Book Image

AWS Observability Handbook

By : Phani Kumar Lingamallu, Fabio Braga de Oliveira
Book Image

AWS Observability Handbook

By: Phani Kumar Lingamallu, Fabio Braga de Oliveira

Overview of this book

As modern application architecture grows increasingly complex, identifying potential points of failure and measuring end user satisfaction, in addition to monitoring application availability, is key. This book helps you explore AWS observability tools that provide end-to-end visibility, enabling quick identification of performance bottlenecks in distributed applications. You’ll gain a holistic view of monitoring and observability on AWS, starting from observability basics using Amazon CloudWatch and AWS X-Ray to advanced ML-powered tools such as AWS DevOps Guru. As you progress, you'll learn about AWS-managed open source services such as AWS Distro for OpenTelemetry (ADOT) and AWS managed Prometheus, Grafana, and the ELK Stack. You’ll implement observability in EC2 instances, containers, Kubernetes, and serverless apps and grasp UX monitoring. With a fair mix of concepts and examples, this book helps you gain hands-on experience in implementing end-to-end AWS observability in your applications and navigating and troubleshooting performance issues with the help of use cases. You'll also learn best practices and guidelines, such as how observability relates to the Well-Architected Framework. By the end of this AWS book, you’ll be able to implement observability and monitoring in your apps using AWS’ native and managed open source tools in real-world scenarios.
Table of Contents (22 chapters)
1
Part 1: Getting Started with Observability on AWS
6
Part 2: Automated and Machine Learning-Powered Observability on AWS
11
Part 3: Open Source Managed Services on AWS
15
Part 4: Scaled Observability and Beyond

Security for Amazon OpenSearch Service

Securing Amazon OpenSearch Service at a high level could be classified into the following types:

  • Encryption: Keeping your data secure at rest and in transit
  • Authentication: Leveraging authentication infrastructure to authenticate to the OpenSearch domain
  • Authorization: Granular authorization can be used to control user actions in your cluster
  • Auditing: Auditing functionality allows you to track and record all user actions, helping you to meet compliance requirements such as the HIPAA and PCI

AWS offers various services to meet the objectives of security in Amazon OpenSearch Service:

  • Encryption: For encryption of data during transit, you can enable node-to-node encryption and also enforce HTTPS for the web URL using certificates.

For encryption of data at rest, you can use AWS Key Management Service to store and manage keys. You can create your own or use the one that is provided by AWS. You could protect...