Half-OT: On Twitter I read a few times people stopped using IAM, but never got an answer when I asked what they were doing instead.
I had the impression IAM was required. Does anyone has more infos on this?
I had the impression IAM was required. Does anyone has more infos on this?
They said, they don't use AMIs and not IAM.
In lieu of IAM you can use federated access from an identity provider like Okta. That will lease a role which can then adopt other roles (even across accounts). Okta is integrated with a more formal IT system like Active Directory and then all your accesses and identity can be managed by them. I think this is the AWS side doc for the setup https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_pr...
I also know Nike does something very similar and shared about it here https://github.com/Nike-Inc/gimme-aws-creds including the Okta side documentation.