AWS Fargate is a serverless compute engine for containers that removes the need to manage EC2 instances. Each Fargate task runs in its own isolated microVM (based on Firecracker), providing kernel-level isolation between customers.
Security practices for containerized workloads on AWS (ECS, EKS, Fargate) including image scanning, runtime security, and network policies.
The framework defining that AWS is responsible for security of the cloud (infrastructure), while customers are responsible for security in the cloud (data, access, configuration).
The security principle of granting only the minimum permissions needed to perform a task - no more, no less.
The practice of securely storing, accessing, and rotating sensitive data like API keys, database passwords, and tokens using services like AWS Secrets Manager.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.