<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Wilmost-Tech]]></title><description><![CDATA[Wilmost-Tech]]></description><link>https://blog.wilmomartinez.1618lab.com</link><generator>RSS for Node</generator><lastBuildDate>Tue, 06 Oct 2026 12:46:34 GMT</lastBuildDate><atom:link href="https://blog.wilmomartinez.1618lab.com/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[Beyond Servers: How Serverless Computing is Revolutionizing App Development]]></title><description><![CDATA[Introduction
In the ever-evolving landscape of technology, serverless computing has emerged as a game-changer, offering a paradigm shift in how backend services are provisioned and managed. Imagine writing and deploying code without the burden of wor...]]></description><link>https://blog.wilmomartinez.1618lab.com/beyond-servers-how-serverless-computing-is-revolutionizing-app-development</link><guid isPermaLink="true">https://blog.wilmomartinez.1618lab.com/beyond-servers-how-serverless-computing-is-revolutionizing-app-development</guid><category><![CDATA[Devops]]></category><category><![CDATA[serverless]]></category><category><![CDATA[Cloud]]></category><category><![CDATA[development]]></category><category><![CDATA[technology]]></category><category><![CDATA[aws lambda]]></category><category><![CDATA[app development]]></category><category><![CDATA[Cloud Computing]]></category><category><![CDATA[scalability]]></category><category><![CDATA[cost-optimisation]]></category><dc:creator><![CDATA[wilmo martinez]]></dc:creator><pubDate>Thu, 25 Apr 2024 00:00:19 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1713996365351/7d492d8a-6f3a-495d-ac17-395aa999f0fd.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2 id="heading-introduction"><strong>Introduction</strong></h2>
<p>In the ever-evolving landscape of technology, serverless computing has emerged as a game-changer, offering a paradigm shift in how backend services are provisioned and managed. Imagine writing and deploying code without the burden of worrying about the underlying infrastructure - that's the promise of serverless computing.</p>
<p>At its core, serverless computing allows developers to focus solely on writing code, without the hassle of managing servers or provisioning resources. In essence, it's like having a virtual team of infrastructure experts at your disposal, handling the heavy lifting behind the scenes.</p>
<p>The era of needing to own physical hardware to run servers is over, which used to be a big, expensive hassle for anyone wanting to create a website. Enter cloud computing, where fixed units of server space could be rented remotely. However, this traditional model often led to over-provisioning, as developers would err on the side of caution to prevent exceeding monthly limits, resulting in wasted resources.</p>
<p>This is where serverless computing shines. With serverless providers, companies are charged based on actual usage, rather than reserving and paying for a fixed amount of bandwidth or servers. The beauty lies in its auto-scaling nature, where resources dynamically scale up or down in response to demand, ensuring optimal performance and cost-efficiency.</p>
<h2 id="heading-what-is-serverless-computing"><strong>What is Serverless Computing</strong></h2>
<p>Serverless is a cloud-native development model that allows developers to build and run applications without having to manage servers.</p>
<p>Despite its name, physical servers are still in the equation, but developers are blissfully unaware of their existence, allowing them to focus on building great products rather than managing infrastructure.</p>
<p>Under a serverless model, a cloud provider runs physical servers and dynamically allocates their resources on behalf of users who can deploy code straight into production.</p>
<h2 id="heading-how-serverless-works"><strong>How Serverless Works</strong></h2>
<p>Serverless architecture relies on functions, or more specifically functions-as-a-service (FaaS). It is a service model that allows developers to run code directly in the cloud without the need to build packages or maintain any infrastructure. Applications are broken up into individual functions that can be invoked and scaled individually.</p>
<h2 id="heading-use-cases-for-serverless-computing"><strong>Use Cases for Serverless Computing</strong></h2>
<p>Serverless architecture is ideal for asynchronous, stateless apps that can be started instantaneously.</p>
<ul>
<li><p>Trigger-based tasks.</p>
</li>
<li><p>Building RESTful APIs.</p>
</li>
<li><p>Asynchronous processing.</p>
</li>
<li><p>Stream processing workloads.</p>
</li>
</ul>
<h2 id="heading-pros-and-cons-of-serverless"><strong>Pros and cons of serverless</strong></h2>
<h3 id="heading-pros"><strong>Pros</strong></h3>
<ul>
<li><p><strong>Lower cost</strong>: Basically you pay for the execution of your function.</p>
</li>
<li><p><strong>Simplified scalability</strong>: Since your are not in charge of infrastructure provisioning.</p>
</li>
<li><p><strong>Improve developer productivity</strong> : Developers have more time to innovate and optimize their application functionalities and business logic.</p>
</li>
</ul>
<h3 id="heading-cons"><strong>Cons</strong></h3>
<ul>
<li><p><strong>Testing and debugging:</strong> Debugging is more complicated because developers do not have visibility into backend processes, and because the application is broken up into separate, smaller functions.</p>
</li>
<li><p><strong>Performance Impact:</strong> other of the downsides of using cloud computing is that processing times can vary widely between runs as the code may be deployed on a different server.</p>
</li>
<li><p><strong>Vendor Lock-In:</strong> Setting up a serverless architecture with one vendor can make it difficult to switch vendors if necessary, especially since each vendor offers slightly different features and workflows.</p>
</li>
</ul>
<h2 id="heading-list-of-serverless-providers"><strong>List of Serverless Providers</strong></h2>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1711064107950/b211630c-fce5-4850-80cc-60329bf48cfe.png" alt="Source: Datadog" class="image--center mx-auto" /></p>
<ul>
<li><p>AWS Lambda</p>
</li>
<li><p>Azure Functions</p>
</li>
<li><p>Google Cloud Functions(GCF)</p>
</li>
<li><p>IMB cloud Functions</p>
</li>
<li><p>Cloudflare Workers</p>
<h2 id="heading-conclusion">Conclusion</h2>
</li>
</ul>
<p>As we wrap up our exploration of serverless computing, one thing is abundantly clear: the future of technology is here, and it's serverless. Gone are the days of fretting over infrastructure management and server maintenance; with serverless computing, developers are liberated to focus their energy where it truly matters - crafting innovative solutions and driving business growth.</p>
<p>By embracing serverless architecture, organizations can unlock a world of possibilities, from seamlessly handling fluctuating workloads to optimizing costs and resources with unparalleled efficiency.</p>
]]></content:encoded></item><item><title><![CDATA[Linux Commands]]></title><description><![CDATA[In the dynamic world of DevOps, where speed, automation, and efficiency reign supreme, mastering the command line is an indispensable skill. Linux, with its powerful command-line interface, is at the heart of many DevOps workflows. In this blog post,...]]></description><link>https://blog.wilmomartinez.1618lab.com/linux-commands</link><guid isPermaLink="true">https://blog.wilmomartinez.1618lab.com/linux-commands</guid><category><![CDATA[Devops]]></category><category><![CDATA[linux for beginners]]></category><category><![CDATA[Linux]]></category><category><![CDATA[linux-commands]]></category><category><![CDATA[cli]]></category><dc:creator><![CDATA[wilmo martinez]]></dc:creator><pubDate>Mon, 04 Dec 2023 11:00:12 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1701525395408/006f66b7-ca54-4e4e-94cc-e104da012c7d.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the dynamic world of DevOps, where speed, automation, and efficiency reign supreme, mastering the command line is an indispensable skill. Linux, with its powerful command-line interface, is at the heart of many DevOps workflows. In this blog post, we'll explore essential Linux commands that every DevOps professional should have in their toolkit.</p>
<h3 id="heading-file-and-directory-operations"><strong>File and Directory Operations:</strong></h3>
<ol>
<li><p><strong>ls</strong> - List directory contents.</p>
<pre><code class="lang-bash"> ls -l /path/to/directory
</code></pre>
</li>
<li><p><strong>cd</strong> - Change directory.</p>
<pre><code class="lang-bash"> <span class="hljs-built_in">cd</span> /path/to/directory
</code></pre>
</li>
<li><p><strong>pwd</strong> - Print working directory.</p>
<pre><code class="lang-bash"> <span class="hljs-built_in">pwd</span>
</code></pre>
</li>
<li><p><strong>touch</strong> - Create an empty file.</p>
<pre><code class="lang-bash"> touch file.txt
</code></pre>
</li>
<li><p><strong>cp</strong> - Copy files or directories.</p>
<pre><code class="lang-bash"> cp sourcefile.txt destination/
</code></pre>
</li>
<li><p><strong>mv</strong> - Move or rename files or directories.</p>
<pre><code class="lang-bash"> mv oldfile.txt newfile.txt
</code></pre>
</li>
<li><p><strong>rm</strong> - Remove files or directories.</p>
<pre><code class="lang-bash"> rm file.txt
</code></pre>
</li>
<li><p><strong>find</strong> - Search for files and directories.</p>
<pre><code class="lang-bash"> find /path/to/search -name <span class="hljs-string">"file.txt"</span>
</code></pre>
</li>
<li><p><strong>du</strong> - Show directory space usage.</p>
<pre><code class="lang-bash"> du -sh /path/to/directory
</code></pre>
</li>
<li><p><strong>df</strong> - Display disk space usage.</p>
<pre><code class="lang-bash">df -h
</code></pre>
</li>
</ol>
<h3 id="heading-process-management"><strong>Process Management:</strong></h3>
<ol>
<li><p><strong>ps</strong> - Show information about running processes.</p>
<pre><code class="lang-bash"> ps aux
</code></pre>
</li>
<li><p><strong>top</strong> - Monitor system activity and processes in real-time.</p>
<pre><code class="lang-bash"> top
</code></pre>
</li>
<li><p><strong>kill</strong> - Terminate processes by process ID (PID).</p>
