📢 MAMIP (Monitor AWS Managed IAM Policies)
Policies changed since last week:
- AWSApplicationMigrationReadOnlyAccess
- AWSApplicationMigrationVCenterClientPolicy
- AWSGlobalAcceleratorSLRPolicy
- AdministratorAccess-Amplify
- AmazonDevOpsGuruServiceRolePolicy
- AmazonRedshiftAllCommandsFullAccess
- AmazonRekognitionCustomLabelsFullAccess
- AmazonRekognitionReadOnlyAccess
- CloudWatchApplicationInsightsFullAccess
Get notified of policy change using this Twitter bot. 🐦

No more making Lambda@Edge functions just to add HTTP headers to CloudFront.
github.com/aws/aws-sdk-go…


I think there's no need for AWS IAM users today. So I made a PoC to "prove" it. First here are the general use-cases for creds
* AWS SSO works great for humans 👍
* Roles work fine inside AWS 👍
* Federation works fine from other clouds 👍
* Raspberry Pi in your closet ❓
1/4

Semgrep 0.70+ now supports scanning Terraform source files (HCL) for misconfigurations and security flaws!
Announcement: r2c.dev/blog/2021/semg…
16 built-in rules: github.com/returntocorp/s…
I will add it to the blog post shortly


Just blogged: Shifting Cloud Security Left — Scanning Infrastructure as Code for Security Issues
Includes a comparison of Terraform static analysis tools and tips for integration in CI/CD pipelines!
blog.christophetd.fr/shifting-cloud…


Proof @QuinnyPig has a favorite and it's @AWSIdentity!


🦫 Meet Ottr: A Serverless Public Key Infrastructure Framework
New open source tool by @Airbnb
Handles end-to-end certificate rotations without the use of an agent
Source code:
github.com/airbnb/ottr
medium.com/airbnb-enginee…


🤔 pwru: Packet, where are you? @ciliumproject
An eBPF-based tool for tracing network packets in the Linux kernel with advanced filtering capabilities
Allows fine-grained introspection of kernel state to facilitate debugging network connectivity issues
github.com/cilium/pwru

re:Invent talk is out for editing!
A least-privilege journey: IAM policies & Access Analyzer
1⃣1⃣ policy pro-tips
8⃣ full policies
6⃣ pics of Pickles
Looking forward to covering fun stuff: conditions, multi-value conditions, cross account, PassRole & everything Access Analyzer

anyway tl;dr here it is. Really keen to hear from folks what I haven't considered. I genuinely can't think of any use cases for IAM users now.
github.com/aidansteele/cl…

Committing my AWS access keys on GitHub just to feel something

"AWS’ temporary event account solution, but the 72 hour expiration policy..." Hold up, AWS provides a mechanism for temporary accounts, but you can only get access to it by hosting remote controlled car competitions?!?

AWS DeepRacer introduces multi-user account management
With a multi-user account set up, organizers (aka Account Administrators) can now provide racers access to the AWS DeepRacer service under their account ID, monitor spending on training and sto... aws.amazon.com/about-aws/what…
I recently started at an org that exploded in growth over a short time, and was presented with an unusual (and unexpected) ... "challenge."
- There is only one AWS account in the organization, and it is the management account. Everything, dev, staging, prod, is deployed in this account.
- 300+ IAM …
Hey everyone, I've been dealing with this situation for 2 weeks now and would appreciate any advice on how to handle this. On Oct 21, my account was hacked and AWS Support granted the intruder access to remove service limits on the account, even though this person was from Japan …
- 🖊️ This newsletter was fwd to you? Subscribe here
- 💌 Want to suggest new content: contact me or reply to this email
- ⚡️ Powered by Mailbrew
- 🐦 Follow me on Twitter or hire me.