5 ms·
I think it will be great if AWS allowed us to use the AWS keys to be used from certain IPs only. It will add additional layer of security which can help to prev
by pritambarhate 4y ago
I think it will be great if AWS allowed us to use the AWS keys to be used from certain IPs only. It will add additional layer of security which can help to prevent a lot of misuse. Just like AWS best practices of putting DB instances in a private VPC can prevent a lot of attack vectors, ability to use AWS Keys only from certain IPs or IP ranges, can also prevent from misuse, even if one accidentally leaks certain keys.
- circular_logic 4y agoThis looks to be possible via this guide https://repost.aws/knowledge-center/iam-restrict-calls-ip-addresses https://repost.aws/knowledge-center/iam-restrict-calls-ip-ad...
- aeyes 4y agoThis example is for a role but for IAM users it works the same way.
- bpodgursky 4y agoI don't think AWS wants to imply in any way that you need to be on a VPN to interact with AWS resources. It's not the direction they are going (Zero trust / RBA https://aws.amazon.com/security/zero-trust/ https://aws.amazon.com/security/zero-trust/).
- Godel_unicode 4y agoZero trust doesn’t mean no VPNs, it means not just VPNs. In other words you can put your control plane behind ACLs (and you should!) but you should still require strong auth from the private network.
- Hikikomori 4y agoIt's already possible, but on a iam action level.
- wmfiv 4y agoSource IP is an IAM global condition so it's available for all requests. https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p...
- bpicolo 4y agoHaven't tried it, but should be able to use service control policies to do this broadly. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_general.html https://docs.aws.amazon.com/organizations/latest/userguide/o... Can definitely do it at the permission policy level as shown in the links others provided.