<pre><code class="lang-bash"> <span class="hljs-built_in">kill</span> PID
</code></pre>
</li>
<li><p><strong>pkill</strong> - Terminate processes by name.</p>
<pre><code class="lang-bash"> pkill process_name
</code></pre>
</li>
<li><p><strong>pgrep</strong> - List processes by name.</p>
<pre><code class="lang-bash"> pgrep process_name
</code></pre>
</li>
<li><p><strong>htop</strong> - Interactive process viewer.</p>
<pre><code class="lang-bash"> htop
</code></pre>
</li>
<li><p><strong>nice</strong> - Run a command with a specified priority.</p>
<pre><code class="lang-bash"> nice -n 10 myprocess
</code></pre>
</li>
<li><p><strong>renice</strong> - Change the priority of a running process.</p>
<pre><code class="lang-bash"> renice -n 15 -p PID
</code></pre>
</li>
<li><p><strong>systemctl</strong> - Manage system services and units.</p>
<pre><code class="lang-bash"> systemctl status service_name
</code></pre>
</li>
<li><p><strong>journalctl</strong> - View and filter system logs.</p>
<pre><code class="lang-bash">journalctl -xe
</code></pre>
</li>
</ol>
<h3 id="heading-network-and-connectivity"><strong>Network and Connectivity:</strong></h3>
<ol>
<li><p><strong>ping</strong> - Check network connectivity to a host.</p>
<pre><code class="lang-bash"> ping google.com
</code></pre>
</li>
<li><p><strong>ifconfig/ip</strong> - Display and configure network interfaces.</p>
<pre><code class="lang-bash"> ifconfig
</code></pre>
</li>
<li><p><strong>netstat</strong> - Network statistics and connection information.</p>
<pre><code class="lang-bash"> netstat -tuln
</code></pre>
</li>
<li><p><strong>ssh</strong> - Securely connect to remote servers.</p>
<pre><code class="lang-bash"> ssh user@remote_server
</code></pre>
</li>
<li><p><strong>scp</strong> - Securely copy files between hosts.</p>
<pre><code class="lang-bash"> scp file.txt user@remote_server:/path
</code></pre>
</li>
<li><p><strong>curl</strong> - Transfer data with URLs.</p>
<pre><code class="lang-bash"> curl &lt;https://example.com&gt;
</code></pre>
</li>
<li><p><strong>ss</strong> - Display socket statistics.</p>
<pre><code class="lang-bash"> ss -tuln
</code></pre>
</li>
<li><p><strong>nmap</strong> - Network exploration tool and security scanner.</p>
<pre><code class="lang-bash"> nmap -p 80 example.com
</code></pre>
</li>
<li><p><strong>traceroute</strong> - Trace the route packets take to a network host.</p>
<pre><code class="lang-bash"> traceroute google.com
</code></pre>
</li>
<li><p><strong>iptables</strong> - Configure firewall rules.</p>
<pre><code class="lang-bash">iptables -A INPUT -p tcp --dport 80 -j ACCEPT
</code></pre>
</li>
</ol>
<h3 id="heading-package-management"><strong>Package Management:</strong></h3>
<ol>
<li><p><strong>apt-get/apt</strong> - Package management on Debian/Ubuntu.</p>
<pre><code class="lang-bash"> sudo apt-get install package_name
</code></pre>
</li>
<li><p><strong>yum/dnf</strong> - Package management on Red Hat/CentOS.</p>
<pre><code class="lang-bash"> sudo yum install package_name
</code></pre>
</li>
<li><p><strong>dnf</strong> - Improved package management for Fedora.</p>
<pre><code class="lang-bash"> sudo dnf install package_name
</code></pre>
</li>
<li><p><strong>zypper</strong> - Package management on openSUSE.</p>
<pre><code class="lang-bash"> sudo zypper install package_name
</code></pre>
</li>
<li><p><strong>dpkg</strong> - Debian package management (low-level).</p>
<pre><code class="lang-bash"> dpkg -i package.deb
</code></pre>
</li>
<li><p><strong>rpm</strong> - Red Hat Package Manager (low-level).</p>
<pre><code class="lang-bash"> rpm -i package.rpm
</code></pre>
</li>
<li><p><strong>apt-cache search</strong> - Search for packages on Debian-based systems.</p>
<pre><code class="lang-bash"> apt-cache search search_term
</code></pre>
</li>
<li><p><strong>yum search/dnf search</strong> - Search for packages on Red Hat-based systems.</p>
<pre><code class="lang-bash"> yum search search_term
</code></pre>
</li>
<li><p><strong>rpm -qa</strong> - List all installed RPM packages.</p>
<pre><code class="lang-bash"> rpm -qa
</code></pre>
</li>
<li><p><strong>pip</strong> - Package installer for Python.</p>
<pre><code class="lang-bash">pip install package_name
</code></pre>
</li>
</ol>
<h3 id="heading-user-and-permission-management"><strong>User and Permission Management:</strong></h3>
<ol>
<li><p><strong>useradd</strong> - Add a new user.</p>
<pre><code class="lang-bash"> sudo useradd new_user
</code></pre>
</li>
<li><p><strong>passwd</strong> - Change user password.</p>
<pre><code class="lang-bash"> sudo passwd username
</code></pre>
</li>
<li><p><strong>usermod</strong> - Modify user attributes.</p>
<pre><code class="lang-bash"> sudo usermod -aG group_name username
</code></pre>
</li>
<li><p><strong>userdel</strong> - Delete a user account.</p>
<pre><code class="lang-bash"> sudo userdel username
</code></pre>
</li>
<li><p><strong>chown</strong> - Change file/folder ownership.</p>
<pre><code class="lang-bash"> sudo chown user:group file.txt
</code></pre>
</li>
<li><p><strong>chmod</strong> - Change file/folder permissions.</p>
<pre><code class="lang-bash"> chmod 644 file.txt
</code></pre>
</li>
