Reading time: 5 minutes
The Press Review is back, in better shape than ever! As always, we strive to keep pace with cloud innovations and keep you up to date on the topics that we believe are the most promising. To complete your monitoring, we also recommend reading the Security press review, and the edition dedicated to AI/ML subjects.
News
How Lidl accidentally took on the big guns of cloud computing: Lidl, Cloud provider? To watch! And what do you think? Personally I hope they give each certification an ugly Christmas sweater??
AWS side
News
AWS has deprecated several products without prior notice: that’s it, AWS succumbs to the trend launched by Google (to remember the general public services or GCP killed by Google, visit Google Cemetery ☠️).
New AWS accounts will no longer be able to use the following services: CodeCommit, Cloud9, Mobile Hub, CloudSearch, CodeStar, Amazon Quantum Ledger Database. Not that it’s a big loss (when will there be a tombstone for Beanstalk?), but the sudden cessation of services has operational repercussions for certain customers and questions AWS’s long-term strategy on certain “legacy” services.
The selection of new products
Cloud shell
S3
RDS
EC2
Backup
Security
The great discovery of recent days: An AWS IAM Security Tooling Reference [2024]. With a wide range of open source tools to offer to your customers for security auditing.
Lessons learned
Some interesting posts around the early summer soap opera, the Crowdstrike breakdown:
Hashicorp side
Blog
Terraform Variable Cross Validation: review of the validation functionality introduced in Terraform 1.9; finally enough to really validate compared to previous versions, including the possibility of referring to other variables, the inhabitantsdata sources & co.
Infrastructure Resource Creation with Backstage: yet another post talking about Terraform combined with Backstage; your opinion?
Automate Rotating Credentials using Terraform: simple and effective, the prize of tips and tricks of the month?
Proper setup of IAM federation in Multi-account AWS Organization for Terragrunt: IAM and Organization to terraform? There is a tutorial for that!
Open source
News
Elasticsearch is once again Open Source: take out the popcorn?
10 years of Kubernetes: quite a milestone!
Announcing Karpenter 1.0: not bad either!
Tools
derailed/popeye: A Kubernetes cluster resource sanitizer
stackrox/kube-linter: KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure that the applications represented there follow best practices.
aws-samples/karpenter-blueprints: Karpenter Blueprints is a list of common workload scenarios following best practices.
openbao/openbao: OpenBao exists to provide a software solution to manage, store and distribute sensitive data, including secrets, certificates and keys.
: A CLI application to support you on your Terraform module journey and share your burden of module dependency updates, just as a brave Hobbit helped Frodo carry his 🙂
Besides the rather cool ref, you will find more details on this post. Or otherwise, there is renovate which we were talking about in these lines not so long ago.
aws-samples/aft-account-suspend-close-solution: Example solution that leverages AWS Control Tower Account Factory Terraform (AFT) to streamline the account closure and suspension process. The solution aims to provide a reliable, efficient and rapid way to manage the decommissioning of organizations’ AWS accounts.
dubrowin/AWS-Reasonable-Account-Defaults: CloudFormation template for creating reasonable account defaults around cost surprise alerts
continues/works: GitHub Action runners 10x cheaper. 5x faster caches. Self-hosted on AWS.
loft-sh/devpod: Codespaces but open source, client only and no opinion: works with any IDE and allows you to use any cloud, kubernetes or just docker localhost.
If you are already thinking about an alternative to Cloud9…
console.wut.dev: AWS Resource Explorer
NirDiamant/RAG_Techniques: This repository presents various advanced techniques for recovery augmented generation (RAG) systems. RAG systems combine information retrieval with generative models to provide accurate, context-rich responses
tagazok/bedrock-embed-web: to give a GUI to your Bedrock POC
A little reading…
Food for thought
Adopting Software Engineering Practices Across the Team: a little reminder that is always good.
Smaller, Safer, More Transparent: Advancing Responsible AI with Gemma: Is Responsible AI a Thing?
Amusing
: Create video cutouts and effects in just a few clicks
: now is the time to ask for the GH usernames of your colleagues, the opportunity to roasting pan and put them on their youthful nicknames? You can also test with your favorite publisher or Cloud Provider!
: I doubt that millennials are the fastest, but we’ll see!
Events
Ryan See you in San Francisco on September 13 for AWS Community Day. He will host a session on EDK Pod Identity, and how to improve security and simplify access to AWS services for Kubernetes pods.
And if you can’t attend the Community Day in San Francisco, we recommend reading Reyan’s article on this subject: Simplifying AWS services access for pods with EKS pod identity.