AWS Security Documentation, by Category
docs.aws.amazon.com
docs.aws.amazon.com
Sure that UX could hurt adoption, but wouldn’t it ultimately boost retention? Success with a cloud IT org means nothing breaks and nothing leaks. Part of helping customers succeed is helping them not to fail to the point of catastrophic business risk. How many billions of private records have been leaked from S3 or ElasticSearch because of simple, detectable, preventable misconfiguration.
AWS provides a number of security and compliance services today- for a price. They would do well to suggest sane defaults like they do with a default VPC.
It only has a single subnet for each availability zone, which is connected to an Internet Gateway, effectively granting all resources with a public address assigned to it Internet access. That combined with the default security group was a recipe for unintended consequences.
One thing I'd recommend is reading up on the Well-Architected Framework[0]. It approaches all the essentials in AWS and will likely save people from reinventing the wheel badly. There are aspects of the Well-Architected Framework that I don't follow, but those aspects become very clear when you understand what they're trying to make you do with it.
I had the impression IAM was required. Does anyone has more infos on this?
In lieu of IAM you can use federated access from an identity provider like Okta. That will lease a role which can then adopt other roles (even across accounts). Okta is integrated with a more formal IT system like Active Directory and then all your accesses and identity can be managed by them. I think this is the AWS side doc for the setup https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_pr...
I also know Nike does something very similar and shared about it here https://github.com/Nike-Inc/gimme-aws-creds including the Okta side documentation.
They said, they don't use AMIs and not IAM.