|
|
|
|
|
by ocdnix
1951 days ago
|
|
Reminds me of Lyft's thing from a couple of months ago: https://news.ycombinator.com/item?id=25000950 I would love to get answers to questions like "which users have access to resource X, including implicitly through one or more assume-role jumps, across these N accounts, including stuff like iam:PassRole, even including tag-based policies?". Add a time dimension too, like "who had access to X between Jun and Aug 2020?", and you'd have a winner. Would such queries be possible here? |
|