|
AWS FOR THE REAL WORLD
⏱️
Reading time: 10 minutes
🎯
Main Learning: Wildcards come from the tooling, not from laziness. Put least privilege at the account level
and let an agent write the policies.
Hey Reader 👋🏽 I have shipped my share of s3:* at unusual hours and told myself I would refactor it later - which obviously never happened 😅 So when someone on r/aws asked why developers can't write least privilege policies and put it down to laziness, I was excited to read through all of the comments. They just explain what it actually costs to avoid them: one denied action at a time, ten minutes per deploy, and a deadline that doesn't move - very relatable, especially if you use CloudFormation in any way 😬 In this issue: the five reasons the thread brought up, where the OP still has a point, and the setup I use instead 🫡 Sponsored by Typesense, a tool we run ourselves.
That's it for this issue. If you take one thing away: stop paying the least privilege cost per role. Put the hard boundary at the account level with separate accounts and SCPs, and let your IaC and your agent write the scoped grants. And read what comes out. A policy nobody reviewed is not least privilege, no matter who typed it 😅 See you in the next one! Sandro & Tobi |
We teach AWS for the real world - not for certifications. Join more than 10,500 developers learning how to build real-world applications on AWS.
AWS FOR THE REAL WORLD ⏱️ Reading time: 10 minutes 🎯 Main Learning: Every convenience layer AWS built on ECS is dead or dying, while ECS itself has not changed since 2014. Build on the primitive, and make the layer above it prove itself first. 📝 Blog Post Hey Reader 👋🏽 Getting started with an AWS service often feels more complicated than it should. Four concepts must be understood before a single container runs. A VPC is required before a single request. So, the fancy CLI that promises to do...
⏱️ Reading time: 21 minutes 🎯 Main Learning: Same CloudFront logs: 12.5s through Kinesis, S3, Glue and Athena, about 1s through Tinybird's managed ClickHouse. 📝 Blog Post Hey Reader 👋🏽 We've been running Plausible for the analytics on awsfundamentals.com. Good software, no complaints. We still wanted the data to be ours: our retention, our schema, nobody's script in the visitor's browser. So we built the dashboard ourselves. Twice, on two different backends, fed by the same CloudFront logs....
AWS FOR THE REAL WORLD ⏱️ Reading time: 11 minutes 🎯 Main Learning: A Karpenter NodePool is a placement policy, not an instance preference. Pin one instance family, and a Spot shortage moves your fleet across availability zones, where every internal call starts costing $0.01 per GB. 📝 Blog Post Hey Reader 👋🏽 Important off topic things first: Sandro got married! 🎉We were in Munich for it and it was a fantastic day! ☀️Highly recommend a wedding over sprint planning or fighting with AWS...