16 ms·
Still not sure how that helps. In both cases, we have creds embedded in the app which can be used (and only used) for access to the AWS resource. In one case d
by jbert 13y ago
Still not sure how that helps. In both cases, we have creds embedded in the app which can be used (and only used) for access to the AWS resource.
In one case directly (via an IAM limited account), in another via a token they can request. In both cases, the acct is limited to one specific AWS resource. In both cases, the creds can be revoked centrally. In both cases the creds are embedded in the app.
Smart people who build these things (AWS) seem to think a TVM is a better solution. I don't understand why.