AI for AWS Documentation
awsdocsgpt.com
awsdocsgpt.com
I want to have a specialist AI that is trained to help me learn how to use the software. 100% what should be happening.
General AI should know how to do stuff too but having an specialist AI implies that the company/group of people/person is making sure to tune the model.
Just an IMO.
You can ask the same questions to ChatGPT and get the same or better answers.
I also know from personal experience with ChatGPT, that you can use it to:
- convert Python/boto3 to any language that has an AWS SDK
- convert CloudFormation to Terraform or the CDK
- write scripts that use the SDK
You will get the occasional hallucination.
I unfortunately don't think we'll be able to solve hallucination anytime soon. Maybe with the successor to the transformer architecture?
We’ve been testing LLM responses with a CLI, we’re using it to generate accuracy statistics, which is especially useful when the use-case Q/A is limited.
If ‘confidence’ can be returned to the user, then at least they can have an indication if there is a higher quality-risk with a given response.
ChatGPT: "I'm sorry, but as of my knowledge cut-off in September 2021, there was no service, tool, or product known as Amazon CodeCatalyst offered by Amazon Web Services (AWS). [...]"
Prompt: how to connect a lambda function to an RDS instance and query it safely?
1. Configure your RDS instance for outbound connections to AWS Lambda. This step involves ensuring that your DB instance is in a public subnet on your VPC and that the instance's "PubliclyAccessible" property is set to true.
There’s also the thing where that’s a positive feedback look and we overflow the worlds corpus with garbage.
I've seen answers like this in Stack Overflow before. Technically correct, but basically broken in every other way: cybersecurity's future is gonna be interesting.
client=boto3.client(<service>, access-key,secret-key)
There is never a reason to include those last two parameters. It’s always a security risk no matter how you do it.In the past few months AWS has added to their UI a popup box that asks you why you are creating access keys, it makes you answer it before generating the keys. Once you give it the answer it tells you better ways to do almost anything you're trying to do, and you have to agree to ignore those suggestions one more time before actually generating the keys.
Basically the standard access keys are really of no use anymore. You should be using roles, OIDC, IAM Identity Center, cognito federated identities, or something else. There are a million ways to identify yourself that are more secure than that and I wish tutorials stopped assuming that you should generate access keys because in no practical 2023 use case should you be doing that anymore. Especially not in any sort of sensitive or corporate environment.
Have you ever noticed how the dumbest people tend be be the loudest, most confident, and most eager to share their opinions? Those are the voices that trained ChatGPT.
It’s a hard pass for me, but I fear I’m going to be forced to used it because the dumbest half of humanity will view it as a peer and use it for everything.
To connect a Lambda function to an RDS (Relational Database Service) instance and query it safely, you can follow these general steps:
1. Configure your Lambda function's execution role: Ensure that your Lambda function has the necessary permissions to access the RDS instance. The role should include the `AWSLambdaVPCAccessExecutionRole` and the appropriate RDS permissions.
2. Place your Lambda function and RDS instance in the same VPC: Ensure that both the Lambda function and the RDS instance are in the same Virtual Private Cloud (VPC) to enable their communication. You can configure the VPC settings in the AWS Management Console.
3. Configure the security group settings: Set up the security groups for your Lambda function and RDS instance to allow the necessary inbound and outbound connections. The Lambda function's security group should allow outbound access to the RDS instance's security group on the RDS port (usually port 3306 for MySQL or 5432 for PostgreSQL).
4. Create a subnet group: If your RDS instance is in a private subnet, create a subnet group that includes the appropriate subnets for your Lambda function to access the RDS instance securely.
5. Connect to the RDS instance from the Lambda function: In your Lambda function code, establish a database connection using the appropriate database client library, such as pymysql for MySQL or psycopg2 for PostgreSQL. Use the connection details (endpoint, username, password, etc.) of your RDS instance.
6. Execute queries safely: To query the RDS instance safely, ensure that your Lambda function's code incorporates secure coding practices. Use parameterized queries or prepared statements to prevent SQL injection attacks. Avoid storing sensitive information (such as database credentials) in your Lambda function code and instead use environment variables or AWS Secrets Manager for secure storage and retrieval.
Remember to regularly update and patch your Lambda function, RDS instance, and associated dependencies to maintain security and stay protected against potential vulnerabilities.
It's worth noting that the exact implementation details may vary depending on your specific use case, programming language, and AWS setup. Consulting the AWS documentation and resources related to Lambda, RDS, and VPC networking can provide more detailed and up-to-date instructions for your specific requirements.
So if it is wrong with MOST of the questions that I am able to validate myself, then how can I trust it on the questions that I am unable to validate myself.
The whole reason I started even doing this passive research is because I had an employee late last year who used to be a decent employee (he was never an all-star, but he got the job done to an average/satisfactory level), and started to all of a sudden perform incredibly poorly.
He was submitting code and solving problems that were just really bad. He was always just an average producer, and was always teetering on the edge during performance reviews, doing just well enough that we kept him around. But he quickly started to make mistake after mistake. Several code reviews I found really strange artifacts and comments in his code that were blatant mistakes. I confronted him about them over the course of several performance reviews and said he blamed stackoverflow "copy pasta". Eventually I actually fired him, since it was getting to a point that almost everything he submitted or produced was problematic in some way and he was burning more of my time than he was saving. So I ended up firing him.
While firing him, in front of HR he finally broke down and admitted that he has been using ChatGPT for everything and he begged us to let him stay and he would stop using it altogether. I of course didn't care at that point and we let him go. But I started to realize the increase of mistakes were all due to ChatGPT leading him astray.
That whole experiment really taught me that ChatGPT is not ready for primetime. If you blindly trusted ChatGPT you will find yourself in the wrong place most of the time. The problem is that unless you already know the answer to the question you are asking, it is very difficult to tell where chatgpt's answers might be correct and were they might be incorrect (because it is usually a mixture of both). This makes it entirely useless for asking questions that you are not comfortable validating.
There are other stories out there, like https://hyperbo.la/w/chatgpt-4000/ which shows it can useful and a force multiplier when used well, but it's like giving a faster car to a bad driver. It'll just result in them crashing faster. If you've got a programmer that doesn't want to program, ChatGPT can't help them be a better programmer since they don't actually want to be one!
If you’re using it to generate code, you can validate it yourself - run the code.
It should be thought of as a time saving tool for experts (and people willing to put the work in), not a magic button for lazy people.
> and the appropriate RDS permissions.
The role doesn’t need any IAM RDS permissions. It needs network access. But then all of the access to the database is controlled by your standard database permissions - not IAM.
I guess there are corner cases like using IAM permissions to connect to your database which can be done. But is not typical
“Is there a more efficient way to connect to the database”
It then went off the rails. It gave me generic answers about using connection pooling that your language framework provides.
Of course that doesn’t help with each Lambda being invoked separately.
I then asked “But each Lambda runs based on its own vm”
It then correctly said that while each Lambda invocation would have its own pool and couldn’t be shared, it could be shared with multiple connections during one invocation.
Which is technically correct. But not the answer I was looking for.
In all fairness, it’s the same type of answers I would expect from a junior to mid developer with limited experience with AWS. I would hire a person who could answer that well.
- What are the considerations?
- Implement it with the considerations
- Did we forget anything?
It understands the need for a proxy from step 1:
https://chat.openai.com/share/7ca37130-a771-457c-8742-a5f941...
It still missed using a paginator to handle the list_roles call returning more than 50 roles.
Once I pointed it out, it did add pagination support.
I'd be surprised if even after the last prompt it wouldn't notice that. Saying "Did we miss anything" leaves it open it to re-evaluate both the implementation and the original considerations
Edit: There's some non-determinism involved, but GPT-4 caught the pagination from planning stage here: https://chat.openai.com/share/3c356d4f-15d4-4f6e-bd29-af6a0b...
https://aws.amazon.com/about-aws/whats-new/2020/06/amazon-rd...
“I’m a beginner. Walk me through step $n”
- Chunking can interfer with context boundaries
- Content vectors can differ vastly from question vectors, for this you have to use hypothetical embeddings (they generate artificial questions and store them)
- Instead of saving just one embedding per text-chuck you should store various (text chunk, hypothetical embedding questions, meta data)
- RAG will miserably fail with requests like "summarize the whole document"
- to my knowledge, openAI embeddings aren't performing well, use a embedding that is optimized for question answering or information retrieval and supports multi language. SOTA textual embedding models can be found on the MTEB Leaderboard [2]. Also look into instructorEmbeddings
- the LLM used for the Q&A using your context should be fine-tuned for this task. There are several open (source?) LLMs based on openllama and others, that are fine tuned for information retrieval. They hallucinate less and are sticking to the context given.
1 https://github.com/underlines/awesome-marketing-datascience/...
I’ve been working with RAG for months, too, and it’s vanishingly rare to see anything but toy examples in the wild. This is a solid, concise list of where the dragons are.
Any idea where all the RAG practitioners hang out and trade war stories? Is there a forum or Discord or something?
