Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My authorization boundaries are almost entirely in Userify within projects and server groups.

I only associate other permissions through AWS instance roles, because I try to not give out specific IAM roles or keys to users or developers AT ALL -- only to the instances they're logging into.

Obviously this probably can't work for all companies and is dependent on how you have your environments set up, but we even run development on EC2 instances, and with Userify we get a color coded view for who can log into which instances, and then those instances already have the correct custom role.

And there, no IAM to individuals at all.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: