AWS re:Invent 2016: Become an AWS IAM Policy Ninja in 60 Minutes or Less (SAC303)

Поделиться
HTML-код
  • Опубликовано: 7 фев 2025
  • Are you interested in learning how to control access to your AWS resources? Have you ever wondered how to best scope down permissions to achieve least privilege permissions access control? If your answer to these questions is "yes," this session is for you. We take an in-depth look at the AWS Identity and Access Management (IAM) policy language. We start with the basics of the policy language and how to create and attach policies to IAM users, groups, and roles. As we dive deeper, we explore policy variables, conditions, and other tools to help you author least privilege policies. Throughout the session, we cover some common use cases, such as granting a user secure access to an Amazon S3 bucket or to launch an Amazon EC2 instance of a specific type.

Комментарии • 21

  • @WilsonMar1
    @WilsonMar1 6 лет назад +11

    This is why this guy is a Ninja and this presentation delivers the goods:
    [1:56] "In my nearly 5 years at Amazon, I carve out a little time each day, each week to look through the forums, customer tickets to try to find out where people are having trouble. I try to solve those same problems myself"

  • @lxp
    @lxp Год назад

    Loving this guy's humour.

  • @JulesMorrison
    @JulesMorrison 7 лет назад +1

    If you want to decode the quoted string output near the end, jq is your friend. Run it through once with a selector to get the raw string, and then a second time to pretty-print it.

  • @rawadrifai3451
    @rawadrifai3451 5 лет назад

    This is the OG Ninja indeed.

  • @gsashee
    @gsashee 6 лет назад +2

    In the "Limited Admin" sample, the admin has access to the iam:ChangePassword action for all resources. What prevents him to change the "true" administrator's password and gain full admin rights to the account?

  • @layer4down
    @layer4down 7 лет назад +2

    Very helpful indeed

  • @wysefavor
    @wysefavor 6 лет назад +1

    how do one create IAM policy to enforce tags whenever any new resources are created in AWS ?
    it can be automated using IAM policy right ?

  • @yaswanthvema4314
    @yaswanthvema4314 5 лет назад

    Could you explain roles and responsibilities for AWS Administrator

  • @reesezl
    @reesezl 7 лет назад

    Very good one!

  • @adrienloridan
    @adrienloridan 5 лет назад

    20 minutes after reading the documentation, I think i finally understood why this iam policies do not work : ec2:RunInstances api action is called when you are launching an instance, it creates multiple ressources like "Key pair", "Network interface" which dont have the ec2:InstanceType condition key, so the launch failed. docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-supported-iam-actions-resources.html docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html

  • @shashankranganath5745
    @shashankranganath5745 6 лет назад

    How do i download the presentation ? Can anyone provide the link ?

    • @vijayshreenivos9417
      @vijayshreenivos9417 6 лет назад

      www.slideshare.net/AmazonWebServices/aws-reinvent-2016-become-an-aws-iam-policy-ninja-in-60-minutes-or-less-sac303

  • @ChristopherNeill
    @ChristopherNeill 5 лет назад

    Why not just open up incognito windows?

  • @carloslugo712
    @carloslugo712 7 лет назад

    How can I get this powerpoint from video?

    • @vijayshreenivos9417
      @vijayshreenivos9417 6 лет назад +2

      www.slideshare.net/AmazonWebServices/aws-reinvent-2016-become-an-aws-iam-policy-ninja-in-60-minutes-or-less-sac303

  • @ahamedrifath5220
    @ahamedrifath5220 7 лет назад

    how to download aws credentials in csv format?

  • @staj
    @staj 7 лет назад +2

    Thanks a lot Jeff, Best re:invent video i've watched so far. Very well done Sir!!!

  • @alecwhitehouse3959
    @alecwhitehouse3959 5 лет назад

    Great session, but needs a more personable intro. :)

  • @muke5hy
    @muke5hy 7 лет назад +3

    I felt little rudeness at the start :(

    • @Guest-gy9vp
      @Guest-gy9vp 7 лет назад

      The same

    • @lxp
      @lxp Год назад +1

      Isn't he joking that there are so few people there?