AWS Certified DevOps Engineer – Professional flashcards
153 free flashcards. Tap a card to flip it.
CloudTrail Organization Trail
Flip cardA CloudTrail trail that logs management and data events for all AWS accounts in an AWS Organization, delivering logs to a centralized S3 bucket.
- Centralizes logging for all member accounts.
- Captures API calls and administrative actions.
- Essential for auditing and compliance across organizations.
Memory trick: CloudTrail Org Trail: All AWS actions, one audit bucket.
CloudWatch Agent
Flip cardA unified agent for collecting metrics and logs from Amazon EC2 instances and on-premises servers, sending them to CloudWatch.
- Collects custom metrics (e.g., memory, disk I/O) and logs.
- Supports both EC2 and on-premises environments.
- Unified agent for logs and metrics.
Memory trick: CloudWatch Agent: Your EC2's Metric & Log Collector.
AWS X-Ray Active Tracing for Lambda/API Gateway
Flip cardEnabling X-Ray active tracing for Lambda functions and API Gateway stages automatically collects detailed trace information for requests.
- Provides end-to-end visibility for serverless applications.
- Captures request segments, subsegments, and metadata.
- Generates service maps to visualize connections and latency.
- Minimal configuration required in Lambda and API Gateway settings.
Memory trick: X-Ray's 'Active Trace' is the easy button for Lambda insights.
CloudWatch Logs Insights
Flip cardA fully integrated, interactive query service within Amazon CloudWatch Logs that allows you to analyze and troubleshoot logs without managing any infrastructure.
- Queries logs stored in CloudWatch Logs.
- Supports powerful query language for filtering and aggregation.
- No servers to manage, pay-per-query pricing model.
Memory trick: Containers Logged Centrally, Quickly Query Insights.
CloudWatch Anomaly Detection
Flip cardA CloudWatch feature that uses machine learning to analyze historical metric data, identify a normal baseline, and alert when current metric values deviate significantly from this baseline.
- Dynamically learns normal metric patterns.
- Reduces false positives compared to static thresholds.
- Ideal for fluctuating metrics like CPU utilization or network traffic.
Memory trick: Anomaly Detection: CloudWatch's AI for 'what's normal?'
CloudWatch Container Insights for Fargate
Flip cardCloudWatch Container Insights provides comprehensive monitoring for containerized applications, including those running on AWS Fargate, by automatically collecting and aggregating metrics and logs.
- Monitors CPU, memory, network, and storage.
- Collects metrics at cluster, service, task, and container levels.
- Integrates with CloudWatch Logs for container logs.
- Provides automatic dashboards and performance visualizations.
Memory trick: Fargate's 'Container Insights' gives you the full picture, automatically.
CloudWatch Log Metric Filters
Flip cardAllows you to extract metric data from log events in CloudWatch Logs, enabling you to create CloudWatch Alarms based on patterns found in your logs.
- Transforms log data into numerical CloudWatch metrics.
- Enables alerting on specific log patterns (e.g., 'ERROR').
- Can count occurrences or extract values for metrics.
Memory trick: Alarms to SNS, Lambda Links Logs & Tickets.
AWS X-Ray
Flip cardA service that helps developers analyze and debug distributed applications by providing an end-to-end view of requests as they travel through your application.
- Traces requests across multiple services and resources.
- Visualizes service maps and identifies performance bottlenecks.
- Supports various programming languages and AWS services.
Memory trick: X-Ray eXamines eXactly eVery eXchange.
Cross-Account CloudWatch Logs Centralization
Flip cardCentralizing CloudWatch Logs from multiple AWS accounts into a single security or logging account for unified analysis and long-term archival.
- Uses CloudWatch Logs subscription filters.
- Often streams logs to Kinesis Data Firehose or Lambda.
- Target destination is typically S3 for archival.
- Requires appropriate IAM roles and resource policies for cross-account access.
