4 ms·
I'd like to add two more: 1) Not giving out your access and secret keys in scripts/buckets. 2) Always using IAM roles with your EC2
by siddharth_mal 11y ago
I'd like to add two more:
1) Not giving out your access and secret keys in scripts/buckets.
2) Always using IAM roles with your EC2
- Bestcoderplanet 11y ago+1 I concentrated on non security related mistakes. security will follow next week... :)
- misiti3780 11y agohow do you avoid 1 - it seems impossible ?
- mhluongo 11y agoIAM roles let you assign temporary credentials to machines running scripts. The machine can then hit an internal AWS URL to get the temporary credentials. Many tools know to look for these credentials by default- eg boto checks for credentials in environment variables, config files, and the machines IAM role.
- idunno246 11y agoAnd there's a few tools to emulate the metadata service locally if you need it on dev laptops which makes it use a role as if a server
- rodrickbrown 11y agoTake a look at hashicorp vault - https://hashicorp.com/blog/vault.html https://hashicorp.com/blog/vault.html
- hrez 11y agoIAM roles is ok as long as you realize that anything and anybody on that instance gets access to those credentials.