Q: How do you set up cross-account logging where all AWS accounts in your org send logs to a central security account?
In each account: create CloudTrail and send to S3 in the security account. Update the security account S3 bucket policy to allow PutObjec...
#AWS #Cost & Architecture #L2 #Cloud #Infrastructure #S3
🎙️ Candidate Opening & Architectural Context
""AWS reliability requires differentiating between AWS control plane limits and host-level resource exhaustion. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
In each account: create CloudTrail and send to S3 in the security account. Update the security account S3 bucket policy to allow PutObject from all org accounts. Or use CloudTrail Organization Trail — one trail covers all accounts in the org automatically.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: In each account: create CloudTrail and send to S3 in the security account. Update the security account S3 bucket policy to allow P."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: In each account: create CloudTrail and send to S3 in the security account. Update the security
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement