Skip to main content

Command Palette

Search for a command to run...

Some notes for my DVA certification:

#AWS DVA notes

Updated
•14 min read•View as Markdown
Some notes for my DVA certification:

(You can see some mixed English and Vietnamese :D, please feel free to use Google Translate extension if you’re interested in reading my notes)

Lambda:

🔑 Tips and tricks:

  • Lambda Insights ≠ X-Ray → phải thêm Insights extension layer

  • Luôn cần CloudWatchLambdaInsightsExecutionRolePolicy để Lambda ghi được logs/metrics

  • Tạo lambda functions để mà write data vào S3. Dev configure all functions to send logs and metrics to CloudWatch + receive reports from one Lambda

🔑 Lambda → private resources: cấu hình VPC access (private subnet + SG)

  • Nếu muốn Lambda có IP thì phải đưa vào VPC

🔑 NAT/PrivateLink/VPN chỉ áp dụng khi có dịch vụ ngoài VPC or cross-account

🔑 Lỗi “timed out after X seconds” → kiểm tra và tăng function timeout; nếu xử lý I/O lớn, cân nhắc tăng bộ nhớ để có băng thông mạng/CPU cao hơn.

🔑 Cold start: chỉnh provisioned concurrency for Lambda function ($ option)

🔑 Dead-letter queue: cover cả TH Lambda chưa xử lí được (timeout)

💡
TH này giả sử mỗi lần Lambda trigger thì được đẩy vào một cái queue (set up 2 cái destination, on success and failure thế những cái chưa được xử lí thì ntn?)

🔑 Lambda call 3rd party service:

  • Reserved concurrency limit số concurrent executions của Lambda function

🔑 Lambda có giới hạn:

  • .zip deployment package tối đa 250 MB uncompressed

  • 50 MB compressed direct upload

  • 250 MB compressed qua S3

Với dependency 500 MB vượt quá limit của .zip.

  • Giải pháp: dùng container image (max 10 GB).

  • Push image lên Amazon ECR, sau đó deploy Lambda từ container image

  • Lambda có thể access ECR images từ nhiều account khác nhau với permission

🔑 Lambda không hỗ trợ attach EBS volume → EBS chỉ gắn được cho EC2 → /tmp chỉ là ephemeral storage và reset mỗi lần cold start

🔑 Tips and tricks:

  • Lambda cần shared, persistent storage trong VPC → EFS + Access Point

  • Cần tách team cập nhật nội dung (lib/data) khỏi triển khai Lambda → đặt nội dung trên EFS, Lambda chỉ read (hoặc RW) qua Access Point

💡
Lambda Env có giới hạn kích thước 4 KB → không đáp ứng 6 KB = cập nhật → redeploy

🔑 Lambda cần config dynamic → Dùng AppConfig Lambda extension (env var chỉ phù hợp thông số nhỏ, ít đổi → redeploy)

RDS:

🔑 Surge traffic: traffic tăng ko kiểm soát được → RDS Prox

Lambda functions + connect to RDS db:

  • Requirement: Store DB creds securely

  • Secret manager: có cơ chế rotation by default

  • Muốn auto-update secret → Secrets Manager + fetch runtime (ko dùng env vars)

  • System Manager chỉ lưu biến môi trường chứ không phải lưu secrets (ko có cơ chế tự động rotation → nếu cần phải liên kết vơi Event Bridge (cron job + lambda)

    • Không nên kết hợp Step Functions bởi vì add cost so với Event Bridge

    • Over-complicated cho simple scheduling task

    • Event Bridge đơn giản và rẻ hơn

💡
Làm thực tế thì mỗi lần rotation thì con DB mình phải reset luôn

Case: upload ảnh để tạo thumb upload vào bucket khác → đang 2 phút muốn xuống thành 30s → increase the amount of memory của Lambda

  • Chỉnh cái bucket policy của S3 nếu mà muốn encrypt in transit:


Lambda + SNS

Push process data to a subset (4 con consumer lambda functions) + Data phải được route dựa trên 1 field của data

  • Nếu gửi tới 4 con Filtering: SNS Topic (Filter gửi đến trường dữ liệu)

    💡
    Ko cần phải subcribe thằng data-processing đẩy vào topic
  • Lambda đang xử lí log: timestamp, processing time, and status of the requests

  • Dùng SNS subscription filter policies để lọc thuộc tính → ko cần code routing hay quản lí nhiều topic/queue → overhead thấp nhất

  • Async Lambda failures + retry → Dead-letter queue (DLQ)

    • DLQ option: SQS queue hoặc SNS topic → Không support SQS queue FIFO

    • DLQ as event source = automatic retry mechanism

    • LEAST overhead → dùng native Lambda features (DLQ)


API Gateway + Lambda:

💡
Nếu liên quan đến timeout nữa thì API Gateway chỉ có limit là 2 mins 30s trong khi max timeout của Lambda là 15 mins

🔑 Tips and tricks:

3rd party auth + API Gateway = Lambda Authorizer!

🔑 Lambda function invoke REST API cho API Gateway. Hiện tại Request được invoke bởi consumer data-set trả bởi Lambda function thì visible

💡
Mapping Template cho phép:
  1. Chỉnh sửa lại req/res dưới dạng Template

  2. Format lại data

  3. Ko cần chỉnh sửa code Lambda

🔑 Tips and tricks:

Data formatting/transformation ở API Gateway = Mapping Templates!


Lambda + SQS:

🔑 Với Lambda + SQS, đặt Visibility Timeout → thời gian xử lý tối đa (thêm buffer) để tránh re-delivery.

X-Ray:

🔑 Tips and tricks:

  • Dùng AWS X-Ray để trace chi tiết latency giữa service → service

  • CloudWatch Logs chỉ đo tổng thời gian Lambda chạy, không tách riêng call đến downstream services

  • CloudWatch Lambda Insights = monitoring performance của Lambda, không thay thế X-Ray

KMS:

🔑 Tips and tricks: Cross-account secret access = IAM policy (Secrets Manager) + KMS key policy (Decrypt + DescribeKey)

  • priviledge: thì không chọn *, nếu mà service ko liên quan đến dịch vụ được mention thì ko chọn

  • KMS keys ko thể replicate giữa accounts

  • AWS managed keys ko cho phép chỉnh key policy → ko đc thêm cross account access.

🔑 Encryption in transit → Lambda encryption helpers với env variables

  • At rest vs In transit:

    • Parameter Store / Secrets Manager / S3 = at rest

    • Lambda encryption helpers = in transit

  • KMS key + Lambda → cần grant permission cho execution role

🔑 Tips and tricks:

  • "Full control over KMS keys" → Customer managed key (không phải AWS managed key)

  • "Part of Lambda configuration" → Lambda environment variables

  • KMS key types:

    • AWS managed key = AWS quản lý, no full control

    • Customer managed key = full control (policies, rotation, access)

  • "Visible only to authorized entities" → KMS key policy control access

  • Parameter Store/DynamoDB = external storage, không phải "Lambda configuration"

Beanstalk Deployment strategies:

🔑 Tips and tricks:

  • Canary = thử nghiệm tính năng với một nhóm nhỏ trước (apply with a small group)

  • Linear = rollout tăng dần theo % (increase by percentages)

  • All-at-once = deploy toàn bộ ngay lập tức (deploy everything all together)

  • In-place = update trực tiếp, không có traffic splitting (update directly, without splitting)

🔑 Tips and tricks:

  • Rolling = batch update, có downtime nhỏ.

  • Immutable = zero downtime, nhưng all-or-nothing.

  • Traffic-splitting = canary style, forward % traffic.

Dynamo DB:

🔑 Khi dùng GSI thì không cần dùng chung partition key, LSI thì được tạo ra ngay từ ban đầu ko thay đổi được → cần dùng chung partition key

  • LSI = same partition key, different sort key

    • Local secondary index hỗ trợ cả strongly consistent và eventually consistent reads
  • GSI = completely different partition key and sort key

    • GSI chỉ hỗ trợ eventually consistent reads

Do đó nếu có latest data keyword thì phải remove eventually consistent options

💡
Tránh scan toàn bộ bảng, GetItem → Dùng Query action

🔑 Tips and Tricks:

  1. Query = chính xác theo key condition, tiết kiệm RCUs

  2. GetItem/BatchGetItem = chỉ biết rõ partition keys

  3. Scan = tránh dùng nếu có index phù hợp

🔑 "New access pattern with different keys" → GSI (Global Secondary Index)

🔑 Optimize query performance and limit partition overload → partition key (UUID random → có độ phân tán cao → customer có unique value (evenly distributed + precent partition overload)

  • Dùng name, date có thể bị hot partitions (common names)

  • High cardinality keys: UUID, email, customer ID

  • Low cardinality keys: date, name, status, country

  • Hot partition = nhiều data/requests tập trung vào vài partitions → performance issue

Cloud Front:

Users request thì có 20 fields. Mỗi application transaction contains sensitive data cần mã hóa. Chỉ có những phần của app cần khả năng để decrypt data

🔑 Liên kết CloudFront distribution với Lambda@Edge function + dùng RSA để store

CloudFront có thể dùng WebSocket

🔑 Mã hóa sensitive env tại edge thì dùng CloudFront Filed-Level Encryption (riêng cái này chỉ encrypt sensitive field in POST request)

🔑 Set the Origin Protocol Policy set to Match Viewer:

1/ Origin Protocol Policy = Match Viewer (connection from CloudFront to ALB)

