3 ms·
Looked at your video demo, does SubImage actually recommend changes and generate terraform? For example instead of exposing 80/443 to the EC2 instance, deploy a
by nodesocket 2y ago
Looked at your video demo, does SubImage actually recommend changes and generate terraform? For example instead of exposing 80/443 to the EC2 instance, deploy a ELB in-front of it that listens on 80/443 publicaly and only allow the ELB to forward traffic to the ec2 instance. Also, utilize attach role to the ec2 instance to avoid storing AWS credentials in environment vars, though if the instance was compromised an attacker could still access the s3 bucket.
- alexchantavy 2y ago> does SubImage actually recommend changes and generate terraform? We recommend changes, though we don't generate Terraform just yet. Great feedback on the specific fixes for this case, thanks.