Files
knowledge-wiki/channels/1547165920269439007.md
T

97 lines
7.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# #aws-jam-2026-general
- **Guild:** `1518726359512387766`
- **Channel:** `1547165920269439007`
- **Workspace:** `/opt/data/channels/aws-jam-2026-general`
- **Purpose:** Work through AWS Jam 2026 challenges using the supplied temporary lab account.
- **Placement rule:** All channel-owned files and command execution belong in the workspace above.
- **Credential rule:** Temporary AWS credentials are stored only under the workspace `secrets/` directory and are never copied into this wiki.
## Current challenge
### Challenge 008 — Sharing is caring: reusable code across Lambdas
- **Status:** Tasks 1–2 completed and verified on 2026-09-09.
- **Region:** `us-west-2`.
- **Task 1:** Published `tattooine-common:1` for `nodejs22.x`/`x86_64` and attached it to both functions, resolving `Runtime.ImportModuleError`.
- **Task 2:** Published `tattooine-common:2` from the task-two artifact for `nodejs22.x`, `nodejs18.x`, and `x86_64`; updated only Function One to v2 and retained Function Two on v1.
- **Result:** Function One/v2 returns `Happy hour at the Sanctuary!`; Function Two/v1 returns `The Spaceport is open now.` Both invoke with HTTP `200` and no `FunctionError`.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-008/`
## Previous challenges
### Challenge 007 — Malware In Your Bucket
- **Status:** Completed and verified on 2026-09-09.
- **Resources:** `file-scanning-upload-0da43cf0`; `bucket-scan-function` in `us-west-2`.
- **Root cause:** The replacement bucket had no object-created notification, and the Lambda had no S3 invoke permission. Its execution role already had correct exact-bucket object-read access.
- **Repair:** Added one exact-bucket/account-constrained S3 invoke permission and one `s3:ObjectCreated:*` Lambda notification; uploaded `test_file.txt` to the existing bucket.
- **Result:** Lambda alert reported `scan_performed: Yes`, `scan_result: Detected`, `detection_rule: AWSome_malware_alert`.
- **Submission answer:** `AWSome_malware_alert`.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-007/`
## Previous challenges
### Challenge 006 — My Pipeline is stuck!
- **Status:** Completed and verified on 2026-09-09.
- **Region/source:** `ap-southeast-2`; commit `17b14f70e4b7c03256e3f2d61ad5e29e23d4ff1c`.
- **Root cause:** `BrokenPipelineLambdaFunction` successfully probed API Gateway but never called CodePipeline's success/failure callback APIs; its role also lacked those two callback permissions.
- **Repair:** Added job-ID handling plus `PutJobSuccessResult`/`PutJobFailureResult` code paths and only the corresponding two role actions. Preserved the existing API/secret flow and pipeline definition.
- **Result:** Local success/failure regression tests passed; deployed package checksum matched; execution `ed88adff-391d-400e-a2ef-e85a80bee461` succeeded with both pipeline actions green and API HTTP `200` logged.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-006/`
## Previous challenges
### Challenge 005 — Fix my build issue
- **Status:** Completed and verified on 2026-09-09.
- **Region/source:** `ap-northeast-1`; commit `6631553933f09f8f3ce5dc6f8f6505fbc8d5bc64`.
- **Root cause:** CodeBuild role `challenge-codebuild-role` lacked artifact S3/KMS read access and the ECR authentication/push actions required by the existing buildspec.
- **Repair:** Extended only its existing `CodeBuild-Policy`, scoping S3, KMS, and ECR push actions to the exact resources; only `ecr:GetAuthorizationToken` uses required resource `*`.
- **Result:** Pipeline execution `9bcbb91c-b1ef-44f3-87d6-143086b29d25` and CodeBuild succeeded; ECR contains `latest` and immutable build tag at digest `sha256:4a3f0ca1bc896ffbc3274584ac844895f7ed979a3c6cd585b0d22152fbd6f43b`.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-005/`
## Previous challenges
### Challenge 004 — AI-Powered Log Analysis using Amazon Bedrock
- **Status:** Tasks 1–2 completed and verified on 2026-09-09.
- **Function:** `bedrock-api-function` in `eu-west-2`.
- **Task 1:** Memory `256 MB`; timeout `60 seconds`.
- **Task 2:** EventBridge rule `bedrock-log-analysis-schedule` is enabled with `rate(12 hours)`; its sole Lambda target and all target settings were preserved.
- **Scope:** Only the requested Lambda configuration and EventBridge schedule were changed; function code and service integrations were unchanged.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-004/`
## Previous challenges
### Challenge 003 — Protect my CloudFront Origin
- **Task 1:** Direct ALB bypass confirmed over HTTP. Submission answer: `I am your origin app you must protect!`
- **Task 2:** Completed and verified. Security group `Jam` now permits only TCP/80 from managed CloudFront origin-facing Prefix List ID `pl-93a247fa`; the `0.0.0.0/0` rule is removed. Direct ALB access times out.
- **Task 3:** Completed and deployed. Only `Application User` sends `x-from-cf: MySuperSecret` to the origin.
- **Task 4:** Completed and verified. Listener priority `1` accepts the exact secret header and returns the application response; the default action returns HTTP `403 text/plain` with `Access denied`.
- **Task 5:** Final live validation passed: Application User HTTP `200`, Malicious User HTTP `403`. Submission answer: `1788947493.297988`.
- **Resources found:** `Application User` and `Malicious User` CloudFront distributions; the Application User origin is ALB `Jam` in `eu-west-2`.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-003/`
## Previous challenges
### Challenge 002 — Static website using S3
- **Status:** Completed and publicly verified on 2026-09-09.
- **Bucket:** `aws-jam-082592851644-jam-fuel` — the only created `aws-jam-*` bucket.
- **Website:** Static hosting enabled with `index.html` and `error.html`; bucket-level public blocks disabled and public policy limited to `s3:GetObject` on this bucket’s objects.
- **Endpoint:** http://aws-jam-082592851644-jam-fuel.s3-website-us-east-1.amazonaws.com
- **Validator submission URL:** https://aws-jam-082592851644-jam-fuel.s3.amazonaws.com/index.html
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-002/`
## Previous challenge
### Challenge 001 — SNS → SQS → Lambda
- **Task 1:** Completed through live AWS CLI mutation and readback on 2026-09-09. The existing topic now has one confirmed SQS subscription to the existing queue; its existing policy authorizes the exact topic. Topic and queue counts were unchanged.
- **Task 2:** Completed through live IAM policy mutation and readback on 2026-09-09. The Lambda role’s existing `sqs` inline policy now additionally allows only `sqs:ReceiveMessage` against the exact queue ARN; no policy was attached and no wildcard was added.
- **Task 3:** Completed through live Lambda mutation and readback on 2026-09-09. One event-source mapping now connects the exact existing queue to the exact existing function and is `Enabled`.
- **Evidence:** `/opt/data/channels/aws-jam-2026-general/challenges/challenge-001/`