<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Newbie |</title><link>https://minhnn-tiny.github.io/tags/newbie/</link><atom:link href="https://minhnn-tiny.github.io/tags/newbie/index.xml" rel="self" type="application/rss+xml"/><description>Newbie</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Sat, 10 Jan 2026 00:00:00 +0000</lastBuildDate><image><url>https://minhnn-tiny.github.io/media/icon_hu_702a800cd775dbac.png</url><title>Newbie</title><link>https://minhnn-tiny.github.io/tags/newbie/</link></image><item><title>CORS and S3: The Internet's 'Stranger Danger' Rule</title><link>https://minhnn-tiny.github.io/blogs/aws-cors/</link><pubDate>Sat, 10 Jan 2026 00:00:00 +0000</pubDate><guid>https://minhnn-tiny.github.io/blogs/aws-cors/</guid><description>&lt;p&gt;Hello fellow cloud explorers! 🚀&lt;/p&gt;
&lt;p&gt;Welcome back to &lt;strong&gt;AWS for Newbies&lt;/strong&gt;! Today, we are tackling a topic that sounds super boring but is actually a secret superhero protecting your internet life: &lt;strong&gt;CORS&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Have you ever tried to load an image or a font on your website, and it just refuses to show up, and your browser console yells something red and scary like this?&lt;/p&gt;
&lt;blockquote class="border-l-4 border-neutral-300 dark:border-neutral-600 pl-4 italic text-neutral-600 dark:text-neutral-400 my-6"&gt;
&lt;p&gt;&lt;em&gt;“Access to fetch at &amp;lsquo;&amp;hellip;&amp;rsquo; has been blocked by CORS policy”&lt;/em&gt; 😱&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let&amp;rsquo;s decode this mystery in a way even a 7-year-old can understand.&lt;/p&gt;
&lt;h2 id="the-golden-rule-stranger-danger-sop"&gt;The Golden Rule: &amp;ldquo;Stranger Danger&amp;rdquo; (SOP)&lt;/h2&gt;
&lt;p&gt;Before we understand CORS, we need to understand the rule it breaks.&lt;/p&gt;
&lt;p&gt;Imagine the internet is a giant neighborhood. Every website lives in its own &lt;strong&gt;House&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Your house address is your &lt;strong&gt;Origin&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;An origin looks like this: &lt;code&gt;https://&lt;/code&gt; + &lt;code&gt;my-awesome-site.com&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The web browser (like Chrome or Firefox) is your overprotective bodyguard. It has a strict rule called the &lt;strong&gt;Same-Origin Policy (SOP)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Here is how SOP works:&lt;/strong&gt;
Your browser says: &amp;ldquo;If you are in House A (&lt;code&gt;my-awesome-site.com&lt;/code&gt;), you can play with toys inside House A. But you are &lt;strong&gt;NOT allowed&lt;/strong&gt; to just reach into House B (&lt;code&gt;google.com&lt;/code&gt;) and grab their toys without asking.&amp;rdquo;&lt;/p&gt;
&lt;h3 id="why-do-we-need-this-rule-"&gt;Why do we need this rule? 🤔&lt;/h3&gt;
&lt;p&gt;Imagine you are logged into your online bank bank website. Then, you open a new tab and visit a malicious website, &lt;code&gt;super-evil-hackers.net&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Without the SOP rule, the evil website could secretly tell your browser: &lt;em&gt;&amp;ldquo;Hey, while you are logged into the bank in that other tab, send me $500!&amp;rdquo;&lt;/em&gt; The browser would do it because it trusts &lt;em&gt;you&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;SOP stops this. It stops &amp;ldquo;strangers&amp;rdquo; (different origins) from touching your private stuff in other tabs.&lt;/p&gt;
&lt;p&gt;Here is a diagram of the browser blocking a &amp;ldquo;stranger&amp;rdquo;:&lt;/p&gt;
&lt;div class="mermaid"&gt;flowchart LR
subgraph Browser
WebsiteA[🏠 Your Website&lt;br/&gt;(Origin A)]
EvilSite[😈 Evil Website&lt;br/&gt;(Origin B)]
end
Bank[🏦 Your Bank&lt;br/&gt;(Origin C)]
WebsiteA -- "Can access" --&gt; WebsiteA
EvilSite -- "❌ SOP BLOCKED! ❌&lt;br/&gt;Cannot touch Bank!" -.- &gt; Bank
style EvilSite fill:#ffe6e6,stroke:#ff0000
style Bank fill:#e6ffe6,stroke:#00aa00
