3 ms·
This is a funny idea, I imagine you could do this with other services as well, for example you could use an API Gateway as long as you give read only keys for
by Znafon 6y ago
This is a funny idea, I imagine you could do this with other services as well, for example you could use an API Gateway as long as you give read only keys for API Gateway and Route53?
- captn3m0 6y agoYeah, but then you're auditing more pieces (is the gateway logging? is it mirroring traffic?). Route53 is also tricky, because you will need to prove the whole chain from your namesever. It won't even work for domains registered outside AWS, because you could have a second NS listed and that needs special treatment to catch. Using the Lambda execution endpoints (the ones that look like https://API-ID.execute-api.REGION.amazonaws.com/STAGE https://API-ID.execute-api.REGION.amazonaws.com/STAGE) avoids a lot of these concerns.