Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jon918
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
jon918
3y ago
Great point on doing things through PRs not clickops. As your practices mature, the need for approvals can shift from the care and feeding of your infrastructure to managing risk. Even with IaC in place, having controls around who can acces
2.
▲
by
jon918
3y ago
Thanks so much for the feedback! > I was thinking of launching an access management project myself. Most access management systems are focused around SSO, and this - due to the SSO tax - is not for every application in a small organizati
3.
▲
by
jon918
3y ago
Thanks - we’ve definitely seen Sym help our early customers safely distribute access decisions. Because the flows are managed in code, teams also get visibility into how these rules are defined and can contribute to improving them, as well
4.
▲
by
jon918
3y ago
Hey I’m Adam’s co-founder, we’d love feedback from the HN community on what we’ve been working on!
5.
▲
by
jon918
4y ago
Author here, I went out on a limb and framed an argument for better approaches to cloud access management using the structure of the paper where Alan Turing introduced the Turing Test.
6.
▲
The Authorization Game
(blog.symops.com)
5 points
by
jon918
4y ago
|
1 comments
7.
▲
by
jon918
4y ago
Itching for the follow up on how how to use organization-based conditions to make things simpler.
8.
▲
by
jon918
6y ago
This is cool, I like the practicality and flexibility of being able to work with the data in Google Sheets without having to do any manual syncing.
9.
▲
by
jon918
7y ago
I wrote a follow up post to this on SSH tunneling: https://news.ycombinator.com/item?id=22665037
10.
▲
by
jon918
7y ago
This is a follow up to last week's post on session manager, a bunch of people had questions on SSH tunneling. Last week's post: https://news.ycombinator.com/item?id=22592875
11.
▲
AWS Session Manager: SSH tunnels with less user management
(blog.symops.io)
15 points
by
jon918
7y ago
|
2 comments
12.
▲
by
jon918
7y ago
Good call to watch out for this stuff. The examples in the repo we set up use the AmazonSSMManagedInstanceCore managed policy, which does not grant any S3 permissions, just various ssm, ssmmessages, and ec2messages permissions.
13.
▲
by
jon918
7y ago
You can do this but it depends on your setup as to how. If you have AWS IAM users (not federated), then you can use MFA conditions in your policies as documented here: https://docs.aws.amazon.com/IAM/latest/UserGui
14.
▲
by
jon918
7y ago
Yeah, this is the same deal. Session Manager will log your sessions which is pretty cool.
15.
▲
by
jon918
7y ago
It does work with hardware tokens, IF you get your AWS IAM credentials using a hardware token. If you're using AWS IAM users then here are instructions: https://docs.aws.amazon.com/IAM/latest/UserGuide/id
16.
▲
by
jon918
7y ago
Cool, will do!
17.
▲
by
jon918
7y ago
I'd love to learn how you're using Session Manager or what other features/integrations you'd like to see us explore. Also if the terraform module packaging is useful. There are additional Session Manager features like po
18.
▲
AWS Session Manager: less infrastructure, more features
(github.com)
199 points
by
jon918
7y ago
|
48 comments
19.
▲
by
jon918
7y ago
This is an example we've been working that creates an Okta-managed user who can get in to a tagged EC2 instance using Session Manager. No bastion/sshd/security group ingress rules required. https://github.com/