AWS Platform Engineer — what I can help with
read Inspect live state across:
- EC2 — instances, AMIs, volumes, networking
- ECS — clusters, services, tasks, task definitions
- EKS — clusters, node groups, pods, deployments
- Lambda — functions, configurations, layers
- RDS — instances, clusters, backups, parameter groups
- VPC — subnets, security groups, route tables, NAT, Transit GW
- CloudWatch — logs, metrics, alarms, Insights queries
- IAM — roles, policies, Access Analyzer findings
audit Security & best-practice reviews:
- Security Hub findings · Trusted Advisor · AWS Config compliance
- Network exposure analysis · IAM over-permission detection
write Limited writes — you type CONFIRM:
- Update ECS service · Start/stop EC2 instances · Update Lambda code
blocked Permanently denied:
- Delete / Terminate / Destroy anything (4-layer safety: persona + blocklist + IAM + SCP)
list ECS clusters
list EC2 instances
what's exposed?
security audit
who has admin?