7.0 KiB
7.0 KiB
#aws-jam-2026-general
- Guild:
1518726359512387766 - Channel:
1547165920269439007 - Workspace:
/opt/data/channels/aws-jam-2026-general - Purpose: Work through AWS Jam 2026 challenges using the supplied temporary lab account.
- Placement rule: All channel-owned files and command execution belong in the workspace above.
- Credential rule: Temporary AWS credentials are stored only under the workspace
secrets/directory and are never copied into this wiki.
Current challenge
Challenge 008 — Sharing is caring: reusable code across Lambdas
- Status: Tasks 1–2 completed and verified on 2026-09-09.
- Region:
us-west-2. - Task 1: Published
tattooine-common:1fornodejs22.x/x86_64and attached it to both functions, resolvingRuntime.ImportModuleError. - Task 2: Published
tattooine-common:2from the task-two artifact fornodejs22.x,nodejs18.x, andx86_64; updated only Function One to v2 and retained Function Two on v1. - Result: Function One/v2 returns
Happy hour at the Sanctuary!; Function Two/v1 returnsThe Spaceport is open now.Both invoke with HTTP200and noFunctionError. - Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-008/
Previous challenges
Challenge 007 — Malware In Your Bucket
- Status: Completed and verified on 2026-09-09.
- Resources:
file-scanning-upload-0da43cf0;bucket-scan-functioninus-west-2. - Root cause: The replacement bucket had no object-created notification, and the Lambda had no S3 invoke permission. Its execution role already had correct exact-bucket object-read access.
- Repair: Added one exact-bucket/account-constrained S3 invoke permission and one
s3:ObjectCreated:*Lambda notification; uploadedtest_file.txtto the existing bucket. - Result: Lambda alert reported
scan_performed: Yes,scan_result: Detected,detection_rule: AWSome_malware_alert. - Submission answer:
AWSome_malware_alert. - Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-007/
Previous challenges
Challenge 006 — My Pipeline is stuck!
- Status: Completed and verified on 2026-09-09.
- Region/source:
ap-southeast-2; commit17b14f70e4b7c03256e3f2d61ad5e29e23d4ff1c. - Root cause:
BrokenPipelineLambdaFunctionsuccessfully probed API Gateway but never called CodePipeline's success/failure callback APIs; its role also lacked those two callback permissions. - Repair: Added job-ID handling plus
PutJobSuccessResult/PutJobFailureResultcode paths and only the corresponding two role actions. Preserved the existing API/secret flow and pipeline definition. - Result: Local success/failure regression tests passed; deployed package checksum matched; execution
ed88adff-391d-400e-a2ef-e85a80bee461succeeded with both pipeline actions green and API HTTP200logged. - Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-006/
Previous challenges
Challenge 005 — Fix my build issue
- Status: Completed and verified on 2026-09-09.
- Region/source:
ap-northeast-1; commit6631553933f09f8f3ce5dc6f8f6505fbc8d5bc64. - Root cause: CodeBuild role
challenge-codebuild-rolelacked artifact S3/KMS read access and the ECR authentication/push actions required by the existing buildspec. - Repair: Extended only its existing
CodeBuild-Policy, scoping S3, KMS, and ECR push actions to the exact resources; onlyecr:GetAuthorizationTokenuses required resource*. - Result: Pipeline execution
9bcbb91c-b1ef-44f3-87d6-143086b29d25and CodeBuild succeeded; ECR containslatestand immutable build tag at digestsha256:4a3f0ca1bc896ffbc3274584ac844895f7ed979a3c6cd585b0d22152fbd6f43b. - Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-005/
Previous challenges
Challenge 004 — AI-Powered Log Analysis using Amazon Bedrock
- Status: Tasks 1–2 completed and verified on 2026-09-09.
- Function:
bedrock-api-functionineu-west-2. - Task 1: Memory
256 MB; timeout60 seconds. - Task 2: EventBridge rule
bedrock-log-analysis-scheduleis enabled withrate(12 hours); its sole Lambda target and all target settings were preserved. - Scope: Only the requested Lambda configuration and EventBridge schedule were changed; function code and service integrations were unchanged.
- Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-004/
Previous challenges
Challenge 003 — Protect my CloudFront Origin
- Task 1: Direct ALB bypass confirmed over HTTP. Submission answer:
I am your origin app you must protect! - Task 2: Completed and verified. Security group
Jamnow permits only TCP/80 from managed CloudFront origin-facing Prefix List IDpl-93a247fa; the0.0.0.0/0rule is removed. Direct ALB access times out. - Task 3: Completed and deployed. Only
Application Usersendsx-from-cf: MySuperSecretto the origin. - Task 4: Completed and verified. Listener priority
1accepts the exact secret header and returns the application response; the default action returns HTTP403 text/plainwithAccess denied. - Task 5: Final live validation passed: Application User HTTP
200, Malicious User HTTP403. Submission answer:1788947493.297988. - Resources found:
Application UserandMalicious UserCloudFront distributions; the Application User origin is ALBJamineu-west-2. - Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-003/
Previous challenges
Challenge 002 — Static website using S3
- Status: Completed and publicly verified on 2026-09-09.
- Bucket:
aws-jam-082592851644-jam-fuel— the only createdaws-jam-*bucket. - Website: Static hosting enabled with
index.htmlanderror.html; bucket-level public blocks disabled and public policy limited tos3:GetObjecton this bucket’s objects. - Endpoint: http://aws-jam-082592851644-jam-fuel.s3-website-us-east-1.amazonaws.com
- Validator submission URL: https://aws-jam-082592851644-jam-fuel.s3.amazonaws.com/index.html
- Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-002/
Previous challenge
Challenge 001 — SNS → SQS → Lambda
- Task 1: Completed through live AWS CLI mutation and readback on 2026-09-09. The existing topic now has one confirmed SQS subscription to the existing queue; its existing policy authorizes the exact topic. Topic and queue counts were unchanged.
- Task 2: Completed through live IAM policy mutation and readback on 2026-09-09. The Lambda role’s existing
sqsinline policy now additionally allows onlysqs:ReceiveMessageagainst the exact queue ARN; no policy was attached and no wildcard was added. - Task 3: Completed through live Lambda mutation and readback on 2026-09-09. One event-source mapping now connects the exact existing queue to the exact existing function and is
Enabled. - Evidence:
/opt/data/channels/aws-jam-2026-general/challenges/challenge-001/