Skip to content
This repository has been archived by the owner on Oct 11, 2021. It is now read-only.

Add note about cloning the bucket for safety purposes #162

Open
villasv opened this issue Mar 14, 2020 · 1 comment
Open

Add note about cloning the bucket for safety purposes #162

villasv opened this issue Mar 14, 2020 · 1 comment
Labels

Comments

@villasv
Copy link
Owner

villasv commented Mar 14, 2020

As I'm increasingly relying on updatable content outside the template (e.g. the metric lambda), it would be best if production deployments don't use this project's public bucket as it becomes a security threat to import and run unmanaged code.

@villasv villasv added the docs label Mar 14, 2020
@villasv
Copy link
Owner Author

villasv commented Apr 27, 2020

After taking a look at other AWS Quick Starts that use lambda (e.g. https://github.com/aws-quickstart/quickstart-cloud9-ide), I've noticed that they have a CopyZipfiles lambda (inline on the template) that makes sure the zipfiles are copied to the account owner own buckets.

This solves the issue of control over the lambda packages, but the issue remains on the startup scripts, which could be eliminated if we use AMIs (#34).

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant