Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsSecure a self-hosted app on AWS by tightening the permissions and network paths it actually needs—not by blocking access indiscriminately. Start with an inventory, then reduce IAM permissions, restrict public entry points, require IMDSv2 where compatible, protect S3, move secrets into managed storage, and monitor the changes. Test each change against the application and its deployment tools before applying it broadly in production.
What to check before changing AWS settings
First, map how the application communicates and which AWS resources it uses. Record its IAM users and roles, EC2 instances, security groups, public IP addresses, load balancers, S3 buckets, secrets, and data stores. Mark the intended public entry points and required outbound connections so a security change does not unexpectedly cut off a dependency.
AWS recommends inventorying publicly accessible data and reviewing granted access in its Security Pillar operational guidance. AWS Config can evaluate recorded resource configurations against desired configurations; Security Hub CSPM can surface findings. Treat a finding as a prompt to investigate, not proof that a resource is exploitable or safe to remediate automatically.
How to reduce IAM permissions without locking out the app
Give each workload an IAM role with temporary credentials and only the access it needs. Look for wildcard actions or resources, stale users and access keys, and credentials embedded in code or instance configuration. An AWS managed policy may be too broad for a particular app; AWS cautions that managed policies are not necessarily least privilege for a specific use case.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Identify what the workload does and the AWS resources it must access.
- Review CloudTrail activity and use IAM Access Analyzer policy generation as evidence about which actions the workload has used. Activity logs are an input to policy design, not a guarantee that every infrequent or future operation has been captured.
- Create a narrower customer-managed policy and test it in a safe environment or staged deployment.
- Monitor application errors and audit events after deployment, and adjust the policy if a required operation was missed.
Do not remove every * through a bulk search-and-replace. Static review may not reveal all service actions an application or deployment process needs. Tie permissions to workload functions and resources, and make changes incrementally.
See the AWS IAM security best practices and IAM Access Analyzer policy generation documentation.
How to restrict EC2 and network exposure
Review every EC2 security group’s inbound rules. Remove ports that do not need to be reachable, especially rules open to 0.0.0.0/0 or ::/0. If a service must be public, allow only the required ports, protocols, and sources. Check subnet network ACLs as well: security groups and network ACLs serve different roles, and the overall design should preserve only intended traffic.
Rank #2
Choose an application entry point
For a web app, one option is to expose a load balancer publicly and keep EC2 instances in private subnets. A web application firewall can add another layer against web exploits and bots. This design is not universal; validate its network paths and dependencies before moving an existing deployment.
For administration, AWS Systems Manager Session Manager can provide shell access without inbound management ports, SSH key handling, or a bastion host. AWS Security Hub describes it as providing access “without the need for inbound ports, managing SSH keys, or maintaining bastion hosts.” See Security Hub controls for the AWS Foundational Security Best Practices standard.
How to require IMDSv2 safely
EC2 instance metadata can provide temporary credentials and configuration, so metadata access needs to be protected. AWS Security Hub flags instances that allow IMDSv1; IMDSv2 uses session-oriented requests. Before requiring IMDSv2 and disabling IMDSv1, check that application code, monitoring agents, and deployment tooling use compatible metadata requests. AWS Config includes an ec2-imdsv2-check control.
Apply the requirement in a test or staged environment, verify that the workload still retrieves metadata and credentials, then roll it out to production. The relevant references are Security Hub controls and AWS Config managed rules.
How to keep S3 buckets and objects private
Unless a bucket intentionally serves public content, enable S3 Block Public Access and inspect settings at both the account and bucket levels. Review bucket policies and access points for wildcard principals such as "Principal": "*" and overly broad actions. AWS advises: “Unless you explicitly require anyone on the internet to be able to read or write to your S3 bucket, make sure that your S3 bucket is not public.”
Free tools Windows power users keep installed
One-click scans. No signup required.
For most modern use cases, AWS recommends disabling ACLs with the bucket-owner-enforced Object Ownership setting. Check upload behavior and integrations first if the application relies on per-object ACLs. Use an IAM role for application access rather than long-lived keys stored in source code or directly on an EC2 instance.
Rank #4
CloudTrail management events do not record every object read or write. Enable S3 data events when object-level operations need to be auditable. AWS Config also has controls for S3 public access and can monitor recorded configuration. See S3 Block Public Access and CloudTrail logging for S3.
How to move application secrets out of code
Store sensitive values in AWS Secrets Manager and grant the workload role access only to the secrets it needs. Plan how the application retrieves and caches each secret, and consider rotation only when the application can handle it safely. Remove old copies from source repositories, deployment artifacts, logs, and local files where appropriate; moving the current value does not remove historical copies.
Avoid putting secret values directly in shell commands: command history or logging can expose them. Review the Secrets Manager best practices before changing how the application receives credentials.
Recommended Free Tools
How to monitor configuration and activity
Use monitoring services for the evidence they collect, rather than treating any one dashboard as a complete security verdict.
- AWS Config: Records resource configurations and evaluates them against desired configurations. Managed rules include checks for security group access, public EC2 exposure, IMDSv2, broad IAM policies, and S3 public access.
- Security Hub CSPM: Runs security checks and aggregates findings. Confirm that the relevant services and standards are enabled for the resources and regions you operate.
- CloudTrail: Records actions by users, roles, and AWS services. Enable S3 data events when object-level tracking is needed; management events alone do not show every object operation.
- IAM Access Analyzer: Helps identify resources shared externally, validate policies, and generate policies from CloudTrail activity.
Configuration checks describe recorded state; event logs describe actions within their coverage. Neither establishes that the whole application is secure. Findings depend on intended access, resource type, region, and which services and event types are enabled. See What is AWS Config? and the CloudTrail User Guide.
How to roll out fixes without disrupting traffic
For each proposed change, compare the exposure it reduces with its compatibility and operational costs. A public instance may be simpler to operate, while a private instance behind a public load balancer reduces direct exposure but requires the right network paths. Direct SSH access may fit an existing workflow; Session Manager avoids inbound management ports but depends on compatible access and operations setup. Narrower policies reduce unnecessary permissions but require careful observation of workload behavior.
- Document the current rule, policy, setting, and the application function it supports.
- Change one control at a time in a non-production environment or a limited rollout.
- Exercise normal traffic, background jobs, deploys, monitoring, backups, and administration—not just the app’s home page.
- Watch application errors, CloudTrail activity, and Config or Security Hub findings after each change.
- Keep a tested recovery path so you can restore required access if a dependency fails.
The right configuration depends on the app’s traffic, dependencies, data sensitivity, and operating model. Validate changes before broad production rollout rather than assuming a standard setting suits every deployment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