2/ Nghĩa là viewer dùng HTTPS thì CloudFront sẽ dùng HTTPS đến origin

3/ Encrypt data giữa CloudFront and ALB

S3:

🔑 Server-side encryption with S3 managed key (SSE-S3) mặc định thôi ko cần phức tạp + KMS thì share được thêm cho bên khác nữa

🔑Loại bỏ thông tin nhạy cảm: PII → S3 Object Lambda (sử dụng lambda function để thay đổi object) (gọi đến lambda, s3 trả về thông tin nhưng phải thông qua lambda)

🔑 Optimize S3 bucket for high request rates:

  • Dùng object key names distributed across multiple prefixes:

    • Multiple prefixes phân tán requests across multiple partitions trong S3

    • S3 tự động scale performance theo số prefixes

    • 3,500 PUT/COPY/POST/DELETE và 5,500 GET/HEAD requests per second per prefix

    • Nhiều prefixes = tăng tổng throughput

Authen → Cognito (App, Mobile)

🔑 User Pool dùng để login

🔑 Identity Pool dùng để give permissions

Step Functions:

🔑 Chạy tuần tự nhiều Lambda → Step Functions (orchestration, retry, timeout, quan sát dễ)

API Gateway:

Case: REST API calls Lambda function

🔑 Chỉ có một môi trường là: API stage + trỏ 2 phía → tạo stage mới → points to prod Lambda function alias

💡
Use API Gateway Usage Plans

Usage Plans trong Amazon API Gateway cho phép:

  • Định nghĩa quota (hạn mức) và rate limit (số request/giây) cho API

  • Gắn API key cho mỗi client để theo dõi và kiểm soát

  • Tạo nhiều gói sản phẩm như Free Tier, Pro, Enterprise...

🔑 Tips and tricks: Khi muốn commercialize API (biến API thành sản phẩm) → dùng API Gateway Usage Plans + API Keys!

🔑 Nhiều API GW → Dev đang làm việc với API in dev env → thay đổi ko được hiển thị

→ Redeploy the API đến stage hiện tại or to a new stage

Sửa API Gateway mà ko thấy thay đổi → Quên deploy to Stage

🔑 Types of APIs được hỗ trợ bởi API Gateway thì là right fit:

WebSocket APIs:

→ Lựa chọn tốt nhất cho real-time communication

  • Kết nối hai chiều giữa client and server
💡
Simulate API mà không cần backend → MOCK integration
  • Mô phỏng response API mà ko gọi đến backend thực tế

  • Test nhanh

🔑 Tips and tricks: Cần ẩn secret (API key) khỏi client → đặt ở API Gateway integration.

🔑 Tips and tricks:

  • WebSocket + Lambda authorizer → REQUEST authorizer + TTL cache.

  • Dùng $context.authorizer.* trong mapping template để truyền claims/roles mà không cần token mỗi request.

Container (ECS):

💡
Design: S3 → Fan Out → SQS Queue (mỗi phòng ban thì sẽ có một cái ID)

Elasticache:

🔑 Microsecond - Memcached support (multi-thread)

🔑 Redis (80% TH phải chọn)

WAF:

🔑 Chỉ filter requests ko mã hóa dữ liệu

SSL + ACM

Case: Áp dụng TTL coi certificate hết hạn khi nào

  • Implement a solution to notify sec 90 days trước khi expires

🔑 Dùng AWS Config -> acm-certificate-expiration-check managed rule để chạy mỗi 24 tiếng. Tạo Event Bridge rile để includes event pattern mà specifies Config Rules Compliance Change → kết hợp bắn sự kiện noncompliant tới SNS topic (email team security)

SNS: FIFO topic

🔑 Yêu cầu: đúng thứ tự giao dịch của user

🔑 Configure the app SDK to publish notifications to SNS topic to send SMS messages to users

🔑 Không gửi trùng lặp (exactly-once delivery)

SNS Fan Out

  • Gửi message đến tất cả subcribers → đồng thời mỗi lambda function là independent subcriber

  • Concurrent execution (nếu một lambda fail thì ko ảnh hưởng đến execution của 2 lambda còn lại)

SQS Queue:

🔑 One to one model → mỗi message chỉ được consume bởi một consumer (ko thể 3 lambda cùng process một message)

🔑 Message batching: lấy được nhiều message nhất

🔑 Long polling to query the queue for new messages + Batch messaging

🔑 Step Functions tốt cho orchestration nhưng tạo dependencies giữa các steps

💡
SQS dead-letter queue relevant questions:
  • ✅ Use StartMessageMoveTask API to move messages from the dead-letter queue to the original SQS queue.

🔥SendMessageBatch chỉ gửi message mới, muốn dùng phải nhận → tốn công code

🔥ChangeMessageVisibility chỉ thay đổi timeout hiển thị message trong cùng queue → ko di chuyển message giữa DLQ và source

🔥PurgeQueue xóa vĩnh viễn tất cả message trong queue → mất dữ liệu

SAM:

SAM cung cấp template chuẩn cho serverless và support test local (sam local) and call SAM CLI within the stage of CodePipeline để build/test/deploy, đáp ứng nhu cầu

🔑 Flow chuẩn của SAM: build → package (S3) → deploy.

1. Build the SAM template locally.
2. Package the SAM template onto Amazon S3.
3. Deploy the SAM template from Amazon S3.

🔑 SAM CLI key commands:

  • sam local invoke: test Lambda locally

  • sam local generate-event = tạo sample events

  • sam local start-api = test API Gateway locally

EFS:

Đây là Network file system, hỗ trợ Fargate và nhiều tasks truy cập đồng thời, dữ liệu persist khi container dừng

CloudFormation:

🔑 CloudFormation xác định resouce dựa trên logical ID trong template, nếu đổi logical ID hoặc name, CloudFormation sẽ delete + tạo resource mới (nếu ko có Deletion Policy giữ lại)

🔑 CloudFormation template sẽ được deployed nhanh ở một region back-up (nếu mà sập) → Dùng StackSets

🔑 Nếu Dev viết Cloud Formation template (nếu có nhiều stack thì cần phải ImportValue function import từ stack Ref thì chỉ dùng cho cùng Stack)

  • Ngoài ra: Output với Export là bắt buộc để share values với other stacks, network team phải có output section

  • Mapping để define static lookup tables

Application Load Balancer:

  • Add X-Forwarded-For header to HTTP server log conf file

    🔑 XFF header chứa original client IP address

Config:

🔑 support dynamic feature flags → application must poll on interval for new feature flag values → value sẽ được cached when they’re retrieved

🔑 AppConfig (Feature Flags) + AppConfig Agent hỗ trợ polling định kỳ, rollout/rollback an toàn, và local caching qua endpoint localhost → tối ưu công suất vận hành, chuẩn bị best practice cho feature flags.

IAM Identity Center (SSO):

🔑 IAM Identity Center credentials là temp cred có thời hạn (thường là 1-12 giở)

  • Dev cần re-authenticate (aws sso login) để refresh cred

  • Đây là behavior bth của SSO, ko phải lỗi conf

AWS Copilot:

🔑 Tips and tricks:

  • "AWS Copilot" + "automated deployment" → Copilot native pipeline feature

  • "MOST operationally efficient" → dùng native tools thay vì custom solutions

  • Copilot pipeline commands: copilot pipeline init, copilot pipeline deploy

  • SAM = serverless, Copilot = containers

CDK (Cloud Development Kit)

❌ cdk synth

→ Chỉ generate CloudFormation template (YAML/JSON). Không tạo bucket bootstrap.

❌ cdk init

→ Dùng để khởi tạo 1 CDK project mới (app template), không liên quan tới deploy.

❌ cdk destroy

→ Xóa stack đã deploy. Không tạo bootstrap bucket và không khắc phục NoSuchBucket.

🔑 Tips and tricks:

Lần đầu deploy CDK vào account/region mới → luôn cần cdk bootstrap.

🧑‍💻 Code Deploy:

  • Cần đăng ký instace (EC2/on-premises) và cấu hình đầy đủ (IAM/agent/tag

👨‍💻Code Artifact:

  • Code Artifact là package manager (npm, pip, maven ..) không phải công cụ test/debug local hay giả lập deployment

  • Native support cho .jar files và Java dependencies

  • Best practice cho managing application dependencies

🔑 ECR = container images, Code Artifact = packages/dependencies

🔑 Tips and tricks:

  • "Test/debug local" + "CodeDeploy package" → Nghĩ ngay đến CodeDeploy Local (codedeploy-local).

  • Cần unit/integration test trên cloud → nghĩ đến CodeBuild

  • Cần quản lý package/dependency → nghĩ đến CodeArtifact, không dùng để test deployment

🖥️ Monitoring services:

  • CloudWatch Logs: đều tích hợp native với API Gateway và Lambda

    • Nếu để filter by key words ví dụ “Error” trong log lines → Tạo metric filter as search term. Tạo alarm on this metric that notifies SNS topic khi metric is 1 or higher
  • CloudWatch Logs Insights: cho phép search, filter, và query log tập trung đa log group (Lambda + API Gateway)

  • Logging ở API Gateway stage + dùng Logs Insights là đường ngắn nhất để tìm lỗi end-to-end

  • Ko cần thêm service như Kinesis, Athena, or Open Search

Additional Notes:

🔑 IP addresses: X-Forwarded-For header: Check the original IP address from the request (suitable for Application Load Balancer tracing ..)

22 views

More from this blog

C

Cloud Security Blog - Andrewhocngu

7 posts