Memory trick: CloudWatch's 'Subscription Stream' funnels all logs to one safe place.
CloudWatch Alarm Actions
Flip cardCloudWatch Alarms can trigger various actions when a metric goes into an 'ALARM' state, such as sending notifications or initiating automated responses.
- Can send notifications via SNS.
- Can trigger Auto Scaling actions (scale out/in).
- Can invoke EC2 actions (stop, terminate, reboot, recover).
- Can create Systems Manager OpsItems.
Memory trick: CloudWatch Alarm 'SNS-Chatbot-Scale' is the perfect trio for CPU spikes.
AWS CloudTrail
Flip cardA service that enables governance, compliance, operational auditing, and risk auditing of your AWS account by logging actions taken by a user, role, or an AWS service.
- Records API calls and other events.
- Logs are stored in S3 for long-term retention.
- Supports log file integrity validation.
Memory trick: CloudTrail Tracks All API Calls for Audit.
AWS X-Ray Active Tracing (Lambda)
Flip cardA setting for AWS Lambda functions that automatically instruments the function and its calls to other AWS services, sending trace data to X-Ray without explicit SDK calls in the function code.
- Automatically traces invocations and downstream AWS service calls.
- Generates segments for each part of the execution.
- Requires minimal configuration, not manual SDK instrumentation.
Memory trick: X-Ray eXplores eVery Lambda eXecution.
AWS Chatbot for CodeBuild Notifications
Flip cardAWS Chatbot integrates AWS CodeBuild notifications (via EventBridge) into chat platforms like Slack, providing real-time build status updates with minimal configuration.
- Integrates AWS services with Slack/Chime.
- Provides rich, formatted notifications with links.
- Requires minimal setup, no custom code.
Memory trick: Chatbot: CodeBuild's voice in Slack.
AWS X-Ray for Step Functions
Flip cardAWS X-Ray provides end-to-end tracing and visualization for AWS Step Functions workflow executions, helping to identify performance bottlenecks and troubleshoot failures.
- Visualizes the entire workflow as a service map.
- Shows latency for each state and transition.
- Allows drilling down into individual step executions.
- Enables optimization and troubleshooting of complex orchestrations.
Memory trick: X-Ray's 'Step-by-Step Scan' reveals workflow secrets.
Amazon OpenSearch Service (Fine-Grained Access Control)
Flip cardA managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. Its fine-grained access control feature allows for highly specific permissions on indices, types, documents, and fields.
- Provides search, analysis, and visualization capabilities.
- Built on OpenSearch (formerly Elasticsearch).
- Fine-grained access control is crucial for sensitive data.
Memory trick: Firehose Feeds OpenSearch Securely with S3.
CloudTrail Data Events for Lambda
Flip cardAWS CloudTrail can record data events for Lambda functions, capturing details of function invocations as API calls, distinct from runtime logs.
- Captures 'Invoke' API calls for Lambda functions.
- Logs are delivered to an S3 bucket.
- Essential for compliance and auditing of function usage.
Memory trick: CloudTrail's 'Data Diary' on S3 is the immutable truth for Lambda calls.
CloudWatch Agent for Hybrid Logging
Flip cardThe CloudWatch Agent centralizes log collection from both on-premises servers and Amazon EC2 instances into Amazon CloudWatch Logs for unified monitoring and analysis.
- Single agent for hybrid environments.
- Collects application logs (Apache, Nginx, custom) and system logs.
- Integrates with CloudWatch Logs for analysis, retention, and alerting.
Memory trick: CloudWatch Agent: Your logs' bridge from on-prem to CloudWatch.
CloudFront Logs with Athena
Flip cardA serverless solution for analyzing large volumes of Amazon CloudFront access logs stored in S3 using standard SQL queries with Amazon Athena.
- CloudFront logs are delivered to S3.
- Athena queries data directly in S3, no data movement.
- Serverless, pay-per-query, ideal for ad-hoc analysis.
Memory trick: CloudFront to S3, then Athena's SQL magic.
Amazon CloudWatch Container Insights
Flip cardA feature of Amazon CloudWatch that collects, aggregates, and summarizes metrics and logs from containerized applications and microservices running on Amazon ECS, Amazon EKS, and AWS Fargate.
- Provides deep visibility into container performance (CPU, memory, network).
- Automatically collects metrics and logs at various granularities.
- Includes dashboards and can create alarms.
Memory trick: Container Insights Monitors EKS, AMP Adds Prometheus Power.
CloudWatch Container Insights
Flip cardA fully managed monitoring solution for containerized applications, collecting, aggregating, and summarizing metrics and logs from container environments like EKS.
- Provides cluster, node, pod, and container-level metrics.
- Automatically collects and aggregates data.
- Offers pre-built dashboards and log analysis capabilities.
Memory trick: Container Insights: Your EKS Cluster's All-in-One Monitor.
CloudWatch Embedded Metric Format (EMF)
Flip cardA specification for publishing custom metrics to Amazon CloudWatch by embedding them within structured JSON log events. CloudWatch automatically extracts these metrics.
- Embeds multiple metrics in a single log event.
- Reduces API calls and overhead for custom metrics.
- Simplifies metric publishing for serverless applications.
Memory trick: EMF Embeds Metrics Effortlessly from Lambda.
CloudTrail Data Events for S3 Monitoring
Flip cardAWS CloudTrail can record S3 object-level API actions (data events), providing detailed audit trails for access to sensitive data within S3 buckets.
- Captures 'GetObject', 'PutObject', 'DeleteObject', etc.
- Provides source IP, user identity, timestamp, and bucket details.
- Essential for security, compliance, and operational troubleshooting.
- Can be integrated with CloudWatch Logs for real-time alerting.
Memory trick: CloudTrail's 'S3 Data Watch' with Alarms catches bad actors in real-time.
Amazon S3 Glacier Deep Archive
Flip cardAmazon S3 storage class designed for long-term archival and digital preservation with the lowest cost storage in the cloud, suitable for data that is rarely or never accessed.
- Lowest cost S3 storage class.
- Retrieval times typically 12-48 hours.
- Ideal for compliance and long-term archival (7-10+ years).
Memory trick: Logs Export to S3, Lifecycle to Deep Archive.
CloudWatch for Lambda
Flip cardAmazon CloudWatch automatically monitors AWS Lambda functions, collecting key performance metrics and logs.
- Provides invocation count, errors, duration, throttles.
- Offers pre-built dashboards and custom alarms.
- Essential for Lambda function health and performance.
Memory trick: CloudWatch is the Lambda's health monitor.
X-Ray, CloudWatch, Anomaly Detection Combo
Flip cardA powerful combination of AWS services for comprehensive monitoring: X-Ray for distributed tracing, CloudWatch for metrics/logs, and Anomaly Detection for automated deviation detection.
- X-Ray visualizes end-to-end request flow and identifies latency.
- CloudWatch collects all application and service metrics/logs.
- Anomaly Detection automatically learns normal metric patterns and alerts on deviations.
Memory trick: X-Ray traces, CloudWatch measures, Anomaly Detection warns.
CloudWatch Agent for Hybrid Log Collection
Flip cardThe CloudWatch agent is a unified agent that can collect logs and metrics from both AWS EC2 instances and on-premises servers, sending them to Amazon CloudWatch.
- Supports Linux and Windows operating systems.
- Collects application logs and system logs.
- Enables centralized logging for hybrid environments.
- Configurable via JSON files for specific log paths.
Memory trick: CloudWatch Agent is the 'Bridge' for logs from on-prem to cloud insights.
AWS X-Ray for Distributed Tracing
Flip cardAWS X-Ray helps developers analyze and debug distributed applications by collecting data about requests that your application serves.
- Provides end-to-end request tracing.
- Generates service maps to visualize connections and latency.
- Supports various AWS services and custom applications.
- Helps identify performance bottlenecks and errors.
Memory trick: X-Ray traces the 'X-marks-the-spot' of bottlenecks in your distributed app.
DynamoDB CloudWatch Metrics
Flip cardAmazon DynamoDB automatically publishes a comprehensive set of operational and performance metrics to Amazon CloudWatch, offering insights into table and index activity.
- Metrics include read/write capacity, latency, throttled requests.
- Published automatically, no agent or custom code needed.
- Can be used with CloudWatch Alarms for real-time alerts.
- Provides granular visibility into table and index performance.
Memory trick: DynamoDB's 'Built-in CloudWatch' is your instant performance gauge.
CloudWatch Agent (On-Premises)
Flip cardA unified agent that can be installed on both EC2 instances and on-premises servers to collect system-level metrics (CPU, memory, disk), custom metrics, and log files, sending them to Amazon CloudWatch.
- Supports hybrid cloud environments (EC2 and on-premises).
- Collects OS, custom metrics, and logs.
- Simplifies metric and log collection into CloudWatch.
Memory trick: CloudWatch Agent Unifies All Metrics Everywhere.
AWS Chatbot
Flip cardA service that makes it easy to monitor and interact with your AWS resources from Slack or Amazon Chime. It can deliver notifications, run commands, and retrieve diagnostic information.
- Integrates AWS services with Slack and Amazon Chime.
- Delivers notifications from services like CloudWatch, SNS, Security Hub.
- Allows running AWS CLI commands directly from chat.
Memory trick: Chatbot Connects CodeBuild's Cries to Slack.
CloudFront Access Logs with Athena
Flip cardCloudFront access logs provide detailed records of every user request, which can be stored in S3 and queried serverlessly using Amazon Athena for analytics.
- Logs contain IP address, user agent, requested URL, and more.
- Stored in S3, enabling cost-effective long-term retention.
- Athena allows ad-hoc SQL queries directly on S3 data.
- Serverless and scalable solution for web analytics.
Memory trick: CloudFront's 'S3-Athena' combo unlocks web visitor secrets.
Kinesis Firehose to OpenSearch for Centralized Logging
Flip cardA managed architecture for centralizing and analyzing petabytes of security logs (VPC Flow, DNS, WAF) from multiple accounts using Kinesis Data Firehose for ingestion and Amazon OpenSearch Service for real-time search and analytics.
- Kinesis Firehose for scalable, managed log ingestion.
- OpenSearch Service for real-time, petabyte-scale search and analysis.
- Supports long-term retention via OpenSearch data tiers (UltraWarm, Cold Storage) or S3 integration.
- Minimizes operational overhead with fully managed services.
Memory trick: Firehose to OpenSearch: All security logs, instantly searchable.
AWS Region & VPC for Isolation
Flip cardAWS Regions define geographical boundaries for data residency, while Virtual Private Clouds (VPCs) provide logically isolated network environments within a Region for customer resources.
- Regions are geographically distinct areas.
- VPCs are isolated networks, configurable by the user.
- Data within a Region generally stays within that Region.
Memory trick: Stay 'regional' and 'private' to keep data 'safe' and 'home'.
Service Control Policies (SCPs)
Flip cardA type of organizational policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, acting as a security guardrail.
- Apply to all IAM users and roles, including the root user.
- Preventative controls: deny actions before they happen.
- Inherited down the Organizational Unit (OU) hierarchy.
- Do not grant permissions; they filter permissions granted by IAM policies.
Memory trick: SCPs are the organizational 'security chief' that sets the ultimate limits.
Redshift COPY Transactionality
Flip cardAmazon Redshift's `COPY` command, when executed within a SQL transaction block (`BEGIN`...`END`), is an atomic operation. This means that either all data specified in the `COPY` command is loaded successfully, or if any error occurs, the entire operation is rolled back.
- Ensures atomicity for large data loads.
