Container Security covers the practices for securing containers across their lifecycle - from building images to running them in production on ECS, EKS, or Fargate.
user in task definitionawsvpc network mode on ECS for per-task security groupsSecurity practices for Amazon EC2 instances including IMDSv2, security groups, instance profiles, EBS encryption, and patching.
Security considerations for AWS Lambda serverless functions, including execution role permissions, function URL auth, VPC placement, and code signing.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
The security principle of granting only the minimum permissions needed to perform a task - no more, no less.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.