&lt;/div&gt;
&lt;h3 id="enter-cors-the-permission-slip"&gt;Enter CORS: The &amp;ldquo;Permission Slip&amp;rdquo;&lt;/h3&gt;
&lt;p&gt;SOP is great for security, but sometimes it&amp;rsquo;s annoying.&lt;/p&gt;
&lt;p&gt;What if House A and House B are best friends? What if my-awesome-site.com needs to fetch a cool image stored on my-image-bucket.com?&lt;/p&gt;
&lt;p&gt;They are different origins, so the browser bodyguard says &amp;ldquo;NOPE!&amp;rdquo; 🛑&lt;/p&gt;
&lt;p&gt;This is where CORS comes in. It stands for Cross-Origin Resource Sharing.&lt;/p&gt;
&lt;p&gt;Here is how CORS works: CORS is like a Permission Slip signed by the parents.&lt;/p&gt;
&lt;p&gt;Your website (House A) tries to get an image from another server (House B).&lt;/p&gt;
&lt;p&gt;Your browser sees this and gets suspicious. Before handing over the image, the browser politely asks House B: &amp;ldquo;Excuse me, House A wants this image. Do they have permission?&amp;rdquo;&lt;/p&gt;
&lt;p&gt;House B checks its rules. If it likes House A, it sends back a special &amp;ldquo;header&amp;rdquo; (the permission slip) that says: Access-Control-Allow-Origin: * (Everyone is okay!) or Access-Control-Allow-Origin:
(Only friends are okay!).&lt;/p&gt;
&lt;p&gt;The browser sees the slip and lets the image through. ✅&lt;/p&gt;
&lt;div class="mermaid"&gt;sequenceDiagram
participant Browser 🛡️
participant MySite as 🏠 My Website (Origin A)
participant OtherServer as 🏢 Other Server (Origin B)
Note over Browser, OtherServer: The CORS Handshake 🤝
MySite-&gt;&gt;Browser: I need data from Origin B!
Browser-&gt;&gt;OtherServer: 🗣️ "Hey, Origin A wants your data. Is that okay?"
alt Permission Granted
OtherServer--&gt;&gt;Browser: ✅ "Yes! Here is my Permission Slip header."
Browser--&gt;&gt;MySite: Okay, here is the data.
else Permission Denied
OtherServer--xBrowser: ❌ "NO. I don't know them."
Browser--xMySite: 🔥 CORS ERROR! Blocked.
end
&lt;/div&gt;
&lt;h2 id="the-sneaky-trick-browser-extensions-"&gt;The Sneaky Trick: Browser Extensions 🕵️‍♀️&lt;/h2&gt;
&lt;p&gt;You asked: How can a browser extension bypass CORS?&lt;/p&gt;
&lt;p&gt;Great question!&lt;/p&gt;
&lt;p&gt;Remember, SOP and CORS are rules enforced by the browser for regular web pages.&lt;/p&gt;
&lt;p&gt;A browser extension (like an AdBlocker or a password manager) doesn&amp;rsquo;t live on a web page. It lives inside the browser itself. It&amp;rsquo;s like giving someone the master keys to the house.&lt;/p&gt;
&lt;p&gt;Extensions have special privileges. They can tell the browser, &amp;ldquo;Shhh, ignore those rules for a second, I&amp;rsquo;m an administrator.&amp;rdquo; This allows them to make requests to any server they want, ignoring CORS completely.&lt;/p&gt;
&lt;h2 id="real-world-use-case-aws-s3-cors-"&gt;Real-World Use Case: AWS S3 CORS ☁️&lt;/h2&gt;
&lt;p&gt;This is the most common place newbies face this mistake!&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s say you built a beautiful website,
. You decide to store all your cat photos in an AWS S3 Bucket because it&amp;rsquo;s cheap and fast.&lt;/p&gt;
&lt;p&gt;Your S3 bucket gets its own address, like
.&lt;/p&gt;
&lt;p&gt;Uh oh! Do you see the problem?&lt;/p&gt;
&lt;p&gt;Your Website Origin: cool-cat-pics.com&lt;/p&gt;
&lt;p&gt;Your Bucket Origin: &amp;hellip;s3.amazonaws.com&lt;/p&gt;
&lt;p&gt;They are different! When your site tries to load the cat photos, the browser blocks them. Broken images everywhere. 😿&lt;/p&gt;
&lt;h2 id="the-fix"&gt;The Fix&lt;/h2&gt;
&lt;p&gt;You need to go into your AWS S3 console, find your bucket, go to the &amp;ldquo;Permissions&amp;rdquo; tab, and scroll down to CORS.&lt;/p&gt;
&lt;p&gt;You need to add a &amp;ldquo;Permission Slip&amp;rdquo; (a JSON configuration) telling the bucket it&amp;rsquo;s okay to talk to your website.&lt;/p&gt;
