Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update broker to use parameterized IAM group policy #252

Open
markdboyd opened this issue Sep 29, 2022 · 2 comments
Open

Update broker to use parameterized IAM group policy #252

markdboyd opened this issue Sep 29, 2022 · 2 comments

Comments

@markdboyd
Copy link
Contributor

In order to reduce the number of IAM users created/managed by the broker, the broker should have a parameterized group policy and add the user/role to that group instead of the broker making an individual policy for each instance.

Recommendation came out of security consulting from AWS. See the meeting notes

POC

Ask @rbogle for further details if necessary

@pburkholder
Copy link
Contributor

Should this be included with broader AWS security recommendations issue?

@markdboyd
Copy link
Contributor Author

@pburkholder Yes, it is tracked in that epic: https://github.com/cloud-gov/private/issues/1204

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants