Skip to content

infrastructure limits and security implications #11

@magenx

Description

@magenx

security:
please do not use any:

  1. ssh connections
  2. ssh keys
  3. sudo ALL
  4. single system and php user
  5. undefined acl
  6. writeable folders
  7. executable awscli
  8. IMDSv1

infrastructure:
please do not limit to nor use:

  1. only single region
  2. only 2 AZ in region
  3. bastion hosts
  4. parameters/ip sync

add more randomness to parameters and variables.
many devs will use it for production and deployment own shops, adopting and replicating these issues.

also you create dual ALB with IGW to internal private network and with CloudFront, doesn't looks like quick start reference infrastructure.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions