Live data from Hacker News

An AWS account just for getting into other AWS accounts

src-bin.com

91–100 of 109 posts

Re: An AWS account just for getting into other AWS accounts

#91
post #62

Earlier quoted context omitted.

Messy? Isn't one of the points of having multiple accounts to reduce mess?

Yeah except having to navigate between the two can be tricky. Also that means we have multiple dynamos and multiple cognitos (in our case, test and prod), which is a pain. I use Firefox for the prod console and Chrome for the test console. Obviously that system doesn't scale past 3-4 accounts. ;)

Firefox Container Tabs work well here for quite a while. But after 20 or so the list of containers will get very long.

Re: An AWS account just for getting into other AWS accounts

#92
post #33

Earlier quoted context omitted.

Everything in GCP is built atop the Google Auth system and tied to a GSuite domain. It’s Org->Folder->Project hierarchy is very similar to AWS Orgs. However, it’s far easier from there. IAM is tied to your gsuite email, and service accounts are also email addresses. One never needs to login with different creds to access another project. You just use your Google login or activate a service account. Projects are a rea…

> One never needs to login with different creds to access another project. You just use your Google login or activate a service account. It's the same in AWS with AWS SSO/IAM Center. You only login once, and you can access every other account (project) you're allowed to access.

But you need to keep going back to the SSO console to switch accounts because only one can be active at once. With GCP you can have multiple tabs open with different accounts.

The best part is that the account is in the URL so you can just link to specific resources in different accounts. So many of our runbooks for GCP are like "click this link" whereas for AWS it is "make sure you are looked into {specific-account} then click this link". The latter is much more error prone and can break your workflow if you were doing something in a different account previously.

Re: An AWS account just for getting into other AWS accounts

#93
post #9

What's this like on Google Cloud? Would you create a project to get into other projects and would that achieve most of what this achieves? And would you use a GSuite address so you don't log into the console just by logging into the email?

You can’t have nested projects, but for the purposes of organizations there is folders and orgs, which are container of containers. GCP’s IAM somewhat addresses the isolation and scope problem mentioned in the article. Not all GCP apis, atleast with respect to OAuth2, properly utilize IAM, insofar that they require overly power OAuth2 scopes. For example, to list cloud functions you need permissions to create and edi…

> For example, to list cloud functions you need permissions to create and edit, too. That’s broken.

Do you have a concrete example of that? Or, maybe you mean the console needs those perms to work?

Re: An AWS account just for getting into other AWS accounts

#94
post #89
post #85

Earlier quoted context omitted.

> seemed quite diplomatic Turns out it is more diplomatic to reach out to someone privately first. God forbid we set a better example than the one being set.

> Turns out it is more diplomatic to reach out to someone privately first. Why

If we are not all polite, we all have to be rude.

Be polite.

Re: An AWS account just for getting into other AWS accounts

#95
post #33

Earlier quoted context omitted.

> One never needs to login with different creds to access another project. You just use your Google login or activate a service account. It's the same in AWS with AWS SSO/IAM Center. You only login once, and you can access every other account (project) you're allowed to access.

But you need to keep going back to the SSO console to switch accounts because only one can be active at once. With GCP you can have multiple tabs open with different accounts. The best part is that the account is in the URL so you can just link to specific resources in different accounts. So many of our runbooks for GCP are like "click this link" whereas for AWS it is "make sure you are looked into {specific-account}…

This* is a feature, not a bug for me – I use separate profiles in Chrome or Container Tabs in Firefox!

Edit: I realized you are talking about switching accounts twitter style. I don't mess with that - I use a separate Chrome profile. Also you are arguing for GCP, I thought you were arguing against it.

* Having separate accounts, not being able to have separate accounts - I know it's possible with AWS as AWS doesn't force you to use a single account.

Re: An AWS account just for getting into other AWS accounts

#96
post #94
post #89

Earlier quoted context omitted.

> Turns out it is more diplomatic to reach out to someone privately first. Why

If we are not all polite, we all have to be rude. Be polite.

> Be polite.

Could you explain how messaging in private is more polite?

Re: An AWS account just for getting into other AWS accounts

#97
post #70
post #59

Earlier quoted context omitted.

Far out - that website looks dodgy as. What on earth is going on with its fonts - it looks like a newspaper vomited onto the screen.

It looks completely normal to me?

I thought it was just on my phone, but it's goofy as on the desktop too, this is what it looks like for me in Firefox: https://imgur.com/a/o0vGIq8

Re: An AWS account just for getting into other AWS accounts

#98
post #96
post #94

Earlier quoted context omitted.

If we are not all polite, we all have to be rude. Be polite.

> Be polite. Could you explain how messaging in private is more polite?

It's impolite to assume on someone's behalf in public.

Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...?

You seem to have a really hard time grasping that this entire comment thread we are part of wouldn't exist if OP had reached out about their concerns in private.

Re: An AWS account just for getting into other AWS accounts

#99
post #98
post #96

Earlier quoted context omitted.

> Be polite. Could you explain how messaging in private is more polite?

It's impolite to assume on someone's behalf in public. Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...? You seem to have a really hard time grasping that this entire comment thread we are part of wouldn't exist if OP had reached out about their concerns in private.

And yet you haven't sent me any emails, hatware. My door is always open, why not practice what you preach rather than be repeatedly harsh and make a scene over existing community norms? Crowley subsequently disclosed the affiliation, we're good.

Maybe you're newer here; It's a courteous social more of the HN community to be actively transparent about potential conflicts of interest.

I'm actually a fan of Crowley, he's got quite a brain.

Best wishes, MD

Re: An AWS account just for getting into other AWS accounts

#100
post #98
post #96

Earlier quoted context omitted.

> Be polite. Could you explain how messaging in private is more polite?

It's impolite to assume on someone's behalf in public. Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...? You seem to have a really hard time grasping that this entire comment thread we are part of wouldn't exist if OP had reached out about their concerns in private.

> It's impolite to assume on someone's behalf in public.

They asked a question, they didn’t state an assumption.

And why is it impolite.

> Could you explain how messaging in private is so hard to do if you have no problem making the comment in public...?

we’re not talking about difficulty, we’re talking about politeness.

> You seem to have a really hard time grasping that this entire comment thread we are part of wouldn't exist if OP had reached out about their concerns in private.

i don’t think i’d be here if it weren’t for you calling him impolite.

in fact, i’m quite surprised you would assume i have a hard time grasping why this thread exists in public rather than messaging me in private. would you mind messaging me on another social media platform directly before you do that? i hear that’s the polite thing to do here.

Post reply on HN