- Prevents partial data loads in case of errors.
- Achieved by wrapping `COPY` in a `BEGIN`...`END` transaction block.
- Crucial for data integrity and consistency in data warehousing.
Memory trick: Treat your 'COPY' like a single package: it either arrives fully or not at all.
Dynamic Secret Retrieval & Rotation
Flip cardA security practice where applications retrieve sensitive credentials (secrets) at runtime from a dedicated secret management service, which also handles automatic rotation of these secrets.
- Eliminates hardcoded secrets and plaintext exposure.
- Automates credential lifecycle management (rotation).
- Uses IAM for fine-grained access control to secrets.
Memory trick: Secrets Manager rotates the key, secure access for apps, you see.
CloudFormation Change Sets
Flip cardAWS CloudFormation Change Sets allow you to preview how proposed changes to a stack template will impact your running resources before you implement them. This is essential for understanding potential disruptions and getting approvals before applying updates, especially in production environments.
- Previews changes to a stack's resources.
- Shows additions, modifications, or deletions.
- Allows for review and approval before execution.
- Crucial for controlled change management.
Memory trick: Change Sets let you 'see' before you 'do'.
AWS Service Catalog
Flip cardAWS Service Catalog allows organizations to create, govern, and manage a catalog of IT services that are approved for use on AWS. These services can include everything from virtual machine images, servers, software, databases, to complete multi-tier application architectures. It enables end-users to self-service these products while adhering to organizational standards.
- Centralized catalog of approved IT services (products).
- Enables self-service provisioning for end-users.
- Ensures governance and compliance with organizational standards.
- Uses CloudFormation templates as the underlying product definition.
Memory trick: Service Catalog is your compliant AWS shopping cart for developers.
Route 53 Failover Routing with Aurora Global Database
Flip cardThis combination provides a robust multi-region disaster recovery solution where Route 53 automatically routes traffic to a healthy region based on health checks, and Aurora Global Database ensures low RPO/RTO for the relational database.
- Route 53 health checks monitor primary region health.
- Failover routing policy automatically switches DNS to secondary region.
- Aurora Global Database replicates data across regions with minimal lag.
- Secondary Aurora region can be promoted to primary for quick recovery.
Memory trick: Route 53 guides, Aurora Global saves the day.
AWS WAF for Web Exploits
Flip cardAWS WAF (Web Application Firewall) protects web applications and APIs from common web exploits like SQL injection and XSS by defining customizable rules to allow, block, or count web requests.
- Integrates with CloudFront, ALB, API Gateway, AppSync, Cognito.
- Filters traffic based on IP addresses, HTTP headers, URI strings, etc.
- Managed rules for common threats are available.
Memory trick: WAF 'guards' the 'web' 'edge' from 'bad' requests.
Secure API Exposure
Flip cardThe process of making API endpoints available while implementing robust security measures, including authentication, authorization, encryption, and protection against common web vulnerabilities.
- Crucial for data protection and compliance.
- Involves multiple layers of security.
- AWS API Gateway is a key service for this.
Memory trick: API Gateway is the secure 'front door' for your application, with WAF and IAM guards.
ECS Task IAM Roles
Flip cardAn AWS IAM role that you can associate with an Amazon ECS task definition to grant specific permissions to the containers within that task.
- Provides granular, least-privilege access to AWS services for tasks.
- Eliminates the need for hardcoded credentials.
- Credentials are automatically managed and rotated by AWS.
Memory trick: Each ECS Task gets its own IAM 'badge' for specific access.
CodeCommit Git Hooks
Flip cardScripts that CodeCommit automatically executes before or after events such as a push, commit, or merge. Pre-receive hooks are server-side and run before a push is accepted, allowing for validation and rejection.
- Automate tasks during Git operations.
- Pre-receive hooks can prevent pushes.
- Useful for enforcing coding standards and security policies.
Memory trick: Git hooks are the 'gatekeepers' preventing secrets from entering the code vault.
