首页 > 其他分享 >Udemy AWS SAA - Intro and IAM

Udemy AWS SAA - Intro and IAM

时间:2024-04-01 12:35:56浏览次数:451  
标签:IAM account users SAA AWS Intro region password your

How to choose an AWS Region if you need to launch a new app

  1. Compliance: with data governance and legal requirement, data never leaves a region w/o your explicit permission
  2. Proximity: to customers, to reduce latency
  3. Available services: some region doesn't have all services
  4. Pricing: varies region to region

Availability Zones:
each region has many availability zones, usually 3, min is 2, max is 6
each AZ is 1+ discrete data centers with redundant power, networking and connectivity, they are separate from each other, but connected with high bandwidth, ultra-low latency

AWS Points of Presence (Edge Locations)网点

AWS has Global Services

  • ldentity and Access Management (lAM)
  • Route 53 (DNS service)
  • CloudFront (Content Delivery Network)
  • WAF (Web Application Firewall)

Most AWS services are Region-scoped

  • Amazon EC2 (Infrastructure as a Service)
  • Elastic Beanstalk (Platform as a Service)
  • Lambda (Function as a Service)
  • Rekognition (Software as a Service)

ldentity and Access Management (lAM)

  • Root account created by default, shouldn't be used or shared
  • Users are ppl in your org, and can be grouped. After getting a root user, we can create an Admin account, then create users account
  • Groups only contain users, not other groups
  • An user can belong to multiple groups
  • We want the users to use their AWS account
  • Permissions: users or groups can be assigned JSON documents called policies to grant their permissions to the AWS services. Please do Least Privilege Principle : don't give more permission than a user needs

Inline policy: a policy only assigned to one person

IAM Policies Structure

An Example for Permission JSON
The "*" below means any, it permits any action and any resource

Two Ways to Protect Your AWS Account
Password Policy

  • Strong passwords = higher security for your accountIn AWS, you can setup a password policy:
    • Set a minimum password lengthRequire specific character types.including uppercase letters
    • lowercase letters
    • numbers
    • non-alphanumeric charactersAllow all lAM users to change their own passwords
    • Require users to change their password after some time (password expiration)
    • Prevent password re-use

Multi Factor Authentication - MFA

  • Users have access to your account and can possibly change configurations or delete resources in your AWS account
  • You want to protect your Root Accounts and lAM users
  • MFA = password you know + security device you own
  • You can use:
    • Virtual MFA device: Google Authenticator (Phone only), Authy (multi-device);
    • Universal 2nd Factor (U2F) Security Key, ex. YubiKey
    • Hardware Key Fob: Gemalto
    • Hardware Key Fob for AWS GovCloud(US): SurePassID

标签:IAM,account,users,SAA,AWS,Intro,region,password,your
From: https://www.cnblogs.com/miramira/p/18108124

相关文章

  • 【博客708】victoriametrics如何处理counter跳变
    victoriametrics如何处理counter跳变背景监控中我们经常会使用一些counter类型的metrics来计算速率,比如:rate(https_request_total)但是如果我们的服务突然由于异常导致重启了,那么这时候counter会重新从0开始计算,那么这时候就会有问题,假设我们原来https_request_total是......
  • 新零售SaaS架构:客户管理系统的应用架构设计
    客户管理系统的应用架构设计应用层定义了软件系统的应用功能,负责接收用户的请求,协调领域层能力来执行任务,并将结果返回给用户,功能模块包括:客户管理:核心功能模块,负责收集和更新客户信息,包括个人资料、联系方式、消费习惯、会员卡、归属信息(比如销售或顾问)和备注。这个模块......
  • 新零售SaaS架构:客户管理系统的应用架构设计
    客户管理系统的应用架构设计应用层定义了软件系统的应用功能,负责接收用户的请求,协调领域层能力来执行任务,并将结果返回给用户,功能模块包括:客户管理:核心功能模块,负责收集和更新客户信息,包括个人资料、联系方式、消费习惯、会员卡、归属信息(比如销售或顾问)和备注。这个模块是CRM......
  • Operating System Concepts 9th: Chapter 1 Introduction
    Anoperatingsystemisaprogramthatmanagesacomputer’shardware.Italsoprovidesabasisforapplicationprogramsandactsasanintermediarybetweenthecomputeruserandthecomputerhardware.操作系统的定义:一个管理计算机硬件,并作为用户与硬件之间的中......
  • Java商城 免 费 搭 建:鸿鹄云商实现多种商业模式,VR全景到SAAS,应有尽有
    鸿鹄云商b2b2c产品概述【b2b2c平台】,以传统电商行业为基石,鸿鹄云商支持“商家入驻+平台自营”多运营模式,积极打造“全新市场,全新模式”企业级b2b2c电商平台,致力干助力各行/互联网创业腾飞并获取更多的收益。从消费者出发,助力企业构建完整电商交易生态,整合资源,创造更有利的......
  • ASAA821-EARB0-7H 金手指连接器 SMD卧贴 间距0.5MM 260P DDR4 FOXCONN(富士康)
    ASAA821-EARB0-7H衔接器主要用于电脑和其他电子产品中,完成电气衔接和信号传输。在实践运用中,它可能需要与相应的插座或其他衔接器配合运用。ASAA821-EARB0-7H是富士康(FOXCONN)企业集团出产的一款金手指连接器。以下是关于该产品的部分信息:品牌:FOXCONN/富士康型号:ASAA821-EAR......
  • NVIDIA人形机器人AI套件:NVIDIA Isaac Manipulator 和 NVIDIA Isaac Perceptor
    IsaacManipulator为机械臂提供了卓越的灵活性和模块化AI功能,并提供了一系列强大的基础模型和GPU加速库。它提供了高达80倍的路径规划加速,零样本感知提高了效率和吞吐量,使开发者能够实现更多新的机器人任务的自动化。早期生态系统合作伙伴包括安川电机、泰瑞达旗下子公司优傲、Pic......
  • 企业级快速开发框架 nbsaas-boot 1.1.8-2024 发布了
    <parent><groupId>com.nbsaas.boot</groupId><artifactId>nbsaas-boot</artifactId><version>1.1.8-2024</version></parent>本次更新内容1.重构代码生成器,采用类提取和字段提取两种方式,提取功能接口,方便后期扩展2.对数据字典注解增加字符串类型3.......
  • Lecture 10 Geometry 1 (Introduction)
    Lecture10Geometry1(Introduction)Examplesofgeometry几何的例子不同形状的几何光滑的曲面复杂的模型、位置摆放布料水滴城市(复杂在东西多)怎么存储怎么渲染这么大级别的东西离得远的情况下如何简化几何模型如何利用光线之间的连续性毛发微观几何树枝......
  • [Container] Introduction to Kubernetes
    DefineKubernetesAlsoknowasK8S,isanopen-sourcesystemforautomatingdeployment,scaling,andmanagementofcontainerizedapplications.Anopensourcecontainerizationorchestrationpaltform.Easolyportableacrosscloudsandon-premisesIncludes......