a quick spin of terraform + aws + security
- HCL 95.4%
- Shell 4.6%
| hardened-server | ||
| .gitignore | ||
| .terraform.lock.hcl | ||
| backend.tf | ||
| README.md | ||
⚠️ Mirror. Primary repository: git.digtvbg.com Development, issues, and PRs happen there. The GitHub repo is read-only.
assessment
Used for educational and assessment purposes only, no liability taken or given.
-
SSHD - disabled
-
Application LB - deployed
-
Latest kernel - deployed
-
AWS WAF v2 - deployed on ALB
-
AWS SSM - operational
-
AIDE - deployed
-
SElinux - enforcing
TODO:
-
custom AMI / dockerize - musl based for even less attack vectors
-
aws shield
-
aws guardduty
-
aws inspector
-
cloudwatch alarms and cloudtrail
-
sns on events
-
crowdsec https://www.crowdsec.net/blog/protect-your-applications-with-aws-waf-and-crowdsec