<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><description>Management for your Cloud Resources</description><title>Ylastic</title><generator>Tumblr (3.0; @ylastic)</generator><link>https://blog.ylastic.com/</link><item><title>Search your AWS Inventory</title><description>&lt;p&gt;Quickly search through the AWS resources in a single AWS account or multiple AWS accounts using &lt;a href="https://bit.ly/39wBzrm" target="_blank"&gt;Ylastic&lt;/a&gt;. View the configuration for any of the retrieved resources easily with
    a single click. Fine tune your search by selecting tags and/or resource ids. Combine multiple criteria to quickly
    filter and view your AWS resources. You can select single or multiple items for each category.&lt;br/&gt;&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="654" data-orig-width="1174" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/bb39d56ca74dd434f00a293351c4ba4e/f9bb0a46b126869e-25/s540x810/db822f574ccf90d163be01795be0162f14bf0ed9.png" data-orig-height="654" data-orig-width="1174"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Detailed resource configuration is easily accessible for all retrieved items.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="642" data-orig-width="1160" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/5578a2cd3a728603052498ab086eb416/f9bb0a46b126869e-2f/s540x810/e39b5a050fd501b1f1e6e8cbb1f99c98fafe5e62.png" data-orig-height="642" data-orig-width="1160"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Filter your search criteria by selecting one or more services.&lt;br/&gt;&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="594" data-orig-width="1163" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/3191cea3625fe22cd3fb3636f652b952/f9bb0a46b126869e-f1/s540x810/aa82114812e800c86351d9c30476dab464595882.png" data-orig-height="594" data-orig-width="1163"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Filter your search criteria by selecting one or more regions.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="580" data-orig-width="1165" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/22d304e3aace228e8140422d4c8200b1/f9bb0a46b126869e-a9/s540x810/363d138fa8421a7829e7fa458584e7186fa570f6.png" data-orig-height="580" data-orig-width="1165"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Filter your search criteria by selecting one or more resource types.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="596" data-orig-width="1163" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/300d0a68b8d36b806115587a7c2fbcdc/f9bb0a46b126869e-35/s540x810/d4b7645b36b2e55901a142cd0aafd2c496c47f9f.png" data-orig-height="596" data-orig-width="1163"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Filter your search criteria by selecting one or more resource Ids.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="525" data-orig-width="1168" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/51274aa887a50f1a273b5ce73bd6abc0/f9bb0a46b126869e-91/s540x810/2c31c131568daef3aa13515d3ffad59b0780755c.png" data-orig-height="525" data-orig-width="1168"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Filter your search criteria by selecting one or more tags.&lt;br/&gt;&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="591" data-orig-width="1141" style="opacity: 1; transform: translateY(0px);"&gt;&lt;img src="https://64.media.tumblr.com/2f4e1145d656172fc649bf2c227bc326/f9bb0a46b126869e-08/s540x810/2c2f06b689b00901d11bbfd37c5543c9fec5a952.png" data-orig-height="591" data-orig-width="1141"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/683508011186126848</link><guid>https://blog.ylastic.com/post/683508011186126848</guid><pubDate>Fri, 06 May 2022 09:33:55 -0400</pubDate><category>aws</category><category>cloud</category><category>console</category><category>containers</category><category>ec2</category></item><item><title>Export EKS Kubernetes Clusters</title><description>&lt;p&gt;New scheduled task in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; for exporting EKS Kubernetes Clusters to a S3 bucket of your choice. Global export can be run at an AWS Organizational unit level to dynamically select clusters in all AWS accounts within that unit. Exports are compressed and encrypted using &lt;a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html" target="_blank"&gt;SSE-KMS&lt;/a&gt; in selected S3 bucket. You can configure the number of exports to retain and the task will automatically prune the old exports. &lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="1124" data-orig-height="380" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/7ead2d691395883239807195ecabf5d8/b94773d51b78c964-ef/s540x810/511b751dcad6f32addfda375bc967e6b950ed36d.jpg" alt="image" data-orig-width="1124" data-orig-height="380"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Exports are bundled into a tarball for compressed storage prior to encryption. Each export is arranged by namespace and resource types within each namespace to make it easy to utilize the exported files.&lt;/p&gt;&lt;figure data-orig-width="682" data-orig-height="404" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/7e55f5b55ad832dc08056e56542851b6/b94773d51b78c964-c4/s540x810/bedfb7fa09e118eed65b1a71c7ef5704e96b4ad8.jpg" alt="image" data-orig-width="682" data-orig-height="404"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The scheduled task can be configured to check for specific cluster tags or you can utilize a wildcard (*) to select all clusters in a region. Specify the S3 bucket to use for saving exports. You can select any account from your AWS organizational unit.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="605" data-orig-height="519" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/d6616f0080df4076fc59cb8e1f94ead4/b94773d51b78c964-26/s540x810/98fd6d260ecf9d6c5eff9919a5a5e3e02220c9cd.jpg" alt="image" data-orig-width="605" data-orig-height="519"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Detailed history of every task run is stored and available. There is no need to specify an account to check for the clusters to export. AWS accounts within your organizational unit are automatically picked up on every run. &lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="1144" data-orig-height="470" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/5ddea82569cc205a409808f11cc17ad4/b94773d51b78c964-d0/s540x810/f7533ac069b80f7a42f41daccb6dfc1e6ed4b7d1.jpg" alt="image" data-orig-width="1144" data-orig-height="470"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Select any individual task run event and view the matched clusters, as well as exports added and deleted.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="861" data-orig-height="579" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/476f4d5d01772385881aa4d0ec60618b/b94773d51b78c964-7b/s540x810/aeb761944bc5b390dca893041d5790a57e031b0c.jpg" alt="image" data-orig-width="861" data-orig-height="579"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/660971026787811328</link><guid>https://blog.ylastic.com/post/660971026787811328</guid><pubDate>Mon, 30 Aug 2021 15:18:12 -0400</pubDate><category>aws</category><category>eks</category><category>kubernetes</category><category>cloud</category></item><item><title>Ylastic Updates</title><description>&lt;p&gt;Several recent product updates incorporated into a single post. Easy access to tags for your AWS resources. Quickly view associated tags for instances, volumes, snapshots, vpcs, subnets, routes tables, security groups, and other resources.&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="1160" data-orig-height="408" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/fee36d0219606d171cbb149fec5e93f6/b0caabd452b23458-35/s540x810/2508c96888910fe2004df090198bb3d3b8a4480a.jpg" alt="image" data-orig-width="1160" data-orig-height="408"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Utilization metrics updates for EKS clusters, nodes, and pods. If you have the Kubernetes metrics-server running in your clusters, then utilization is retrieved and automatically displayed next to the resource.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="1136" data-orig-height="558" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/fc17a0bd5c35e174fb0e5a60c82b1197/b0caabd452b23458-20/s540x810/e2537e940418237af77f14a4f7aaa9ed5ef60f4d.jpg" data-orig-width="1136" data-orig-height="558"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Updates to EKS and Kubernetes management for multi-account/cross region resource access.&lt;/p&gt;&lt;figure data-orig-width="1132" data-orig-height="550" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/401e7201a3029e39e07c2489e3b039b3/b0caabd452b23458-b1/s540x810/388d4c6ea357a05353864f636face6f624424225.jpg" data-orig-width="1132" data-orig-height="550"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Change retention for individual backups. If you wish to keep some of the backups created by a scheduled backup task, just add the tag &amp;lsquo;ylastic_retain_backup&amp;rsquo; to a snapshot(for volume backups) or an AMI (for instance backups). You can do this for any of the tasks used for backing up volumes and instances, as well as tasks for replicating volumes and instances to other accounts and regions.&lt;/p&gt;&lt;figure data-orig-width="456" data-orig-height="532" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/53b0b969216b752f481dabad319a994c/b0caabd452b23458-a6/s540x810/bdb839414ee9f0cedc7cf7dc434f1487d147db89.png" data-orig-width="456" data-orig-height="532"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/653967439378382848</link><guid>https://blog.ylastic.com/post/653967439378382848</guid><pubDate>Mon, 14 Jun 2021 07:59:10 -0400</pubDate><category>aws</category><category>ec2</category><category>eks</category><category>kubernetes</category><category>containers</category></item><item><title>Launch Templates</title><description>&lt;p&gt;Cross-region, cross-account launch templates. View and access all your launch  templates in one place.&lt;/p&gt;&lt;figure data-orig-width="1166" data-orig-height="506" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/e0b213a95f60333eaab7ebf22a18bd0b/5a1b88c27a7f0e07-45/s540x810/d31571e65210190b7f4b397e55d61e1cc16dec07.jpg" alt="image" data-orig-width="1166" data-orig-height="506"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;View each template version as JSON, a details view separated by sections, and more.&lt;/p&gt;&lt;figure data-orig-width="1110" data-orig-height="480" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/b6f1c7e9a54091455e801c9617d879e8/5a1b88c27a7f0e07-25/s540x810/754a69fe17af78cb6b25190aaf3ab3f20970cc84.jpg" alt="image" data-orig-width="1110" data-orig-height="480"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Compare launch template versions. Select any two versions and view all changes or just the adds, deletes, or updates.&lt;/p&gt;&lt;figure data-orig-width="1158" data-orig-height="532" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/38aefea7704a0c3595c7458ffe6a702f/5a1b88c27a7f0e07-ab/s540x810/49bd0dd08bea3f382018175c9b5e64c3f89547f6.jpg" alt="image" data-orig-width="1158" data-orig-height="532"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/653705920895909888</link><guid>https://blog.ylastic.com/post/653705920895909888</guid><pubDate>Fri, 11 Jun 2021 10:42:27 -0400</pubDate><category>aws</category><category>ec2</category><category>console</category><category>cloud</category><category>management</category></item><item><title>EKS and Kubernetes Management</title><description>&lt;p&gt;Kubernetes is an open source container orchestration platform to deploy, manage, and scale containerized
    applications. &lt;a href="https://aws.amazon.com/eks/" target="_blank"&gt;Elastic Kubernetes Service (EKS)&lt;/a&gt; is a managed
    service from AWS which makes it easy to run Kubernetes in the AWS cloud. You can choose to
    manage Kubernetes infrastructure yourself with EC2 or get an automatically provisioned, managed Kubernetes
    control plane with Amazon EKS. Worker nodes can be provisioned on EC2 instances or a serverless data plane
    with Fargate. &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; already supports &lt;a href="https://bit.ly/2G2JRsq" target="_blank"&gt;ECS
        container management&lt;/a&gt;. We are extending it with full support for managing your EKS Kubernetes resources
    running in AWS with Ylastic - across regions
    and across AWS accounts. All your Kubernetes clusters along with an overview of their workloads (deployments,
    controllers, daemon sets, jobs and more), CPU/memory
    limits, requests and utilization are available in one view.&lt;/p&gt;
&lt;figure data-orig-width="1787" data-orig-height="571" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/1d918f16ecb55bf08206c816b7b621a9/3a2ab45a87c245e9-50/s540x810/5722d0bcd1c7a893535a6914149bf09c48976dcc.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1787" data-orig-height="571"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Nodes represent worker machines in a cluster to run your
    application containers. Each node contains the services that are needed to run pods. When you deploy an
    application in a cluster, the Kubernetes control plane seamlessly handles the distribution of work on to the
    individual nodes.&lt;br/&gt;&lt;/p&gt;
&lt;figure data-orig-width="1789" data-orig-height="862" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/ab3818e86edfef447611ca49a99553bb/3a2ab45a87c245e9-da/s540x810/3f1c3d6586e6d38a06d5e6246368c48198302896.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1789" data-orig-height="862"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;A pod is a group of one or more containers
    deployed on a worker node of a cluster. It is also the unit of replication in Kubernetes. Clusters can have multiple
    pods and each pod is assigned an unique IP
    address for connectivity.&lt;br/&gt;&lt;/p&gt;
&lt;figure data-orig-width="1786" data-orig-height="744" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/f20b47dbce9abd8c3d54bc9c656bf3c4/3a2ab45a87c245e9-32/s540x810/dc43f48c02e02a0c99dc071541f8fff93d158af0.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1786" data-orig-height="744"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Services are Kubernetes objects used to expose the access to application containers
    running on
    different pods within your cluster or outside your network.&lt;br/&gt;&lt;/p&gt;
&lt;figure data-orig-width="1787" data-orig-height="756" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/e0b13d9ca94661e27528b9fa2291d42f/3a2ab45a87c245e9-06/s540x810/abd6ed7acf23259c104c4bb24e8afdc1f92aac25.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1787" data-orig-height="756"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Deployment defines the set of instructions for creating pods and other required
    objects in your
    application. You can manage the specific number of pod replicas by
    specifying it in the deployment. Even if you delete any pod manually, the configured deployment which is also
    monitoring it, will immediately create a new pod as defined. Using a deployment, you can declare the desired
    state of the system, and Kubernetes will automatically manage the resources to ensure your desired state.&lt;br/&gt;&lt;/p&gt;
&lt;figure data-orig-width="1786" data-orig-height="647" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/d568c65932ceb806277debd14bff137b/3a2ab45a87c245e9-d1/s540x810/b6d7bd580722b8db2db035492c19c02a65c3eb1e.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1786" data-orig-height="647"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Kubernetes can be configured to provide persistent storage access to your
    application containers
    using storage classes and volumes. These volumes can be Amazon
    Elastic Block Store (EBS), Elastic File System (EFS), and several other types, and can be attached to your worker
    nodes to provide persistent storage.&lt;br/&gt;&lt;/p&gt;
&lt;figure data-orig-width="1786" data-orig-height="459" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/306a33d2ca60d3fded6d4df2353c4d26/3a2ab45a87c245e9-ba/s540x810/e934a55131241d71d3848055a65b665e2aab43ee.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1786" data-orig-height="459"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Kubernetes supports multiple virtual clusters backed by the same physical cluster.
    These virtual
    clusters are
    called namespace and they are all logically isolated from each other. &lt;/p&gt;
&lt;figure data-orig-width="1787" data-orig-height="654" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/e2bd766dfd971556b8a802b160bee430/3a2ab45a87c245e9-87/s540x810/d0e115d75178e9ea32318a1d06cc185f978d934a.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1787" data-orig-height="654"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;EKS managed node groups contain the EC2 instances that are used for running your
    Kubernetes
    workloads. They are managed for you by AWS, but are only needed if you want to use EC2 and are not needed if you go
    the serveless route and use EKS Fargate clusters.&lt;br/&gt;&lt;/p&gt;
&lt;figure data-orig-width="1788" data-orig-height="517" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/68cbdf5214762f7e5ad4409dc3a44857/3a2ab45a87c245e9-60/s540x810/5bcdd1862e181fa3610fc750cb56216299a2d6b3.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1788" data-orig-height="517"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Managed node groups make it easy to add worker nodes (EC2 instances) that provide
    compute capacity for your
    clusters.&lt;/p&gt;
&lt;figure data-orig-width="1792" data-orig-height="487" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/43176d42c66a960d0b1377a8780fd27e/3a2ab45a87c245e9-13/s540x810/9a8d00ecb84900ea91449a9068451b25ef2a2a98.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1792" data-orig-height="487"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Access and view Kubernetes events being generated by all your clusters and the
    resources contained within
    them in one place.&lt;/p&gt;
&lt;figure data-orig-width="1790" data-orig-height="652" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/f44831ea6cf6fa6302953b48a3b16911/3a2ab45a87c245e9-cc/s540x810/732dbf2535811892037c96a3f75a7fc9e5df712f.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1790" data-orig-height="652"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Access and view updates to your managed node groups and clusters generated by AWS EKS
    in one place.&lt;/p&gt;
&lt;figure data-orig-width="1784" data-orig-height="759" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/5b035879b984b14620c822fc8c296646/3a2ab45a87c245e9-b4/s540x810/0bedaadbb2f46f8c410025da8976078892d9572d.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1784" data-orig-height="759"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Every object within Kubernetes is defined as an API object and accessible by ReST
    using the API server. You
    can edit any object as JSON and save changes to apply the updates to the object. Edit your Kubernetes objects easily
    in Ylastic with a dual window editor so you can see the changes being made to the resource. Save to apply changes. &lt;/p&gt;
&lt;figure data-orig-width="2251" data-orig-height="1013" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/9c9d7e92b2a762cb21dc7b98265c8d7e/3a2ab45a87c245e9-fe/s540x810/3ba24d154f56f2b383eb902e87f24d270a5035a0.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="2251" data-orig-height="1013"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;EKS container insights collects, aggregates, and summarizes metrics from your
    containerized applications on
    AWS. View your application metrics across regions and accounts in one page. Want to see the insights for a cluster
    in a different account/region within your organizational unit? Just select the account and region in the drop down
    to view the metrics. No switching pages, reloading consoles, changing roles.  &lt;/p&gt;
&lt;figure data-orig-width="1789" data-orig-height="894" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/d33a31e25bcbd799db27c85380fe074f/3a2ab45a87c245e9-5f/s540x810/0e57c512e82f3a801e1c3fedcd01063ba91b20b9.png" alt="image" style="max-width: 95%; width: 95%; height: auto;" data-orig-width="1789" data-orig-height="894"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Global CloudOps for your AWS organization. Simplify and streamline your container
    management workflow with
    easy access to all your ECS and EKS resources.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/633139891528663040</link><guid>https://blog.ylastic.com/post/633139891528663040</guid><pubDate>Tue, 27 Oct 2020 10:34:13 -0400</pubDate><category>aws</category><category>containers</category><category>kubernetes</category><category>docker</category><category>management</category></item><item><title>VPC Updates</title><description>&lt;p&gt;VPC resource page updates in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt;. VPC endpoints enable you to use a private connection between your VPC and any supported AWS services or any  VPC endpoint services that uses PrivateLink. Traffic between your VPC and AWS service that you are connecting to via an endpoint, does not leave the Amazon network. The new VPC endpoints page for gateway and interface endpoints is cross-region and cross-account. If you are using AWS Organizations, the view is by an AWS Organizational Unit and encompasses all accounts in that OU.&lt;/p&gt;&lt;figure data-orig-width="1314" data-orig-height="590" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/cbad39480749e318c4f132ca81d77dae/78cb75a4895bc3d5-b0/s540x810/62af6dc289049285b361c660c317603d7627237a.png" alt="image" style="max-width: 80%; width: 80%; height: auto;" data-orig-height="590" data-orig-width="1314"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;br/&gt;VPC peering connections enable you to route traffic between two VPCs privately. The resources in either VPC are able to communicate with one other as if they are within the same network. The new VPC peering page in Ylastic gives you access to your VPC Peering connections, cross-region and cross-account.&lt;/p&gt;&lt;figure data-orig-width="1309" data-orig-height="563" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/ea1d15dabb7f2f996121571f0b044243/78cb75a4895bc3d5-73/s540x810/82d65e573927ed65e097e13bda6613c21deb58fc.png" alt="image" style="max-width: 80%; width: 80%; height: auto;" data-orig-height="563" data-orig-width="1309"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;br/&gt;Diagrams for VPC peering connections with both requester and accepter VPC and all their components. You can diagram peering within an AWS account or peering connections with another AWS account in the organization. No digging through lots of resource pages, no switching regions. Click a button and generate a diagram of the peering.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="1226" data-orig-width="1796"&gt;&lt;img src="https://64.media.tumblr.com/d0c607a7cdce30aef22c5bfe599c01ab/78cb75a4895bc3d5-59/s540x810/4ab2c708c7f83be02c413d585f40e0242b1f2b4a.png" style="max-width: 80%; width: 80%; height: auto;" alt="image" data-orig-height="1226" data-orig-width="1796"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/628964052294680576</link><guid>https://blog.ylastic.com/post/628964052294680576</guid><pubDate>Fri, 11 Sep 2020 08:21:02 -0400</pubDate><category>aws</category><category>vpc</category><category>cloud</category><category>security</category><category>console</category></item><item><title>EC2 resource page updates</title><description>&lt;p&gt;EC2 resource page updates in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt;. Health check information for load balancer target groups readily available without accessing a separate tab. Sparklines now displayed for Requests, Healthy hosts and Unhealthy hosts.&lt;/p&gt;&lt;figure data-orig-width="1419" data-orig-height="533" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/5d7c54e15f6653f85907f7e17394a261/31c13596c87da317-36/s540x810/54475582fd63a7b86d0b8ea53f65d59c014dac40.png" alt="image" style="max-width: 75%; width: 75%; height: auto;" data-orig-height="533" data-orig-width="1419"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Load balancers page displays sparklines for Requests, Healthy hosts and Unhealthy hosts. The displayed sparklines differ based on the load balancer type, as there are some differences in the metrics available for each type.&lt;/p&gt;&lt;figure data-orig-width="1393" data-orig-height="626" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/a57701cec50e1d68d3e391c87ba17cf4/31c13596c87da317-c2/s540x810/986e718ea0a07aa01595a9771575ec2903af523c.png" alt="image" style="max-width: 75%; width: 75%; height: auto;" data-orig-height="626" data-orig-width="1393"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;All resources that can be targeted by Cloudwatch alarms now display the active resource alarms in a sub-tab, making it easier to manage alarms for the resource.&lt;/p&gt;&lt;figure data-orig-width="1432" data-orig-height="540" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/fca52098450b93b8914b0cd220c40c17/31c13596c87da317-fb/s540x810/f80a521a0b7e1d129d4ddbacf93fcfd0f6883aa4.png" alt="image" style="max-width: 75%; width: 75%; height: auto;" data-orig-height="540" data-orig-width="1432"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/628691137436254208</link><guid>https://blog.ylastic.com/post/628691137436254208</guid><pubDate>Tue, 08 Sep 2020 08:03:10 -0400</pubDate><category>aws</category><category>cloud</category><category>cloudwatch</category><category>elasticloadbalancing</category><category>console</category><category>devops</category></item><item><title>CIS Benchmark Security Reports for AWS Organizations</title><description>&lt;p&gt;The &lt;a href="https://t.umblr.com/redirect?z=https%3A%2F%2Fwww.cisecurity.org%2F&amp;amp;t=NmEwNDk3MWY0MzE3MDkzMzE4ZTM0NDFmY2FlM2NlYTUzMjVlYmFjZixhV0dkdUFPcQ%3D%3D&amp;amp;b=t%3AAihVWONs3BKFpmmX-X6hRg&amp;amp;p=https%3A%2F%2Fblog.ylastic.com%2Fpost%2F166747895056%2Fcis-benchmark-security-reports-for-aws&amp;amp;m=1&amp;amp;ts=1599067703" target="_blank"&gt;Centre for Internet Security&lt;/a&gt; (CIS) benchmarks are industry-accepted best practices for securely configuring traditional IT components. CIS has released several benchmarks or a set of security configuration best practices for AWS environments. &lt;a href="https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub.pdf#securityhub-standards-cis" target="_blank"&gt;The CIS AWS Foundations Benchmark  for AWS&lt;/a&gt; provides a guidance for configuring the security options for the following basic set of foundational AWS services. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;AWS Config&lt;br/&gt;&lt;/li&gt;&lt;li&gt;AWS CloudTrail&lt;/li&gt;&lt;li&gt;AWS CloudWatch&lt;/li&gt;&lt;li&gt;AWS Identity and Access Management (IAM)&lt;br/&gt;&lt;/li&gt;&lt;li&gt;AWS Simple Notification Service (SNS)&lt;/li&gt;&lt;li&gt;AWS Simple Storage Service (S3)&lt;/li&gt;&lt;li&gt;AWS VPC&lt;br/&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This security benchmark is integrated into &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt;, to make it really easy to audit your AWS infrastructure. You can create on-demand reports checking compliance with the benchmark or even schedule reports to run on a timeline of your choice to periodically check compliance. No separate tools/apps needed. Run reports against a single AWS account or ALL the accounts in an AWS organization. We updated the integration to make it easier to access the report information.&lt;/p&gt;&lt;figure data-orig-width="957" data-orig-height="331" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/212b97cdd0f8d0e8f5bad1740b760e21/efad595fe8645aaa-b6/s540x810/d4379753bcb6cc9eca747e1bbcf7ff16094c3891.png" alt="image" data-orig-width="957" data-orig-height="331"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Select any report to view the details for the report. Results are separated by AWS account and if you are using AWS Organizations, the report will display information on all the accounts that were tested as a part of that run. &lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="959" data-orig-height="298" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/e7b05473d26091f70288b2b7b6f80f9d/efad595fe8645aaa-b9/s540x810/0f8d00f4a0319a272413550e8441f8b866094087.png" alt="image" data-orig-width="959" data-orig-height="298"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Each report checks for compliance in four different categories. The Identity and Access Management category contains 24 checks focused on security for IAM, such as the use of root account, multi-factor authentication (MFA), inactive accounts, and password policy. &lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="901" data-orig-height="374" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/d5b5ea53182d72891a96b6c26df377c1/efad595fe8645aaa-02/s540x810/4a40e650aa017b41d60447278a41e1aed505e50f.png" alt="image" data-orig-width="901" data-orig-height="374"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The logging category contains 8 checks focused on logging AWS API calls and security options for the logging.&lt;/p&gt;&lt;figure data-orig-width="901" data-orig-height="377" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/ad40ee61ceb23d3c33d682a5f48ceafb/efad595fe8645aaa-c5/s540x810/781618d28243b7ed590f6f83b6d6a5c073eed6a0.png" alt="image" data-orig-width="901" data-orig-height="377"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The monitoring category contains 15 checks focused on prevention and detection of unauthorized use of the AWS account.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="901" data-orig-height="363" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/40d6d1dba1924b236e9c095d5c309ea8/efad595fe8645aaa-7f/s540x810/c4925537cb46840fbb5a4c8fab61d962d72ba4c9.png" alt="image" data-orig-width="901" data-orig-height="363"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The networking category contains 5 checks for checking the configuration of the security related aspects of VPC.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="899" data-orig-height="362" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/587b88e0cb7ff7c8099e0575a0ecb212/efad595fe8645aaa-71/s540x810/311d5f5cf501d2c35d84c4819a4c2a5d35f049ab.png" alt="image" data-orig-width="899" data-orig-height="362"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Create an on-demand report at any time or if you prefer, you can setup the reports to run on a schedule to evaluate your infrastructure.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="740" data-orig-height="505" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/4da57dd682bf14893bd96c025c490f41/efad595fe8645aaa-46/s540x810/a9f849cc515b8a54fb1b8cef5943161099f67936.png" alt="image" data-orig-width="740" data-orig-height="505"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Integrated and simple CIS benchmark security auditing for your AWS infrastructure. &lt;/p&gt;</description><link>https://blog.ylastic.com/post/628176742336659456</link><guid>https://blog.ylastic.com/post/628176742336659456</guid><pubDate>Wed, 02 Sep 2020 15:47:05 -0400</pubDate><category>aws</category><category>security</category><category>reports</category><category>cloud</category><category>benchmark</category></item><item><title>Container Management - AWS ECS and ECR</title><description>&lt;p&gt;Cross account and cross region management for your clusters, services, tasks, images, task sets, task definitions, scheduled tasks, container instances, vulnerability scans, container insights, repositories and events - now in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt;. Container resources aggregated within your organizational units to make it easier to understand your environment as well as access all the pertinent information in one place. There are a lot of different components in ECS. This blog post will walk you through each component and how you can manage those resources in Ylastic. ECS services allow you to always have a specified number of tasks running in a cluster. All your services are displayed in one place aggregated across regions and accounts in an OU. Select a service to view further details and associated configuration. The latest CPU and memory utilization metrics for each service are displayed in a sparkline graph next to the service name. You can view service CloudWatch metrics by clicking the sparkline to display the related charts. Click a button to generate a diagram for the service the service tasks as well as associated AWS components such as the VPC network, logs, IAM roles and more and their relationships and connections.