3 ms·
If you are hand-managing VPCs then there is every chance that this additional layer of complexity will lead to mistakes. You could argue that the increase in co
by danial 7y ago
If you are hand-managing VPCs then there is every chance that this additional layer of complexity will lead to mistakes. You could argue that the increase in cognitive load of managing them can offset the benefits of an additional defense-in-depth control. New developers joining the team are likely to make mistakes and this is the sort of thing that doesn't get caught in code reviews either.
However, VPC configurations are an essential defense-in-depth that can be programmatically managed. AWS-managed VPCs are certainly not hand managed.
While maintaining Cloudformation or Terraform templates is still a pain, the good news is that it is becoming increasingly easier via frameworks like AWS CDK. This allows your deployment code to programatically generate the infrastructure and VPC configuration. This decreases the likelihood of mistakes made in configuration and increases the chances of such mistakes being caught during code reviews.
- braindongle 7y agoYes. Also, if you're not serverless but are containerized, ECS/Fargate has a simple workflow through the console that in turn runs Cloudformation and sets things up (VPC, gateway, load balancer, security groups...) with sensible defaults. You do still need to learn how to lock things down, inbound/outbound rules especially. For pros, the console is simply not the way, but for your first Spiffy Dockerized App, this is great. Also, the new Amazon-managed firewall rules for web-apps are killer for app developers who are not security pros![0] Lest this sound like Fanboyism, our long-term strategy is Firebase, calling AWS APIs when necessary :) [0] https://aws.amazon.com/blogs/aws/announcing-aws-managed-rules-for-aws-waf/ https://aws.amazon.com/blogs/aws/announcing-aws-managed-rule...