Live data from Hacker News

An AWS account just for getting into other AWS accounts

src-bin.com

101–109 of 109 posts

Re: An AWS account just for getting into other AWS accounts

#101
post #99
post #98

Earlier quoted context omitted.

It's impolite to assume on someone's behalf in public. Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...? You seem to have a really hard time grasping that this entire comment thread we are part of wouldn't exist if OP had reached out about their concerns in private.

And yet you haven't sent me any emails, hatware. My door is always open, why not practice what you preach rather than be repeatedly harsh and make a scene over existing community norms? Crowley subsequently disclosed the affiliation, we're good. Maybe you're newer here; It's a courteous social more of the HN community to be actively transparent about potential conflicts of interest. I'm actually a fan of Crowley, he'…

You get what you give. I don't think I need to send emails to the one who has no problem calling others out in public.

It's pretty simple, I requested that concerns about conflict of interest are taken offline. But, here you are, making snide remarks in public at another person. Zero for two.

For what it's worth, I spoke up on this because I would be quite annoyed if someone did not give me the courtesy of correcting a mistake in private before broadcasting publicly about it. It doesn't matter if it comes from a stranger or a trusted friend. I can tell you aren't picking this up, but I'm happy to explain it ad nauseum so you can be a better individual to your peers.

>It's a courteous social more of the HN community

From what I can tell, the "norm" is to gang up on new folks without thinking critically about it. It's reddit with less complexity and more ego.

You get what you give.

> why not practice what you preach

From your profile: "I subscribe to the ideology of live and let live."

...

Re: An AWS account just for getting into other AWS accounts

#102
post #100
post #98

Earlier quoted context omitted.

It's impolite to assume on someone's behalf in public. Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...? You seem to have a really hard time grasping that this entire comment thread we are part of wouldn't exist if OP had reached out about their concerns in private.

> It's impolite to assume on someone's behalf in public. They asked a question, they didn’t state an assumption. And why is it impolite. > Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...? we’re not talking about difficulty, we’re talking about politeness. > You seem to have a really hard time grasping that this entire comment thread we are part of wou…

No post body was provided.

Re: An AWS account just for getting into other AWS accounts

#103
post #99

Earlier quoted context omitted.

And yet you haven't sent me any emails, hatware. My door is always open, why not practice what you preach rather than be repeatedly harsh and make a scene over existing community norms? Crowley subsequently disclosed the affiliation, we're good. Maybe you're newer here; It's a courteous social more of the HN community to be actively transparent about potential conflicts of interest. I'm actually a fan of Crowley, he'…

You get what you give. I don't think I need to send emails to the one who has no problem calling others out in public. It's pretty simple, I requested that concerns about conflict of interest are taken offline. But, here you are, making snide remarks in public at another person. Zero for two. For what it's worth, I spoke up on this because I would be quite annoyed if someone did not give me the courtesy of correcting…

There is a lot of value in the CoI being visible quickly. While with an email there could be an unbound delay in the CoI being visible. And often visibility for such things drops off quite hard.

If 90% of the impressions happen within an hour of the post happening and it takes 2 hours for the CoI being visible, then 90% of people probably weren't aware of it.

Re: An AWS account just for getting into other AWS accounts

#104
post #100

Earlier quoted context omitted.

> It's impolite to assume on someone's behalf in public. They asked a question, they didn’t state an assumption. And why is it impolite. > Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...? we’re not talking about difficulty, we’re talking about politeness. > You seem to have a really hard time grasping that this entire comment thread we are part of wou…

Quoted post unavailable.

That's an awfully impolite accusation

Re: An AWS account just for getting into other AWS accounts

#106

Earlier quoted context omitted.

You get what you give. I don't think I need to send emails to the one who has no problem calling others out in public. It's pretty simple, I requested that concerns about conflict of interest are taken offline. But, here you are, making snide remarks in public at another person. Zero for two. For what it's worth, I spoke up on this because I would be quite annoyed if someone did not give me the courtesy of correcting…

There is a lot of value in the CoI being visible quickly. While with an email there could be an unbound delay in the CoI being visible. And often visibility for such things drops off quite hard. If 90% of the impressions happen within an hour of the post happening and it takes 2 hours for the CoI being visible, then 90% of people probably weren't aware of it.

No post body was provided.

Re: An AWS account just for getting into other AWS accounts

#107

Earlier quoted context omitted.

There is a lot of value in the CoI being visible quickly. While with an email there could be an unbound delay in the CoI being visible. And often visibility for such things drops off quite hard. If 90% of the impressions happen within an hour of the post happening and it takes 2 hours for the CoI being visible, then 90% of people probably weren't aware of it.

Quoted post unavailable.

I regularily don't check emails for hours at a time, and would really apprciate someone publicly "calling me out" if I were to forget disclosing a CoI. And I am sure we could as @dang for how quickly impressions drop off on HN specifically. Reddit is the most similar platform and there, a topic usually is active for a few hours at most, so after that window, the disclosure would be practically useless.

And how is stating a disagreement bullying? You can just disengage if tgis is that unpleasant to you.

Sure, it'd be nicer to privately do it, but IMO in such cases, informing the public is the more important part rather than being nice. (There were no insults, no accusations of it being intentional or such, which I'd personally count as nice enough)

Or do you believe we have to coddle everyone online? (I am being serious, and do not intend to troll, but can see how it can be taken as trolling)

Re: An AWS account just for getting into other AWS accounts

#108

Earlier quoted context omitted.

For enterprises it seems this is already baked-in, ie. when you're a Google Workspace (previously GSuite) user, your project selector has an inherent hierarchy stemming from the domain, ie. example.com -> project1, project2, etc. and, in my limited experience, switching between accounts on the command line is pretty good. But this article still makes a good point about keeping different environments in different silo…

It seems that with isolation between projects on gcloud the number of separate accounts needed is less, which is good because it's also harder and more expensive to create multiple accounts. If gsuite is used very carefully, 1 is enough, but I think 2 would be better for most.

I think you're misunderstanding AWS accounts; they're not talking about AWS "logins", they're talking about actual "accounts" which are the entities that house resources like GCP projects. You can have an "organization" that has many accounts under it with sensible IAM, although it's less clean than GCP.

Re: An AWS account just for getting into other AWS accounts

#109

> Don’t do this! Any principal in your management account, by default, is able to assume the OrganizationAccountAccessRole in each and every one of the accounts created using the organizations:CreateAccount API. I should note that if you use AWS Control Tower Account Factory to create the member accounts then this role does not get created. The "Audit" account that is created by Control Tower is probably the best one…

> Any principal in your management account, by default, is able to assume the OrganizationAccountAccessRole in each and every one of the accounts created using the organizations:CreateAccount API.

This is an untrue statement. For a principal in the management account to assume OrganizationAccountAccessRole, they need to have a principal-based policy that gives sts:AssumeRole permissions for it. Otherwise, great article. We use this pattern at $DAYJOb

Post reply on HN