&lt;/p&gt;&lt;figure data-orig-width="937" data-orig-height="437" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/e71baa2631ab525c9d4a774e15fc4675/75a6f21df017ee62-f4/s540x810/329a92c64d3c56fe91bb3491d960bd35a08856cb.png" alt="image" data-orig-width="937" data-orig-height="437"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Clusters are the logical grouping unit in ECS. They can contain services or simple tasks, each of which may contain a mix of tasks that can use either the Fargate or EC2 launch types. The capacity can be provisioned for a cluster either through Autoscaling groups or a Fargate capacity provider. All information for a cluster is available in one place by selecting the cluster. The latest CPU and memory utilization metrics for each cluster are displayed in a sparkline graph next to the cluster name. You can view cluster CloudWatch metrics by clicking the sparkline to display the related charts. Click a button to generate a diagram for the cluster.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="937" data-orig-height="313" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/305fd6052d1d2d6d99d5acd05c999e8b/75a6f21df017ee62-7e/s540x810/0c2fb4cacd68c49967104dbd5601f0c53f8db5eb.png" alt="image" data-orig-width="937" data-orig-height="313"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Tasks are the fundamental units of work in ECS. Task runs are based off a template called the task definition. The concept is quite similar to the way you run Autoscaling instances using a launch configuration as a template. You can run as many tasks as you want from a single task definition. Tasks can be one-off where they do a certain thing and then cease to exist. You can also run tasks as a part of a service which allows them to continuously run in a cluster. View all the task information in one place as well as easily generate a diagram for the task that shows all associated AWS components such as the VPC network, logs, IAM roles and more and their relationships as well as connections.&lt;/p&gt;&lt;figure data-orig-width="921" data-orig-height="272" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/1bb94fafdf86aecf93b4a141ea36a579/75a6f21df017ee62-10/s540x810/5cd29666b905a26796213da1815a1f6be052b939.png" alt="image" data-orig-width="921" data-orig-height="272"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;ECS tasks can also be run on a regular, scheduled basis. This allows you to launch container services that you need to run only at certain times. The scheduled tasks page gives you access to all the schedules and their respective configurations in your environment. Select any schedule to view all the tasks that running as a part of that schedule.&lt;/p&gt;&lt;figure data-orig-width="854" data-orig-height="390" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/61e944d0c8c529b5e788cee1281d7b49/75a6f21df017ee62-b0/s540x810/98981566d3030a3f83dae893439c56d0734ca8cb.png" alt="image" data-orig-width="854" data-orig-height="390"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Task Definitions provide a definition of your tasks - a template to describe the structure of your container as well as how the container should be provisioned. It specifies the docker images to use, the CPU and memory allocation for your container, any needed environment variables, exposed ports, network types and more. View detailed information on your task definitions and details of all the clusters and tasks running that are currently using each task definition.&lt;/p&gt;&lt;figure data-orig-width="937" data-orig-height="246" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/daab16a0c49d10910476780d04d4d8dc/75a6f21df017ee62-68/s540x810/a1df41f9dbea07b23c86327f3d62a42fdc0db656.png" alt="image" data-orig-width="937" data-orig-height="246"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The actual docker image that will be used to start your containers is specified in the task definition. Images can be stored in a repository on AWS ECR and they are pulled as needed when containers are instantiated. View all the images being used by all the containers that are running your task and services in one place. You can manually scan an image or have ECR automatically scan the image for known vulnerabilities in software packages when you push the image to the repository. After a while it can get really confusing to know which images are being used all over your infrastructure and if they are affected by any vulnerabilities that need to be addressed ASAP. No need to hunt through a lot of pages trying to find out your current security status. One place to find all the information you need to address the security concerns from running outdated packages. &lt;/p&gt;&lt;figure data-orig-width="948" data-orig-height="309" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/13e26dd4e52584e88ba9366fe0baae8e/75a6f21df017ee62-71/s540x810/85c2e9f5296b1a1bbecf982689b4b64918ce79e5.png" alt="image" data-orig-width="948" data-orig-height="309"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;View a detailed vulnerability scan listing for any image from one place. Links to the specific CVE listed in the security advisory are also available.&lt;/p&gt;&lt;figure data-orig-width="838" data-orig-height="373" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/82e21f90fbd2ed218f73f8a1abe1b089/75a6f21df017ee62-60/s540x810/339fa2f38b5b368ae2d5c0b10588da52fde08193.png" alt="image" data-orig-width="838" data-orig-height="373"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The images you use for your containers can be stored in ECR and pulled from that repository when your containers are instantiated to run tasks. View all your repositories and their configuration information aggregated in one place. Select a repository to see each image in that repository, its details as well as vulnerability scan information for that image.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="876" data-orig-height="358" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/766ab1e9045c8556f8efb85141abbfc0/75a6f21df017ee62-2d/s540x810/5a8c8ad44f735b05584fa6ebf6ffb1a7d10b917d.png" alt="image" data-orig-width="876" data-orig-height="358"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;You need compute capacity to actually host your docker containers and run them either as tasks or long running services. AWS gives you two different ways to accomplish this - the traditional EC2 instances or the server less compute with Fargate launch types. If you are using the EC2 launch type for your application, you can view and interact with all the container instances in your environment in one place and quickly view all associated information.&lt;/p&gt;&lt;figure data-orig-width="937" data-orig-height="272" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/90cd12344cc7596dbd138809cd9f7701/75a6f21df017ee62-f5/s540x810/e7fe27a4e8530240d0fcfbca320f94bdbcf8c4b2.png" alt="image" data-orig-width="937" data-orig-height="272"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;If you wish to use EC2 instances, then you need to run instances with the ECS agent installed. AWS provides ECS optimized AMIs in  several different variants, that are highly recommended to use as the base for your ECS container instances. Access and launch instances from these optimized Amis easily without hunting through SSM parameters and AMI pages. The latest and greatest updated AMIs from the ECS team are available in one place. &lt;/p&gt;&lt;figure data-orig-width="788" data-orig-height="409" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/652f2487209f32350bd6616b305a63d3/75a6f21df017ee62-ca/s540x810/ef1597d6d54a3c9649c148e033aa746612d82182.png" alt="image" data-orig-width="788" data-orig-height="409"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;As you update your applications to new versions, you need a way to deploy those new versions into your containers on ECS. You can perform a rolling update using the ECS service scheduler (the default option available to you on ECS). You can also perform the deployment using other controllers such as either AWS Code Deploy or something completely external outside AWS and in your own environment such as Jenkins. In order to use these two options, ECS leverages the concept of task sets, which are essentially definitions of how to perform your deployments. The task sets page in Ylastic gives you access to all your task sets information and their configuration.&lt;/p&gt;&lt;figure data-orig-width="936" data-orig-height="262" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/39f8976b09c0f712e7fa9e3ecf316d05/75a6f21df017ee62-bc/s540x810/3650e0e4f19fb1fca98bb43a24e3f9a368a14361.png" alt="image" data-orig-width="936" data-orig-height="262"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The container launches, tasks and services starting and stopping, ECS agent connects/disconnects, and other state changes in your cloud environment can quickly overwhelm you with an information overload.  The events page in Ylastic aggregates ECS events in one place from all your running clusters, service, and tasks. One place to get a quick overview on the state of your Amazon ECS resources.&lt;/p&gt;&lt;figure data-orig-width="937" data-orig-height="317" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/0be7ab2c89bef02dec19ae085de86f6d/75a6f21df017ee62-44/s540x810/2fcb3cbc4f3767e120c29d6bbddae2eb6e627d78.png" alt="image" data-orig-width="937" data-orig-height="317"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Select any ECS resource on any of the above pages, and view all associated information in one place. This includes CloudTrail events, configuration details, services, tasks, audit events, and more.&lt;/p&gt;&lt;figure data-orig-width="1009" data-orig-height="232" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/ab4e6e490b469faa6325615459e0ce7d/75a6f21df017ee62-4f/s540x810/358009b3600be435636307ebf32dc8343de39ef7.png" alt="image" data-orig-width="1009" data-orig-height="232"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;CloudWatch Container Insights collects, aggregates, and summarizes metrics and logs from your containerized applications and microservices. The metrics that are collected include utilization for container resources such as CPU, memory, disk, and network. Easily view and go through charts for all these metrics.