# #aws-jam-2026-general - **Guild:** `1518726359512387766` - **Channel:** `1547165920269439007` - **Workspace:** `/opt/data/channels/aws-jam-2026-general` - **Purpose:** Work through AWS Jam 2026 challenges using the supplied temporary lab account. - **Placement rule:** All channel-owned files and command execution belong in the workspace above. - **Credential rule:** Temporary AWS credentials are stored only under the workspace `secrets/` directory and are never copied into this wiki. ## Current challenge ### Challenge 008 — Sharing is caring: reusable code across Lambdas - **Status:** Tasks 1–2 completed and verified on 2026-09-09. - **Region:** `us-west-2`. - **Task 1:** Published `tattooine-common:1` for `nodejs22.x`/`x86_64` and attached it to both functions, resolving `Runtime.ImportModuleError`. - **Task 2:** Published `tattooine-common:2` from the task-two artifact for `nodejs22.x`, `nodejs18.x`, and `x86_64`; updated only Function One to v2 and retained Function Two on v1. - **Result:** Function One/v2 returns `Happy hour at the Sanctuary!`; Function Two/v1 returns `The Spaceport is open now.` Both invoke with HTTP `200` and no `FunctionError`. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-008/` ## Previous challenges ### Challenge 007 — Malware In Your Bucket - **Status:** Completed and verified on 2026-09-09. - **Resources:** `file-scanning-upload-0da43cf0`; `bucket-scan-function` in `us-west-2`. - **Root cause:** The replacement bucket had no object-created notification, and the Lambda had no S3 invoke permission. Its execution role already had correct exact-bucket object-read access. - **Repair:** Added one exact-bucket/account-constrained S3 invoke permission and one `s3:ObjectCreated:*` Lambda notification; uploaded `test_file.txt` to the existing bucket. - **Result:** Lambda alert reported `scan_performed: Yes`, `scan_result: Detected`, `detection_rule: AWSome_malware_alert`. - **Submission answer:** `AWSome_malware_alert`. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-007/` ## Previous challenges ### Challenge 006 — My Pipeline is stuck! - **Status:** Completed and verified on 2026-09-09. - **Region/source:** `ap-southeast-2`; commit `17b14f70e4b7c03256e3f2d61ad5e29e23d4ff1c`. - **Root cause:** `BrokenPipelineLambdaFunction` successfully probed API Gateway but never called CodePipeline's success/failure callback APIs; its role also lacked those two callback permissions. - **Repair:** Added job-ID handling plus `PutJobSuccessResult`/`PutJobFailureResult` code paths and only the corresponding two role actions. Preserved the existing API/secret flow and pipeline definition. - **Result:** Local success/failure regression tests passed; deployed package checksum matched; execution `ed88adff-391d-400e-a2ef-e85a80bee461` succeeded with both pipeline actions green and API HTTP `200` logged. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-006/` ## Previous challenges ### Challenge 005 — Fix my build issue - **Status:** Completed and verified on 2026-09-09. - **Region/source:** `ap-northeast-1`; commit `6631553933f09f8f3ce5dc6f8f6505fbc8d5bc64`. - **Root cause:** CodeBuild role `challenge-codebuild-role` lacked artifact S3/KMS read access and the ECR authentication/push actions required by the existing buildspec. - **Repair:** Extended only its existing `CodeBuild-Policy`, scoping S3, KMS, and ECR push actions to the exact resources; only `ecr:GetAuthorizationToken` uses required resource `*`. - **Result:** Pipeline execution `9bcbb91c-b1ef-44f3-87d6-143086b29d25` and CodeBuild succeeded; ECR contains `latest` and immutable build tag at digest `sha256:4a3f0ca1bc896ffbc3274584ac844895f7ed979a3c6cd585b0d22152fbd6f43b`. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-005/` ## Previous challenges ### Challenge 004 — AI-Powered Log Analysis using Amazon Bedrock - **Status:** Tasks 1–2 completed and verified on 2026-09-09. - **Function:** `bedrock-api-function` in `eu-west-2`. - **Task 1:** Memory `256 MB`; timeout `60 seconds`. - **Task 2:** EventBridge rule `bedrock-log-analysis-schedule` is enabled with `rate(12 hours)`; its sole Lambda target and all target settings were preserved. - **Scope:** Only the requested Lambda configuration and EventBridge schedule were changed; function code and service integrations were unchanged. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-004/` ## Previous challenges ### Challenge 003 — Protect my CloudFront Origin - **Task 1:** Direct ALB bypass confirmed over HTTP. Submission answer: `I am your origin app you must protect!` - **Task 2:** Completed and verified. Security group `Jam` now permits only TCP/80 from managed CloudFront origin-facing Prefix List ID `pl-93a247fa`; the `0.0.0.0/0` rule is removed. Direct ALB access times out. - **Task 3:** Completed and deployed. Only `Application User` sends `x-from-cf: MySuperSecret` to the origin. - **Task 4:** Completed and verified. Listener priority `1` accepts the exact secret header and returns the application response; the default action returns HTTP `403 text/plain` with `Access denied`. - **Task 5:** Final live validation passed: Application User HTTP `200`, Malicious User HTTP `403`. Submission answer: `1788947493.297988`. - **Resources found:** `Application User` and `Malicious User` CloudFront distributions; the Application User origin is ALB `Jam` in `eu-west-2`. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-003/` ## Previous challenges ### Challenge 002 — Static website using S3 - **Status:** Completed and publicly verified on 2026-09-09. - **Bucket:** `aws-jam-082592851644-jam-fuel` — the only created `aws-jam-*` bucket. - **Website:** Static hosting enabled with `index.html` and `error.html`; bucket-level public blocks disabled and public policy limited to `s3:GetObject` on this bucket’s objects. - **Endpoint:** http://aws-jam-082592851644-jam-fuel.s3-website-us-east-1.amazonaws.com - **Validator submission URL:** https://aws-jam-082592851644-jam-fuel.s3.amazonaws.com/index.html - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-002/` ## Previous challenge ### Challenge 001 — SNS → SQS → Lambda - **Task 1:** Completed through live AWS CLI mutation and readback on 2026-09-09. The existing topic now has one confirmed SQS subscription to the existing queue; its existing policy authorizes the exact topic. Topic and queue counts were unchanged. - **Task 2:** Completed through live IAM policy mutation and readback on 2026-09-09. The Lambda role’s existing `sqs` inline policy now additionally allows only `sqs:ReceiveMessage` against the exact queue ARN; no policy was attached and no wildcard was added. - **Task 3:** Completed through live Lambda mutation and readback on 2026-09-09. One event-source mapping now connects the exact existing queue to the exact existing function and is `Enabled`. - **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-001/`