Drift Detection: Alerting when an administrator manually modifies a resource and pulls it out of ISO/CIS compliance.
2. Immutable Infrastructure (The "No-SSH" Patching Strategy)
The Paradigm Shift: In modern platforms, you never SSH into a server to run apt-get upgrade or use Ansible to patch live nodes. You replace them entirely.
Golden AMIs / Golden Images: Building pre-hardened, pre-patched OS images using HashiCorp Packer or EC2 Image Builder.
Vulnerability Remediation SLA: How to go from "Critical CVE announced" to "Entire 100-node fleet patched" within 24 hours.
3. Zero-Downtime Node Rotation
Rolling Upgrades: Safely evicting workloads from old unpatched nodes to new patched nodes.
Karpenter AMI Drifting: Configuring Karpenter to automatically detect when a new Golden AMI is published and roll the fleet gracefully.
π οΈ Job-Essential Exercises
The CIS Benchmark Audit:
Enable AWS Security Hub and turn on the "CIS AWS Foundations Benchmark" standard. Review the dashboard to identify what resources in your account are failing ISO/CIS standards (e.g., root MFA missing, default VPCs in use).
The Golden Image Pipeline:
Write a HashiCorp Packer template. The pipeline should spin up an Ubuntu base image, run OS-level security patches (apt-get update && apt-get upgrade), install the AWS SSM agent, and output a private "Golden AMI" to your account.
The Zero-Downtime Fleet Rotation:
Deploy a sample application with a PodDisruptionBudget requiring minAvailable: 2.
Update your Karpenter EC2NodeClass to use your newly minted Golden AMI.
Trigger a node drift replacement and watch Kubernetes cordon, drain, and replace the underlying compute infrastructure without dropping a single HTTP request.