Intéressant comme workflow, l'objectif est de laisser les users/soft créer des EC2 comme ils veulent et avoir les droits seulement sur les EC2 qu'ils ont créé.
Comment ça marche ? auto tagging des EC2 avec l'userid à la création couplé avec une policy qui autorise les action seulement si le tag avec l'userid est présent.
pacon
Dans le meme genre sans l'auto tagging :
http://blogs.aws.amazon.com/security/post/Tx29HCT3ABL7LP3/Resource-level-Permissions-for-EC2-Controlling-Management-Access-on-Specific-Ins
-
https://blogs.aws.amazon.com/security/post/Tx150Z810KS4ZEC/How-to-Automatically-Tag-Amazon-EC2-Resources-in-Response-to-API-Eventswoot nice! ça peut être bien utile
via Doo
-
https://github.com/appbaseio/mirageça a l'air un peu plus compliqué qu'avec irc à première vue
-
https://github.com/hipchat/hubot-hipchatI have a bad habit: grep -r search *
It does not search in hidden files/dir...
Better to do this:
grep -r search .
-
http://stackoverflow.com/questions/10375689/how-can-i-grep-hidden-filesliving in the windows side is a pain
-
http://scnr.net/blog/index.php/archives/61These are the resource's available collections:
classic_addresses
dhcp_options_sets
images
instances
internet_gateways
key_pairs
network_acls
network_interfaces
placement_groups
route_tables
security_groups
snapshots
subnets
volumes
vpc_addresses
vpc_peering_connections
vpcs
-
http://boto3.readthedocs.io/en/latest/reference/services/ec2.html#service-resourcePour un cluster Aurora donné, 3 endpoints :
You can determine which DB instance in an Aurora DB cluster that a connection is connected to by checking the innodb_read_only global variable, as shown in the following example.
SHOW GLOBAL VARIABLES LIKE 'innodb_read_only';
The innodb_read_only variable will be set to ON if you are connected to an Aurora Replica and OFF if you are connected to the primary instance.
-
http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_Aurora.htmlBecause terminal > web interface
To briefly list all env (one env by line):
aws elasticbeanstalk describe-environments|jq -r '.Environments|.[]| [.ApplicationName, .EnvironmentName, .VersionLabel, .Status, .CNAME] | @csv'|sort
To get all info about one env (pass EnvironmentName):
aws elasticbeanstalk describe-environments --environment-names toto-prod
List all subnets:
aws ec2 describe-subnets|jq -r '.Subnets|.[]|.SubnetId'
List all ec2 instanceId:
aws ec2 describe-instances|jq -r '.Reservations|.[]|.Instances|.[]|.InstanceId'
List all ec2 instanceId with its associated subnetId:
aws ec2 describe-instances|jq -r '.Reservations|.[]|.Instances|.[]|[.InstanceId, .SubnetId] | @csv'
-
https://links.infomee.fr/?uMBmyg