Create a Post
Sergej_Gurenko
Contributor

Dome9 AWS Lambda Serverless monitoring - pre-requrements

Jump to solution

Hello Dome9 Experts,

 

Customer is asking what are the requirements for AWS Lambda monitoring (and potentially active protection) for AWS Lambda functions. Please see detials below,

 

I checked Dome9 documentation - Enable Serverless Protection  Documentation is generally very good and down to the point. There is a following picture illustrating serverless onboarding:

Serverless-enable

 There are no details listing on what are pre-requrements. The questions are:

  • Can the customer enable server-less while AWS is in red-only (monitoring) integration?
  • Is Dome9 IAM Safety pre-requirement?

 

 

Regards,

Serg

 

P.S. Is it possible to update the documentation?

0 Kudos
1 Solution

Accepted Solutions
Alfred_Trevino
Employee
Employee

Hi Serg,

Agree with you. This feature for serverless security is fairly new feature for Dome9 apologies on the documentation. 

IAM safety is not needed, You can enable this in a on boarded read only account.

 

From memory this is how it looks to onboard and what is needed.

1. Have to have an on boarded cloud account of course.

2. navigate to the serverless area and click on cloud accounts and click on enable serverless protection as you mentioned previously.

3. this will take you to the next step of deploying a cloudformation template (much like the cloud provider on boarding done initially) which will deploy in the AWS environment with several resources such as a storage bucket, lambda, log, and  giving cross account access to read into these resources as we will looking at code running in parallel to analyze.  This will facilitate the runtime and build time processes via cli tools for further security. 

Let me know if you have any questions, and I'll nudge the doc folks 😉

If you have any questions please feel free to message. thanks -Alfred

View solution in original post

1 Reply
Alfred_Trevino
Employee
Employee

Hi Serg,

Agree with you. This feature for serverless security is fairly new feature for Dome9 apologies on the documentation. 

IAM safety is not needed, You can enable this in a on boarded read only account.

 

From memory this is how it looks to onboard and what is needed.

1. Have to have an on boarded cloud account of course.

2. navigate to the serverless area and click on cloud accounts and click on enable serverless protection as you mentioned previously.

3. this will take you to the next step of deploying a cloudformation template (much like the cloud provider on boarding done initially) which will deploy in the AWS environment with several resources such as a storage bucket, lambda, log, and  giving cross account access to read into these resources as we will looking at code running in parallel to analyze.  This will facilitate the runtime and build time processes via cli tools for further security. 

Let me know if you have any questions, and I'll nudge the doc folks 😉

If you have any questions please feel free to message. thanks -Alfred

View solution in original post