<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[AWS Discussion Forum - Portal]]></title>
		<link>https://letstalkaws.com/</link>
		<description><![CDATA[AWS Discussion Forum - https://letstalkaws.com]]></description>
		<pubDate>Tue, 14 Apr 2026 13:41:32 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Best Practices for Securing AWS Lambda and API Gateway in a Serverless Architecture?]]></title>
			<link>https://letstalkaws.com/thread-92.html</link>
			<pubDate>Tue, 10 Oct 2023 09:10:04 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=205">kiroval479</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-92.html</guid>
			<description><![CDATA[I've recently started transitioning some of our monolithic applications to a serverless architecture using AWS Lambda and API Gateway. While I am amazed at the scalability and ease-of-use that comes with serverless, I'm also aware that new architectural patterns introduce new security considerations.<br />
<br />
Current Setup:<br />
<br />
Services: Predominantly AWS Lambda, API Gateway, and DynamoDB.<br />
Architecture: Microservices pattern with each service exposed via API Gateway and business logic handled by Lambda.<br />
Traffic: Our applications receive moderate to high traffic, with expected spikes during product launches and sales.<br />
Concerns and Questions:<br />
<br />
How should I handle authentication and authorization efficiently in a serverless pattern, especially considering the stateless nature of Lambda?<br />
Are there specific security best practices or patterns when interfacing API Gateway with Lambda?<br />
How can I ensure secure data transit between services, especially when integrating with other AWS services or external APIs?<br />
What monitoring and alerting mechanisms should I put in place to detect and respond to potential security threats?<br />
Are there any tools or AWS services specifically geared towards enhancing security in a serverless environment?<br />
I've gone through the <a href="https://www.edureka.co/aws-certification-training" target="_blank" rel="noopener" class="mycode_url">AWS</a> Well-Architected Framework and have a basic understanding of security pillars. However, real-world experiences and nuanced insights from this community would be invaluable.<br />
<br />
Thank you in advance for your guidance and sharing your expertise!]]></description>
			<content:encoded><![CDATA[I've recently started transitioning some of our monolithic applications to a serverless architecture using AWS Lambda and API Gateway. While I am amazed at the scalability and ease-of-use that comes with serverless, I'm also aware that new architectural patterns introduce new security considerations.<br />
<br />
Current Setup:<br />
<br />
Services: Predominantly AWS Lambda, API Gateway, and DynamoDB.<br />
Architecture: Microservices pattern with each service exposed via API Gateway and business logic handled by Lambda.<br />
Traffic: Our applications receive moderate to high traffic, with expected spikes during product launches and sales.<br />
Concerns and Questions:<br />
<br />
How should I handle authentication and authorization efficiently in a serverless pattern, especially considering the stateless nature of Lambda?<br />
Are there specific security best practices or patterns when interfacing API Gateway with Lambda?<br />
How can I ensure secure data transit between services, especially when integrating with other AWS services or external APIs?<br />
What monitoring and alerting mechanisms should I put in place to detect and respond to potential security threats?<br />
Are there any tools or AWS services specifically geared towards enhancing security in a serverless environment?<br />
I've gone through the <a href="https://www.edureka.co/aws-certification-training" target="_blank" rel="noopener" class="mycode_url">AWS</a> Well-Architected Framework and have a basic understanding of security pillars. However, real-world experiences and nuanced insights from this community would be invaluable.<br />
<br />
Thank you in advance for your guidance and sharing your expertise!]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Purchasing Windows Server Reserved Instance]]></title>
			<link>https://letstalkaws.com/thread-87.html</link>
			<pubDate>Fri, 17 Mar 2023 18:54:43 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=189">rnrstar</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-87.html</guid>
			<description><![CDATA[I'm looking to plunk down and buy a reserved instance for some Windows Server 2019 standard instances. I just want to make sure I'm selecting the right instance as my options appear to be Windows, Windows with SQL Server Standard, Windows with SQL Server Web, and Windows with SQL Server Enterprise. I don't need SQL server. I'm thinking that the Windows option is the correct one even though it doesn't say server.]]></description>
			<content:encoded><![CDATA[I'm looking to plunk down and buy a reserved instance for some Windows Server 2019 standard instances. I just want to make sure I'm selecting the right instance as my options appear to be Windows, Windows with SQL Server Standard, Windows with SQL Server Web, and Windows with SQL Server Enterprise. I don't need SQL server. I'm thinking that the Windows option is the correct one even though it doesn't say server.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[AWS VPN]]></title>
			<link>https://letstalkaws.com/thread-85.html</link>
			<pubDate>Sat, 04 Mar 2023 10:27:43 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=183">Tucix</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-85.html</guid>
