Tuesday, June 21, 2022
HomeCyber SecurityDownside with sharing AWS Parameters Cross-Account | by Teri Radichel | Bugs...

Downside with sharing AWS Parameters Cross-Account | by Teri Radichel | Bugs That Chunk | Jun, 2022


An excessive amount of context switching

I’ve a multi-account AWS setup the place my accounts are devoted to sure duties. It’s simpler to compartmentalize permissions and outline belief boundaries this manner.

The issue with sharing AWS Techniques Supervisor Parameter Retailer parameters is that I can’t merely grant entry to a parameter utilizing a useful resource coverage and IAM coverage and entry it through an ARN like I can do with KMS.

As an alternative, I’ve to imagine a task within the different account to get the worth, then exit the assume position to proceed processing my script.

I discussed in different posts how I create an AMI in a central account. I retailer the newest AMI ID in a parameter. Now I wish to entry that AMI ID from my builder account.

I’ve to imagine a task within the AMI account, and I don’t actually need that builder position to have any permissions within the AMI account in any respect.

Then I’ve to unset my variables to imagine the position to modify again to the builder account.

Then I’ve to imagine a task within the account the place I wish to construct the sources.

Until I missed one thing, on the time of this writing, you may’t simply reference the parameter with an ARN.

Function request: AWS System Supervisor Parameter Retailer parameters ought to work like KMS Key ARNs with IAM insurance policies and useful resource insurance policies.

If this helped you otherwise you had this downside, please clap!

Teri Radichel — Observe me @teriradichel on Twitter

© 2nd Sight Lab 2022

____________________________________________

About this weblog:

Need to be taught extra about Cybersecurity and Cloud Safety? Take a look at: Cybersecurity for Executives within the Age of Cloud on Amazon

Want Cloud Safety Coaching? 2nd Sight Lab Cloud Safety Coaching

Is your cloud safe? Rent 2nd Sight Lab for a penetration take a look at or safety evaluation.

Have a Cybersecurity or Cloud Safety Query? Ask Teri Radichel by scheduling a name with IANS Analysis.

Cybersecurity & Cloud Safety Assets by Teri Radichel: Cybersecurity and Cloud safety courses, articles, white papers, displays, and podcasts



RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments