On the other hand, I have a tool that calls some AWS services that may in turn call other AWS services. Now if something fails because of IAM denial, I have to go through the logs to figure out what it needed, sometimes it's not even in the logs (S3). Then add it to the policy and repeat to see the next failed call.
I imagine being able to call real API calls, make them succeed and record what permissions it needed for each of those API calls. I don't need that as a permanent log, just as a development tool.
https://docs.localstack.cloud/user-guide/aws/iam/#explainabl...
afaics the only challenge is mapping some of the apis to iam as its only 85% 1:1
There's also tools for helping with iam like (generator, and linter)
Yeah. Try to create an Elastic beanstalk app with only EB permissions.
Is it reliable though? I have experienced many situations where a role has access to a policy and yet the policy simulator said that access is denied due to "organization policy" with no further ability to drill down to which policy it thinks denies access. And it did that when the role did have access to the resource and could work with that resource successfully. So I stopped trusting the simulator. I wonder if others too have experienced similar issues with the simulator.