- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- CNAPP
- :
- Re: Dome9 AWS Lambda Serverless monitoring - pre-r...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dome9 AWS Lambda Serverless monitoring - pre-requrements
Hello Dome9 Experts,
Customer is asking what are the requirements for AWS Lambda monitoring (and potentially active protection) for AWS Lambda functions. Please see detials below,
I checked Dome9 documentation - Enable Serverless Protection Documentation is generally very good and down to the point. There is a following picture illustrating serverless onboarding:
There are no details listing on what are pre-requrements. The questions are:
- Can the customer enable server-less while AWS is in red-only (monitoring) integration?
- Is Dome9 IAM Safety pre-requirement?
Regards,
Serg
P.S. Is it possible to update the documentation?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Serg,
Agree with you. This feature for serverless security is fairly new feature for Dome9 apologies on the documentation.
IAM safety is not needed, You can enable this in a on boarded read only account.
From memory this is how it looks to onboard and what is needed.
1. Have to have an on boarded cloud account of course.
2. navigate to the serverless area and click on cloud accounts and click on enable serverless protection as you mentioned previously.
3. this will take you to the next step of deploying a cloudformation template (much like the cloud provider on boarding done initially) which will deploy in the AWS environment with several resources such as a storage bucket, lambda, log, and giving cross account access to read into these resources as we will looking at code running in parallel to analyze. This will facilitate the runtime and build time processes via cli tools for further security.
Let me know if you have any questions, and I'll nudge the doc folks 😉
If you have any questions please feel free to message. thanks -Alfred
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Serg,
Agree with you. This feature for serverless security is fairly new feature for Dome9 apologies on the documentation.
IAM safety is not needed, You can enable this in a on boarded read only account.
From memory this is how it looks to onboard and what is needed.
1. Have to have an on boarded cloud account of course.
2. navigate to the serverless area and click on cloud accounts and click on enable serverless protection as you mentioned previously.
3. this will take you to the next step of deploying a cloudformation template (much like the cloud provider on boarding done initially) which will deploy in the AWS environment with several resources such as a storage bucket, lambda, log, and giving cross account access to read into these resources as we will looking at code running in parallel to analyze. This will facilitate the runtime and build time processes via cli tools for further security.
Let me know if you have any questions, and I'll nudge the doc folks 😉
If you have any questions please feel free to message. thanks -Alfred