			<description><![CDATA[Hello,<br />
 <br />
I totally disagree with the following sentence, because by definition a VPN provides a private connection based on FAI requirements (private IP addresses) :<br />
<br />
"<br />
a VPG is the AWS-side of an AWS VPN. A VPN does not provide a private connection and is not reliable as you can never guarantee the latency over the internet<br />
"<br />
 Is there something wrong in my reasoning ?<br />
<br />
Thanks,]]></description>
			<content:encoded><![CDATA[Hello,<br />
 <br />
I totally disagree with the following sentence, because by definition a VPN provides a private connection based on FAI requirements (private IP addresses) :<br />
<br />
"<br />
a VPG is the AWS-side of an AWS VPN. A VPN does not provide a private connection and is not reliable as you can never guarantee the latency over the internet<br />
"<br />
 Is there something wrong in my reasoning ?<br />
<br />
Thanks,]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[session policy]]></title>
			<link>https://letstalkaws.com/thread-84.html</link>
			<pubDate>Sat, 04 Mar 2023 09:04:52 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=183">Tucix</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-84.html</guid>
			<description><![CDATA[Hello,<br />
<br />
What is a session policy in the context of the IAM ?<br />
 I know what Resource-based policy and Identity-based policy are, but not session policy. <br />
<br />
Regards,]]></description>
			<content:encoded><![CDATA[Hello,<br />
<br />
What is a session policy in the context of the IAM ?<br />
 I know what Resource-based policy and Identity-based policy are, but not session policy. <br />
<br />
Regards,]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Auto-Scaling Group ASG]]></title>
			<link>https://letstalkaws.com/thread-83.html</link>
			<pubDate>Thu, 02 Mar 2023 19:30:10 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=183">Tucix</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-83.html</guid>
			<description><![CDATA[Hello,<br />
<br />
Based on my knowledge, there are two types of scaling : the up/down scaling and the out/in scaling.<br />
<br />
I'm a bit surprised to see that in AWS Courses (so as in AWS Solution Architects Exam Preparation Book) I missed the up/down scaling !<br />
<br />
Indeed, I always found that typical example :<br />
<br />
- in the "Increase Group Size" Window in the "Take the action" item the CAPACITY UNIT is activated (that is to say, this represents the instance number).<br />
<br />
In case of a up/down scaling, we are supposed to modify the CPU and/or the RAM. <br />
<br />
But I never see such information in the "Take action" item, is that normal ?<br />
<br />
Regards,]]></description>
			<content:encoded><![CDATA[Hello,<br />
<br />
Based on my knowledge, there are two types of scaling : the up/down scaling and the out/in scaling.<br />
<br />
I'm a bit surprised to see that in AWS Courses (so as in AWS Solution Architects Exam Preparation Book) I missed the up/down scaling !<br />
<br />
Indeed, I always found that typical example :<br />
<br />
- in the "Increase Group Size" Window in the "Take the action" item the CAPACITY UNIT is activated (that is to say, this represents the instance number).<br />
<br />
In case of a up/down scaling, we are supposed to modify the CPU and/or the RAM. <br />
<br />
But I never see such information in the "Take action" item, is that normal ?<br />
<br />
Regards,]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Target group health check failed]]></title>
			<link>https://letstalkaws.com/thread-82.html</link>
			<pubDate>Fri, 24 Feb 2023 10:54:35 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=182">sreekarachanta</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-82.html</guid>
			<description><![CDATA[Folks we are facing the below issue , can anyone help me here?  <br />
<br />
Issue: Target group health check failing .<br />
<br />
We configured blue green ecs deployment . When we have a single ec2 instance in the cluster and when we create ECS service with desired task count as 1 - the task will place a container on port 8080.  <br />
<br />
Next time when we do a deployment - the service fails since the port 8080 is already in use in the container instance . So we decided to use the dynamic port mapping in task definition but in that case the target group health check is failing with the settings like in the image.<br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://letstalkaws.com/images/attachtypes/image.png" title="JPG Image" border="0" alt=".jpg" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=20" target="_blank" title="">PHOTO-2023-02-24-10-43-39.jpg</a> (Size: 35.77 KB / Downloads: 512)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[Folks we are facing the below issue , can anyone help me here?  <br />
<br />
Issue: Target group health check failing .<br />
<br />
We configured blue green ecs deployment . When we have a single ec2 instance in the cluster and when we create ECS service with desired task count as 1 - the task will place a container on port 8080.  <br />
<br />
Next time when we do a deployment - the service fails since the port 8080 is already in use in the container instance . So we decided to use the dynamic port mapping in task definition but in that case the target group health check is failing with the settings like in the image.<br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://letstalkaws.com/images/attachtypes/image.png" title="JPG Image" border="0" alt=".jpg" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=20" target="_blank" title="">PHOTO-2023-02-24-10-43-39.jpg</a> (Size: 35.77 KB / Downloads: 512)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[EC2 key pair]]></title>
