2. Even better, should aws let customers proceed if they have mis-configurations?
2. Even better, should aws let customers proceed if they have mis-configurations?
AWS basically rents digital chainsaws. You hope they know how to use it, but you know a fair number probably don't.
Of course Amazon assumes that you know what you're doing, so it won't include such scans by default. If you set up a container to be world accessible, you're probably intending to do so, otherwise you wouldn't expose it like that.
If you're unsure, you can always pay extra to have Amazon verify such things for you, but they're not your IT infra manager and neither should they be.
https://docs.aws.amazon.com/securityhub/latest/userguide/sec...
If you’re launching EC2 and installing ES on it, you’re probably going to have to create your own Config rules for auditing.