<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>RDS on 黄文卓 | DevOps Engineer</title>
    <link>https://socake.github.io/tags/rds/</link>
    <description>Recent content in RDS on 黄文卓 | DevOps Engineer</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-CN</language>
    <managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor>
    <webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster>
    <copyright>© 2026 Wenzhuo Huang</copyright>
    <lastBuildDate>Thu, 30 Apr 2026 15:30:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/rds/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Playbook：AWS Aurora 公网入口收紧的渐进路径——从 0.0.0.0/0 到零信任</title>
      <link>https://socake.github.io/playbook/aurora-public-access-tightening/</link>
      <pubDate>Thu, 30 Apr 2026 15:30:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/playbook/aurora-public-access-tightening/</guid>
      <description>很多团队的生产 Aurora 长期挂着 0.0.0.0/0 全协议规则，加上几条来源不明的 IP 白名单。直接删规则会立刻打断跨 Region 服务和开发者本地调试，于是收紧工作年复一年被推迟。本文给出一条工程化路径：先用 Flow Logs + Athena + CloudTrail 摸清依赖，把跨 Region 业务切到 VPC Peering + Route53 Private Hosted Zone，再用 SSM Port Forwarding 替代开发者直连，最后原子切换 SG 并清理长尾白名单。每一步都给可直接执行的脚本和 IAM Policy。覆盖 4 个真实踩到的坑。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/playbook/aurora-public-access-tightening/featured.jpg" />
    </item>
    
  </channel>
</rss>
