Q: You enabled AWS CloudTrail across your organization. However, when you search the logs to find out who uploaded a specific image `logo.png` into an S3 bucket, nothing appears. You only see bucket creation events. Where is the log?
By default, CloudTrail only records Management Events (Control Plane actions). These include creating infrastructure (CreateBucket, RunIn...
#AWS #Cost & Architecture #L2 #Cloud #Infrastructure #S3
🎙️ Candidate Opening & Architectural Context
""AWS reliability requires differentiating between AWS control plane limits and host-level resource exhaustion. The interviewer is testing: Management Events vs Data Events.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
By default, CloudTrail only records Management Events (Control Plane actions). These include creating infrastructure (CreateBucket, RunInstances, UpdateSecurityGroup). It natively ignores Data Events (Data Plane actions) like s3:GetObject, s3:PutObject, or dynamodb:PutItem because logging trillions of them would result in astronomical CloudTrail bills. To see the logo.png upload, you must explicitly edit the CloudTrail configuration and opt-in to paying to record Data Events specifically targeting that S3 bucket.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: By default, CloudTrail only records Management Events (Control Plane actions). These include creating infrastructure (CreateBucket."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: By default, CloudTrail only records Management Events (Control Plane actions). These include cr
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement