In this chapter, we looked at best practices for securing a Serverless app. We also looked at the security model recommended by AWS, and the basic constructs provided for securing accesses and infrastructure resources in an AWS account. We also underwent a practical walkthrough of securing the application that we created by launching resources in a VPC and encrypting the environment variables supplied to Lambda. This chapter can be treated as a primer in securing the Serverless system and its components on AWS. Security is ever-changing, and it is recommended that the reader keeps abreast of the different innovations that happen in this field.




















































