4 ms·
Agreed on cloud IAM. AWS, GCP, and Azure handle fine-grained access well. The problem is higher-level platforms and SaaS. Once agents need feedback from deploy
by NBenkovich 8mo ago
Agreed on cloud IAM. AWS, GCP, and Azure handle fine-grained access well.
The problem is higher-level platforms and SaaS. Once agents need feedback from deployment, CI, logs, or config tools, permissions often collapse into “full token or nothing”. Vercel is just one example.
That’s the gap I’m pointing at.
- verdverm 8mo agoMaybe the problem is your SaaS choices I don't have problems with permissions in any of those things you listed. Do mainly k8s based infra
- vitramir 8mo agoterraform cloud, argocd, vercel and supabase (modern stack for micro apps), sentry (doesn't have per project permissions), sendgrid, etc... What does your stack look like beyond Kubernetes and AWS? It’s hard to imagine everything there supports truly fine-grained permissions.
- verdverm 8mo agoActually, almost everything stays within the private cloud, health care industry GCP (main), AWS/Azure (b/c customers), Jenkins/Argo TF/Helm are IaC and run from containers, no hashicorp services CloudSQL, why are you sending your db queries to a SaaS? LGTM for observability The vendors we do have are WIF'd (i.e. code & secops scanning) WIF is the key, mature vendors are supporting WIF, and amazingly the hyperscalers are supporting each others WIFs for cross-cloud, so we can give a GCP SA, AWS perms and vice versa