DynamoDB Global Tables
Flip cardDynamoDB Global Tables provide a fully managed, multi-region, multi-master database solution that enables fast, local read and write performance for globally distributed applications, along with disaster recovery capabilities.
- Built on DynamoDB Streams for automatic data replication.
- Provides multi-master replication across specified AWS regions.
- Ensures low-latency access for users worldwide.
- Simplifies disaster recovery and global application deployment.
Memory trick: Global Tables link your data across continents, making every read feel local and every write instant.
S3 Security Best Practices
Flip cardA set of guidelines and configurations for Amazon S3 buckets to protect data at rest, control access, and ensure data durability and integrity.
- Encryption at rest (SSE-KMS preferred).
- Least privilege access control (Bucket Policies, IAM).
- Protection against accidental deletion (Versioning, MFA Delete, Object Lock).
Memory trick: KMS encrypts, Policies restrict, Versioning + MFA protects from delete.
Amazon CloudFront CDN
Flip cardA fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs globally with low latency and high transfer speeds.
- Caches content at edge locations worldwide.
- Reduces load on origin servers (e.g., S3).
- Improves user experience by serving content from nearest location.
Memory trick: CloudFront: Catch content fast, clients cheer.
CloudFormation StackSets
Flip cardAWS CloudFormation StackSets extend the functionality of stacks by enabling you to deploy and manage CloudFormation stacks across multiple AWS accounts and regions from a single CloudFormation template. This allows for consistent provisioning and updates of infrastructure across an organization.
- Deploys identical stacks across multiple accounts and regions.
- Managed from a central administrative account.
- Ensures consistent infrastructure across the organization.
- Supports rolling updates and error handling.
Memory trick: StackSets are like a global copy-paste for your CloudFormation.
SAM Function Policies
Flip cardIn AWS Serverless Application Model (SAM), the `Policies` property for an `AWS::Serverless::Function` resource allows you to define specific IAM permissions directly within the function's template. These policies are attached to the Lambda function's execution role, enabling fine-grained control over what the function can access.
- Grants least privilege directly to the function's execution role.
- Supports inline policies defined in the SAM template.
- Can use predefined SAM policy templates or custom IAM policy statements.
- Essential for security and separation of concerns in microservices.
Memory trick: For precise Lambda permissions, use `Policies` directly in SAM.
CloudFormation Guard
Flip cardA policy-as-code tool that allows developers to define rules to validate CloudFormation templates against organizational policies before deployment.
- Enforces security and compliance policies pre-deployment.
- Integrates into CI/CD pipelines for automated checks.
- Prevents non-compliant infrastructure provisioning.
Memory trick: Guard your templates before they build the wrong thing.
ECS Fargate Target Tracking Scaling
Flip cardTarget Tracking scaling for Amazon ECS Fargate automatically adjusts the number of tasks in a service to keep a specific metric (e.g., CPU utilization, ALB request count) at a target value.
- Proactive and reactive scaling.
- Automatically adjusts capacity to maintain performance.
- Simplifies auto-scaling configuration.
- Ideal for fluctuating workloads.
Memory trick: Fargate scales to target, keeps costs in sight.
Asynchronous Decoupling with SQS
Flip cardAn architectural pattern where components communicate indirectly through a message queue like Amazon SQS, preventing direct dependencies.
- Buffers requests, protecting downstream services from overload.
- Enhances fault tolerance by allowing services to process messages at their own pace.
- Prevents cascading failures and improves overall system resilience.
Memory trick: Decouple with queues, conquer cascading chaos.
S3 Cross-Region Replication (CRR)
Flip cardAn S3 feature that automatically replicates objects from a source bucket in one AWS Region to a destination bucket in another AWS Region.
- Asynchronous replication.
- Requires versioning to be enabled on both source and destination buckets.
- Used for disaster recovery, compliance, and latency reduction.
Memory trick: Cross-Region Replication: Copy data, conquer crises.
