| ▲ | chaos_emergent 2 days ago | |
What’s the value of having a ton of silo’d accounts, especially for the use case demonstrated by the readme where there are multiple staging and production accounts? | ||
| ▲ | thedougd 2 days ago | parent | next [-] | |
Blast radius. One example… What happens when you give an identity s3:* on resource: *? It can read/modify every bucket in the account that doesn’t have a resource policy with an explicit deny. | ||
| ▲ | casper14 2 days ago | parent | prev | next [-] | |
This is not super uncommon, especially when selling to enterprises who demand complete data isolation. | ||
| ▲ | 0hardik1 2 days ago | parent | prev [-] | |
[dead] | ||