docs: Mark cloudwatch-hardware-monitoring-cronjob
role as deprecated
#1579
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this change?
The
cloudwatch-hardware-monitoring-cronjob
role is not compatible with IMDSv2 and therefore violates FSBP EC2.8. This change marks the role as deprecated and points to usingaws-cloud-watch-agent
instead.The docs for
aws-cloud-watch-agent
is updated too to provide an example configuration file for ease. The configuration was taken from https://github.com/guardian/deploy-tools-platform/pull/843.How to test
The ultimate test is to migrate from
cloudwatch-hardware-monitoring-cronjob
toaws-cloud-watch-agent
and to comment on the helpfulness of the documentation.What is the value of this?
A clearer path for teams to resolve FSBP EC2.8 issues in their services.
Have we considered potential risks?
N/A.