Posts

AWS - VPC Peering

Image
  A VPC peering connection is a one-to-one relationship between two VPCs.   You can create multiple VPC peering connections for each VPC that you own, but transitive peering relationships are not supported. Transitive peering means VPC-A is connecting to VPC-C via another VPC-B is not possible. In short, VPC peering is a channel to establish a connection between 2 different VPC's. I have 2 VPC's: 1) Default VPC - CIDR 172.31.0.0/16 2) Demo VPC - CIDR 10.0.0.0/16 We are going to create a VPC Peering between them and update the route table on both the VPC's accordingly. For demo purpose, I have launched an ec2 instance on "Demo VPC" and setup an httpd server. We are trying to access that httpd server from another ec2 instance launched on "Default VPC". I get time out when I try to curl from the ec2 instance launched on "Default VPC" to the httpd service running on "Demo VPC". Now, Let's create a peering connection. Under VPC, Sel...

AWS Single Sign On - SSO

Image
  AWS SSO  securely creates or connects your workforce identities and manages their access centrally across AWS accounts and applications. For a single account, the users and group can be managed via IAM. If there are multiple accounts managed through AWS Organization, manually creating users/groups across the accounts via IAM is tedious work. AWS SSO is a solution for it. Where the user/group is created in AWS SSO and it can be assigned to the AWS Accounts. NOTE: * SSO can enabled in only one region. * SSO is integrated with AWS Organization. * AWS Organization must be used for SSO. I have already set up AWS Organization - Please refer to  AWS Organization Let's enable SSO.  We can log in using the AWS Access Portal URL. Now, We will start creating a user. The user is created. Now, We will create a  Permission Set.  Permission sets define the level of access that users in IAM Identity Center have to their assigned AWS accounts.  Under permission set, ...

AWS - Budget Alert

Image
  In this post, we will see how to set up budget alerts with email and SNS. We will create a SNS topic and subscription. Finally, create a budget alert and set the threshold, and add the SNS topic for notification. Creating a topic called "budget-sns" and make sure this SNS has access from the budget service. Create a subscription. Now, let's start with AWS Budget. We are done with creating a budget alert. The first time it takes 24 hours to activate the budget alert.

AWS - STS Security Token Service

Image
  AWS Security Token Service (STS) that enables you to request temporary, limited privilege credentials for IAM Users or Federated Users). AWS STS has these specific properties when assigning temporary access. ·          It can range from a few minutes to a few hours. ·          Once the AWS STS provided temporary token expires, it cannot be reused at any point. ·          You can invoke AWS STS only through  AWS SDKs or AWS CLIs. Let's see with an example. We are going to create a user and set up to access the S3 bucket using STS. I created a user called "s3demouser" with no permission attached to it. Created an S3 bucket with NO policy attached to it. Let's try to list the bucket with users's Access and Secret keys. We are getting "Access Denied" which is expected. Let's create a policy that provides S3 Read Only Access - The policy name is s3-readonly. Now...

AWS Organizations - Part I

Image
  AWS Organization – Manage multiple accounts. Central account to manage multiple accounts. Billing is managed on a central account (Management/Master/root Account) instead of multiple accounts. Consolidate billing – One bill for all the accounts in the organization. Management account is the root of the hierarchy. Grouping of accounts into OU (Organization Units). Login with your root account to create an Organization. Your root account is called "Management Account". 1) We can add a new AWS account - Need a unique email ID not used in AWS before. 2) Add an existing AWS account - Send mail invitation. Let's see how to add a new account: I am creating an account by the name “Development”. Email ID should be unique and must not be mapped to any other AWS Account. IAM role for this account. NOTE: The IAM role that is created will have FULL ACCESS on the new account. I repeated the same process to create a DEVELOPMENT and PRODUCTION account. So, I have 3 accounts: 1) Man...