3 ms·
We use an IAM Role for each type/role of vm and per environment/region. I am using more and more inline-policies because in most cases is hard to reuse a manage
by jfroma 10y ago
We use an IAM Role for each type/role of vm and per environment/region. I am using more and more inline-policies because in most cases is hard to reuse a managed policies. Also, there is a very low limit for managed policies within a Role: 10.
How do we maintain mental sanity? We define all our infrastructure on code (terraform) and we have found the right abstraction in the tool: modules. One module output is used as input on another module. Let's say you have a module to create and configure a bucket exporting the arn of the bucket, then another module to create the autoscaling-group along with its security groups, IAM Role and Policy. All changes are made through pull-requests and reviewed.
If you want to know who has access to a resource you read the dsl. I havent seen any tool to query aws api that way. It might be complex to build because policies can have all sort of wildcards.
- colemorrison 10y agoOh wow. That's an interesting case for inline policies. Now that I think about it, yes there's plenty of cases for reusable ones, and there seem to be just as many cases where a policy is unique to exactly that one service/situation.