<li><p><strong>visudo</strong> - Edit the sudoers file.</p>
<pre><code class="lang-bash"> sudo visudo
</code></pre>
</li>
<li><p><strong>groups</strong> - Show groups a user belongs to.</p>
<pre><code class="lang-bash"> groups username
</code></pre>
</li>
<li><p><strong>id</strong> - Display user and group information.</p>
<pre><code class="lang-bash"> id username
</code></pre>
</li>
<li><p><strong>setfacl/getfacl</strong> - Manage access control lists.</p>
<pre><code class="lang-bash">setfacl -m u:username:rw file.txt
</code></pre>
</li>
</ol>
<h3 id="heading-system-monitoring-and-performance"><strong>System Monitoring and Performance:</strong></h3>
<ol>
<li><p><strong>free</strong> - Display system memory usage.</p>
<pre><code class="lang-bash"> free -m
</code></pre>
</li>
<li><p><strong>uptime</strong> - Show system uptime and load averages.</p>
<pre><code class="lang-bash"> uptime
</code></pre>
</li>
<li><p><strong>vmstat</strong> - Virtual memory statistics.</p>
<pre><code class="lang-bash"> vmstat 1
</code></pre>
</li>
<li><p><strong>iostat</strong> - Input/output statistics.</p>
<pre><code class="lang-bash"> iostat -d 1
</code></pre>
</li>
<li><p><strong>sar</strong> - Collect and report system activity information.</p>
<pre><code class="lang-bash"> sar -u 1 5
</code></pre>
</li>
<li><p><strong>top/htop</strong> - Real-time system resource monitoring.</p>
<pre><code class="lang-bash"> top
</code></pre>
</li>
<li><p><strong>ps</strong> - View process information and resource usage.</p>
<pre><code class="lang-bash"> ps aux
</code></pre>
<p> <strong>lsof</strong> - List open files and their associated processes.</p>
<pre><code class="lang-bash"> lsof
</code></pre>
</li>
<li><p><strong>iotop</strong> - Monitor I/O usage by processes.</p>
<pre><code class="lang-bash"> iotop
</code></pre>
</li>
<li><p><strong>atop</strong> - Advanced performance monitor.</p>
<pre><code class="lang-bash"> atop
</code></pre>
</li>
</ol>
<h3 id="heading-backup-and-restore"><strong>Backup and Restore:</strong></h3>
<ol>
<li><p><strong>tar</strong> - Create and extract tar archives.</p>
<pre><code class="lang-bash"> tar -cvzf backup.tar.gz /path/to/backup
</code></pre>
</li>
<li><p><strong>rsync</strong> - Synchronize files and directories.</p>
<pre><code class="lang-bash"> rsync -av <span class="hljs-built_in">source</span>/ destination/
</code></pre>
</li>
<li><p><strong>dd</strong> - Copy and convert files.</p>
<pre><code class="lang-bash"> dd <span class="hljs-keyword">if</span>=input_file of=output_file
</code></pre>
</li>
<li><p><strong>dump</strong> - Create filesystem backups.</p>
<pre><code class="lang-bash"> dump -0u -f /path/to/backup.dump /dev/sdX
</code></pre>
<p> <strong>restore</strong> - Restore files from backups.</p>
<pre><code class="lang-bash"> restore -r -f /path/to/backup.dump
</code></pre>
<p> <strong>cron</strong> - Schedule automated backups.</p>
<pre><code class="lang-bash"> crontab -e
</code></pre>
<p> <strong>at</strong> - Schedule one-time tasks.</p>
<pre><code class="lang-bash"> at now + 1 hour
</code></pre>
</li>
<li><p><strong>rsnapshot</strong> - Backup tool using rsync and hard links.</p>
<pre><code class="lang-bash"> rsnapshot daily
</code></pre>
</li>
<li><p><strong>borg</strong> - Deduplicating backup program.</p>
<pre><code class="lang-bash"> borg create backup::backupname /path/to/backup
</code></pre>
</li>
<li><p><strong>duplicity</strong> - Encrypted bandwidth-efficient backup.</p>
<pre><code class="lang-bash"> duplicity /<span class="hljs-built_in">source</span> ssh://user@backup_server/destination
</code></pre>
</li>
</ol>
<h3 id="heading-log-and-troubleshooting"><strong>Log and Troubleshooting:</strong></h3>
<ol>
<li><p><strong>tail</strong> - Display the last part of a file (commonly used with log files).</p>
<pre><code class="lang-bash"> tail -f /var/<span class="hljs-built_in">log</span>/syslog
</code></pre>
</li>
<li><p><strong>grep</strong> - Search for patterns in files.</p>
<pre><code class="lang-bash"> grep <span class="hljs-string">"error"</span> /var/<span class="hljs-built_in">log</span>/application.log
</code></pre>
</li>
<li><p><strong>journalctl</strong> - Query the systemd journal.</p>
<pre><code class="lang-bash"> journalctl -u service_name
</code></pre>
</li>
<li><p><strong>dmesg</strong> - Display kernel ring buffer messages.</p>
<pre><code class="lang-bash"> dmesg | grep error
</code></pre>
</li>
<li><p><strong>strace</strong> - Trace system calls and signals.</p>
<pre><code class="lang-bash"> strace -p PID
</code></pre>
</li>
<li><p><strong>ltrace</strong> - Library call tracer.</p>
<pre><code class="lang-bash"> ltrace <span class="hljs-built_in">command</span>
</code></pre>
</li>
<li><p><strong>nc/netcat</strong> - Network utility for debugging and data transfer.</p>
<pre><code class="lang-bash"> nc -zv host port
</code></pre>
</li>
<li><p><strong>tcpdump</strong> - Network packet analyzer.</p>
<pre><code class="lang-bash"> tcpdump -i eth0 port 80
</code></pre>
</li>
<li><p><strong>ss</strong> - Socket statistics.</p>
<pre><code class="lang-bash"> ss -tuln
</code></pre>
<p> <strong>watch</strong> - Execute a program periodically and display the output.</p>
<pre><code class="lang-bash"> watch -n 1 command_to_watch
</code></pre>
</li>
</ol>
]]></content:encoded></item><item><title><![CDATA[Adding HTTP Security Headers Using Lambda@Edge.]]></title><description><![CDATA[In the previous section, we've got the basics down on Lambda@Edge and web security headers. Now, let's roll up our sleeves and learn how to set up a Lambda function that'll give your web defenses a rock-solid boost. In Part II, we'll walk you through...]]></description><link>https://blog.wilmomartinez.1618lab.com/adding-http-security-headers-using-lambdaedge-1</link><guid isPermaLink="true">https://blog.wilmomartinez.1618lab.com/adding-http-security-headers-using-lambdaedge-1</guid><category><![CDATA[AWS]]></category><category><![CDATA[aws lambda]]></category><category><![CDATA[Security]]></category><category><![CDATA[Web Development]]></category><category><![CDATA[HTTP security headers]]></category><dc:creator><![CDATA[wilmo martinez]]></dc:creator><pubDate>Tue, 21 Nov 2023 12:00:10 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1700518052296/a3d13889-24ce-4016-8921-43e7e7ac1afe.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the previous section, we've got the basics down on Lambda@Edge and web security headers. Now, let's roll up our sleeves and learn how to set up a Lambda function that'll give your web defenses a rock-solid boost. In Part II, we'll walk you through deploying a Lambda@Edge to shield your web apps from the latest threats and vulnerabilities.</p>
<h3 id="heading-security-inspection"><strong>Security inspection</strong></h3>
<p>The first step is to check the status of our website. We going to use <a target="_blank" href="https://observatory.mozilla.org/">https://observatory.mozilla.org/</a> to scan our domain.</p>
<p>for this demo, I will use my domain <code>wilmomartinez.com</code> but replace this domain name with your own.</p>
<p>The following is the result of the scanning.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699888709111/425a860a-148e-4fa3-8ed0-2b8e8cf28632.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-create-a-lambda-function"><strong>Create a Lambda Function</strong></h3>
<p>Lets create the lambda function that would add the security headers to the responses from the origin in our CloudFront distribution.</p>
<p>In the AWS Lambda console go to functions, click <code>create function</code> and select Author from scratch. In the create function session will specify the following:</p>
<div class="hn-table">
<table>
<thead>
<tr>
<td>Field</td><td>Value</td></tr>
</thead>
<tbody>
<tr>
<td>Name</td><td>lambda-edge-security-headers</td></tr>
<tr>
<td>Runtime</td><td>Node.js 18.x</td></tr>
<tr>
<td>Role</td><td>Chose an existing role</td></tr>
<tr>
<td>Existing role</td><td>existing role</td></tr>
</tbody>
</table>
</div><p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699889726374/d3aa7e42-6014-435f-bed1-f79123d95ed1.png" alt class="image--center mx-auto" /></p>
<p>Then click the <code>create function</code> button.</p>
<h3 id="heading-write-function-code"><strong>Write function code</strong></h3>
<p>I used the following code for the lambda function. It basically sets <code>Strict-Transport-Security</code>, <code>Content-Security-Policy</code>, <code>X-XSS-Protection</code>, <code>X-Content-Type-Options</code>, <code>X-Frame-Options</code>, and <code>Referrer-Policy</code> headers, then returns the updated response that include the security headers.</p>
<pre><code class="lang-javascript"><span class="hljs-meta">'use strict'</span>;

<span class="hljs-keyword">export</span> <span class="hljs-keyword">const</span> handler = <span class="hljs-keyword">async</span> (event, context, callback) =&gt; {
    <span class="hljs-built_in">console</span>.log(<span class="hljs-string">'Event: '</span>, <span class="hljs-built_in">JSON</span>.stringify(event, <span class="hljs-literal">null</span>, <span class="hljs-number">2</span>));

    <span class="hljs-keyword">const</span> response = event.Records[<span class="hljs-number">0</span>].cf.response;

    response.headers[<span class="hljs-string">'strict-transport-security'</span>] = [{ <span class="hljs-attr">value</span>: <span class="hljs-string">'max-age=31536000; includeSubDomains'</span> }];
    response.headers[<span class="hljs-string">'content-security-policy'</span>] = [{<span class="hljs-attr">key</span>: <span class="hljs-string">'Content-Security-Policy'</span>, <span class="hljs-attr">value</span>: <span class="hljs-string">"default-src 'none'; img-src 'self'; script-src 'self'; style-src 'self'; object-src 'none'"</span>}]; 
    response.headers[<span class="hljs-string">'x-xss-protection'</span>] = [{ <span class="hljs-attr">value</span>: <span class="hljs-string">'1; mode=block'</span> }];
    response.headers[<span class="hljs-string">'x-content-type-options'</span>] = [{ <span class="hljs-attr">value</span>: <span class="hljs-string">'nosniff'</span> }];
    response.headers[<span class="hljs-string">'x-frame-options'</span>] = [{ <span class="hljs-attr">value</span>: <span class="hljs-string">'DENY'</span> }]; 
