- allow access for zabbix to the monitoring endpoint in the security group
block all public access to the configuration bucket
use data to search for the AMI instead of var
- ignore changes in AMI (don't enforce instance replacement when the latest AMI is updated)
- add explicit kms dependency - add customizable user data