.jpg>
It works when I allow all origins on my bucket but I don’t want to do that.
Anybody had experience with something like this?
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
Have you tried adding www.example.com as an allowed origin for the S3 bucket?
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
“I have a bucket with CORS configuration allowing only certain domains as origins.” Al ready mentioned that
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
example.com is one of the certain domains
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
Maybe open a support ticket with Cloudflare? This seems like a fairly common task, surprised there’s not more documentation (after doing a quick google)
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
Yes, I am also thinking it might be something simple in the end. There is this https://developers.cloudflare.com/images/image-resizing/control-origin-access/ I hope that will not be solution to have to have cloudflare workers
data:image/s3,"s3://crabby-images/842c3/842c3d1b80fa9922827a01b7fda14575513a977b" alt="attachment image"
Choose between Cloudflare Images and Cloudflare Image Resizing, two products tailored to your different needs.
data:image/s3,"s3://crabby-images/d4e4e/d4e4e188370b6e03a72bc09cd5c3d1f7c4285ca7" alt="Choukri avatar"
You can use Cloudflare Image Resizing with either a pre-defined URL format or, for advanced use cases, with Cloudflare Workers.
Which of those resizing option you’re using ?
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
https://<ZONE>/cdn-cgi/image/<OPTIONS>/<SOURCE-IMAGE>
data:image/s3,"s3://crabby-images/f9ee6/f9ee6abc7a96b1a845d6c57f63b86253692827e1" alt="Adnan avatar"
as mentioned in the original question
<https://www.example.com/cdn-cgi/image/https://my-bucket.s3-eu-central-1.amazonaws.com/images/myimage.jpg>
data:image/s3,"s3://crabby-images/e7754/e7754b98c87d1ee2ad960c8b409806803093680a" alt="Andy avatar"
Looking for something to run custom devops scripts from. What do people tend to use ATM? Lamdba/Rundeck/Airflow/ArgoWorkflows? We use AWS with EKS so a k8s solution is an option.
data:image/s3,"s3://crabby-images/960b2/960b22776c71458036b0a3f985dd4329c033580f" alt="Denis avatar"
We use Lambdas, we use SSM Docs, we use terraform local-exec, we use kubernetes jobs. So, my answer would be “it depends”
data:image/s3,"s3://crabby-images/d4e4e/d4e4e188370b6e03a72bc09cd5c3d1f7c4285ca7" alt="Choukri avatar"
can you elaborate on what the script will do ? that will make answering your question easier
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
I just downloaded the terraform codebuild project but make keeps erroring out
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
You need to share the exact output in order for anyone to be able to help
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
makes sense @Erik Osterman (Cloud Posse)
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
So we assume you have curl installed
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
ah
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
im running on windows and installed a vm of debian
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
ill install that now
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
any other packages?
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
make: *** /mnt/c/Users/S903935/OneDrive: Is a directory. Stop
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
im running make Makefile @Erik Osterman (Cloud Posse)
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
is there a guide somewhere @Erik Osterman (Cloud Posse).
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
I often use make to compile programs. But, sometimes, only with some packages, when the directory contains a space, it says: No such file or directory Example: If I run make in the directory /home/
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
it seems like i am running into this
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
im just moving my github directory, that will solve this
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i want to make sure I understand everything correctly, this is a template which will allow me to automate my codebuild projects, correct?
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
Terraform Module to easily leverage AWS CodeBuild for Continuous Integration
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
please message me with a reply as I am going to head to bed and will check back when i wake up
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i dont want the conversation to be buried
2022-08-12
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
hey is anyone around?
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i was able to migrate the github project into a place where there is no spaces, now i am getting curl could not resolve host cloudposse.tools when i try make Makefile
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
is there some other guides with more details in it?
