AWS Cloud Operations Blog
Category: Advanced (300)
Cloud Native Application Monitoring for AWS
This blog post will show you how DXC used AWS management tools and services to create a custom cloud native application monitoring framework. DXC made this advanced monitoring offering available to their customers, which resulted in improved customer satisfaction. The business driver DXC has a robust set of tools and capabilities to solve customers’ application […]
AWS Config Rule Development Kit library: Build and operate rules at scale
AWS would like to introduce you to the RDKLib, an open source Python library you can use to build, develop, and deploy custom AWS Config rules at scale. RDKLib works with the AWS Config Rule Development Kit. It is designed to work at the AWS Lambda layer, so you can use the library without needing […]
Running bash commands in AWS CloudFormation templates
Oftentimes we find customers who want to extend their AWS CloudFormation templates by running a few lines of code during template execution. For example, to call an external API. In these cases, customers were directed to use either custom resources, resource types, or macros to accomplish the task. This is such a common pattern that […]
Introducing CloudWatch Lambda Insights
CloudWatch Lambda Insights is a monitoring and troubleshooting solution for serverless applications running on AWS Lambda. The solution collects, aggregates, and summarizes system-level metrics including CPU time, memory, disk, and network. It also collects, aggregates, and summarizes diagnostic information such as cold starts and Lambda worker shutdowns to help you isolate issues with your Lambda […]
Customizing account configuration with AWS Control Tower lifecycle events
In this blog post, we show how to customize the networking configuration in an AWS account. For example by deleting the default VPCs in all AWS Regions, using AWS Resource Access Manager to share the appropriate VPC subnets and using AWS Firewall Manager to apply security groups to VPCs in the account.
Using AWS Systems Manager OpsCenter and AWS Config for compliance monitoring
In this post, I show how AWS Systems Manager OpsCenter can be used to centrally record and mitigate alerts from AWS Config. When AWS Config detects a resource that is out of compliance, an OpsItem is created. This OpsItem is used to track details of the noncompliant resource, record investigative actions, and provide access to […]
AWS Organizations, AWS Config, and Terraform
In this post, I show how you can use AWS Organizations, AWS Config, and HashiCorp’s Terraform to deploy guardrails at scale. AWS Config provides configuration, compliance, and auditing features that are required for governing your resources and providing security posture assessment at scale. With its recent support for AWS Organizations, AWS Config makes it possible […]
AWS CloudFormation StackSet Orchestration: Automated deployment using AWS Step Functions
We often use AWS CloudFormation StackSets to automatically deploy infrastructure into many different accounts. Whether they are managed by AWS Control Tower or AWS Organizations, StackSets provide a simple and automated way to handle the creation of resources and infrastructure right after provisioning a new account. You can automatically deploy StackSets to accounts that belong […]
Use AWS License Manager API operations to manage your software licenses in the cloud
Learn with Shree on how to use AWS License Manager public API operations to manage your software licenses in the cloud.
Deploying application configuration to serverless: Introducing the AWS AppConfig Lambda extension
At AWS, we feel strongly that separating application configuration from application code is a best practice. Being able to deploy configuration independently from code makes it possible to build services like Service Quotas and launch new services and features right as we announce them. If we didn’t separate these, even a simple configuration change would […]