    response.headers[<span class="hljs-string">'Referrer-Policy'</span>] = [{ <span class="hljs-attr">value</span>: <span class="hljs-string">'strict-origin'</span> }];  

    <span class="hljs-keyword">return</span> response;
};
</code></pre>
<p>See more about security headers:</p>
<ul>
<li><p><a target="_blank" href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options">https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options</a> *</p>
</li>
<li><p><a target="_blank" href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security">https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security</a></p>
</li>
</ul>
<h3 id="heading-test-the-function"><strong>Test the function</strong></h3>
<p>It is highly recommended to test if our functions execute successfully and return the expected response before proceeding with the association with CloudFront. To do that we are going to take advantage of the test invoke function in the Lambda console.</p>
<p>Click the <code>test</code>, and you will be prompted with the window to configure your test event. In this case we will use the <code>CloudFront Modify Response Header</code> template. Select invoke</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699908320480/07d955a3-b6bc-4f78-b8d8-48c3a0de91d4.png" alt class="image--center mx-auto" /></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699909235545/5232a1c5-1cb8-419b-aa3a-2ba7f65705cc.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-deploy-lambda"><strong>Deploy lambda</strong></h3>
<p>once we confirm that our lambda works as expected, now is time to deploy.</p>
<p>In order to deploying a function to Lambda@Edge we need to complete to process:</p>
<ul>
<li><p>Create a function version</p>
</li>
<li><p>Associate the function version with the CloudFront distribution by selecting an applicable Cache Behavior and an event trigger type (viewer request, viewer response, origin request or origin response).</p>
</li>
</ul>
<p>We can do both at once by selecting in <code>Actions</code> the option Deploy to <code>Lambda@Edge</code></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699909288188/d608c53f-030e-4e4e-bc49-0696883cda52.png" alt class="image--center mx-auto" /></p>
<p>Set the trigger properties as shown below and click <code>Deploy</code></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1700516804123/672464ff-c8f8-4be5-987f-dad813b5d8d9.png" alt class="image--center mx-auto" /></p>
<p>After that, we will see the message that both, lambda version and CloudFront trigger has bee successfully created.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699909369253/d92b09c9-6eb7-491a-aa87-4d9794d8e7c6.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-validate-the-security-headers"><strong>Validate the security headers</strong></h3>
<p>Lets check the header response form our Cloudflare distribution now.</p>
<pre><code class="lang-bash">curl --head https://&lt;your cloudfront distribution or Domain name&gt;
</code></pre>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699910484341/292eaeae-8889-460c-8925-4ea3ec40b95a.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-rerun-inspection"><strong>Rerun inspection</strong></h3>
<p>Lets rescan our domain.</p>
<p><a target="_blank" href="https://observatory.mozilla.org/">https://observatory.mozilla.org/</a>. Now we have a A+ score</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699911113511/86375511-d21b-4032-8abe-5374048aa20c.png" alt class="image--center mx-auto" /></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1699911586586/69c017f1-de47-4472-9549-90f9ad1ff7ba.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-conclusion"><strong>Conclusion</strong></h3>
<p>Enhancing security through Lambda@Edge involves strategically integrating security headers into the origin response trigger of a CloudFront distribution behavior. In this demonstration, We've gone through the process of creating a Lambda@Edge function, associating it with a CloudFront distribution trigger, and verifying the effectiveness while actively monitoring the results. While this demo shows what Lambda@Edge can do, there's a lot more it can offer for coming up with clever and flexible ways to boost and strengthen security.</p>
]]></content:encoded></item><item><title><![CDATA[Adding HTTP Security Headers Using Lambda@Edge.]]></title><description><![CDATA[Security is critical for web applications as they often handle sensitive user data and transactions. Security headers play a crucial role in safeguarding web applications by mitigating common vulnerabilities. AWS Lambda@Edge facilitates the implement...]]></description><link>https://blog.wilmomartinez.1618lab.com/adding-http-security-headers-using-lambdaedge</link><guid isPermaLink="true">https://blog.wilmomartinez.1618lab.com/adding-http-security-headers-using-lambdaedge</guid><category><![CDATA[Security]]></category><category><![CDATA[serverless]]></category><category><![CDATA[AWS]]></category><category><![CDATA[Web Development]]></category><category><![CDATA[lambda@edge]]></category><dc:creator><![CDATA[wilmo martinez]]></dc:creator><pubDate>Tue, 31 Oct 2023 12:00:10 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1698681338354/c4f5a0b1-3616-4908-9a1b-02c92308d974.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Security is critical for web applications as they often handle sensitive user data and transactions. Security headers play a crucial role in safeguarding web applications by mitigating common vulnerabilities. AWS Lambda@Edge facilitates the implementation of these security headers by allowing us to execute custom code at the edge locations of the AWS CloudFront CDN.</p>
