5 ms·
Well, I'll pass. Prompt: how to connect a lambda function to an RDS instance and query it safely? 1. Configure your RDS instance for outbound connections to A
by CSDude 3y ago
Well, I'll pass.
Prompt: how to connect a lambda function to an RDS instance and query it safely?
1. Configure your RDS instance for outbound connections to AWS Lambda. This step involves ensuring that your DB instance is in a public subnet on your VPC and that the instance's "PubliclyAccessible" property is set to true.
- klysm 3y agoLol yeah no thanks. This is one of things that makes me nervous about using LLMs. If the internet contains shitty solutions for solving a problem, it’s going to recommend shitty solutions. Inexperienced folks won’t know better. There’s also the thing where that’s a positive feedback look and we overflow the worlds corpus with garbage.
- WrtCdEvrydy 3y ago> Inexperienced folks won’t know better. I've seen answers like this in Stack Overflow before. Technically correct, but basically broken in every other way: cybersecurity's future is gonna be interesting.
- scarface_74 3y agoOne of my pet peeves about almost every answer on Stack Overflow is that the answer always starts with client=boto3.client(<service>, access-key,secret-key) There is never a reason to include those last two parameters. It’s always a security risk no matter how you do it.
- klysm 3y agoThis is great example, and I think it’s a smaller version of the same problem.
- jacurtis 3y agoFor that matter, using an access-key or secret-key at all is basically an anti-pattern now. In the past few months AWS has added to their UI a popup box that asks you why you are creating access keys, it makes you answer it before generating the keys. Once you give it the answer it tells you better ways to do almost anything you're trying to do, and you have to agree to ignore those suggestions one more time before actually generating the keys. Basically the standard access keys are really of no use anymore. You should be using roles, OIDC, IAM Identity Center, cognito federated identities, or something else. There are a million ways to identify yourself that are more secure than that and I wish tutorials stopped assuming that you should generate access keys because in no practical 2023 use case should you be doing that anymore. Especially not in any sort of sensitive or corporate environment.
- klysm 3y agoI really do appreciate the effort they’ve gone through there though - they didn’t have to.
- esquire_900 3y agoI think they do. Given the damage that leaked keys can do (especially in the Bitcoin mining area) it must be an expensive problem for them.
- poxrud 3y agoIt’s still the fastest and most common way to get aws cli working on a local dev machine.
- scarface_74 3y agoIf you’re part of any decently large organization, you’re probably using Control Tower or another solution that lets you create temporary credentials easily.
- donmcronald 3y ago> If the internet contains shitty solutions for solving a problem, it’s going to recommend shitty solutions. Have you ever noticed how the dumbest people tend be be the loudest, most confident, and most eager to share their opinions? Those are the voices that trained ChatGPT. It’s a hard pass for me, but I fear I’m going to be forced to used it because the dumbest half of humanity will view it as a peer and use it for everything.
- scarface_74 3y agoAsking the same question to Chatgpt To connect a Lambda function to an RDS (Relational Database Service) instance and query it safely, you can follow these general steps: 1. Configure your Lambda function's execution role: Ensure that your Lambda function has the necessary permissions to access the RDS instance. The role should include the `AWSLambdaVPCAccessExecutionRole` and the appropriate RDS permissions. 2. Place your Lambda function and RDS instance in the same VPC: Ensure that both the Lambda function and the RDS instance are in the same Virtual Private Cloud (VPC) to enable their communication. You can configure the VPC settings in the AWS Management Console. 3. Configure the security group settings: Set up the security groups for your Lambda function and RDS instance to allow the necessary inbound and outbound connections. The Lambda function's security group should allow outbound access to the RDS instance's security group on the RDS port (usually port 3306 for MySQL or 5432 for PostgreSQL). 4. Create a subnet group: If your RDS instance is in a private subnet, create a subnet group that includes the appropriate subnets for your Lambda function to access the RDS instance securely. 5. Connect to the RDS instance from the Lambda function: In your Lambda function code, establish a database connection using the appropriate database client library, such as pymysql for MySQL or psycopg2 for PostgreSQL. Use the connection details (endpoint, username, password, etc.) of your RDS instance. 6. Execute queries safely: To query the RDS instance safely, ensure that your Lambda function's code incorporates secure coding practices. Use parameterized queries or prepared statements to prevent SQL injection attacks. Avoid storing sensitive information (such as database credentials) in your Lambda function code and instead use environment variables or AWS Secrets Manager for secure storage and retrieval. Remember to regularly update and patch your Lambda function, RDS instance, and associated dependencies to maintain security and stay protected against potential vulnerabilities. It's worth noting that the exact implementation details may vary depending on your specific use case, programming language, and AWS setup. Consulting the AWS documentation and resources related to Lambda, RDS, and VPC networking can provide more detailed and up-to-date instructions for your specific requirements.
- 8note 3y agoThis all looks about right, but how would somebody without aws experience be able to validate it without making a mess?
- vasili111 3y agoI find the links from where AI got information more useful than answer of AI.
- Jianghong94 3y agoAWS has some great documentations