4 ms·
AWS IAM user cost consumptiom
Why it is not possible to have the option of showing the service and cost consumption of each IAM user separately in AWS?
- playingalong 4y agoBecause the service would need to remember for its whole lifetime who created it. And the next thing people would ask to be able to donate resources to someone else And here we land with the tagging system. Most of the AWS resources accept tags. And you could have a tag called owner. And then tools like Cost Explore can break down the costs for you by Owner. The only thing you need to do yourself is to have a system or convention to enforce/encourage all resources to be tagged.
- devKnight 4y agoDoes the data for that exist? If AWS has a way to extract that information through an API, could be a killer app
- QuinnyPig 4y agoIndirectly for some use cases; take the resource ID and find out what created it via the CloudTrail management event that gets logged when the thing was created.
- version_five 4y agoThere is a YC company called Vantage that does AWS cost analysis that I see posting on here sometimes. They may have some thoughts and a perspective on if / how it is possible
- QuinnyPig 4y agoFor a variety of reasons. * Many deployments are done via roles, not IAM users. * That pesky "jenkins" user is not in fact "John Enkins" but is in fact a CI/CD system. * The model breaks down entirely once you get past a certain level of complexity. Shared resources (CloudWatch Logs, CloudTrail events, oh god the NAT gateways) get really hard to slice up in easily agreeable ways; cross-account access becomes a nightmare to track costs across. * Most relevant of all: the system wasn't designed to do this from the start, and there's a mountain of technical debt to dig out from under before it could be done.
- zeeshah 4y agoThankyou for the insight. I wish AWS had some mechanism that could somehow calculate the IAM consumption.