|
|
|
|
|
by planetafro
1044 days ago
|
|
Curious -- in this scenario, who is doing security, governance, compliance, observability, etc...? You are probably masking a lot of benefits of a mature and competent IT team. ...or you are assuming A LOT of risk allowing velocity-driven software engineering teams to run amok. |
|
AWS IAM is baked into every single product natively. It isn't perfect and their JSON dialect is annoying at times, but having granular RBAC for storage, compute, ops, network in a single language is incredible for security.
And using IaC, you can put guardrails on specific tasks that IT does often. Manual reviews become automated.
It is a ton of conversion and up front work, but there are upsides.
And then of course there is the instant global reliability, where a lot of formerly complicated sysops becomes automated as well
Final thought: other than the hardware abstraction, everything I talked about re: IAM could be done with a local software stack, if it existed.