<h3 id="heading-what-are-security-headers"><strong>What are security headers</strong></h3>
<p>HTTP security headers are a subset of HTTP headers that are related specifically to security. They are exchanged between a client (usually a web browser) and a server to specify the security details of HTTP communication.</p>
<h3 id="heading-the-most-important-http-security-headers"><strong>The most important HTTP security headers</strong></h3>
<ul>
<li><p><strong>Content-Security-Policy:</strong> is a crucial security header that helps prevent cross-site scripting (XSS) and data injection attacks. It defines which resources (e.g., scripts, images, styles) can be loaded and executed on a web page. It limits the sources from which content can be loaded, enhancing security.</p>
</li>
<li><p><strong>Strict-Transport-Security(HSTS):</strong> HSTS instructs web browsers to enforce secure HTTPS connections for a specified duration, protecting users from potential man-in-the-middle attacks and ensuring all communication with your website is encrypted.</p>
</li>
<li><p><strong>X-Content-Type-Options:</strong> This header prevents browsers from interpreting files as a different MIME type than declared, which can help mitigate attacks like MIME sniffing. Setting it to "nosniff" enhances security by reducing the risk of content-type confusion.</p>
</li>
<li><p><strong>XFrame-Options:</strong> X-Frame-Options prevents your web pages from being embedded in frames or iframes on other websites. This guards against clickjacking attacks, where attackers attempt to trick users into performing actions without their knowledge.</p>
</li>
<li><p><strong>Referrer-Policy:</strong> Referrer-Policy controls what information is included in the HTTP Referer header when a user clicks on a link. This can help protect user privacy and limit the exposure of sensitive information.</p>
</li>
<li><p><strong>X-XSS-Protection:</strong> This header is designed to block or sanitize potential cross-site scripting (XSS) attacks in the browser. Enabling this header helps protect users by preventing malicious scripts from executing.</p>
</li>
</ul>
<h3 id="heading-what-is-lambda-edge-how-it-can-help-us"><strong>What is lambda edge how it can help us?</strong></h3>
<p>Lambda@Edge provides the ability to execute a Lambda function at an Amazon CloudFront Edge Location. This capability enables intelligent processing of HTTP requests at locations that are close (for latency) to your customers. You can run a Lambda@Edge function in response to four different CloudFront events.</p>
<p>Some of the use cases :</p>
<ul>
<li><p>Dynamic Content Delivery</p>
</li>
<li><p>Security and Compliance</p>
</li>
<li><p>Real-time Image Optimization</p>
</li>
<li><p>Bot Detection and Mitigation</p>
</li>
<li><p>User Authentication and Authorization</p>
</li>
</ul>
<h3 id="heading-how-it-works">How it works?</h3>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1698699150694/8bc6767b-cf08-4f3f-9a4b-bec421fba330.png" alt class="image--center mx-auto" /></p>
<ol>
<li><p>The viewer navigates to the website.</p>
</li>
<li><p><strong>Before</strong> CloudFront serves content from the cache it will trigger any Lambda function associated with the <strong>Viewer Request</strong> trigger for that behavior.</p>
</li>
<li><p>CloudFront serves content from the cache if available, otherwise, it goes to step</p>
</li>
<li><p><strong>Only after</strong> CloudFront cache ‘<strong>Miss’</strong>, <strong>Origin Request</strong> trigger is fired for that behavior.</p>
</li>
<li><p>S3 Origin returns content.</p>
</li>
<li><p><strong>After</strong> content is returned from S3 but <strong>before</strong> being cached in CloudFront, <strong>Origin Response</strong> trigger is fired.</p>
</li>
<li><p><strong>After</strong> content is cached in CloudFront, <strong>Viewer Response</strong> trigger is fired and is the final step before the viewer receives content.</p>
</li>
<li><p><strong>Viewer</strong> receives content.</p>
</li>
</ol>
<h3 id="heading-conclusion">Conclusion</h3>
<p>In this section, we covered the essentials of Lambda@Edge and web security headers. In the second part of this article, We will explore the practical aspects of implementing a Lambda function to improve your online security.</p>
]]></content:encoded></item><item><title><![CDATA[Cloud Resume Challenge]]></title><description><![CDATA[What is the cloud resume challenge
The Cloud Resume Challenge is a multiple-step resume project that helps build and demonstrate fundamental skills for pursuing a career in the Cloud. The project was published by Forrest Brazeal.
