4 ms·
Haven't dealt with Google much but Azure and AWS have good and bad points with identity. Azure is much easier to define RBAC access for individual resources in
by devonbleak 10y ago
Haven't dealt with Google much but Azure and AWS have good and bad points with identity.
Azure is much easier to define RBAC access for individual resources in the portal, but doesn't give a unified view of what a user has access to (that I've found).
AWS IAM provides a much more consistent experience across services - I have a key pair or role and that key pair/role works across all the AWS services according to the policies defined. Compare to Azure Storage Account access for example.
AWS IAM can get frustrating when you take into consideration interaction between things like user policy, bucket policy and VPC endpoint policy when trying to access S3 from an EC2 instance in a VPC.
AWS IAM policies can make it difficult to express some use cases, mostly relying on tags and the console doesn't support tags on resource creation for many services. I've also run into bugs in cloudformation where it ignores or doesn't support putting tags on redshift clusters, meaning the only way I could give someone access to create a redshift cluster with tags was either through the CLI or APIs directly.
AWS IAM Roles and Instance Profiles are amazing for granting access to EC2 instances, and they added similar functionality for containers in ECS recently also.
Overall I like the AWS approach better because I find it much easier to implement as code and also probably because I've been using it for much longer.