Centralized Egress Inspection with TGW
Flip cardA Transit Gateway (TGW) facilitates centralized egress traffic inspection by routing all internet-bound traffic from spoke VPCs through an inspection VPC containing a firewall appliance, before reaching the Internet Gateway.
- TGW simplifies inter-VPC routing at scale.
- Enables hub-and-spoke network topology.
- Allows for mandatory traffic inspection before internet access.
Memory trick: All 'traffic' must 'pass' through the 'transit' 'inspection' 'gate'.
Aurora Global Database
Flip cardA single Amazon Aurora database that spans multiple AWS Regions, enabling fast local reads and rapid disaster recovery from a regional outage.
- Asynchronous, continuous replication across regions.
- RPO typically 1 second, RTO less than 1 minute for regional failover.
- Supports up to 5 secondary regions.
Memory trick: Global Database: Go global, guarantee uptime.
Route 53 Failover Routing
Flip cardAmazon Route 53 failover routing policy allows you to route traffic to a healthy backup resource when your primary resource becomes unhealthy, ensuring high availability and disaster recovery.
- Routes traffic to a secondary resource if the primary fails.
- Relies on Route 53 health checks to determine resource health.
- Essential for achieving high availability and disaster recovery (DR).
- Can be configured for active-passive or active-active setups.
Memory trick: When the primary road closes, Failover Routing automatically guides traffic to the detour.
Scheduled Scaling
Flip cardA feature of AWS Auto Scaling that allows you to adjust the capacity of your Auto Scaling group based on a predictable schedule.
- Ideal for predictable traffic patterns (e.g., daily, weekly, seasonal spikes).
- Ensures resources are provisioned proactively before demand increases.
- Can be used to scale both out and in.
Memory trick: Schedule your scaling, save your servers from suffering.
Secrets Manager with CloudFormation
Flip cardAWS Secrets Manager securely stores, manages, and automatically rotates database credentials and other secrets. CloudFormation can integrate with Secrets Manager using dynamic references to retrieve these secrets during stack creation or updates, ensuring secrets are never hardcoded in templates and are managed securely.
- Stores secrets securely (encrypted at rest and in transit).
- Offers automatic rotation for various database types.
- CloudFormation uses dynamic references to retrieve secrets at deploy time.
- Applications retrieve secrets dynamically at runtime from Secrets Manager.
Memory trick: Secrets Manager is your vault for CloudFormation's dynamic secrets.
Amazon CodeGuru Security
Flip cardAn AWS machine learning-powered service that automatically finds security vulnerabilities in your application code and provides recommendations to fix them. It can detect issues like hardcoded secrets, sensitive data exposure, injection flaws, and more.
- Static Application Security Testing (SAST).
- Detects security vulnerabilities and hardcoded secrets in code.
- Integrates with popular code repositories (e.g., GitHub, CodeCommit).
Memory trick: CodeGuru Security is the 'secret detective' of your code repositories.
Lambda Provisioned Concurrency
Flip cardLambda Provisioned Concurrency keeps a specified number of execution environments initialized and ready to respond to invocations instantly. This eliminates cold start latency for those pre-warmed instances, providing consistent low-latency performance.
- Eliminates cold start latency for pre-warmed instances.
- Ensures consistent low-latency performance for critical functions.
- Configurable per function version or alias.
- You pay for the configured concurrency even when idle.
Memory trick: Provisioned Concurrency keeps your Lambda oven pre-heated, ready for instant baking.
SSM Patch Manager with Maintenance Windows
Flip cardAWS Systems Manager Patch Manager automates the patching of EC2 instances, and Maintenance Windows allow scheduling these operations during non-peak hours to minimize disruption.
- Automates OS and application patching.
- Schedules patching during defined windows.
- Ensures compliance and reduces security vulnerabilities.
Memory trick: Patch Manager schedules the fix, Maintenance Window keeps the doors open.