|
AWS FOR THE REAL WORLD
β±οΈ
Reading time: 5 minutes
π―
Main Learning: Deploy AWS's open-source TEAM solution for temporary admin access with approval workflows
π¬
Hey Reader ππ½ I hope you had a great weekend and have a great week ahead. One thing I see over and over again in AWS setups: admin permissions are either handed out way too easily or way too hard. There is no middle ground. In other systems this was already solved. You shouldnβt have to DM somebody for admin access. We donβt want to face it, but there are actions which only admins can do:
But first of all, let's look at our sponsor for this newsletter, which is Coder - start using AI Agents securely in your corporation. This issue is sponsored by Coder. Thanks for supporting AWS Fundamentals! Back to TEAM: Even if you donβt need admin access a lot, it still makes sense to have a process for it. What typically happens: you give your developers admin access and forget to take it away. This is where the TEAM application comes in. TEAM stands for Temporary Elevated Access Management. Itβs an AWS sample (not a managed service) that handles the process of granting and revoking admin access automatically. In this issue, I show you how to set it up and how it works. Rather watch a video? Iβve recorded one for you!
That's it for this week! Sandro & Tobi |
We teach AWS for the real world - not for certifications. Join more than 10,500 developers learning how to build real-world applications on AWS.
AWS FOR THE REAL WORLD β±οΈ Reading time: 12 minutes π― Main Learning: Run an always-on AI agent on a $5 Lightsail instance with zero open ports, SSM access, and GitHub as a time machine for your agent's brain π Blog Post π¬ Watch on YouTube Hey Reader ππ½ the past weeks there is obviously one driving topic: OpenClaw π¦ We love seeing that a developer from our neighbor country π¦πΉ built a tool that got so MUCH hype. That is why we needed to try it out as well! While I (Sandro) added OpenClaw to my...
AWS FOR THE REAL WORLD β±οΈ Reading time: 8 minutes π― Main Learning: How to securely connect Claude Code to a private RDS database using MCP, SSM tunnels, and VPC endpoints π Blog Post π» GitHub Repository π¬ Watch on YouTube Hey Reader ππ½ AI coding assistants are great. If you give them the right context. Your database schema is one of the most valuable pieces of context you can provide. But there's a problem: your RDS is in a private subnet. As it should be. So how do you connect Claude Code to...
AWS FOR THE REAL WORLD β±οΈ Reading time: 8 minutes π― Main Learning: How to pause Step Function workflows for human approval using the callback pattern π Blog Post π» GitHub Repository π¬ Watch on YouTube Hey Reader ππ½ I've used this pattern in almost every project I've built. Whenever you need a human in the loop - approvals, reviews, manual checks - and you still want to see what's happening, Step Functions are perfect. Lambda is my go-to for almost everything. APIs S3 triggers event consumers...