|
AWS FOR THE REAL WORLD
β±οΈ
Reading time: 10 minutes
π―
Main Learning: Wildcards come from the tooling, not from laziness. Put least privilege at the account level
and let an agent write the policies.
π
Hey Reader ππ½ I have shipped my share of s3:* at unusual hours and told myself I would refactor it later - which obviously never happened π So when someone on r/aws asked why developers can't write least privilege policies and put it down to laziness, I was excited to read through all of the comments. They just explain what it actually costs to avoid them: one denied action at a time, ten minutes per deploy, and a deadline that doesn't move - very relatable, especially if you use CloudFormation in any way π¬ In this issue: the five reasons the thread brought up, where the OP still has a point, and the setup I use instead π«‘ Sponsored by Typesense, a tool we run ourselves.
That's it for this issue. If you take one thing away: stop paying the least privilege cost per role. Put the hard boundary at the account level with separate accounts and SCPs, and let your IaC and your agent write the scoped grants. And read what comes out. A policy nobody reviewed is not least privilege, no matter who typed it π See you in the next one! Sandro & Tobi |
We teach AWS for the real world - not for certifications. Join more than 10,500 developers learning how to build real-world applications on AWS.
AWS FOR THE REAL WORLD β±οΈ Reading time: 6 minutes π― Main Learning: One stack, reused for every project. Hono on Lambda, Postgres with Drizzle, a TanStack SPA on S3 and CloudFront, and Better Auth for login. π Blog Post Hey Reader ππ½we've build a lot of fullstack applications so far: client projects side projects (this one, shopify apps, etc.) example tutorial apps Over the past few years we switched up tech stacks a lot. That taught us what actually matters in a stack and what is just...
AWS FOR THE REAL WORLD β±οΈ Reading time: 11 minutes π― Main Learning: Most teams should stay serverless. EKS only pays off at real scale. π Blog Post Hey Reader ππ½For years we told everyone the same thing: don't run Kubernetes! And we meant it. Running k8s yourself is a second full-time job. Cluster upgrades, etcd backups, some networking plugin that falls over on a Tuesday and nobody can say why.We're serverless people through and through. Lambda first, a queue behind it, scale to zero, go...
AWS FOR THE REAL WORLD β±οΈ Reading time: 12 minutes π― Main Learning: Most of the complaints in the viral "leaving AWS" post are skill issues β but egress pricing is a fair hit. π Blog Post Hey Reader ππ½Recently, a post with the title "I returned to AWS and was reminded why I left" hit 810 upvotes on Hacker News last week and went pretty viral with it.I read it twice before forming an opinion. My honest take: most of the complaints are skill issues! π€·βοΈNevertheless, the post is well written and...