3 ms·
Maybe through the GUI, it's a single step with the CLI.
by turtlebits 7y ago
Maybe through the GUI, it's a single step with the CLI.
- awestroke 7y agoPlease elaborate. How is this achieved in one step with the CLI?
- 013a 7y agoWell, you'll have a two-hundred line IAM policy and a half-dozen API calls encoded into a script, but once you have that script its just one step! All you do is run the script!
- giancarlostoro 7y agoAnd if something in the script goes wrong midway through, you've automated a big mess! I love it! Really should, I've always thought AWS was just a bunch of hacked together services and it kinda shows. This is why you don't let the engineers talk to the customers... er design for the customers.
- zbruhnke 7y agoNot OP but pretty sure they just mean this `aws s3api create-bucket --bucket somecoolname --region us-west-2 --grant-write iamuser`
- aeternum 7y agoAnd now a single user has access, such scalability!
- zbruhnke 7y agoWell technically this could also be a group. I don’t know why all the hate for IAM permissions here. They are complicated but also extremely powerful if setup correctly. We manage all of our IAM policies and groups with terraform and it’s incredibly easy to understand imho
- caro_douglos 7y agoHella hate. Personally I found grappling with what they were initially difficult but then I finally dug in and watched howto propaganda...great job whoever did that at amazon. It’s the one thing I don’t hate about the company. [1] It’s a ton easier for on boarding and giving contractors temporary access to resources. *former worker at 3rd party merchant [1] https://www.aws.training/LearningLibrary https://www.aws.training/LearningLibrary
- deleted 7y ago[deleted]
- kmcquade 7y agoWith this. https://github.com/salesforce/policy_sentry https://github.com/salesforce/policy_sentry (Disclaimer: I am the author) Not one step exactly, but it is by far the easiest way to write least privilege IAM policies. Otherwise, it becomes impossible to ensure IAM policies are written securely and at scale. This way, all custom IAM policies are written with the exact same methodology.