How to protect access keys to S3 and RDS in this approach. Everyone can extract them from your HTML/JS code and use for their own purpose.
http://docs.aws.amazon.com/AWSJavaScriptSDK/guide/browser-co...
So basically, instead of embedding the AWS access keys in HTML, you use AWS.config.credentials = new AWS.WebIdentityCredentials(...) with the OAuth access tokens you get from Google or Facebook.
For RDS, I suspect DocSavage is likely to soon learn that browsers don't speak RDBMS wire protocols; they'll need a CRUD wrapper at least. The canonical AWS "serverless" solution would be API Gateway + Lambda.