
Visibility into your infrastructure is essential for operations and optimization.
Amazon CloudWatch:
Monitoring and observability service
Collects metrics from all AWS services (CPU, memory, network)
Create custom metrics; set alarms; create dashboards
CloudWatch Logs — collect and store log data
CloudWatch Events/EventBridge — react to AWS service events
AWS CloudTrail:
Logs all API calls in your account
Who made the call, when, from what IP, what they did
Enabled by default; stored 90 days; extend with S3
Essential for security auditing and compliance
AWS Trusted Advisor:
Analyzes your account and recommends improvements in 5 areas: Cost Optimization, Performance, Security, Fault Tolerance, Service Limits
Basic plan: 7 core security and service limit checks
Business/Enterprise plans: full checks
AWS Systems Manager:
Operational hub for AWS; manage and automate operations tasks
Parameter Store — secure storage for configuration and secrets
Session Manager — secure shell access to EC2 without opening port 22
AWS Personal Health Dashboard: Personalized alerts about AWS events affecting your specific resources.
Reference:
TaskLoco™ — The Sticky Note GOAT