BriefGPT [2] is implementing this and it uses the following prompt at ingestion-time:
"Given the user's question, please generate a response that mimics the exact format in which the relevant information would appear within a document, even if the information does not exist. The response should not offer explanations, context, or commentary, but should emulate the precise structure in which the answer would be found in a hypothetical document. Factuality is not important, the priority is the hypothetical structure of the excerpt. Use made-up facts to emulate the structure. For example, if the user question is "who are the authors?", the response should be something like 'Authors: John Smith, Jane Doe, and Bob Jones' The user's question is:"
1 https://python.langchain.com/docs/modules/chains/additional/...
Glacier is a term that is not directly mentioned in the provided sources.
Prompt: What is a glacier?
A glacier is a large mass of ice that moves slowly over time due to the accumulation of snow, ice, and other forms of frozen precipitation.
Seems like it’s just using a general model?
https://www.phind.com/search?cache=d0b3a85b-17f9-4def-b8d0-b...
They're all so eager to please they will basically never say "that's actually not possible", and invent some plausibly sounding bullshit.
For beginners who are struggling to tell the difference between 1/ how to do something that's possible, 2/ how to do something that SHOULD be possible but just currently isn't, and 3/ how to do something that is RIDICULOUS and shouldn't even ever be possible, ChatGPT is worse than nothing :(
I originally thought this was an official Amazon website...their lawyers would probably say the same thing...
I launched “Last Week in AWS” with AWS in the domain name seven years ago. AWS has never made an issue of it, though they obviously have that option.
I also have the option (and ownership) to migrate to “Last Week in the Cloud” and talk about their competitors, so it’s likely everyone is happier this way—but I confess to not kicking the bear hard enough to find out.
I’m sure you know that your name is brought up frequently inside AWS.
it even gets real time indexing from slack of aws deep java library, and from discord of deepset haystack project
Also, I'd argue that it is very easy to be worse than AWS's own docs. A chatbot that hallucinates inaccurate answers, while sounding plausible and confident is far worse than documentation that is 100% accurate, but lacking in some areas.
I'd rather receive an answer of "I don't know" or "it isn't documented" than an explanation that seems legit, so I spend 15 hours building a solution in accordance to a LLM's response and then find out that its not possible or real the way it was explained by the LLM.
I've tried the using OpenAI w embeddings (iirc), but this was slow, got expensive quickly, and it struggled to answer questions about the text accurately. Curious if there's better standard approaches now.
I think you have to do lots of experiment on this till you find your best information retrieval strategy
Made this up as reason for dedicated vpc: “Better performance: By using dedicated hardware, you have better control over the performance of your instances in the VPC. This can be beneficial for applications that have stringent performance requirements.”
Beyond that it will simply have the output/personality of a person with rote-memory.
Still a language model and not a facts model.
How do I connect two VPCs from separate organizations (VPC peering)
How do I only allow authorized applications to access my S3 bucket (BPA, IAM policies, a lot of best practices docs)
With the bonus effect that you could retrain the LLM as often as you like, as new software is released, and it could always be aware of the latest features (and even the bugs and vulnerabilities.)
""" Complete the following code:
// Find all files with a binary pattern in a directory. Return the list of files and the offset of the match in a tuple fn find_in_files(start_dir: &str, pattern: &[u8]) -> vec<(String, usize)> """
No way this won't be abused shortly.
"how do I avoid high NAT gateway bills when an ECS service keeps downloading the same image over and over?"
It offered three replies. The first and third were outright incorrect, the second was (technically) correct:
https://i.imgur.com/la98cxC.png
Also: I'm assuming you haven't actually secured a license to use the AWS logo.
I ran into these issues when building this for my own company's docs, at least.
Well… Thanks a ton for that!
Great idea and setup, but not quite as helpful as I would like yet.
Asking GPT4 is also consistently less of a headache than asking the devops guy and getting a 20min explanation for a simple question.
A: Amazon Bedrock is a programming example that uses the AWS SDK for Java 2.x to work with Amazon EC2. It provides examples and code snippets for programming tasks related to Amazon EC2 using the AWS SDK for Java 2.x.
- Make a VPC. - Add an Instance. - Abstract the region and AZ, into vars.
etc... every time I wanted to change the code, I asked the bot to do the refactor, and it did.
Overall, I'm impressed. It wasn't the most complicated thing, but it didn't dive off the deep end.
These are fun projects!
How does this work?
For example the terseness / symbols of APL, Perl, or event set notation.
LLMs could train and output the shorter symbolic notation, and it could be expanded for human readability by another program at export.
When asked how to create a private HTTP gateway it happily tells you how to do it , but it’s actually impossible.
When the docs are wrong or misleading you'll still get burned, even if the model doesn't hallucinate responses
No, AWS is not designed to take all your money. AWS offers a variety of payment options and cost-saving measures to help you manage your expenses effectively. ...
how do you use wrangler and glue to make athena tables using terraform