Posts

AWS - STS Security Token Service

Image
  AWS Security Token Service (STS) that enables you to request temporary, limited privilege credentials for IAM Users or Federated Users). AWS STS has these specific properties when assigning temporary access. ·          It can range from a few minutes to a few hours. ·          Once the AWS STS provided temporary token expires, it cannot be reused at any point. ·          You can invoke AWS STS only through  AWS SDKs or AWS CLIs. Let's see with an example. We are going to create a user and set up to access the S3 bucket using STS. I created a user called "s3demouser" with no permission attached to it. Created an S3 bucket with NO policy attached to it. Let's try to list the bucket with users's Access and Secret keys. We are getting "Access Denied" which is expected. Let's create a policy that provides S3 Read Only Access - The policy name is s3-readonly. Now...

AWS Organizations - Part I

Image
  AWS Organization – Manage multiple accounts. Central account to manage multiple accounts. Billing is managed on a central account (Management/Master/root Account) instead of multiple accounts. Consolidate billing – One bill for all the accounts in the organization. Management account is the root of the hierarchy. Grouping of accounts into OU (Organization Units). Login with your root account to create an Organization. Your root account is called "Management Account". 1) We can add a new AWS account - Need a unique email ID not used in AWS before. 2) Add an existing AWS account - Send mail invitation. Let's see how to add a new account: I am creating an account by the name “Development”. Email ID should be unique and must not be mapped to any other AWS Account. IAM role for this account. NOTE: The IAM role that is created will have FULL ACCESS on the new account. I repeated the same process to create a DEVELOPMENT and PRODUCTION account. So, I have 3 accounts: 1) Man...

AWS Permission Boundaries

Image
  AWS Permission Boundaries sets the maximum permission that an entity can have, Permission Boundaries are attached to a USER and ROLE. Let's say a user called admin_a has full IAM Access but cannot create any other resources (Let's take EC2 for instance). So, admin_a can create another user called admin_b and granting admin_b will full access to EC2 resources. Now, admin_a can log in using admin_b credentials and create EC2 resources.  Let's see that: Now, I logged in as admin_a user.  As an admin_a user, I cannot access EC2 resources. But, I have IAM full access. So, creating another user admin_b with EC2 full access. Now, I logged in with the admin_b credential and spun an EC2 instance.  This poses a security risk. So, to mitigate this issue we are going to set "Permission Boundaries" for the user " admin_a ". So, admin_a can have the same or fewer permissions than what he has. I created a policy called " Permission_Boundary_Demo "...

AWS - S3 Replication of Existing Objects

Image
  In my previous pos t, We have seen how to set up S3 replication. In this post, we will see how to set up replication and trigger an ad-hoc batch operation to replicate existing objects. Source Bucket: rsinfominds-source-bucket Destination Bucket: rsinfominds-destination-bucket NOTE: Versioning needs to be enabled on both the buckets. The source bucket is created and uploaded with 3 files. Now, We have 2 buckets. Let's create replication from the source bucket. Upon selecting "Yes, Replicate Existing Objects".  It takes to Batch Operation Job. Now that job is created and triggered. You can see the object replicating on the destination bucket.

AWS - APIGW with IAM Authorizer

Image
  In the previous post, we saw how to create an API GW with Lambda.  In this post, we will see how to add an IAM Authorizer to the API GW.  So, all the calls to API GW must be authenticated and authorized via the IAM user's Access and Secret Keys. I already have an IAM user called "rsinfominds". I added APIGW Invoke permission to the user and made a note of the access and secret key. Now, We have an IAM user. Let's update the existing API GW with the IAM authorizer. Finally hit deploy to save the changes. Now, It's time to test it via Postman. It works. We got the reply "Hello from Lambda".

AWS - Secrets

Image
AWS Secrets Manager helps you manage, retrieve, and rotate database credentials, application credentials, OAuth tokens, API keys, and other secrets throughout their lifecycles. In Secrets Manager, a secret consists of secret information, the secret value, plus metadata about the secret. A secret value can be a string or binary.  Let's start with creating a simple secret and how to view using a Python program. Here my secret is going to be a simple key: value pair. To access the secret, I have created an IAM Role and " RoleToRetrieveSecretAtRuntime” with permission to “ GetSecretValue ”. Updating the secret's access policy. The above permission states role " RoleToRetrieveSecretAtRuntime" can perform "GetSecretValue". We are done with the secret part. Now, We are going to use a Python program to view the secret from an EC2 instance.  NOTE: EC2 instance should be attached with the role  RoleToRetrieveSecretAtRuntime import boto3 from botocore.exceptions...