Guardrails Using AWS Organizations and Terraform

preview_player
Показать описание
AWS Organizations is relatively new, having been released in 2017. The evolution from simply being consolidated billing to security controls seemed like a natural progression. In 2021 Organizations is one of the best tools in your arsenal to protect accounts. In this talk we’ll explore the pros and cons of using a feature in AWS Organizations called SCPs ( Security Control Policies ).

SCPs are the most restrictive and broadest net we can cast with regard to the usage of APIs in the AWS control plane. We’ll look to understand how SCPs work, the tooling to configure them, and finally why Terraform is the best option we have to craft these policies. Attendees will leave with a firm understanding of the trade offs as well as a set of recommendations on why they should consider employing this model.

Key Takeaways
- What is AWS Organizations and Multi Account
- How can you use terraform to create guardrails
- Understand why Terraform is an excellent approach to creating SCPs

-

HashiCorp is the leader in multi-cloud infrastructure automation software. The HashiCorp software suite enables organizations to adopt consistent workflows to provision, secure, connect, and run any infrastructure for any application. HashiCorp open source tools Vagrant, Packer, Terraform, Vault, Consul, Nomad, Boundary, and Waypoint are downloaded tens of millions of times each year and are broadly adopted by the Global 2000. Enterprise versions of these products enhance the open source tools with features that promote collaboration, operations, governance, and multi-data center functionality.

Twitter: @hashicorp
Рекомендации по теме