4 ms·
You can simulate a policy with AWS IAM Policy Simulator
by lockedinspace 4y ago
You can simulate a policy with AWS IAM Policy Simulator
- krab 4y agoThis doesn't cut it. That tool helps if your role/user has a lot of policies that might interact between each other. But you already need to know the exact "actions" and context. On the other hand, I have a tool that calls some AWS services that may in turn call other AWS services. Now if something fails because of IAM denial, I have to go through the logs to figure out what it needed, sometimes it's not even in the logs (S3). Then add it to the policy and repeat to see the next failed call. I imagine being able to call real API calls, make them succeed and record what permissions it needed for each of those API calls. I don't need that as a permanent log, just as a development tool.
- sickmate 4y agoYou can do this with Localstack, however it's gated behind their pro service. https://docs.localstack.cloud/user-guide/aws/iam/#explainable-iam https://docs.localstack.cloud/user-guide/aws/iam/#explainabl...
- kapilvt 4y agoAll of the sdks support client side monitoring (CSM), so these sort of tools can be built client side. https://boto3.amazonaws.com/v1/documentation/api/1.10.46/guide/sdk-metrics.html#enable-sdk-metrics https://boto3.amazonaws.com/v1/documentation/api/1.10.46/gui... afaics the only challenge is mapping some of the apis to iam as its only 85% 1:1 There's also tools for helping with iam like (generator, and linter) https://github.com/salesforce/policy_sentry https://github.com/salesforce/policy_sentry https://github.com/duo-labs/parliament https://github.com/duo-labs/parliament
- krab 4y ago> mapping some of the apis to iam as its only 85% 1:1 Yeah. Try to create an Elastic beanstalk app with only EB permissions.
- kapilvt 4y agoactually Ian (aws hero) has a tool that does exactly this https://github.com/iann0036/iamlive https://github.com/iann0036/iamlive
- krab 4y agoOh, thanks a lot!
- distcs 4y ago> You can simulate a policy with AWS IAM Policy Simulator Is it reliable though? I have experienced many situations where a role has access to a policy and yet the policy simulator said that access is denied due to "organization policy" with no further ability to drill down to which policy it thinks denies access. And it did that when the role did have access to the resource and could work with that resource successfully. So I stopped trusting the simulator. I wonder if others too have experienced similar issues with the simulator.