At the moment, it usually takes me several iterations to tune the policy.
At the moment, it usually takes me several iterations to tune the policy.
People forget, AWS is massive and taking care of edge case after edge case while being in a bullet point war with other cloud providers.
Request logging can be performed asynchronously and has much more relaxed latency requirements, but data needs to be aggregated and replicated for durability.
The extremely different requirements pretty much guarantee that these will be two completely separate systems; by Conway's Law, this means two completely separate teams. In practice, logging is more aimed at business analytics and billing.
You're right that the information should be available, and there's no technical reason why it can't be made available, but there are technical reasons which influence the social reasons why it's not available.
It gives me a little hope on the direction and ability to embed Cedar in non-AWS contexts.
In the real case I don't know what context the actions carry that I may use for filtering, I don't know the action names and I may not even know the full list of API calls the tool I use wants to make.
AWS knows (could record) all of the above for me.
You do know all of this with Cedar as the service owner though. You know the attributes on the entities, you know the policies. Something is going over my head, because I don't think I understand the use case. Can you give a concrete example?
Imagine I'm a new AWS customer that creates their account, starts an Elastic Beanstalk application and tries to automate deployment via CI. The access key will need some permissions to EB, EC2, S3, maybe RDS, ECR... The best thing I can do at the moment is to expect that an example policy is somewhere in the docs.
I've been in that position and more often than not I end up doing the "wrong" thing and give a key wider permissions than needed because trying to lock it down is so frustrating (especially if your CI process is long/expensive). Having to wait 5+ minutes for a CI to reach to the end and realized you missed 1 permissions, rinse and repeat 10+ times for "just one more permission" is frustrating/time consuming.
EDIT: Just saw this further down in the thread https://github.com/iann0036/iamlive (which you already replied to) which looks like it does pretty much what I'm looking for.
Cedar has nothing to do with AWS except that it's open sourced by AWS (I think?). It has nothing to do with IAM, an existing way to model policy specifically for AWS owned resources.
What you do once you model your application's authorization concerns in Cedar to make it so action:foo is exposed as usable on resource:bar is up to you, and your business. An anaylzer can be implemented on top of this for your domain and offer the functionality you're describing, but that seems out of scope for Cedar the modeling specification and evaluation engine to provide.
Imagine Cedar as a way for you, a SaaS provider, to add granular access policies like AWS for your own specific resources be it customers, rental cars, food orders, or advertising campaigns. I suspect the majority of use cases aren’t multi-tenant SaaS concerns but very complex authorization over resources internally across services in an organization. Does micro service A have access to update data on resource bar? It’s still hard to model and enforce those things as organizations grow, especially in a domain specific way.
It seems to me it's a tool made in AWS by some team close to AWS IAM. My original comment didn't relate that much to Cedar itself. Rather, I tried to express my long held frustration with AWS IAM which Cedar doesn't solve even though it must have costed a lot of effort.
Don't worry too much about it. I'm just a random Internet commenter talking about a topic that's not even mentioned in the original article but tangentially connected.
The hosted offering is AWS runs an evaluation engine at scale ensuring it's low latency so your own customers can access resources gated by your own entity and policy definitions.
When we started working on Cerbos[1] the very first external bit of tooling we released was the Cerbos Playground[2] which does exactly what you say - allows you to see the requests and responses as they make changes to their policies, making it easier to test and refine their rules.
This is a great starting point to prototype and test whether a decoupled authorization system is right for your use case. Cerbos uses YAML rather than a custom DSL to try and address the fact that authorization requirements generally don't sit with developers, rather a product owner of some sorts who is going to want to be able to comprehend the logic behind the permissions model.
[1] https://www.oreilly.com/library/view/aws-cookbook/9781492092...
[2] https://docs.aws.amazon.com/IAM/latest/UserGuide/access-anal...
We have some buckets where the cloud trail storage with 1y retention is more than the bucket itself.
On the other hand, I have a tool that calls some AWS services that may in turn call other AWS services. Now if something fails because of IAM denial, I have to go through the logs to figure out what it needed, sometimes it's not even in the logs (S3). Then add it to the policy and repeat to see the next failed call.
I imagine being able to call real API calls, make them succeed and record what permissions it needed for each of those API calls. I don't need that as a permanent log, just as a development tool.
https://docs.localstack.cloud/user-guide/aws/iam/#explainabl...
afaics the only challenge is mapping some of the apis to iam as its only 85% 1:1
There's also tools for helping with iam like (generator, and linter)
Yeah. Try to create an Elastic beanstalk app with only EB permissions.
Is it reliable though? I have experienced many situations where a role has access to a policy and yet the policy simulator said that access is denied due to "organization policy" with no further ability to drill down to which policy it thinks denies access. And it did that when the role did have access to the resource and could work with that resource successfully. So I stopped trusting the simulator. I wonder if others too have experienced similar issues with the simulator.