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i would like to know where exactly you are supposed to customize the variables as well as which ones you shouldnt customize
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
anyone around?
data:image/s3,"s3://crabby-images/dfed7/dfed7bb76ce83f846564d41c35c2d88fde33f841" alt="Warren Parad avatar"
I guess not
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
hmm, it is friday
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i really wanted to give the build a shot but its hard without detailed info
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
ive been trying to find an easy way to build out our codebuild projects for our ci/cd pipeline
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
it is a bit of a pain to create projects for each micro-service manually
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
any help would be much appreciated
data:image/s3,"s3://crabby-images/dfed7/dfed7bb76ce83f846564d41c35c2d88fde33f841" alt="Warren Parad avatar"
You are using github, just use GH actions. Codebuild is almost never the answer
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i rely heavily on the buildspec part
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
deploy out to my eks cluster
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
works really well
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
The cloudposse.tools domain resolves for me
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i downloaded the file just as it was and tried compiling
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
There is no command that I’m familiar with that is make Makefile
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
What problem are you trying to solve?
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Are you trying to consume the terraform module?
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
how do you run it?
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i thought it needed to be compiled and that was what the Makefile was
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
hence why i ran that
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
I would follow the readme. There should be a usage section
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
thats the problem, i did
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
its not clear
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
You create a new directory, copy and paste the terraform code from the usage section, then run terraform init and terraform plan
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
That’s it :)
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
ok, let me try that
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Here’s a good blog post on using modules in general
https://spacelift.io/blog/what-are-terraform-modules-and-how-do-they-work
data:image/s3,"s3://crabby-images/7ae61/7ae616edc4fbe1cc76d4457b112649c124e240e9" alt="attachment image"
Terraform modules are a way of extending your present Terraform configuration with already existing parts of reusable code, to reduce the amount of code you have to develop for similar infrastructure components. Others would say that the module definition is a single or many .tf files stacked together in their own directory. Both sides would be right.
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
havent really used terraform
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
read some about it
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
but this is the first time i am actually trying to use it
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
i usually stick to cloudformation
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Let’s move this over to the #terraform channel
data:image/s3,"s3://crabby-images/f322a/f322a4017987627d54c18938f79cccbea27ba234" alt="Shawn Stout avatar"
sure
2022-08-15
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
I need to know about lambda workflow we have code on S3 every time it will fetch the code while execute or it cache some where
data:image/s3,"s3://crabby-images/ed1cc/ed1cc3b37566a4ab4a5f969233221ed998e04094" alt="Alex Mills avatar"
The code is stored in Lambda, not S3. S3 is just used as a mechanism to upload large code bundles to AWS, and then it is copied from S3 into the Lambda environment.
data:image/s3,"s3://crabby-images/ed1cc/ed1cc3b37566a4ab4a5f969233221ed998e04094" alt="Alex Mills avatar"
This is evident as you can edit the code in the Lambda console, using the editor in the web UI, and then if you checked some previously uploaded code in S3, the changes will only exist in the Lambda environment
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
Thank you so much
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
Code Source
data:image/s3,"s3://crabby-images/dfed7/dfed7bb76ce83f846564d41c35c2d88fde33f841" alt="Warren Parad avatar"
Let’s not ping randow people. If you are stuck with something specific post a code example with the error you are getting. It’s the quickest way to get help.
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
?
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
Any one please
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
ok @Warren Parad
data:image/s3,"s3://crabby-images/5899c/5899c66f046ee21cb69a2803ba0c1c9599617625" alt="deniz gökçin avatar"
Hi all!
Has anyone here have any experience with docker compose - ecs integration? I am trying to make service discovery work but the the cloudmap namespace can not be resolved inside the ecs container. Any help is appreciated!
2022-08-16
data:image/s3,"s3://crabby-images/10695/106959b787cf55a36d351203c78aa2a7d26e2ff0" alt="rei avatar"
I am currently having problems pulling aws docker images from their public registries:
$ docker pull 602401143452.dkr.ecr.us-west-2.amazonaws.com/amazon/aws-load-balancer-controller:v2.4.3
Error response from daemon: Head "<https://602401143452.dkr.ecr.us-west-2.amazonaws.com/v2/amazon/aws-load-balancer-controller/manifests/v2.4.3>": no basic auth credentials
$ docker pull 602401143452.dkr.ecr.eu-west-1.amazonaws.com/amazon/aws-load-balancer-controller:v2.4.3
Error response from daemon: Head "<https://602401143452.dkr.ecr.eu-west-1.amazonaws.com/v2/amazon/aws-load-balancer-controller/manifests/v2.4.3>": no basic auth credentials
Can anyone relate? From inside or outside the AWS network, with or without docker-login credentials, still same error
data:image/s3,"s3://crabby-images/e9713/e97132c98c2b7d20932612d42bab708642bd2faa" alt="Murphy Zhang avatar"
Hi all! Found a bug? What can I do? Please help me. Thanks. Murphy.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Submit a pull request to fix it
data:image/s3,"s3://crabby-images/e9713/e97132c98c2b7d20932612d42bab708642bd2faa" alt="Murphy Zhang avatar"
• Yes, I will, if I cannot get an answer. And I’d rather it was just a configuration error.
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
use the old provider
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
an file the issue
data:image/s3,"s3://crabby-images/e9713/e97132c98c2b7d20932612d42bab708642bd2faa" alt="Murphy Zhang avatar"
The aws version is 4.25.0.
data:image/s3,"s3://crabby-images/e9713/e97132c98c2b7d20932612d42bab708642bd2faa" alt="Murphy Zhang avatar"
data:image/s3,"s3://crabby-images/eec9c/eec9c069e67081ff29b6f64624e3b7786e271095" alt="J Norment avatar"
Hi everyone. I’m looking for a way to set log retention with aws_glue_job, but the result doesn’t seem to work as it suggests that it should in the documentation. It just occurred to me, as I’m writing the question, that I’ve been trying to specify the logging parameters as NonOverridableArguments, so I’m going to look into not doing that, but I was curious if anyone knew of a resource that had a clear explanation of how the different options of logging behaved ( including the unrelated security_configuration object that also includes settings for logs, and appears to mandate the name of the log group. )
data:image/s3,"s3://crabby-images/27165/27165862055d6da08f07e2ad5f2099d1e4b59fba" alt="Chandler Forrest avatar"
Ran into an issue with the most recent changes to the Cloudposse SFTP Transfer module. The latest PR adds functionality to set home directories via the sftp_user input variable (very helpful). I noticed if users are created with the restricted_home variable set to true, and then later that variable is set to false; the in-place updates to users fail with the following errors:
Error: error updating Transfer User (redacted): InvalidParameter: 1 validation error(s) found.
│ - minimum field size of 1, UpdateUserInput.HomeDirectoryMappings.
│
│
│ with module.transfer-sftp.aws_transfer_user.default["redacted"],
│ on .terraform/modules/transfer-sftp/main.tf line 53, in resource "aws_transfer_user" "default":
│ 53: resource "aws_transfer_user" "default" {
│
╵
╷
│ Error: error updating Transfer User (redacted): InvalidParameter: 1 validation error(s) found.
│ - minimum field size of 1, UpdateUserInput.HomeDirectoryMappings.
│
│
│ with module.transfer-sftp.aws_transfer_user.default["redacted"],
│ on .terraform/modules/transfer-sftp/main.tf line 53, in resource "aws_transfer_user" "default":
│ 53: resource "aws_transfer_user" "default" {
│
╵
data:image/s3,"s3://crabby-images/27165/27165862055d6da08f07e2ad5f2099d1e4b59fba" alt="Chandler Forrest avatar"
I wsa able to get around this issue by deleting all of the users, and re-creating them with the restricted_home variable set to false. Should the restricted_home variable be set per_user as an input?