&lt;/p&gt;&lt;figure data-orig-width="1022" data-orig-height="608" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/97c02d149b730f50c2e1b23e732681e2/75a6f21df017ee62-8c/s540x810/e7aae872de8452c40e625855db5c9fcf987d39f9.png" alt="image" data-orig-width="1022" data-orig-height="608"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;There are a lot of moving parts and components involved in running a containerized application in the cloud. Ylastic gives you the ability to get a quick overview of your ECS environment - generated from your infrastructure with a click. Diagrams of your ECS resources - clusters, services and tasks are available, which display the associated ECS resources and any other AWS components in use. Relationships between the resources are retrieved and displayed along with the containing VPC network.&lt;/p&gt;&lt;figure data-orig-width="764" data-orig-height="1074" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/80f846cd21c588582ad1f2c5a4019f58/75a6f21df017ee62-27/s540x810/0253a2ea78160388aa2473ec0953203c814cdb3f.png" alt="image" data-orig-width="764" data-orig-height="1074"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Easy to use, intuitive container management. Global CloudOps for your AWS cloud environment - Govern, manage, schedule and diagram your resources.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/627612372888158208</link><guid>https://blog.ylastic.com/post/627612372888158208</guid><pubDate>Thu, 27 Aug 2020 10:16:40 -0400</pubDate><category>aws</category><category>containers</category><category>microservices</category><category>cloud</category><category>docker</category><category>ecs</category></item><item><title>IAM diagrams</title><description>&lt;p&gt;AWS Identity and Access Management (IAM) is one of the core services in your cloud environment and is the focal point for your security configuration within AWS. Every service in AWS utilizes IAM for securing resource access. Understanding the way each of the IAM components fit together and how they combine to provide security to your cloud resources is essential for all users and businesses in the AWS cloud. The latest addition to &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; gives you the ability to generate diagrams of your IAM setup - users, groups, roles and policies from your existing environment. A user diagram will display the groups that include the user, as well as many other relationships - inline and attached policies, active and inactive access keys, SSH public keys used for CodeCommit access, and MFA devices associated with the user. &lt;/p&gt;&lt;figure data-orig-width="998" data-orig-height="700" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/884f56358cbc3a645975dcac84687943/d8ddb7c474eaea4a-8d/s540x810/4d4f5c6fd6d1a2f4f199682ecf62be9bfb443fca.png" alt="image" data-orig-width="998" data-orig-height="700"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;A diagram for an IAM role connects all the associated components and displays their relationship to each other. A common pattern in AWS is IAM role chaining where you use one role to assume another role. Ylastic will automatically traverse down the chain and display any roles that can be used for role chaining, as well as the specific policies and permissions granted to those additional roles, giving you a comprehensive overview of the role and the way it is connected within your environment.&lt;/p&gt;&lt;figure data-orig-width="1014" data-orig-height="957" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/9147dfb498ba4ff7d6c8398242bc578a/d8ddb7c474eaea4a-99/s540x810/b3cafee2ba71fe234aadeea5efdaa9cbc219b579.png" alt="image" data-orig-width="1014" data-orig-height="957"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;IAM groups are used for aggregating users, to provide a simpler way to assign permission policies to multiple users, instead of having to individually assign permissions to each user. Group diagrams will display all users in the group as well as the group policy attachments and their permissions.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="997" data-orig-height="528" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/dcbe796ce95638e48f2bd67724118c8a/d8ddb7c474eaea4a-d0/s540x810/f6c6ea2b26349209c0abd668063b3763844c094a.png" alt="image" data-orig-width="997" data-orig-height="528"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Policies attached to the various IAM entities - users, groups and roles, are used to control access within AWS. Each policy defines a set pf permissions for a set of resources and specifies whether a request for those resources is allowed or denied. A policy diagram in Ylastic will not only show you the permissions associated with the policy, it will also display all the entities in your account that have that policy attached.&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="905" data-orig-height="511" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/fdcfe55630e03e62129af46151652631/d8ddb7c474eaea4a-53/s540x810/5c5638f28893648471068c3cc849e1243b6ef9c0.png" alt="image" data-orig-width="905" data-orig-height="511"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The policy permissions display expands any wildcard permissions within the policies. This makes it really easy to quickly see how many read/write or identity(role assumption) permissions are being granted. Global CloudOps for your AWS cloud environment - Govern, manage, schedule and diagram your resources.&lt;br/&gt;&lt;/p&gt;</description><link>https://blog.ylastic.com/post/624110855268810752</link><guid>https://blog.ylastic.com/post/624110855268810752</guid><pubDate>Sun, 19 Jul 2020 18:41:33 -0400</pubDate><category>aws</category><category>iam</category><category>diagram</category><category>console</category><category>security</category><category>cloud</category></item><item><title>AWS network diagrams</title><description>&lt;p&gt;VPC is the heart of your AWS cloud environment and understanding and visualizing its various components and their relationships is crucial to running an efficient and secure cloud operation. You can now easily generate VPC network diagrams from your existing AWS infrastructure in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt;. View a complete diagram of any VPC - private and public subnets, associated route tables that control traffic flow, and all of the other components comprising the network and their connections to one another.&lt;/p&gt;&lt;figure data-orig-width="893" data-orig-height="946" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/43fda17faa9cebe93540deb0fe66caa1/03a93e267f8c7cc1-f5/s540x810/da4b891f41d47857a4fd3658f44ab542fa879dd8.png" alt="image" data-orig-width="893" data-orig-height="946"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The generated diagrams cover all the different components within a VPC network:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Subnets (public and private)&lt;/li&gt;&lt;li&gt;Route Tables&lt;/li&gt;&lt;li&gt;Network Access Control Lists&lt;/li&gt;&lt;li&gt;Internet, VPN and Customer Gateways&lt;/li&gt;&lt;li&gt;NAT Gateways&lt;/li&gt;&lt;li&gt;Transit and egress only gateways&lt;/li&gt;&lt;li&gt;Elastic Network Interfaces&lt;/li&gt;&lt;li&gt;VPN connections to corporate data centers&lt;/li&gt;&lt;li&gt;VPC peering connections&lt;/li&gt;&lt;li&gt;VPC endpoints&lt;/li&gt;&lt;li&gt;VPC flow logs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="958" data-orig-height="444" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/6aa953f6e171023ba2157590421da72e/03a93e267f8c7cc1-f0/s540x810/d87c58b7dec6d7144f2b71ad5e52a7b55f87697c.png" alt="image" data-orig-width="958" data-orig-height="444"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Outbound routes from your VPC, such as connections to your corporate networks and data centers via Customer gateways and VPN are also displayed. Traffic routes outbound to the internet (both IPv4 and IPv6) are clearly delineated as well.&lt;/p&gt;&lt;figure data-orig-width="977" data-orig-height="607" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/d52bbabfce7c1d66d55a0eb44f9a4f10/03a93e267f8c7cc1-52/s540x810/54ce20546ece45e13b5b2ffbf646e004667feedb.png" alt="image" data-orig-width="977" data-orig-height="607"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Further drill down into your network architecture and the main sub-component of a VPC - a subnet. Select any subnet and view the components hosted in the subnet and their relationships. A subnet diagram is rendered as a subset of the containing VPC, and it displays only the routes to the entries defined in its associated route table. This makes it very easy to get an isolated view of your subnet design.&lt;/p&gt;&lt;figure data-orig-width="811" data-orig-height="859" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/bc694558094343625581903ea100782e/03a93e267f8c7cc1-31/s540x810/dee0b6b215fef5a6e75dec0038df534cd8ccdcd7.png" alt="image" data-orig-width="811" data-orig-height="859"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Focus all the way from a VPC down to the individual subnets and visualize the way different networking resources are connected and how they work together in the VPC environment.&lt;/p&gt;&lt;figure data-orig-width="881" data-orig-height="791" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/5203dec2dc7822e446cd3b73c869d9da/03a93e267f8c7cc1-0f/s540x810/5a6b74ed82de3a760c4135268d9e0036ddc134e1.png" alt="image" data-orig-width="881" data-orig-height="791"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Easy to use, global CloudOps for AWS environments.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/623463833477038080</link><guid>https://blog.ylastic.com/post/623463833477038080</guid><pubDate>Sun, 12 Jul 2020 15:17:25 -0400</pubDate><category>aws</category><category>network</category><category>diagram</category><category>console</category><category>vpc</category></item><item><title>Tracking service updates</title><description>&lt;p&gt;New in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; - easily track service updates from AWS as well as Ylastic. The dashboard view displays the 5 most recent updates. &lt;/p&gt;&lt;figure data-orig-width="1001" data-orig-height="814" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/7620f8b91f8cb580b2b489b9495ffdda/275dea53e4d1c097-3c/s540x810/a1ce941b0e4089c1ef618fbd6fdc99ccecdd7547.png" alt="image" data-orig-width="1001" data-orig-height="814"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Drill down and filter/search through updates for either service easily on dedicated pages. The updates from various AWS information sources are all aggregated in one page.&lt;/p&gt;&lt;figure data-orig-width="1006" data-orig-height="511" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/6fb22c366f56d03df479177840f8373f/275dea53e4d1c097-2a/s540x810/aaf84900414db4b5860ee03b2b2857f554e43092.png" alt="image" data-orig-width="1006" data-orig-height="511"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Easily search/filter through updates to Ylastic in one place. Click the links to navigate to specific Ylastic console pages with the updates or blog posts with more information on each feature enhancement.&lt;/p&gt;&lt;figure data-orig-width="1005" data-orig-height="580" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/e4e122afdb2958775e77b927308c9b5c/275dea53e4d1c097-78/s540x810/30ee5529ce4963be6b05671297675944369be702.png" alt="image" data-orig-width="1005" data-orig-height="580"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Easy access to all the information you need in one place. Global CloudOps for your AWS environment. &lt;/p&gt;</description><link>https://blog.ylastic.com/post/621717813053259776</link><guid>https://blog.ylastic.com/post/621717813053259776</guid><pubDate>Tue, 23 Jun 2020 08:45:10 -0400</pubDate><category>aws</category><category>updates</category><category>cloud</category></item><item><title>Visualize AWS Security groups</title><description>&lt;p&gt;Getting a handle on security groups that control access to your VPC/EC2-Classic can be a daunting task. Inbound rules, outbound rules, CIDR blocks, all these different security groups, and so on. It would be really nice to be able to visualize how they all tie together. Updates to &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; for visualizing your AWS VPC and EC2 security groups, and a navigator to easily zoom, pan and even peruse the diagram full-screen. &lt;/p&gt;&lt;figure data-orig-width="962" data-orig-height="697" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/8a68bb077fd0c382554a3607f41c48ab/1e2709790a2962b5-5f/s540x810/408d7f8ea5b6a5c902c0066d258667e2a0b6cf93.png" alt="image" data-orig-width="962" data-orig-height="697"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;All pertinent information displayed for the security group. Both inbound and outbound rules are separated and displayed by protocol - IPv4 and IPv6. Rules information is aggregated to make it easy to view groups with a large number of rules. &lt;/p&gt;&lt;figure data-orig-width="895" data-orig-height="611" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/143fd35cd0da698bc7d0f7cb47c266b8/1e2709790a2962b5-39/s540x810/02e7616888d707fea488b9a32e08877754171b5c.png" alt="image" data-orig-width="895" data-orig-height="611"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/621171378463424512</link><guid>https://blog.ylastic.com/post/621171378463424512</guid><pubDate>Wed, 17 Jun 2020 07:59:49 -0400</pubDate><category>aws</category><category>ec2</category><category>vpc</category><category>cloud</category><category>security</category></item><item><title>Export AWS resource data to PDF, CSV, JSON, Excel, XML</title><description>&lt;p&gt;Easily export data from any of the resource pages in &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; to multiple formats - PDF, CSV, JSON, Excel or XML. &lt;/p&gt;&lt;figure data-orig-width="918" data-orig-height="326" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/0fb13074b23f4ec552f0fedcf9f33e24/4755066522d0814e-8e/s540x810/c0af9004415a14e4cf2144d8ca068b3451df16ab.png" alt="image" data-orig-width="918" data-orig-height="326"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Exported data includes all regions. You can export at either an AWS account level, or even at an AWS Organizational Unit level (to include ALL AWS accounts contained in that unit).&lt;/p&gt;&lt;figure data-orig-width="923" data-orig-height="287" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/88c3a5165a3433283a577ff89bb2dcce/4755066522d0814e-9e/s540x810/f13b6ba4005898c76dc7072e2cc8cafb180223e5.png" alt="image" data-orig-width="923" data-orig-height="287"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/620559159078813696</link><guid>https://blog.ylastic.com/post/620559159078813696</guid><pubDate>Wed, 10 Jun 2020 13:48:51 -0400</pubDate><category>aws</category><category>cloud</category><category>management</category><category>report</category></item><item><title>IAM Access Analyzer for Organizations</title><description>&lt;p&gt;AWS IAM &lt;a href="https://aws.amazon.com/iam/features/analyze-access/" target="_blank"&gt;Access Analyzer&lt;/a&gt; helps identify unintended access to your account resources and data, which can be a security risk.  IAM can identify resources shared with external principals through analysis of all the resource-based policies in your account, and then generate findings to include information about the access granted to the external principal. You can review findings to determine whether the access is intended and safe, or the access is unintended and a security risk. Access Analyzer generates its findings separately in each region.  In an AWS Organization with mutliple AWS accounts that uses multiple regions, this information is not very easy to access in a single place. &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; can retrieve, aggregate and display all your analyzer findings across ALL regions and from ALL AWS accounts within an AWS organizational unit. &lt;/p&gt;&lt;figure data-orig-width="1004" data-orig-height="467" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/da9db4936f06cc572e60a4c43adc974c/660fe3e9b60ba6b5-b1/s540x810/3c143a98f8e1c4afde1fa4c1055f3e53992aaea8.png" alt="image" data-orig-width="1004" data-orig-height="467"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Select any finding to view details of all the actions granted to the external principal. You can archive a finding if the access level is appropriate or rescan the resource if you have made changes to access granted to it. You can also review details of the resource in question easily, as well as re-activate any finding that you have archived in case you want to revisit that finding.&lt;/p&gt;&lt;figure data-orig-width="1004" data-orig-height="466" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/617ac8c607a49bab4cc7e6b4616853b2/660fe3e9b60ba6b5-54/s540x810/4a61066a3763159d7e8c924c2c0adc9d4584c141.png" alt="image" data-orig-width="1004" data-orig-height="466"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;All actions flagged by IAM that have been granted to the principal are hyperlinked in Ylastic. Click to view complete detail of the granted permission so you can quickly review and take action.&lt;/p&gt;&lt;figure data-orig-width="981" data-orig-height="464" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/8bb38c4f2e0b258e6c313b8bd994fc5d/660fe3e9b60ba6b5-58/s540x810/6d940ee0234c29512d9dad34746ab28f62f04cf9.png" alt="image" data-orig-width="981" data-orig-height="464"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;All the information you need to manage your cloud resources, available to you quickly, easily and in one place. Global cloudops for your AWS environment.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/620095499516755968</link><guid>https://blog.ylastic.com/post/620095499516755968</guid><pubDate>Fri, 05 Jun 2020 10:59:11 -0400</pubDate><category>aws</category><category>iam</category><category>cloud</category><category>security</category><category>management</category></item><item><title>Scheduled RDS exports to S3</title><description>&lt;p&gt;You can now easily schedule the export of RDS DB snapshot data to an Amazon S3 bucket from &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt;. The exported data from RDS is stored in Apache Parquet format that is compressed and consistent, as well as encrypted using a KMS key provided by you for S3 server-side encryption.&lt;/p&gt;&lt;figure data-orig-width="999" data-orig-height="193" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/0ef9f15f9f50e27c4ef3012f512e5155/ff8eb0ff3103a3f0-6f/s540x810/f15260704202b64223d52fc681ea54f165727928.png" alt="image" data-orig-width="999" data-orig-height="193"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Easily export multiple instances by specifying a tag based filter when you create a scheduled task.&lt;/p&gt;&lt;figure data-orig-width="904" data-orig-height="644" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/a8acedb8347f8331cef306f24ea9a007/ff8eb0ff3103a3f0-a8/s540x810/c76c097476798b997fdf057562cf28387b297450.png" alt="image" data-orig-width="904" data-orig-height="644"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;View and access all your S3 exported backups easily and aggregated across all regions in one page.&lt;/p&gt;&lt;figure data-orig-width="1000" data-orig-height="333" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/c78e9511e7c2661e8a96084a24c90ba3/ff8eb0ff3103a3f0-f8/s540x810/00f5f02f378ef233260335302465a29fc7b177ff.png" alt="image" data-orig-width="1000" data-orig-height="333"/&gt;&lt;/figure&gt;</description><link>https://blog.ylastic.com/post/619906414113095680</link><guid>https://blog.ylastic.com/post/619906414113095680</guid><pubDate>Wed, 03 Jun 2020 08:53:45 -0400</pubDate><category>aws</category><category>rds</category><category>cloud</category><category>management</category><category>schedule</category></item><item><title>Schedule instance backups to include cross-account resources in an AWS Organization</title><description>&lt;p&gt;AWS Organizations is an essential feature that enables grouping of multiple AWS accounts into organizational units(OU), with the ability to apply policy, security and compliance requirements across the whole organization or individual OU. &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; fully integrates AWS Organizations with the ability to manage and govern your AWS resources at the OU level. All functions in Ylastic can be done at the level of an OU, spanning all the AWS accounts that comprise the unit. New in Ylastic is the ability to make backups of your cross account instances in an OU. So with a single task in Ylastic, you can backup all instances matching a tag, across multiple regions, across all accounts in an OU. The backups can be to a destination account within your OU, and can also be made to multiple regions. An example to illustrate the power of OU backups. We have three instances running in three different regions - Virginia, Ohio and Frankfurt. Each instance is running in a different AWS account - Production, Analytics, and Design. The three accounts are all part of an OU named Zeno. Instances are tagged with a key ‘env’ and a value of ‘spark’. We are going to back up all three instances to a Backups account in this OU.