3 ms·
IAM isn't easy, but I don't think there is any way to build such a powerful system without at least having the possibility for it to become ultra-complex. The
by anyoneamous 3y ago
IAM isn't easy, but I don't think there is any way to build such a powerful system without at least having the possibility for it to become ultra-complex.
The challenge then becomes taming the complexity while still being "secure enough", i.e. as secure as possible without hindering your business purpose. This is where I take issue with many security specialists in the cloud ecosystem - every single one I have encountered has been good for nothing more than rattling off the best practices (which I already knew). The difficult part of security is understanding the trade-offs you are making, and assessing the risk - but the security people never seem to be intellectually equipped to help with that, only to dole out checklists.
- koromak 3y agoAWS should make it easy to know which permissions are needed. That is really the problem here. You should be able to dry-run a stack deployment, and get a response with every single permission needed at the finest granularity possible. Theres ugly work arounds that only work some of the time to do this. There should be a rock solid way instead.
- belter 3y agoYou do know you can create your IAM Policies from Cloutrail logs? "Generate policies based on access activity" - https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_generate-policy.html https://docs.aws.amazon.com/IAM/latest/UserGuide/access_poli... "IAM Access Analyzer makes it easier to implement least privilege permissions by generating IAM policies based on access activity" - https://aws.amazon.com/blogs/security/iam-access-analyzer-makes-it-easier-to-implement-least-privilege-permissions-by-generating-iam-policies-based-on-access-activity/ https://aws.amazon.com/blogs/security/iam-access-analyzer-ma...