&lt;p&gt;It looks something like this (simplified):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;AllowedOrigins&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;[https://cool-cat-pics.com](https://cool-cat-pics.com)&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;AllowedMethods&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;GET&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;MaxAgeSeconds&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;3000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;AllowedHeaders&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;*&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This config tells S3: &amp;ldquo;If cool-cat-pics.com asks to GET a photo, say YES!&amp;rdquo;&lt;/p&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;SOP (Stranger Danger): The browser rule that stops different websites from talking to each other for security.&lt;/p&gt;
&lt;p&gt;CORS (Permission Slip): The way servers tell the browser it&amp;rsquo;s okay to break the SOP rule for specific friends.&lt;/p&gt;
&lt;p&gt;S3 Needs CORS: Because your bucket and your website are usually two different &amp;ldquo;houses&amp;rdquo; on the internet.&lt;/p&gt;
&lt;p&gt;Keep practicing, and don&amp;rsquo;t fear the red error messages! 🦸‍♂️🦸‍♀️&lt;/p&gt;</description></item><item><title>The Route 53 Name Server Mistake: Who Points to Whom?</title><link>https://minhnn-tiny.github.io/blogs/aws-name-servers/</link><pubDate>Sat, 03 Jan 2026 00:00:00 +0000</pubDate><guid>https://minhnn-tiny.github.io/blogs/aws-name-servers/</guid><description>&lt;p&gt;Hi friends! 👋&lt;/p&gt;
&lt;p&gt;Welcome back to our &lt;strong&gt;AWS for Newbies&lt;/strong&gt; series! Today, we are going to talk about a &amp;ldquo;silent killer&amp;rdquo; of websites: &lt;strong&gt;The Domain Name Server (DNS) Setup Mistake&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It sounds technical, but I promise to explain it so simply that even your 7-year-old cousin (or your cat 🐱) could understand it.&lt;/p&gt;
&lt;h2 id="the-scenario"&gt;The Scenario&lt;/h2&gt;
&lt;p&gt;Imagine you just bought a shiny new domain name, like &lt;code&gt;my-awesome-shop.com&lt;/code&gt;, from a registrar like &lt;strong&gt;GoDaddy&lt;/strong&gt; or &lt;strong&gt;Namecheap&lt;/strong&gt;. This is where you &lt;em&gt;own&lt;/em&gt; the name.&lt;/p&gt;
&lt;p&gt;Now, you want to manage your website using &lt;strong&gt;AWS Route 53&lt;/strong&gt; because you are building a cool cloud app. You create a &amp;ldquo;Hosted Zone&amp;rdquo; in AWS.&lt;/p&gt;
&lt;p&gt;Now you have two things:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;The Registrar&lt;/strong&gt; (where you bought the name).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AWS Route 53&lt;/strong&gt; (where you want to manage the traffic).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You need to connect them. But &lt;strong&gt;who points to whom?&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="the-big-mistake-"&gt;The Big Mistake ❌&lt;/h2&gt;
&lt;p&gt;Many beginners look at their Route 53 settings, see a list of strange server names (like &lt;code&gt;ns-123.awsdns-01.com&lt;/code&gt;), and think:&lt;/p&gt;
&lt;blockquote class="border-l-4 border-neutral-300 dark:border-neutral-600 pl-4 italic text-neutral-600 dark:text-neutral-400 my-6"&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Oh, these look different from what is in my GoDaddy account! I should change these AWS records to match GoDaddy!&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;STOP! Don&amp;rsquo;t do that!&lt;/strong&gt; 🛑&lt;/p&gt;
&lt;p&gt;If you change the records inside AWS to match your Registrar, your website will break. It’s like buying a new house but putting your &lt;em&gt;old&lt;/em&gt; address on the new mailbox. The mailman (the internet) still goes to the old house.&lt;/p&gt;
&lt;h2 id="the-phone-book-analogy-"&gt;The &amp;ldquo;Phone Book&amp;rdquo; Analogy 📖&lt;/h2&gt;
