@andreas@social.cloudonaut.io
@andreas@social.cloudonaut.io avatar

andreas

@andreas@social.cloudonaut.io

AWS Monitoring, S3 Security, and all other things AWS. #awscommunity

This profile is from a federated server and may be incomplete. Browse more on the original instance.

andreas, to random
@andreas@social.cloudonaut.io avatar

❓Who is attending AWS Summit in Berlin next week?

andreas, to random
@andreas@social.cloudonaut.io avatar

📣We just released widdix/mastodon-on-aws v0.18.0 including the following changes.

1️⃣ Mastodon v4.2.5
2️⃣ Scheduled task to cleanup media files older than 180 days.
3️⃣ Parameter to reduce number of RDS snapshots.

Upgrade to the latest version to reduce costs and fix a critical security issue with Mastodon.

https://github.com/widdix/mastodon-on-aws?tab=readme-ov-file#update

andreas, to random
@andreas@social.cloudonaut.io avatar

⚠️ A major risk when using customer-managed KMS keys is that someone deletes the key, and thus, all data is encrypted with the key. How to mitigate the risk?

1️⃣ AWS does not allow to delete keys immediately but enforces a waiting period of 7 to 30 days.
2️⃣ Customers use key policies, IAM policies, or SCPs to restrict access to the kms:ScheduleKeyDeletion action.

But there is another risk of losing access to a key: modifying the key policy. (1/2)

andreas,
@andreas@social.cloudonaut.io avatar

It is possible to alter a key policy so that no one, not even the AWS account root user, has access to the key anymore.

Neither AWS nor most organizations do mitigate this risk. Will we see ransomware-like attacks based on KMS key policy modifications?

simon, to fedibikes German
@simon@sueden.social avatar

Moin, kennt jemand aus der Fahrrad-Bubble eine hochwertige Alternative zum minderwertigen -Schloss? Unseres hat ca. 2 Jahre gehalten, bis der Kunststoff an der vermuteten Sollbruchstelle riss. @fedibikes

andreas,
@andreas@social.cloudonaut.io avatar

@simon @fedibikes Wir haben eine Kupplung von Weber am Thule. Super praktisch und stabil. https://www.weber-products.de/

SecureOwl, to random

If you work at Amazon and are expected to be on-call, a reminder to do as your CEO says and head to the office before you start working on whatever incident or outage is happening at whatever time of day, no matter how long that may take - it’s where you’ll do your best work after all.

andreas,
@andreas@social.cloudonaut.io avatar

@SecureOwl From all I read and hear, the working environment seems to be toxic in many areas.

andreas, to random
@andreas@social.cloudonaut.io avatar

HashiCorp adopting the Business Source License 1.1 is a nightmare. Building products based on Terraform is no longer a safe bet as the license says:

„You may make production use of the Licensed Work, provided such use does not include offering the Licensed Work to third parties on a hosted or embedded basis which is competitive with HashiCorp's products.“

But what if HashiCorp enters a new market tomorrow and you are now competing with their offering? 🤯

#awscommunity #amazonwebservices

andreas,
@andreas@social.cloudonaut.io avatar

@matdevdug I agree, the license is very vague. It‘s therefore risky to use HashiCorp‘s former OSS projects.

Hopefully, we will see a successful OSS fork.

andreas, to random
@andreas@social.cloudonaut.io avatar

Pro tip: replace your AWS support subscription with a ChatGPT subscription. You will get wrong answers from both, but ChatGPT is a lot faster and cheaper. 🙈

janl, to random
@janl@narrativ.es avatar

current conundrum: buy fair trade / organic / sustainable underwear that lasts me ~12 months or buy other random shit that lasts much longer.

What are you choosing and what are your experiences? (Online shops only).

andreas,
@andreas@social.cloudonaut.io avatar

@janl I‘m a huge fan of Manomama. Lasts for years. Produced nearby my hometown.

https://www.manomama.de

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • modclub
  • everett
  • rosin
  • Youngstown
  • slotface
  • ethstaker
  • mdbf
  • kavyap
  • osvaldo12
  • DreamBathrooms
  • anitta
  • Durango
  • ngwrru68w68
  • tester
  • khanakhh
  • love
  • tacticalgear
  • cubers
  • GTA5RPClips
  • Leos
  • normalnudes
  • provamag3
  • cisconetworking
  • JUstTest
  • All magazines