AWS re:Invent 2018: [REPEAT 1] Managing Modern Infrastructure in Enterprises (ENT227-R1)

preview_player
Показать описание
In this session, Verizon shares how it uses AWS Systems Manager for inventory, compliance, and patch management solutions. Learn about the challenges that large enterprises face when they attempt to retrofit legacy solutions for cloud environments, and discover best practices for using AWS Systems Manager for minimal access policies, custom Amazon Machine Images, tagging policies, encryption, and more.
Рекомендации по теме
Комментарии
Автор

Great content! As this is a talk about SSM, I think it is important to note for users that they should NEVER use the default "AmazonEC2RoleforSSM", as this imposes a high security risk on environments. This policy allows any instance to GET and PUT objects on ANY S3 bucket on the same account -- therefore if an instance is compromised, be prepared to be the next company all over the news with the "massive data leak" headline we are getting used to.
I tried reporting this issue to AWS several times, but as of today, it is still an ongoing issue,

Tyron