Wonk is a tool for combining a set of AWS policy files into smaller sets
github.com
github.com
For instance, if one policy on a user grants access to Service:GetThis and Service:GetThat, and another policy grants access to Service:Get, then Wonk only includes Service:Get in the final results.
While Wonk is still a young project, we've been using it in production for a while now. Hope this can help someone else!
I have never not had a resource limit increase request denied.
You can do this as granular as you like...
Still, that doesn't fix the problem - it just defers it. For example, you can ask that the maximum number of managed policies on a user gets bumped from 10 to 20. That sounds like a lot, but if you want to use AWS-managed policies like to set up least-access privileges, you'll be using lots of them like "CloudWatchReadOnlyAccess" and "AmazonEC2ReadOnlyAccess". If you use more than 20 services, the problem's still going to bite you.
This is done only through your rep, and with them talking to some internal teams....
Have a good relationship with your rep, and I have never gotten a "no" from Amazon....
Again, this is done through actually talking to them.
For example, I was spinning up thousands of instances for some things... and had to take full control of my limits with the agreement that I would pay for that which I spun regardless....
ALTHOUGH, once we had a dev accidentally check in secrets to github, on the 201st repo, which as our paid plan was 200 repos, it automatically mad #201 public - and within an hour we had hundreds of instances lit up in literally every AZ on the globe to mine for some german op....
It took us several hours to kill and close all that... but in the end, AWS just let go of the six-figure bill that would have ensued....
Your project is dope... I just want people to know that limits are soft-set.
The only limits that are hard set are the actual number of nodes available for anything in a given AZ/Region -- but their capacity is way beyond what it was a few years ago, so I don't see that as an issue any more.
However, again, your tool is dope.
---
EDIT: Also, I admit, I have not faced your issue, so aside from mine just being general advice, I do not mean to detract from your post or your release of effort.
:-)
(also, some of their best reps had moved to GCP a while ago - so I don't know who the current crop of 'best reps' is, else I would connect you.
My bad.
So in some ways, it's a shame this is even necessary, but it really is. Really good of you to release this.
I generally like AWS a lot, but there are surely plenty of dark corners in the service. Wonk let us shine some light into a couple of them.
AWS Console with MFA enabled will require MFA.
They can self-manage MFA/password at any point.
Do you currently, or plan to, handle Condition constraints? Also, how does wonk handle combinations with statements that have the Deny effect?
> Note: actions are always grouped by similar principals, resources, conditions, etc. If two statements have different conditions, say, they are processed separately.
That is, if a rule has constraints, it's grouped with other rules that have the exact same constraints. As of today, it doesn't do anything to smartly work across the various groups. Deny statements work the same way: they're grouped with other Deny statements.