Hacker News new | ask | show | jobs
by alanfranz 1633 days ago
> It is obviously catered towards large organisations

And yet it seems that only the big cloud providers offer a reasonable authentication and authorization approach.

For many other providers, api keys lend full account access (no resource limitation, no read-only/subset of actions), which is unacceptable from a security pov.