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
@Chandler Forrest please create an issue with a minimal viable reproducible example and we can then see what the error is. The additional inputs off the sftp_users
should be optional so if they are not, then this may be a bug but it’s hard to debug without all the necessary context
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
Can we get s3 bucket access logs to cloudwatch logs ?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
Yes. But your question is too generic, please be more specific
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
The bucket access logs need to sync with cloudwatch logs
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
this logs @Alex Jurkiewicz
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
S3 access logs can only be written to another S3 bucket. But you can process log files as they come in and write to cloudwatch logs using custom compute. For example, a Lambda function. However, I’m not sure why you would need this. What’s wrong with having the access logs in S3?
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
just for info i have config on same bucket
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
we have some file on S3 we need know access count for each file
2022-08-17
data:image/s3,"s3://crabby-images/217cf/217cfba268950205afbc3f5ea740e8322746b33e" alt="Anmol Gupta avatar"
Hello, team!
2022-08-19
data:image/s3,"s3://crabby-images/30ec5/30ec55ecc792bae04c502335beefa8a22a77760a" alt="david.gregory_slack avatar"
Hey all, possibly-stupid question: can AWS Support plans be set up with Terraform? Or is there some other way of sensibly managing support plans across a nontrivial org?
data:image/s3,"s3://crabby-images/0d1e1/0d1e181a4dd3f2c5a6bfd900cd8ee90549a64974" alt="Christopher Wade avatar"
Neither the mainline AWS or the AWSCC providers seem to have a “support” related resource, so I think that’s a no.
data:image/s3,"s3://crabby-images/27165/27165862055d6da08f07e2ad5f2099d1e4b59fba" alt="Chandler Forrest avatar"
Support plans can only be changed by the root account creds -> which aren’t often used with IAC.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
In AWS org, you only need to turn on support at the org root. Not each individual account
data:image/s3,"s3://crabby-images/0c2a3/0c2a39176cfaf6b69c6c0f18c7e39c948273dfc2" alt="MrAtheist avatar"
This can only be done by submitting a support ticket under Account management > General Account Question ;
and more specifically you need to specify each sub account you want to enable under the root, as the plan is technically billed per account
https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/consolidatedbilling-support.html
data:image/s3,"s3://crabby-images/30ec5/30ec55ecc792bae04c502335beefa8a22a77760a" alt="david.gregory_slack avatar"
Thanks all
2022-08-20
2022-08-22
2022-08-23
data:image/s3,"s3://crabby-images/5899c/5899c66f046ee21cb69a2803ba0c1c9599617625" alt="deniz gökçin avatar"
hello!
has anyone ever deployed an SSR nextjs app on AWS? I am experimenting with Amplify and want to ask what are some problems you all had with Amplify hosting. Thanks!
2022-08-24
data:image/s3,"s3://crabby-images/9b316/9b3169958d52475bc8fa10a83235db44c9846057" alt="Gile Shoby avatar"
Hello team, During effort to use newer version of terraform module cloudposse/terraform-aws-emr-cluster I come accross issue and before opening Issue on github I am suggested in template to ask for support here first.
While trying to update from version tag 0.23.0 and use latest version tag 1.0.0 I come on following error during terraform plan:
Error: Unsupported block type
on ../.tfmodules/terraform-aws-emr-cluster/main.tf line 523, in resource "aws_emr_cluster" "default":
523: dynamic "auto_termination_policy" {
Blocks of type "auto_termination_policy" are not expected here.
Any suggestion how to proceed or to open issue on github instead?