			<link>https://letstalkaws.com/thread-79.html</link>
			<pubDate>Thu, 29 Sep 2022 00:33:51 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=154">fborges5555</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-79.html</guid>
			<description><![CDATA[Hi gurus.<br />
<br />
I have an ec2 instance already with a Key-pair, is there a way I can have a second Key-pair for a user to use SSH tunnel to this ec2 that already exists?<br />
<br />
Thanks gurus]]></description>
			<content:encoded><![CDATA[Hi gurus.<br />
<br />
I have an ec2 instance already with a Key-pair, is there a way I can have a second Key-pair for a user to use SSH tunnel to this ec2 that already exists?<br />
<br />
Thanks gurus]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Working on creating an ELK Stack]]></title>
			<link>https://letstalkaws.com/thread-77.html</link>
			<pubDate>Tue, 20 Sep 2022 19:53:18 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=151">semajlions</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-77.html</guid>
			<description><![CDATA[Any ideas as to what may cause this Logstash error?<br />
<br />
Error occurs after running this command<br />
<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code># /usr/share/logstash/bin/logstash -f /etc/logstash --config.test_and_exit<br />
<br />
[2022-09-20T19:41:49,063][FATAL][logstash.runner          ] The given configuration is invalid. Reasod one of [ &#92;t&#92;r&#92;n], "#", "input", "filter", "output" at line 6, column 1 (byte 132) after<br />
<br />
[2022-09-20T19:41:49,066][FATAL][org.logstash.Logstash    ] Logstash stopped processing because of anystemExit) exit</code></div></div><br />
<br />
I've modified line 6 numerous times and even eliminated the filter, same error.]]></description>
			<content:encoded><![CDATA[Any ideas as to what may cause this Logstash error?<br />
<br />
Error occurs after running this command<br />
<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code># /usr/share/logstash/bin/logstash -f /etc/logstash --config.test_and_exit<br />
<br />
[2022-09-20T19:41:49,063][FATAL][logstash.runner          ] The given configuration is invalid. Reasod one of [ &#92;t&#92;r&#92;n], "#", "input", "filter", "output" at line 6, column 1 (byte 132) after<br />
<br />
[2022-09-20T19:41:49,066][FATAL][org.logstash.Logstash    ] Logstash stopped processing because of anystemExit) exit</code></div></div><br />
<br />
I've modified line 6 numerous times and even eliminated the filter, same error.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Working on creating an ELK Stack]]></title>
			<link>https://letstalkaws.com/thread-76.html</link>
			<pubDate>Tue, 20 Sep 2022 18:57:33 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=151">semajlions</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-76.html</guid>
			<description><![CDATA[Hello, my name is James, and I am studying to become an Associate Solution Architect, at work my manager has tasked me to create an ELK Stack. I've run into some issues and hoping to get some assistance in this forum.]]></description>
			<content:encoded><![CDATA[Hello, my name is James, and I am studying to become an Associate Solution Architect, at work my manager has tasked me to create an ELK Stack. I've run into some issues and hoping to get some assistance in this forum.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[AWS CLOUDWATCH LOGS_$context.requestOverride.header.*]]></title>
			<link>https://letstalkaws.com/thread-75.html</link>
			<pubDate>Wed, 24 Aug 2022 10:33:00 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://letstalkaws.com/member.php?action=profile&uid=146">Jyotheesh_K</a>]]></dc:creator>
			<guid isPermaLink="false">https://letstalkaws.com/thread-75.html</guid>
			<description><![CDATA[Trying to fetch header values from request using Access logging Variables(&#36;context.requestOverride.header.*) provided by AWS for an API Gateway. This Particular value is not Logging in CloudWatch.Please find attached document.<br />
<br />
Please let me know if I need to do anything further.<br />
<br />
<br />
Thanks &amp; Regards<br />
Jyotheesh K<br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://letstalkaws.com/images/attachtypes/doc.png" title="Microsoft Word 2007 Document" border="0" alt=".docx" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=17" target="_blank" title="">AWS CLoudWatchLogs-requestheader.docx</a> (Size: 33.37 KB / Downloads: 484)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[Trying to fetch header values from request using Access logging Variables(&#36;context.requestOverride.header.*) provided by AWS for an API Gateway. This Particular value is not Logging in CloudWatch.Please find attached document.<br />
<br />
Please let me know if I need to do anything further.<br />
<br />
<br />
Thanks &amp; Regards<br />
Jyotheesh K<br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://letstalkaws.com/images/attachtypes/doc.png" title="Microsoft Word 2007 Document" border="0" alt=".docx" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=17" target="_blank" title="">AWS CLoudWatchLogs-requestheader.docx</a> (Size: 33.37 KB / Downloads: 484)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
	</channel>
</rss>