Do you have an S3 bucket or DDB table with your companies crown jewels? ππ Now IAM Access Analyzer tells you all the users and roles in your organization that have access to them gems. π§΅ (1/8)
17.06.2025 14:40 β π 10 π 2 π¬ 1 π 1
AWS IAM updates last week:
- SecurityAudit got an update π₯³ mostly S3 tables
- network-firewall getting flow operations
- route53-recovery-control-config (???) getting resource policies
I'm still not sure why every week there seem to be version updates to some policies, but without actual changes?!
31.03.2025 21:33 β π 0 π 0 π¬ 0 π 0
Are you doing the refactor yourself, or just getting a new context window to do it?
I've had good results getting Claude to write the tests, then it's easier for me to refactor (it loves if/else statements more than I do) without regressions.
27.03.2025 20:45 β π 0 π 0 π¬ 1 π 0
Vibe coding digrams #FAIL
GenAI remains a key part of my daily workflow, but it feels like I'm running in to more limitations - anyone else?
In this case, the LLM kept trying the same thing, even though it detected there was a problem with it (very neat!)
26.03.2025 19:19 β π 1 π 0 π¬ 1 π 0
As more "stuff" gets made (code/blogs/etc) by AI, don't underestimate the power of giving presentations/speaking to advance your career!
Speaking at meetups and conferences has given me such a high ROI for the effort, and it gets easier the more you do it!
26.03.2025 06:48 β π 0 π 0 π¬ 0 π 0
GitHub - PatMyron/cloudformation-resource-providers: automated monorepo of public CloudFormation AWS resource providers
automated monorepo of public CloudFormation AWS resource providers - PatMyron/cloudformation-resource-providers
Having access to the actual resource providers that CloudFormation uses to provision resources has saved me a few times!
This is repo is a great compilation by Pat Myron
Just remember, if you use CDK, you use CloudFormation too π
25.03.2025 09:48 β π 0 π 0 π¬ 0 π 0
Interesting (maybe) AWS IAM action/policy updates from last week (ending 23/3):
- deeplens gone πͺπ€
- cleanrooms gets protected (?) jobs
- connect gets data lake integration
15 separate updates detected this week, which is more than usual, but not to show for it...
24.03.2025 11:19 β π 0 π 0 π¬ 0 π 0
Here's my dependency diagram for YourPublic.Cloud
Each one of these is its own AWS CloudFormation stack, with its own deployment, tests, etc
The complexity of SaaS is π€― no wonder it took me so long... and it's not finished yet!
21.03.2025 03:46 β π 0 π 0 π¬ 0 π 0
Anyone here actually HAPPY with how their company is using GenAI/LLMs today?
I heard on a podcast that ~50% of people use AI in their work, but only ~7% of companies... and that just doesn't add up! π
Do you have a good approach? If so, share it with us please! π
20.03.2025 09:48 β π 0 π 0 π¬ 0 π 0
GitHub - aws-samples/aws-cross-account-break-glass-example
Contribute to aws-samples/aws-cross-account-break-glass-example development by creating an account on GitHub.
How do you do break glass access on AWS?
I saw this example repo from AWS, but I wonder what other solutions people are using...
What do you do if your IdP or Identity Center goes down?
18.03.2025 23:48 β π 0 π 0 π¬ 0 π 0
Interesting AWS IAM action updates from last week:
- Bedrock gets prompt routing
- Support will allow starting and getting interactions
- Batch will get consumable resources (?)
- Can't set challenge questions for your account anymore
It's not often you see IAM actions removed, but it can happen!
17.03.2025 23:11 β π 0 π 0 π¬ 0 π 0
Early bird sponsorship for AWS Community Day Australia 2025 is only available for another week!
It's on August 15 in Brisbane.
A bunch of sponsorship packages have already been sold, so if you want to get the best price reach out ASAP!
awscommunitydayaus.com/
17.03.2025 02:37 β π 1 π 0 π¬ 0 π 0
And the winner of the Longest AWS Service Name Award goes to... AWS Chatbot! π€
12.03.2025 02:07 β π 2 π 0 π¬ 1 π 0
Bitten by a subtle async bug today, and Claude.ai saved me
Using the array index notion on what would *eventually* be an array was instead trying to access the Promise object... and failing silently π€¦ββοΈ
It didn't pick it up until I asked very specifically about this logic, but the answer was spot on
11.03.2025 10:26 β π 0 π 0 π¬ 0 π 0
And to keep being updated by changes on AWS IAM Managed Policies, please consider following @mamip.bsky.social βοΈ
10.03.2025 09:19 β π 1 π 1 π¬ 0 π 0
Interesting AWS IAM policy & action updates from last week:
- New iotmanagedintegrations action namespace
- New gameliftstreams action namespace
- CloudWatch RUM getting resource policies soon
- AWSFaultInjectionSimulatorECSAccess new version, but only the CreateDate changed? π€¨
10.03.2025 09:07 β π 1 π 0 π¬ 1 π 0
Safe.eth on X: "Investigation Updates and Community Call to Action" / X
Investigation Updates and Community Call to Action
New details on the ByBit/Safe{Wallet} breach, and uhhh wow, some really silly blunders on the DPRK side. They still succeeded which is the most upsetting part of all of this. Let's bully some threat actor tradecraft! Aπ§΅
x.com/safe/status/...
06.03.2025 17:21 β π 23 π 12 π¬ 1 π 2
Shout out to Brigid Johnson for one of the best explainers of AWS Resource Control Policies (RCPs) out there!
