4 ms·
That is insane. AWS has more complicated policies, GCP literally lacks ability to even have easy security posture in many cases.
by bfeynman 2y ago
That is insane. AWS has more complicated policies, GCP literally lacks ability to even have easy security posture in many cases.
- decimalenough 2y agoThat's quite the claim, can you provide an example? GCP is permissive out of the box and things like the Compute Engine service account having the basic Editor role by default is a bit of a footgun, but they're trivially turned off.
- lol768 2y agoI'm afraid it's something I need to agree with. So many areas where resource-based conditions just do not work with particular GCP product offerings and you're forced to give out much broader access than you should be giving out. It's half-arsed and prevents you implementing PoLP. AWS has a steeper learning curve here, but I've never been unable to constrain down e.g. access to an SNS topic in the way I want to.
- ExoticPearTree 2y agoI second that. AWS is insanely granular.
- Aeolun 2y agoFeel like AWS is the opposite. It’s often a pain to go as granular as you can go.
- bfeynman 2y agoIn GCP there are many tier-1 services where that is not even possible. It's also definitely gotten way easier to do this using IaC etc.