Really should, I've always thought AWS was just a bunch of hacked together services and it kinda shows. This is why you don't let the engineers talk to the customers... er design for the customers.
https://github.com/salesforce/policy_sentry
(Disclaimer: I am the author)
Not one step exactly, but it is by far the easiest way to write least privilege IAM policies. Otherwise, it becomes impossible to ensure IAM policies are written securely and at scale. This way, all custom IAM policies are written with the exact same methodology.
`aws s3api create-bucket --bucket somecoolname --region us-west-2 --grant-write iamuser`
I don’t know why all the hate for IAM permissions here.
They are complicated but also extremely powerful if setup correctly.
We manage all of our IAM policies and groups with terraform and it’s incredibly easy to understand imho
It’s a ton easier for on boarding and giving contractors temporary access to resources.
*former worker at 3rd party merchant