Website down…?
Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
11–20 of 33 posts
Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#12Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#13[0]: https://docs.aws.amazon.com/IAM/latest/UserGuide/access-anal...
Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#14See also: https://github.com/puresec/serverless-puresec-cli
Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#15Could you expand on how this compares to IAM's built-in Access Analyzer[0]? [0]: https://docs.aws.amazon.com/IAM/latest/UserGuide/access-anal...
Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#16Could you expand on how this compares to IAM's built-in Access Analyzer[0]? [0]: https://docs.aws.amazon.com/IAM/latest/UserGuide/access-anal...
Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#17Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#18How would you compare your offering to https://github.com/iann0036/iamlive (an opensource implementation of IAM generation from client-side monitoring or proxy, released in Feb 2021)?
Re: Launch HN: Slauth.io (YC S22) – IAM Policy Auto-Generation
#19This is... Not a useful number of policies. I've got a terraform setup for my one person business and I probably have two orders of magnitude more policies than this.
Who is this targeted at? Which policies am I supposed to use these three on? What kind of service only has three policies? How am I supposed to evaluate your service with this small number of policies? The problem is that they might be the "perfect" global maximum goodness policies, but they exist in a web of policies that all need to be correct together. So three does nothing to show me how good your service is, and it's not useful (afaict) for ongoing work.
Here's how I can see you fixing this:
- Just charge me. Give me a trial. Let me pay up front and have a money back policy. Let me generate what I need and see whether it's useful.
- Give me unlimited free policies, but charge for things like tightening down resource access (e.g., narrowing access to specific S3 buckets instead of just narrowing access to S3).