Hacker News new | past | comments | ask | show | jobs | submit login

These recommendations are great, and for us the direction is definitely everything on roles. I was curious to see what others do concretely.



We have both out of necessity. IAM policies on roles/users/groups are a given, but here are some concrete examples of what we're using resource policies for:

- Granting cross-account access to resources without requiring an explicit sts:AssumeRole on the other side (in some cases for things like CloudTrail and billing reports this is the only option)

- Enforcing SSE on S3 buckets (implemented as a DENY in the bucket policy with conditions to check for missing SSE headers)




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: