3 ms·
I don't see how microservices necessarily lead to what you call micro level permissions. If anything it's IAAS/PAAS and the inherent requirements that springs
by lostmyoldone 6y ago
I don't see how microservices necessarily lead to what you call micro level permissions.
If anything it's IAAS/PAAS and the inherent requirements that springs from that, to explicitly manage access that has started to drive this.
Still, some deployment environments makes it extremely tedious to actually manage fine grained, least necessary privilege access. Especially for smaller outfits, setting up all the security specs for a quite typical setup at a good granularity has a lot of the feel of writing assembler code for a mcu with a bad datasheet.
Figuring out which rights you actually need is sometimes hilariously convoluted, as examples often use excessively large scopes, and sometimes even figuring out which service to attach them to can be extremely non-obvious.
I hope that in time there'll be tools on top of the k8s specs that takes these chores out of the equation, maybe there already are?
I haven't tracked k8s closely, as it seems to mostly cater to larger outfits as of now.
- tedk-42 6y agoIf your microservice only updates billing details on a dynamodb table, it'll never be vulnerable to having someone take over it and stealing all the data from it. It's what I call a micro level permission. The principal/actor can only write to one resource. Where places get it wrong is when their application writes to dynamodb, reads from S3, does a scan on another table etc. It leads Devs to making overly permissive permissions while they debug why their app isn't working like it use to.