&lt;p&gt;Let&amp;rsquo;s imagine the Internet is a giant city.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Registrar (GoDaddy/Namecheap):&lt;/strong&gt; This is the &lt;strong&gt;Town Hall&lt;/strong&gt;. They keep the master list of who lives where. When someone asks, &amp;ldquo;Where is &lt;code&gt;my-awesome-shop.com&lt;/code&gt;?&amp;rdquo;, the Town Hall checks their list to see which &lt;strong&gt;Phone Book&lt;/strong&gt; to use.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Route 53:&lt;/strong&gt; This is your personal &lt;strong&gt;Phone Book&lt;/strong&gt;. It contains the specific directions (IP addresses) to your website, your email, and your database.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="why-the-mistake-fails"&gt;Why the Mistake Fails&lt;/h3&gt;
&lt;p&gt;If you change the names &lt;em&gt;inside&lt;/em&gt; Route 53 (your Phone Book) to match the Registrar, you aren&amp;rsquo;t telling the Town Hall anything new. The Town Hall still thinks, &amp;ldquo;Oh, look at the default GoDaddy Phone Book.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;You effectively wrote &amp;ldquo;GoDaddy&amp;rdquo; on the cover of your AWS book, but the Town Hall never looks at your AWS book in the first place!&lt;/p&gt;
&lt;h3 id="the-correct-way-"&gt;The Correct Way ✅&lt;/h3&gt;
&lt;p&gt;You must go to the &lt;strong&gt;Town Hall (Registrar)&lt;/strong&gt; and tell them:&lt;/p&gt;
&lt;blockquote class="border-l-4 border-neutral-300 dark:border-neutral-600 pl-4 italic text-neutral-600 dark:text-neutral-400 my-6"&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;Hey! Stop looking at your old default book. Please look at &lt;strong&gt;THIS&lt;/strong&gt; specific AWS Phone Book instead.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You need to copy the AWS server names and paste them into your Registrar&amp;rsquo;s settings.&lt;/p&gt;
&lt;h2 id="visualizing-the-fix"&gt;Visualizing the Fix&lt;/h2&gt;
&lt;p&gt;Here is a simple diagram to show the flow of authority.&lt;/p&gt;
&lt;div class="mermaid"&gt;flowchart TD
User((User)) --&gt; Registrar[Registrar System&lt;br/&gt;Town Hall]
subgraph WRONG ["The Mistake (WRONG)"]
Registrar -.-&gt; OldDNS[Old/Default DNS]
OldDNS --x Route53_Bad[AWS Route 53&lt;br/&gt;You changed NS records here]
Route53_Bad -- Broken Link --&gt; Website
end
subgraph RIGHT ["The Correct Way (RIGHT)"]
Registrar -- Update pointers here! --&gt; Route53_Good[AWS Route 53&lt;br/&gt;Keep original AWS NS records]
Route53_Good --&gt; Website[Your Website]
end
style WRONG fill:#ffe6e6,stroke:#ff0000,stroke-width:2px
style RIGHT fill:#e6ffe6,stroke:#00aa00,stroke-width:2px
&lt;/div&gt;
&lt;h2 id="step-by-step-guide"&gt;Step-by-Step Guide&lt;/h2&gt;
&lt;p&gt;Here is how to solve this in 3 easy steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Find Your AWS &amp;ldquo;Phone Numbers&amp;rdquo;
Go to your Route 53 Hosted Zone. Look for the record type NS (Name Server). You will see 4 lines that look like this:&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;ns-111.awsdns-22.com&lt;/li&gt;
&lt;li&gt;ns-333.awsdns-44.net&lt;/li&gt;
&lt;li&gt;ns-555.awsdns-66.org&lt;/li&gt;
&lt;li&gt;ns-777.awsdns-88.co.uk&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Copy these! 📝&lt;/p&gt;
&lt;ol start="2"&gt;
&lt;li&gt;
&lt;p&gt;Go to Your Registrar
Log in to where you bought your domain (GoDaddy, Namecheap, etc.). Look for a setting called &amp;ldquo;Custom DNS&amp;rdquo; or &amp;ldquo;Manage Name Servers&amp;rdquo;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Swap Them Out
Delete the old default servers and paste in the 4 AWS servers you copied earlier.
Pro Tip: Do not add the little dot (.) at the very end if your registrar doesn&amp;rsquo;t like it.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;And that&amp;rsquo;s it! By changing the settings on the Registrar&amp;rsquo;s side, you are officially telling the internet to trust AWS with your traffic.
It might take a few minutes (or up to 48 hours) for the &amp;ldquo;Town Hall&amp;rdquo; to update its records globally. Be patient, grab a juice box 🧃, and wait for your site to go live!&lt;/p&gt;
&lt;p&gt;Happy Clouding! ☁️&lt;/p&gt;</description></item></channel></rss>