Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
aws-simple
Advanced tools
A Node.js interface for AWS that allows easy configuration and deployment of simple web projects.
A Node.js interface for AWS that allows easy configuration and deployment of simple web projects.
Install aws-simple
as development dependency, e.g. with:
yarn add --dev aws-simple
Create an AWS IAM user with programmatic access and the following attached policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["cloudformation:*", "apigateway:*", "s3:*"],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": ["lambda:*"],
"Resource": "arn:aws:lambda:*:*:function:mystack-*"
},
{
"Effect": "Allow",
"Action": ["iam:*"],
"Resource": "arn:aws:iam::*:role/mystack-*"
},
{
"Effect": "Allow",
"Action": ["iam:CreateServiceLinkedRole"],
"Resource": "arn:aws:iam::*:role/aws-service-role/ops.apigateway.amazonaws.com/*"
},
{
"Effect": "Allow",
"Action": ["route53:*"],
"Resource": "arn:aws:route53:::*"
}
]
}
Note: Please replace the stack ID (mystack
) with your own. All resources
created with CloudFormation will have this stack ID as prefix.
Install the aws
CLI, e.g. with:
brew install awscli
Then set up the AWS CLI profile using the access key from the AWS IAM user you just created:
aws configure --profile johndoe
AWS Access Key ID [None]: XXXXXXXXXXXXXXXXXXXX
AWS Secret Access Key [None]: YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
Default region name [None]: eu-central-1
Default output format [None]: json
Note: Please replace the profile (johndoe
) and also the region
(eu-central-1
) if necessary.
Create a top-level configuration file called aws-simple.config.js
in your
project. The following describes a very simple stack including a static HTML
file:
exports.default = {
stackId: 'mystack',
s3Configs: [
{
type: 'file',
publicPath: '/',
localPath: 'dist/app/index.html',
bucketPath: 'index.html'
}
]
};
Before you can use the AWS CDK you must bootstrap your AWS environment to create the infrastructure that the AWS CDK CLI needs to deploy your AWS CDK app:
yarn cdk bootstrap --app 'yarn aws-simple create' --profile johndoe
yarn cdk deploy --app 'yarn aws-simple create' --profile johndoe
yarn aws-simple upload --profile johndoe --region eu-central-1
yarn aws-simple start --port 1985 --cached
Usage: aws-simple <command> [options]
Commands:
aws-simple create [options] Create a stack using the CDK
aws-simple upload [options] Upload files to S3
aws-simple start [options] Start local DEV server
Options:
--version Show version number [boolean]
-h, --help Show help [boolean]
In my job I mainly build frontend web applications for existing backend/CMS systems. AWS is often used as a cloud platform. Since many of the tech stacks are similar again and again, I have created an abstraction for the AWS CDK/SDK. This allows you to easily create an API Gateway with a custom domain and optional alias record, make static files available via S3 and e.g. provision a BFF (Backend for Frontend) via Lambda.
Since existing backend/CMS systems are used, there is rarely a need for own persistence layers. Therefore, setting these up is not part of this abstraction for the time being.
I deliberately kept it simple. A project with a more complex setup should be set up manually with the AWS CDK/SDK.
npm version 1.0.0 && git push --follow-tags
After a new release has been created by pushing the tag, it must be published via the GitHub UI. This triggers the final publication to npm.
Copyright (c) 2019, Clemens Akens. Released under the terms of the MIT License.
FAQs
Production-ready AWS website deployment with minimal configuration.
The npm package aws-simple receives a total of 747 weekly downloads. As such, aws-simple popularity was classified as not popular.
We found that aws-simple demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.