Live data from Hacker News

Cleaning Up Dead Bodies in AWS IAM

noq.dev

21–30 of 69 posts

Re: Cleaning Up Dead Bodies in AWS IAM

#21
post #10

Earlier quoted context omitted.

If I’ve learned anything, the only people who care about doing things are at the very, very bottom. No one up the chain actually cares about doing things. They talk about doing things, present grand slidedecks internally and at conferences about doing things, have project/product/engineering managers constantly planning on doing things and thinking about better/faster ways to do them. But really there’s an entire pyr…

You guys have it so wrong. Their job is to get you to do things. With slide decks. Presentations. Speeches. Roadmaps. Stories. Visions. Carrots. That’s their job. As well as to aggregate the litany of statuses into an über status at the end of the week/month/quarter so that their higher ups see work being done. What they do is different from what you do so you only see them not doing what you’re doing, not what they…

In a working org you are right.

In many orgs measurement of work takes precedence over actually achieving work.

Re: Cleaning Up Dead Bodies in AWS IAM

#22
post #13

Earlier quoted context omitted.

This is the sort of ladder-climbing VP behavior you see from someone who is too concerned about avoiding failures that they don't actually do anything productive. Don't launch any projects in a firm direction because if they fail, it's a failure of commission. Wastes lots of time churning what-if scenarios, blocking things & generating reports no one wants in case he gets asked for them, so he can't be accused of a f…

This comment opened my eyes in a strange way to my boss (dir of infra). This is so on the nose for how he operates it was almost painful to read.

Most folks (certainly not all!) at the Director level and higher by definition spend their entire day talking about work other people are doing rather than doing it themselves. It's the nature of the beast, especially if you operate with a manager only having one or two small (3-6) person teams to manage. You can get a flatter org chart where managers have 15 or 20 direct reports, which makes it impossible for the manager to both be a good manager and GSD, or you can have managers who still GSD but you have so many of them you start to add layers so that the C-level can still do what they need to (get investment, or drive revenue, or strategic partnerships or whatever depending on your scale/stage).

It's depressingly easy to end up in a situation where the line employees are overworked and underpaid, the first level managers are stressed out trying to really manage well their half-dozen direct reports while still producing work themselves, and the Directors and VPs end up passing reports back and forth all day, every day.

Re: Cleaning Up Dead Bodies in AWS IAM

#23
post #9

>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super g…

FWIW I’ve worked extensively in AWS IAM for over a decade and have never heard of half the acronyms in the article. Don’t be intimidated.

My condolences.

Re: Cleaning Up Dead Bodies in AWS IAM

#24

At my last company they asked me to find all the users who no longer needed access to our AWS account, as well as create a report for teams to review if each of their members needed access to the roles they have access to. It took a little bit to understand the IAM model, but I created dozens of reports for a few hundred engineers. Dead users were deleted, but literally nobody reviewed group access with the reports I…

ACLs/Policies (especially the very fine-grained ones used by AWS now) + groups + roles + users + resources

Probably maps to the SAT / NP-complete space. Congrats! Management of security permissions is virtually guaranteed to be non-polynomial.

Re: Cleaning Up Dead Bodies in AWS IAM

#25
post #8

Earlier quoted context omitted.

Acronyms are the worst. I guess people do it to sound cool or something, but I once maintained a legacy project that had an acronym for a name. Not a single person working at the entire company knew what the acronym originally meant, and of course, it was never documented.

Analyst firms (ie Gartner) are a big driver of this too. Couple that with the start up / VC model which needs to create new 'categories' to demonstrate differentiation, and you have a total mess.

I work for a vendor that sells a CNAPP. I've worked with this product before and it's been around for several years.

Until last week, I had never heard or read the term CNAPP.

"CNAPP is a term first coined by Gartner in 2021 to describe an all-in-one platform that unifies security and compliance capabilities to prevent, detect, and respond to cloud security threats. A CNAPP integrates multiple cloud security solutions that have been traditionally siloed in a single user interface, making it easier for organizations to protect their entire cloud application footprint."

Thanks, Gartner. What a racket they have as a self-ordained arbiter of market segments.

Re: Cleaning Up Dead Bodies in AWS IAM

#28
post #26

This website is marketing nonsense. I need to understand the technical underpinnings of it. Why does this help me?

If you don't see how it helps you, you probably don't need it. Either because it's not a problem you have or deal with, or because the site doesn't flag up anything with you.

Re: Cleaning Up Dead Bodies in AWS IAM

#29

>Discover why conventional CSPM/CIEM tools fall short in cleaning up AWS IAM, and explore a better solution with Noq and IAMbic We live in a noun hell where every technical topic has a high barrier to entry that makes it hard to casually learn anything. It's difficult to be even a traditional generalist in this ecosystem, and yet the market treats people as if the only way to be considered valuable is to be a super g…

There is a middle ground, if the author cares enough: the ``[1] and ``[2] markup tags were designed to solve those problems in an unobtrusive way. It makes folks unfamiliar able to hover-over (or long-press, I believe) the dotted underlined terms to know, and stays out of the way for those who already know them

1: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/ab...

2: (evidently deprecated but still parsed) https://developer.mozilla.org/en-US/docs/Web/HTML/Element/ac...

Re: Cleaning Up Dead Bodies in AWS IAM

#30
post #16

Earlier quoted context omitted.

“Getting shit done” is 3D chess we play to convince ourselves there is a goal when it’s just more low effort toil.

Work is work they give me a paycheck to write code. Rather write some code than deal with a chickenshit leader who wants 100 iterations of project plans for work we will never do or generating reports that no one will ever read. Being paid to sit at a computer and not doing real work all day is more torturous than simply having actual tasks and work to do.

[flagged]
Post reply on HN