About me
Before I go...]]></description><link>https://blog.wilmomartinez.1618lab.com/cloud-resume-challenge</link><guid isPermaLink="true">https://blog.wilmomartinez.1618lab.com/cloud-resume-challenge</guid><category><![CDATA[AWS]]></category><category><![CDATA[#Learning #CloudResumeChallnge]]></category><category><![CDATA[serverless]]></category><category><![CDATA[aws lambda]]></category><dc:creator><![CDATA[wilmo martinez]]></dc:creator><pubDate>Thu, 21 Sep 2023 12:00:12 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1695267557305/59a97d38-bb30-4fbe-9aef-b38f64bed773.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3 id="heading-what-is-the-cloud-resume-challenge">What is the cloud resume challenge</h3>
<p>The <a target="_blank" href="https://cloudresumechallenge.dev/">Cloud Resume Challenge</a> is a multiple-step resume project that helps build and demonstrate fundamental skills for pursuing a career in the Cloud. The project was published by <a target="_blank" href="https://forrestbrazeal.com/">Forrest Brazeal.</a></p>
<h3 id="heading-about-me">About me</h3>
<p>Before I got into technology, I had a background in electronics and worked as a customer service representative in a call center for several years, in addition to serving as NOC technician in a telecom company.</p>
<p>I had the opportunity to work as NOC technician in a data center, and that experience changed my life because it introduced me to the world of technology. I started to learn about cloud technologies and eventually acquired a set of tools like Python, Linux, cloud computing, cybersecurity, Docker, Kubernetes, and the list is still growing</p>
<h3 id="heading-why-i-took-it">Why I took it?</h3>
<ul>
<li><p>Get practice (working with services that I haven't worked before)</p>
</li>
<li><p>Build something functional from scratch</p>
</li>
<li><p>Learn about serverless architecture</p>
</li>
<li><p>Prove myself that I will be able to make it</p>
</li>
</ul>
<h3 id="heading-why-should-you-do-it-too">Why should you do it too?</h3>
<p>If you are just starting in the cloud or just want to practice your skills, this challenge is a good point to start. The following are some of the reasons:</p>
<ul>
<li><p>Get hands-on experience in the cloud</p>
</li>
<li><p>understand how services interact with each other</p>
</li>
<li><p>Get a better understanding of how web services work</p>
</li>
<li><p>Get confidence</p>
</li>
<li><p>Build your portfolio</p>
</li>
</ul>
<h3 id="heading-the-process">The process</h3>
<p>The Challenge is broken up into 5 Chunks:</p>
<p>Chunk 0. Certification Prep<br />Chunk 1. Building the front-end<br />Chunk 2. Building the API<br />Chunk 3. Front-end/back-end integration<br />Chunk 4. Automation (IaC, CI/CD)</p>
<p>The Challenge involved creating an HTML resume and hosting it as a static website on an S3 bucket, implementing HTTPS for security, setting up a custom DNS domain name connected to a CDN for optimized speed and performance, coding in Python to track visitor counts, establishing a database for visitor data storage, scripting in JavaScript to retrieve the count via an API gateway, deploying the website through a CI/CD pipeline from a version-controlled repository, and configuring all resources using Infrastructure as Code (IaC) on AWS.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1695265653601/9a706be9-9aa5-421a-bf1b-40059ddb9080.png" alt class="image--center mx-auto" /></p>
<p><strong>AWS services that I use</strong>: <em>S3, ACM, CloudFront, Cloudformation, Rout53, Apigateway, Dynamodb, Lambda functions</em></p>
<h3 id="heading-conclusion">Conclusion</h3>
<p>The following quote became a reality at every stage of the process.</p>
<blockquote>
<p>The work will teach you how to do it.</p>
</blockquote>
<p>Don't get discouraged by what you don't know yet; just start, and commit to it, and you will learn a lot.</p>
<p>You can check my finished version: https://wilmomartinez.com</p>
]]></content:encoded></item></channel></rss>