AWS IAM Roles Anywhere - Introduction & Demo | Amazon Web Services

preview_player
Показать описание
IAM Roles Anywhere allows servers, containers, and applications to use X.509 digital certificates to obtain temporary AWS credentials for the same IAM roles and policies that you normally have configured for your AWS workloads.

Important Links

Subscribe:

ABOUT AWS
Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform, offering over 200 fully featured services from data centers globally. Millions of customers — including the fastest-growing startups, largest enterprises, and leading government agencies — are using AWS to lower costs, become more agile, and innovate faster.

#IAM #AWS #AmazonWebServices #CloudComputing
Рекомендации по теме
Комментарии
Автор

This is a very cool feature. AWS is breaking more barrier. This was a requirement at a previous gig. Now with this feature, you can keep your on-premises workload and still use AWS in an hybrid fashion.

olublessed
Автор

I see how this reduces operational complexity, but a genuine question: how does it improve security posture? If the private key is compromised anyone with that key can obtain AWS credentials until the certificate expires, or until it's known that it was compromised, and the cert is added to the x509 certificate revocation list. Given that you would protect your long-term access keys in the same way you would protect your private key, is the risk not the same?

MattVanStone
Автор

while this is a great feature, many companies will not be able to afford $400/month private CA cost. this will definitely be a game changer in many organisations.

kavyeshs
Автор

What would be session life in this case, dose it carries max session duration of respective iam role or infinite?

ShirishShukla