&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;figure data-orig-width="1011" data-orig-height="243" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/51198ffc797dd0f13b1a7f56de60c267/38e50902f229084b-0a/s540x810/0872800aa4975932d75c6084f4ed491d175a4aa0.png" alt="image" data-orig-width="1011" data-orig-height="243"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Add a task specifying the tag, select source regions, and destination regions. Also select the account for backing up these instances. You can control how many backups you want to retain at any time. Set a time to run. Save the task and you are all done.&lt;/p&gt;&lt;figure data-orig-width="948" data-orig-height="574" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/dcd39c4fcecc2a0a23945db8214a2386/38e50902f229084b-f8/s540x810/442960ced52be8f993ae6c68a62b3ae5066139e4.png" alt="image" data-orig-width="948" data-orig-height="574"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Here is the task we just created - Backup all instances in regions Frankfurt, Ohio, and Virginia that have a tag matching env=spark in all AWS accounts in OU zeno, to region Virginia in AWS account Backups. &lt;/p&gt;&lt;figure data-orig-width="1013" data-orig-height="206" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/b351f85b3fb50fb97355640a655ec5ef/38e50902f229084b-43/s540x810/c6ea2f9113276c1a63bba764fe63106a882f7393.png" alt="image" data-orig-width="1013" data-orig-height="206"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The task runs at the time scheduled, and creates the backups in the account specified. You can see a history of the task execution, along with time taken and other information. No switching accounts, no switching regions. One place to check the backups created and all other information related to the backup. &lt;/p&gt;&lt;figure data-orig-width="1015" data-orig-height="425" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/1ea402bf8649a3ee95a8cb043f48a792/38e50902f229084b-6e/s540x810/542dc99a8798f2b31b2a3b60c85ed2d3ec71a697.png" alt="image" data-orig-width="1015" data-orig-height="425"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Click the details icon to view resources that were created, and deleted for the specific task execution.&lt;/p&gt;&lt;figure data-orig-width="873" data-orig-height="302" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/a913bff6319ac18271ab84d7b9ced726/38e50902f229084b-ab/s540x810/9aa0cb839aa5ea522a8a6ba6714273438ea1fc04.png" alt="image" data-orig-width="873" data-orig-height="302"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;You can see the backups for each instance, by just selecting the instance. All backups (cross-account/cross-region) are displayed in one place making it super simple to restore an instance from a backup. &lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="396" data-orig-width="1011"&gt;&lt;img src="https://64.media.tumblr.com/e0bae4ed19e60c815dc240d2c6543047/38e50902f229084b-45/s540x810/9bfa27b3c7063085402f705f2e7ff770d5a703aa.png" data-orig-height="396" data-orig-width="1011"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Cross region, cross account AWS cloud management - global cloudOps for your AWS Organization.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/189210427026</link><guid>https://blog.ylastic.com/post/189210427026</guid><pubDate>Thu, 21 Nov 2019 10:29:13 -0500</pubDate><category>aws</category><category>ec2</category><category>backup</category><category>organizations</category></item><item><title>Resource configuration and compliance history for AWS Organizations</title><description>&lt;p&gt;AWS Config provides a detailed view of the configuration of the AWS resources within your AWS account. It keeps track of how the resources are related to one another and how they were configured in the past. This makes it easier to see how both the configurations as well as relationships between resource change over time. tracks all changes made to them. You can also create AWS Config rules to represent your ideal configuration settings and use those rules to evaluate the configuration settings of your AWS resources. Customizable, predefined rules called managed rules are also made available by AWS to help you get started. AWS Config continuously tracks the configuration changes that occur among your resources, checks whether these changes violate any of the conditions in your rules. If a resource violates a rule, AWS Config flags the resource and the rule as noncompliant. So AWS config provides both a resource configuration history as well as a history of compliance events for your resources. AWS Config is not enabled by default for AWS accounts. You can enable and configure it for your account on the &lt;a href="https://amzn.to/2Ofctiy" target="_blank"&gt;setup page&lt;/a&gt;. &lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="891" data-orig-width="1012"&gt;&lt;img src="https://64.media.tumblr.com/61f2ee85e8fa43045ba70e2746f93bfe/990c23dd9da2ade6-5b/s540x810/054d65902806cef2a8b39aa3c22825861530aebe.png" data-orig-height="891" data-orig-width="1012"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Once you have Config enabled, AWS will start delivering activity and compliance log files to the specified S3 bucket as events happen within your account. &lt;a href="http://bit.ly/2y1VKtV" target="_blank"&gt;Integrate with Ylastic&lt;/a&gt; on your accounts page to enable several Config related features within Ylastic. The integration will also create the plumbing required to connect with Config through SNS to receive and process activity for this account anytime AWS generates new events. Ylastic will connect things, download, process, and integrate the data to provide you with up to date API activity as well as analytics. You can view and search through all resource configuration events cross-region and cross-account (if you are using AWS Organizations).&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="667" data-orig-width="1013"&gt;&lt;img src="https://64.media.tumblr.com/8c5ddadc42789fed5778714cb2c26990/990c23dd9da2ade6-99/s540x810/d650f4267292eea7d298147ede08392f8c536caf.png" data-orig-height="667" data-orig-width="1013"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;All of the compliance events (cross-region and cross-account) are available on a separate tab. This makes it easier to focus on specific compliance rules and specific resources.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="595" data-orig-width="1010"&gt;&lt;img src="https://64.media.tumblr.com/6bc0fd72ac24e705838d48dc62855a05/990c23dd9da2ade6-c8/s540x810/f60af83e65b2b23413a341214ac3e73f44778abc.png" data-orig-height="595" data-orig-width="1010"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Click to view the complete details for either a resource configuration or a compliance event. &lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="512" data-orig-width="1019"&gt;&lt;img src="https://64.media.tumblr.com/c14da86b47f224fa7b90104ef9121a35/990c23dd9da2ade6-74/s540x810/318949c9da70c09a4d431a9c0ad89c036daa7ffc.png" data-orig-height="512" data-orig-width="1019"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Ylastic extends this further with a deep integration of the resource configuration history and compliance history with an individual resource page. So for instance, you can select a security group, and immediately view its resource configuration history without the need to go to another page. Since Ylastic is a cross-region, cross-account console, ALL your resources (in this case security groups) are available in one place.&lt;/p&gt;&lt;figure data-orig-width="1014" data-orig-height="681" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/ebd67de9c88f98c3aa850090ca23ea74/990c23dd9da2ade6-67/s540x810/c28ec4680c10358ba1aa87016206bcf96ea852fc.png" alt="image" data-orig-width="1014" data-orig-height="681"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Click on any of the events in the timeline to view the changes made to that resource at that specific time.&lt;/p&gt;&lt;figure data-orig-width="1019" data-orig-height="740" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/7aa685617daf4c9246a4e13cb60a6dba/990c23dd9da2ade6-ad/s540x810/a74d5f1bc08fead8110c2a922da6fe4982ef5a99.png" alt="image" data-orig-width="1019" data-orig-height="740"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;You can also view the compliance status of your rules and resources which are readily available on a sub-tab.&lt;/p&gt;&lt;figure class="tmblr-full" data-orig-height="683" data-orig-width="1015"&gt;&lt;img src="https://64.media.tumblr.com/3599fb0729ccb2858f696faecbff4437/990c23dd9da2ade6-63/s540x810/c3b1eefb1ebcd3bc7d99e4c2e2fba2a5544aa53d.png" data-orig-height="683" data-orig-width="1015"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Click any compliance event to see more details, along with a link to the actual rule that was responsible for the flag raised by Config on your resource.&lt;/p&gt;&lt;figure data-orig-width="1012" data-orig-height="353" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/cbcf6450ab7ed49ca26527690a4c8cfa/990c23dd9da2ade6-70/s540x810/488f42613b5d2518a34f26305ea5cd772182b438.png" alt="image" data-orig-width="1012" data-orig-height="353"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Cross region, cross account AWS cloud management - global cloudOps for your AWS Organization.&lt;br/&gt;&lt;/p&gt;</description><link>https://blog.ylastic.com/post/189110061131</link><guid>https://blog.ylastic.com/post/189110061131</guid><pubDate>Sat, 16 Nov 2019 16:19:48 -0500</pubDate><category>aws</category><category>cloud</category><category>config</category><category>compliance</category><category>security</category></item><item><title>Global views for AWS Organization environments</title><description>&lt;p&gt;An AWS cloud environment has a lot of different facets and moving parts to it. It can be quite a task to get a good overview of where things stand and how they are distributed by region. This can get especially hard if you are using many AWS accounts, all managed under the umbrella of an AWS Organizational unit. Constantly logging in and and out of accounts or switching regions so you can get to your resources is both time consuming and can be quite frustrating. &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; simplifies management and governance for your AWS environment by letting you view/manage your environment at either an AWS account level or at an AWS Organization level. That means you can view an AWS account at either a cross-region level aggregating resources from all regions in that account, or you can go to a higher level, and view/manage your resources cross-account and cross-region, aggregating resources from ALL accounts within an AWS Organizational unit. No logging out, no switching regions. The information you need available in a single pane. The dashboard presents 10 different overviews of your AWS environment. All views are global - aggregated cross-region and cross-account (if you are using AWS Organizations). You can click on links within each view to go to specific detail and management pages for those resources. &lt;b&gt;&lt;i&gt;Activity&lt;/i&gt;&lt;/b&gt; view displays your latest CloudTrail API activity as well as the latest configuration change activity.&lt;/p&gt;&lt;figure data-orig-width="1010" data-orig-height="706" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/3af6cd64896415ec719b82703a8e9c6b/5a993338a94f1c55-b1/s540x810/639041a16669ae751e94e7d8df3e20c934ec6723.png" alt="image" data-orig-width="1010" data-orig-height="706"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Advisor&lt;/i&gt;&lt;/b&gt; view displays the aggregated Trusted Advisor check results in 5 different categories across accounts.&lt;/p&gt;&lt;figure data-orig-width="1011" data-orig-height="705" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/10f88532f78bdaab39509e0fd10fb321/5a993338a94f1c55-fa/s540x810/afbe7e8a5660f0a101e0378269fd50a13683ea7f.png" alt="image" data-orig-width="1011" data-orig-height="705"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Backups&lt;/i&gt;&lt;/b&gt; view aggregates the current state of backups for your entire AWS environment - both backup and restore jobs.&lt;/p&gt;&lt;figure data-orig-width="1014" data-orig-height="707" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/0243d9b25abc101ddffac939a66ced99/5a993338a94f1c55-0a/s540x810/0f639eab162a67c773bc3ebb35eeb88f37fd557e.png" alt="image" data-orig-width="1014" data-orig-height="707"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Health&lt;/i&gt;&lt;/b&gt; view aggregates the state of your CloudWatch alarms as well as any scheduled changes, service issues and account notifications.&lt;/p&gt;&lt;figure data-orig-width="1011" data-orig-height="707" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/6f33b9a79afa51f85c3737fa893fd259/5a993338a94f1c55-60/s540x810/4bc6fa8616a49436723cf28ebacae5b721faaa8a.png" alt="image" data-orig-width="1011" data-orig-height="707"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Inventory&lt;/i&gt;&lt;/b&gt; view displays the latest inventory report with all the configuration information from resources in your AWS environment.&lt;/p&gt;&lt;figure data-orig-width="1012" data-orig-height="707" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/5b49d6ef3eedb2f2f9a6866e1ec3467f/5a993338a94f1c55-45/s540x810/4443a5bbe27ceb73c710fc484d2dd18ca508ed33.png" alt="image" data-orig-width="1012" data-orig-height="707"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Resources&lt;/i&gt;&lt;/b&gt; view displays an aggregated cross-region and cross-account count of resources in your AWS environment.&lt;/p&gt;&lt;figure data-orig-width="1014" data-orig-height="706" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/51e23869de3ec4b79ffff5818478aa3c/5a993338a94f1c55-66/s540x810/fa1e000a36dbcc4cd95970464da0168417cc3bbc.png" alt="image" data-orig-width="1014" data-orig-height="706"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Scheduling&lt;/i&gt;&lt;/b&gt; view displays an overview of your scheduled tasks and their execution status, as well as run metrics.&lt;/p&gt;&lt;figure data-orig-width="1013" data-orig-height="706" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/759f64a6152b515a432b945e5125461a/5a993338a94f1c55-2d/s540x810/ef6bc6470a67f33eb991c83c01f6f6bc43a8f81a.png" alt="image" data-orig-width="1013" data-orig-height="706"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Security&lt;/i&gt;&lt;/b&gt; view displays a summary of all the SecurityHub findings and insights along with the status of the last run CIS benchmark security report.&lt;/p&gt;&lt;figure data-orig-width="1010" data-orig-height="736" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/4d0e8f0a56a92c41e177dbdd467978a4/5a993338a94f1c55-9e/s540x810/f2af20201fd95adafa9c7fcaa38466d63db7963e.png" alt="image" data-orig-width="1010" data-orig-height="736"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Spending&lt;/i&gt;&lt;/b&gt; view displays daily spending for your AWS environment over the last 30 days.&lt;/p&gt;&lt;figure data-orig-width="1013" data-orig-height="708" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/0a6d73066bd689a0e953286d0b32df5d/5a993338a94f1c55-66/s540x810/da02b83f4cdc6196f6777cc203e093bcb10fbac5.png" alt="image" data-orig-width="1013" data-orig-height="708"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;i&gt;Support&lt;/i&gt;&lt;/b&gt; view aggregates your support tickets from AWS and their metrics.&lt;/p&gt;&lt;figure data-orig-width="1010" data-orig-height="705" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/04d544d9219f5408d0723c7799ecba7c/5a993338a94f1c55-35/s540x810/876f733200cd9d58e54f4b476f94edb0adc33cc6.png" alt="image" data-orig-width="1010" data-orig-height="705"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Cross region, cross account AWS cloud management - global cloudOps for your AWS Organization.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/189036742536</link><guid>https://blog.ylastic.com/post/189036742536</guid><pubDate>Wed, 13 Nov 2019 08:37:36 -0500</pubDate><category>aws</category><category>cloud</category><category>management</category><category>console</category><category>organizations</category></item><item><title>CloudTrail for AWS Organizations</title><description>&lt;p&gt;AWS CloudTrail records all the AWS API calls made in your account or on behalf of your AWS account. The recorded event information is saved as log files to an S3 bucket. The log files include complete details of the API call, such as, the identity of the user, the start time of the AWS API call, the source IP address, the request parameters, and the response elements returned by the service. This information is invaluable for troubleshooting and for investigating security issues. &lt;a href="http://bit.ly/2i2cR3B" target="_blank"&gt;Ylastic&lt;/a&gt; provides comprehensive and complete integration of CloudTrail API activity into the management console. You can view and dissect CloudTrail activity cross-account and cross-region. A single pane to display activity from ALL accounts and ALL regions in your AWS organization. In order to get started with CloudTrail, you must first enable it for your AWS account, as it is not turned on by default by AWS. Enable it from the &lt;a href="https://console.aws.amazon.com/cloudtrail/home?region=us-east-1#/configuration" target="_blank"&gt;CloudTrail setup page&lt;/a&gt; by providing the name of the trail itself, and an S3 bucket to use for storing the activity information. &lt;/p&gt;&lt;figure data-orig-width="1014" data-orig-height="779" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/b8bd6d774912fa47eea0488f32993598/c94e25337beebd0d-08/s540x810/71f87c81c2d00cb854e69dd776fe5f25a4a6c303.png" alt="image" data-orig-width="1014" data-orig-height="779"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Once you have CloudTrail enabled, AWS will start delivering activity log files to the specified S3 bucket as events happen within your account. Integrate with Ylastic to enable several CloudTrail related features within Ylastic. The integration will also create the plumbing required to connect with CloudTrail through SNS to receive and process activity for this account anytime AWS generates new events. Ylastic will connect things, download, process, and integrate the data to provide you with up to date API activity as well as analytics. &lt;/p&gt;&lt;figure data-orig-width="1015" data-orig-height="788" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/6fbb891e00eaf7b174262c29f41fe6c6/c94e25337beebd0d-62/s540x810/65323f0c4c9b62bbf1d9bccb5da1fbd3cc691a31.png" alt="image" data-orig-width="1015" data-orig-height="788"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;View and search API activity across all regions and accounts in one page without switching regions or logging into other accounts to keep track of things. All activity in your AWS Organizational unit is available for easy analysis.&lt;/p&gt;&lt;figure data-orig-width="1014" data-orig-height="698" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/29e3c158a95580acdf22b61458c77ca0/c94e25337beebd0d-13/s540x810/5e7e85360db0ea988c1e6782ffcd2cbc2e82451d.png" alt="image" data-orig-width="1014" data-orig-height="698"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;The actual event data generated by CloudTrail is available to you If you need access to the original event or wish to examine all the parameters that were part of the API call.&lt;/p&gt;&lt;figure data-orig-width="994" data-orig-height="628" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/0abfb423ca537c2e6d9ef0ace34f6907/c94e25337beebd0d-42/s540x810/73b3e4fd970b867bd29ead74b00fd6a717361a8d.png" alt="image" data-orig-width="994" data-orig-height="628"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;Activity is separated to make it easier to drill-down into errors flagged by CloudTrail. &lt;/p&gt;&lt;figure data-orig-width="1015" data-orig-height="653" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/a5a3e31de181031f8294760c84dcfc53/c94e25337beebd0d-d2/s540x810/8764ed04b38d7ecf9f08318e01c1410317265362.png" alt="image" data-orig-width="1015" data-orig-height="653"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;You can view the API failures separately so you can quickly diagnose permissions failures and deep-dive into security issues. &lt;/p&gt;&lt;figure data-orig-width="1013" data-orig-height="374" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/f481a2fcf02fa2e5ae6e9bcee941f247/c94e25337beebd0d-b4/s540x810/5f03ad64bef2a23213783d48d135bacab0f12f7a.png" alt="image" data-orig-width="1013" data-orig-height="374"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;API activity is deeply integrated with every part of the Ylastic management console. It is available to you on every resource page with a sub tab that displays all CloudTrail activity for that specific resource.  &lt;/p&gt;&lt;figure data-orig-width="1015" data-orig-height="496" class="tmblr-full"&gt;&lt;img src="https://64.media.tumblr.com/14ab808caf79c98f492dd8dd231244ea/c94e25337beebd0d-c9/s540x810/2e5fdb939abd040f93ffbc68c6ea6b3702349f95.png" alt="image" data-orig-width="1015" data-orig-height="496"/&gt;&lt;/figure&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;CloudTrail is an invaluable resource as a total audit trail of all activity in your AWS account, whether it is by your users or a third party partner. Enable it, integrate with Ylastic, and track changes and activity in your AWS account. Cross region, cross account CloudTrail - global cloudOps for your AWS Organization.&lt;/p&gt;</description><link>https://blog.ylastic.com/post/189013854541</link><guid>https://blog.ylastic.com/post/189013854541</guid><pubDate>Tue, 12 Nov 2019 08:42:39 -0500</pubDate><category>aws</category><category>cloud</category><category>cloudtrail</category><category>security</category></item></channel></rss>
