Files
knowledge-wiki/channels/1547165920269439007.md

7.0 KiB
Raw Permalink Blame History

#aws-jam-2026-general

  • Guild: 1518726359512387766
  • Channel: 1547165920269439007
  • Workspace: /opt/data/channels/aws-jam-2026-general
  • Purpose: Work through AWS Jam 2026 challenges using the supplied temporary lab account.
  • Placement rule: All channel-owned files and command execution belong in the workspace above.
  • Credential rule: Temporary AWS credentials are stored only under the workspace secrets/ directory and are never copied into this wiki.

Current challenge

Challenge 008 — Sharing is caring: reusable code across Lambdas

  • Status: Tasks 1–2 completed and verified on 2026-09-09.
  • Region: us-west-2.
  • Task 1: Published tattooine-common:1 for nodejs22.x/x86_64 and attached it to both functions, resolving Runtime.ImportModuleError.
  • Task 2: Published tattooine-common:2 from the task-two artifact for nodejs22.x, nodejs18.x, and x86_64; updated only Function One to v2 and retained Function Two on v1.
  • Result: Function One/v2 returns Happy hour at the Sanctuary!; Function Two/v1 returns The Spaceport is open now. Both invoke with HTTP 200 and no FunctionError.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-008/

Previous challenges

Challenge 007 — Malware In Your Bucket

  • Status: Completed and verified on 2026-09-09.
  • Resources: file-scanning-upload-0da43cf0; bucket-scan-function in us-west-2.
  • Root cause: The replacement bucket had no object-created notification, and the Lambda had no S3 invoke permission. Its execution role already had correct exact-bucket object-read access.
  • Repair: Added one exact-bucket/account-constrained S3 invoke permission and one s3:ObjectCreated:* Lambda notification; uploaded test_file.txt to the existing bucket.
  • Result: Lambda alert reported scan_performed: Yes, scan_result: Detected, detection_rule: AWSome_malware_alert.
  • Submission answer: AWSome_malware_alert.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-007/

Previous challenges

Challenge 006 — My Pipeline is stuck!

  • Status: Completed and verified on 2026-09-09.
  • Region/source: ap-southeast-2; commit 17b14f70e4b7c03256e3f2d61ad5e29e23d4ff1c.
  • Root cause: BrokenPipelineLambdaFunction successfully probed API Gateway but never called CodePipeline's success/failure callback APIs; its role also lacked those two callback permissions.
  • Repair: Added job-ID handling plus PutJobSuccessResult/PutJobFailureResult code paths and only the corresponding two role actions. Preserved the existing API/secret flow and pipeline definition.
  • Result: Local success/failure regression tests passed; deployed package checksum matched; execution ed88adff-391d-400e-a2ef-e85a80bee461 succeeded with both pipeline actions green and API HTTP 200 logged.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-006/

Previous challenges

Challenge 005 — Fix my build issue

  • Status: Completed and verified on 2026-09-09.
  • Region/source: ap-northeast-1; commit 6631553933f09f8f3ce5dc6f8f6505fbc8d5bc64.
  • Root cause: CodeBuild role challenge-codebuild-role lacked artifact S3/KMS read access and the ECR authentication/push actions required by the existing buildspec.
  • Repair: Extended only its existing CodeBuild-Policy, scoping S3, KMS, and ECR push actions to the exact resources; only ecr:GetAuthorizationToken uses required resource *.
  • Result: Pipeline execution 9bcbb91c-b1ef-44f3-87d6-143086b29d25 and CodeBuild succeeded; ECR contains latest and immutable build tag at digest sha256:4a3f0ca1bc896ffbc3274584ac844895f7ed979a3c6cd585b0d22152fbd6f43b.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-005/

Previous challenges

Challenge 004 — AI-Powered Log Analysis using Amazon Bedrock

  • Status: Tasks 1–2 completed and verified on 2026-09-09.
  • Function: bedrock-api-function in eu-west-2.
  • Task 1: Memory 256 MB; timeout 60 seconds.
  • Task 2: EventBridge rule bedrock-log-analysis-schedule is enabled with rate(12 hours); its sole Lambda target and all target settings were preserved.
  • Scope: Only the requested Lambda configuration and EventBridge schedule were changed; function code and service integrations were unchanged.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-004/

Previous challenges

Challenge 003 — Protect my CloudFront Origin

  • Task 1: Direct ALB bypass confirmed over HTTP. Submission answer: I am your origin app you must protect!
  • Task 2: Completed and verified. Security group Jam now permits only TCP/80 from managed CloudFront origin-facing Prefix List ID pl-93a247fa; the 0.0.0.0/0 rule is removed. Direct ALB access times out.
  • Task 3: Completed and deployed. Only Application User sends x-from-cf: MySuperSecret to the origin.
  • Task 4: Completed and verified. Listener priority 1 accepts the exact secret header and returns the application response; the default action returns HTTP 403 text/plain with Access denied.
  • Task 5: Final live validation passed: Application User HTTP 200, Malicious User HTTP 403. Submission answer: 1788947493.297988.
  • Resources found: Application User and Malicious User CloudFront distributions; the Application User origin is ALB Jam in eu-west-2.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-003/

Previous challenges

Challenge 002 — Static website using S3

Previous challenge

Challenge 001 — SNS → SQS → Lambda

  • Task 1: Completed through live AWS CLI mutation and readback on 2026-09-09. The existing topic now has one confirmed SQS subscription to the existing queue; its existing policy authorizes the exact topic. Topic and queue counts were unchanged.
  • Task 2: Completed through live IAM policy mutation and readback on 2026-09-09. The Lambda role’s existing sqs inline policy now additionally allows only sqs:ReceiveMessage against the exact queue ARN; no policy was attached and no wildcard was added.
  • Task 3: Completed through live Lambda mutation and readback on 2026-09-09. One event-source mapping now connects the exact existing queue to the exact existing function and is Enabled.
  • Evidence: /opt/data/channels/aws-jam-2026-general/challenges/challenge-001/