MoinMoin Logo
  • Comments
  • Immutable Page
  • Menu
    • Navigation
    • RecentChanges
    • FindPage
    • Local Site Map
    • Help
    • HelpContents
    • HelpOnMoinWikiSyntax
    • Display
    • Attachments
    • Info
    • Raw Text
    • Print View
    • Edit
    • Load
    • Save
  • Login

Navigation

  • Start
  • Sitemap
Revision 48 as of 2026-08-29 10:04:17
  • AWS

Contents

  1. AWS
    1. User credentials
    2. Serverless blog web application architecture
    3. IPv6 info
    4. Lambda authorizer (API gateway)
    5. Add inbound rule in RDS to a lambda function
    6. Stuff
    7. Lakehouse and Datawarehouse (Kimball/Inmon)

AWS

Amazon Web Services

Lambda Java samples:

  • lambda samles

  • sample apps java basic

User credentials

  • root vs iam

  • aws access keys best practices

  • IAM best practices

Instead of sharing the credentials of the AWS account root user, create individual IAM users, granting each user only the permissions they require.

Follow the best practice of using the root user only to create your first IAM user.

There are two types of credentials:

  • Root user credentials, allow full access to all resources in the AWS account.
  • IAM credentials, control access to AWS services and resources for users in your AWS account

Serverless blog web application architecture

  • https://github.com/aws-samples/lambda-refarch-webapp

  • https://s3.amazonaws.com/aws-lambda-serverless-web-refarch/RefArch_BlogApp_Serverless.png

    • Amazon Route 53 (routes to specific places based on region)
    • Amazon CloudFront (deliver static content per region hosted inside S3)

    • Amazon Simple Storage Service (S3)
    • Amazon Cognito (Authentication and authorization)
    • Amazon API Gateway (routes requests to backend logic)
    • AWS Lambda (backend business logic)
    • AWS DynamoDB (managed DB)
    • AWS Identity and Access Management (IAM) - web service to control access to AWS resources

IPv6 info

  • introducing ipv6 only subnets and ec2 instances

  • using instance addressing amazon-dns

  • using instance addressing #working with ipv6 addresses

Lambda authorizer (API gateway)

A lambda authorizer (API gateway) requires a resource based policy statement, with principalId and policy document.

  • API gateway lambda authorizer output

JSON example

   1 {
   2   "principalId": "user|12345",
   3   "policyDocument": {
   4     "Version": "2012-10-17",
   5     "Statement": [
   6       {
   7         "Action": "execute-api:Invoke",
   8         "Effect": "Allow",
   9         "Resource": "arn:aws:execute-api:region:account-id:api-id/stage/METHOD/path"
  10       }
  11     ]
  12   },
  13   "context": {
  14     "stringKey": "value",
  15     "numberKey": 123,
  16     "booleanKey": true
  17   }
  18 }

Add inbound rule in RDS to a lambda function

   1 RDS_DB_PORT=5432
   2 RDS_SG=$(aws rds describe-db-instances --db-instance-identifier rds-instance-id \
   3     --query "DBInstances[0].VpcSecurityGroups[*].VpcSecurityGroupId" --output text)
   4 echo "RDS security group $RDS_SG"
   5 
   6 LAMBDA_SG=$(aws lambda get-function-configuration --function-name lambda-function-name \
   7     --query "VpcConfig.SecurityGroupIds[*]" --output text)
   8 echo "Lambda function security group $LAMBDA_SG"
   9 
  10 aws ec2 authorize-security-group-ingress --group-id $RDS_SG \
  11     --protocol tcp -port $RDS_DB_PORT --source-group $LAMBDA_SG

Stuff

   1 aws lambda list-functions
   2 aws ecs describe-task-definition -- task-definition 
   3 # a task definition sets a docker image for a task/container
   4 

Lakehouse and Datawarehouse (Kimball/Inmon)

Motoserver (mock a lakehouse/datawarehouse):

  • S3
  • Glue
  • Athena (DuckDB)

Dimensional modelling, Athena star schema

Cheap storage of a data lake (S3)

High speed SQL (Athena/Redshift)

ETL, extract , transform in a staging area, load in the warehouse

ELT, extract raw data, load it into a data lake (S3), transform only when we need to query it

Top-down Inmon method, corporate data warehouse uisng 3rd normal form (3NF) (DB normalization)

  • define schema/structure in AWS glue. enforce schema in all S3 buckets
  • use Athena federated query to get raw data into bronze raw s3 (bronze layer)
  • 3NF warehouse (silver layer) use Athena to transform the raw data into a normalized structure stored as a parquet files in S2. single version of the truth. Athena looks at glue catalog to turn parquet files into a 3NF table with rows and columns
  • Data mart (gold layer) create athena views that use the 3NF warehouse optimized for each business unit

Bronze (raw) discovery and ingestion Silver (warehouse) strict 3NF, single version of truth Gold (Marts) star schema, business reporting, most similar to a cube

2010, SQL databases, MDX cubes

2026, use SQL that evolved to include "window functions" and "grouping sets"

Analytical SQL (OLAP) 2026

Standard SQL (OLTP)

  • MoinMoin Powered
  • Python Powered
  • GPL licensed
  • Valid HTML 4.01