Eventually I'll have time to go through the docs in detail π
06.03.2025 06:26 β π 0 π 0 π¬ 0 π 0
www.reddit.com/r/aws/commen...
05.03.2025 02:26 β π 0 π 0 π¬ 0 π 0
How did you learn to use AWS?
This thread made me realise I was lucky - I learnt AWS when there were only a few services (not even IAM!)
I guess there's got to be *some* upside to getting old π΄
05.03.2025 02:26 β π 0 π 0 π¬ 1 π 0
I wanted one scan per day (for free accounts - paid get more), but I also want to fail reports that take too long.
Unfortunately I used the same interval for both checks, so a report would be PENDING up until the interval, then it would be marked FAILβED.
Super.
Efficient.
Fail.
#buildinpublic
04.03.2025 11:26 β π 0 π 0 π¬ 0 π 0
Interesting AWS IAM policy updates from last week:
* New qdeveloper action namespace (no API yet)
* bedrock invocation and session actions
* Backup Search Operator managed policy
* cloudshell gets ApproveCommand
* SageMaker Studio gets more Bedrock specific managed policies
03.03.2025 02:00 β π 0 π 0 π¬ 0 π 0
Thanks! That's definitely been the #1 answer
02.03.2025 06:22 β π 0 π 0 π¬ 0 π 0
I broke my sign ups last week π₯
How are people doing end-user/E2E testing in production?
I need recommendations!
28.02.2025 02:50 β π 0 π 0 π¬ 1 π 0
Centralize root access for member accounts - AWS Identity and Access Management
Learn how to secure the root user credentials of your AWS accounts managed using AWS Organizations.
Quick AWS security win:
Step 1) Enable privileged root actions
Step 2) Delete the root credentials for all your member accounts
Step 3) Sleep better at night π΄
27.02.2025 05:23 β π 0 π 0 π¬ 0 π 0
I've got limited space for another short-term/async consulting client.
I specialise in AWS IAM and security reviews, keeping cost and compliance on AWS under control, and building serverless solutions to business problems.
If you need help on AWS, let me know!
26.02.2025 09:03 β π 0 π 0 π¬ 0 π 0
I'm thinking about running another workshop: For beginners, covering ALL the different AWS policy types (I'm looking at you, Resource Control Policies!) with plenty of service-specific examples.
Let me know if that's interesting to you, or tag someone who might be!
25.02.2025 11:04 β π 1 π 0 π¬ 0 π 0
Always check the scale!
I made an AWS IAM permissions error in my Lambda function that broke signups.
If I can still get it wrong after writing awsiamguide.com, then anyone can...
24.02.2025 08:03 β π 0 π 0 π¬ 0 π 0
Cloud Therapist @hashicorp
AWS Hero
Co-Host of vBrownBag
We rise by lifting others
Fearlessly Stupidβ’ π€£
https://linktr.ee/mistwire
writer @ Core Memory β’ my two accomplishments here are that i invited AOC and i started the first-ever Hellthread β’ signal: kylie.111
I build stuff, sometimes AI builds stuff for me.
I tweet whenever AWS updates its Managed Policies. Occasionally, I might spoil a surprise for you.
Bootstrapper, software developer, poker player.
Founded 2005: HelpSpot
Founded 2014: LaraJobs (@larajobs.com)
Founded 2025: Outro (@outro.fm)
CoHost: Mostly Technical Podcast (@mostlytechnical.com)
Artsy photos: https://www.instagram.com/ianlandsman/
AWS Serverless Hero π (thoughts are my own) -
https://www.serverlessadvocate.com/
Award-winning consultancy, empowering SaaS teams to deliver more on AWS. We're an AWS Advanced Consulting Partner, and a Kubernetes Certified Service Provider. Part of Ten10.
Cofounder at Freeman & Forrest, author, cartoonist, and Pwnie Award-winning songwriter. Ex-Google. Here to help.
Independent AI researcher, creator of datasette.io and llm.datasette.io, building open source tools for data journalism, writing about a lot of stuff at https://simonwillison.net/
Snarkmonger. Chief Cloud Economist at The Duckbill Group.
he/him.
Get my opinionated take on AWS news: http://lastweekinaws.com/t/
Signal: 833-AWS-BILL (833-297-2455)
Your Friendly Cloud Antagonist
Proficient at drawing the rest of the π¦
Cloud and container security β’ Security research and open source at Datadog
π¨ππ«π·
https://christophetd.fr
Aging security nerd, Brooklyn resident, recovering Twitter addict (and we all know this isn't helping)
An open source encyclopedia of offensive security techniques that can be used in cloud environments. Created and maintained by @frichetten.com
Creator of Detection Engineering Weekly (https://detectionengineering.net), Sec Research/Intel/Detection @ Datadog
Security Researcher @ Datadog. πΆ Head in the (Azure) clouds.
Sometimes blogging, always curious. Aim to be, rather than to seem.
Blogs at https://kknowl.es.
βοΈπΉπ¨βπ©βπ§βπ§
Hardening for food. Open Source, Cloud and Security. Giving π€ to Prowler since 2016. Linux, DFIR, CISSP, Heavy Metal. Del Atleti. http://prowler.com
Security Research and Advocacy @ Datadog. Former Principal and Cloud Penetration Testing lead @BishopFox. I like to build, break, learn, and share. β©CloudFox, CloudFoxable, BadPods, IAM Vulnerable