[AWS - DA] Advanced Identity
AWS identity Advanced DA
2023-09-14 08:59:12 时间
AWS STS - Security Token Service
- Allows to grant limited and temporary access to AWS resource (up to 1 hour)
- AssumeRole: Assume roles within your account or cross account
- GetSessionToken: for MFA, from a user or AWS account root user
- DecodeAuthorizationMessage: decode error message when an AWS API is denied
- AssumeRoleWithSAML: return credentials for users logged with SAML
- GetRederationToken: obtaini temporary creds for a federated user
- GetCallerIdentity: return details about the IAM user or role userd in the API called
STS with MFA
- User GetSessionToken from STS
- Appropriate IAM policy using IAM conditions
- aws:MultiFactorAuthPresent: true
- Reminder, GetSessionToken
- return:
- AccessID
- Secrect Key
- SessionToken
- Expiration date
IAM Policies & S3 Bucket Policies
- IAM Policies are attached to user, roles, groups
- S3 Bukcet Policies are attached to bucekts
- When evaluating if an IAM Principal can perform an operation X on a bucket, the union of its assigned IAM policeis and S3 bucket policies will be evaluated
相关文章
- 黑客通过 BGP 劫持亚马逊AWS 256 个 IP:窃取了价值 168 万的加密货币
- Matano:一款针对AWS的开源安全湖平台
- AWS正尝试使用ChatGPT;BuzzFeed也因使用ChatGPT致股价上涨3倍;理想吉利纷纷重仓智能化丨每日大事件
- 2022 H1中国公有云服务市场:阿里云、华为云、腾讯云、天翼云、AWS排名前五
- 从AWS自研交换机的初心看背锅侠的未来
- AMD专访:收购Pensando不是为了AWS,但是Chiplet可以搞起来
- ORA-47045: Identity string for Factor string is used by one or more identity maps. ORACLE 报错 故障修复 远程处理
- MySQL Error number: MY-011431; Symbol: ER_KEYRING_AWS_FAILED_TO_GENERATE_KEY_DUE_TO_INTERNAL_ERROR; SQLSTATE: HY000 报错 故障修复 远程处理
- MySQL Error number: MY-011440; Symbol: ER_KEYRING_AWS_FAILED_TO_RE_ENCRYPT_KEY; SQLSTATE: HY000 报错 故障修复 远程处理
- Amazon AWS云服务常见问题解答(AWS云架构师面试必备)架构师
- MongoDB的Atlas扩展了对AWS的服务详解大数据
- AWS 采用自制的 KVM 作为新的管理程序
- 狼来了!AWS宁夏区域可能6、7月份投入运营
- 硬核观察 #357 ElasticSearch 继续对抗亚马逊 AWS 的开源分叉
- 数据库使用AWS连接本地MySQL数据库(aws调用本地mysql)
- AWS快速拉取MySQL日志,轻松管理日志记录(aws拉取mysql日志)
- 云服务器上MySQL的迁移AWS解决之道(aws mysql 迁移)
- 使用AWS管理MySQL,了解相关费用支出(aws mysql 费用)
- 在AWS上搭建MySQL数据库系统的中文化指南(aws mysql 中文)
- 利用AWS拉取MySQL日志,轻松掌控数据安全(aws拉取mysql日志)
- Redis实现从AWS迁移简化(redis迁移aws)