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Make sure youre using the latest aws provider version
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
I see it in latest 3.x provider version too so you must be using an older version of the aws provider
data:image/s3,"s3://crabby-images/9b316/9b3169958d52475bc8fa10a83235db44c9846057" alt="Gile Shoby avatar"
What confused me when I was looking at it earlier is that there is no reference in my code to auto_termination_policy which is marked as optional
Also currently at 3.63.0
AWS provider and requirement in our docs says requirement is aws >= 3.5.0
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
Perhaps the requirement needs to be bumped
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
for now, you can remove your pin, or remove the .terraform.lock.hcl
file locally and run another terraform init
to see if it will resolve the issue
data:image/s3,"s3://crabby-images/9b316/9b3169958d52475bc8fa10a83235db44c9846057" alt="Gile Shoby avatar"
thanks for suggestions
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
did it work?
data:image/s3,"s3://crabby-images/9b316/9b3169958d52475bc8fa10a83235db44c9846057" alt="Gile Shoby avatar"
sorry but would not be able to provide you with answer since I am not trying it atm
data:image/s3,"s3://crabby-images/4d072/4d0722b6aa230593938f89dc1b4f0b9bab35e181" alt="RB avatar"
no worries, let us know when you can
data:image/s3,"s3://crabby-images/7e1fd/7e1fd3309867f3cbc7cb771b2eaa87b0adf34f3f" alt="Ashwin Jacob avatar"
Tailscale - I have been using tailscale to connect to my private resources and it has been working great! However, I ran into a big problem recently. I got some contractors and shared my node with them. I just found out that it doesn’t share the Subnet relayed traffic (reference: https://tailscale.com/kb/1084/sharing/#sharing--subnets-subnet-routers) Anyone have alternatives to tailscale that will help solve my problem?
I did think of creating a Gmail Account for them with the same domain as me but that would be an extra cost for each contractor just to have access to Tailscale.
Learn how to give another Tailscale user access to a private device within your network, without exposing it publicly.
data:image/s3,"s3://crabby-images/7e1fd/7e1fd3309867f3cbc7cb771b2eaa87b0adf34f3f" alt="Ashwin Jacob avatar"
Looking for that same underlying technology like tailscale if possible. I love this tool and would love to recommend it to more people but this is a big annoyance
Learn how to give another Tailscale user access to a private device within your network, without exposing it publicly.
data:image/s3,"s3://crabby-images/1e7fb/1e7fb012e9114db9a49ef4fb0140243909a277f1" alt="Matt Gowie avatar"
Lots of competitors in the market — What I’d suggest looking into is these tools in the following order: StrongDM >= Teleport > CloudFlare Access > HashiCorp Boundary > AWS Client VPN. Search for any of those tools in this Slack and you’ll get plenty of hits. BeyondCorp is one of the most talked about topics.
Tailscale is the best though and for a very good price. I would suggest just accepting the Gmail account cost — You’ll save more of your own money + time not switching away to reduce a hundred or two hundred in yearly spend?
data:image/s3,"s3://crabby-images/7e1fd/7e1fd3309867f3cbc7cb771b2eaa87b0adf34f3f" alt="Ashwin Jacob avatar"
Thank you Matt! I actually found a good workaround bc I really wanted to stick with tailscale. Since they are developer contractors, I was able to use GitHub as the Identity Provider.
Also a nice note to everyone here, tailscale does support several OpenID Connect identity providers. Found here: https://tailscale.com/kb/1119/sso-saml-oidc/
This will need to be a new task for me to provide a better identity provider
Tailscale allows WireGuard® to support several OpenID Connect (OIDC) identity providers, including Google, Azure AD, Okta, and others. Almost everyone can use one of the included providers.
data:image/s3,"s3://crabby-images/1e7fb/1e7fb012e9114db9a49ef4fb0140243909a277f1" alt="Matt Gowie avatar"
That works too. And definitely best to stick with tailscale — it’s a great tool.
data:image/s3,"s3://crabby-images/1f56f/1f56ffd63d6a7249b7f50ce533ad1fd0d08692be" alt="Sean Turner avatar"
Anyone use AWS code artifact? love it? hate it? We are considering it for pip
. CI would push (already uses OIDC with circle CI), and devs would pull for docker container based environments
data:image/s3,"s3://crabby-images/1e7fb/1e7fb012e9114db9a49ef4fb0140243909a277f1" alt="Matt Gowie avatar"
Might be a good question for #office-hours
data:image/s3,"s3://crabby-images/1f56f/1f56ffd63d6a7249b7f50ce533ad1fd0d08692be" alt="Sean Turner avatar"
Thought the same thing. I had missed it when I posted this
2022-08-25
2022-08-28
data:image/s3,"s3://crabby-images/2c542/2c5428cb5f8a5bfd303be4b4c99320e0efcb7b39" alt="James avatar"
Hey guys, Is AWS subnets operate at network layer 2?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
what do you mean “operate at”?
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
It’s probably most correct to say subnets operate at layer 3, since they primarily group traffic by IP. But “operate at” is a very broad phrase…
A subnet is a range of IP addresses in your VPC. You can launch AWS resources into a specified subnet. Use a public subnet for resources that must be connected to the internet, and a private subnet for resources that won’t be connected to the internet.
data:image/s3,"s3://crabby-images/2c542/2c5428cb5f8a5bfd303be4b4c99320e0efcb7b39" alt="James avatar"
yep its layer 3
data:image/s3,"s3://crabby-images/2c542/2c5428cb5f8a5bfd303be4b4c99320e0efcb7b39" alt="James avatar"
thanks Alex
2022-08-29
2022-08-30
2022-08-31
data:image/s3,"s3://crabby-images/8d7d2/8d7d21bfed29fe20b3ae51c69817cc3a4e77c91e" alt="mado avatar"
Let’s say I have a S3 bucket called “abc” and a folder in it like “abc/tmp”. I already restricted IAM policy to restrict access to only PutObject in “abc/tmp” and “abc/tmp/*”. But somehow the api I created can still upload files to a random folder like “abc/tmp99999”… Any other restrictions I have to set??
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
How certain are you the restriction is for abc/tmp/*
and not abc/tmp*
?
data:image/s3,"s3://crabby-images/8d7d2/8d7d21bfed29fe20b3ae51c69817cc3a4e77c91e" alt="mado avatar"
Pretty straightforward like Effect:Allow, ActionPutObject, Resourceaws
::abc/tmp, arn:aws
::abc/tmp/*
data:image/s3,"s3://crabby-images/b2ee3/b2ee3ca080f64d8b69284d7f2d54d1b8bb5013b6" alt="loren avatar"
That policy is on the iam user/role/group? Is there more than one policy, maybe allowing more s3 actions than you thought? Also, what is the s3 bucket policy? Does it have an allow statement that might match?
data:image/s3,"s3://crabby-images/a4e68/a4e68e34f10c8b4ea55eb1bf537d97c20e184816" alt="kirupakaran avatar"
Hi, Anyone aware of avoiding bot attacks ? my project has been attacked by bots, my infra is aws and cloudflare.
data:image/s3,"s3://crabby-images/62ea3/62ea3a0f57be2a1b9349cb1d798270aab599c544" alt="Alex Jurkiewicz avatar"
You might need to be a little more specific as to the type of attack
data:image/s3,"s3://crabby-images/a4e68/a4e68e34f10c8b4ea55eb1bf537d97c20e184816" alt="kirupakaran avatar"
My developer said, it is an just bot attack, i dont know the more details.
data:image/s3,"s3://crabby-images/02ca5/02ca5905a965d292a71f224a0dbf6c6d3e5ad9e5" alt="sai kumar avatar"
Preliminary Security group check needs to do verify whether any protocol has anywhere access [ 0.0.0.0/0 ]
data:image/s3,"s3://crabby-images/a4e68/a4e68e34f10c8b4ea55eb1bf537d97c20e184816" alt="kirupakaran avatar"
No @sai kumar
data:image/s3,"s3://crabby-images/841d8/841d8f1ee11a8cded4e036c005f1c6950035c636" alt="Max avatar"
data:image/s3,"s3://crabby-images/a4e68/a4e68e34f10c8b4ea55eb1bf537d97c20e184816" alt="kirupakaran avatar"
@Max Thank you.