mirror of
				https://github.com/nickpoida/og-aws.git
				synced 2025-03-09 15:40:06 +00:00 
			
		
		
		
	added link to awslabs/git-secrets in IAM Gotchas (#235)
* added link to awslabs/git-secrets in IAM Gotchas last section of this area * updated line 586 per request
This commit is contained in:
		
							parent
							
								
									c40f0ee608
								
							
						
					
					
						commit
						5e07c98ceb
					
				
					 1 changed files with 1 additions and 0 deletions
				
			
		| 
						 | 
				
			
			@ -585,6 +585,7 @@ We cover security basics first, since configuring user accounts is something you
 | 
			
		|||
	-	But be careful not to cache credentials for too long, as [they expire](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html#instance-metadata-security-credentials). (Note the other [dynamic metadata](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#dynamic-data-categories) also changes over time and should not be cached a long time, either.)
 | 
			
		||||
-	🔸Some IAM operations are slower than other API calls (many seconds), since AWS needs to propagate these globally across regions.
 | 
			
		||||
-	❗The uptime of IAM’s API has historically been lower than that of the instance metadata API. Be wary of incorporating a dependency on IAM’s API into critical paths or subsystems — for example, if you validate a user’s IAM group membership when they log into an instance and aren’t careful about precaching group membership or maintaining a back door, you might end up locking users out altogether when the API isn’t available.
 | 
			
		||||
-	❗**Don't check in AWS credentials or secrets to a git repository.**  There are bots that scan GitHub looking for credentials.  Use scripts or tools, such as [git-secrets](https://github.com/awslabs/git-secrets) to prevent anyone on your team from checking in sensitive information to your git repos. 
 | 
			
		||||
 | 
			
		||||
S3
 | 
			
		||||
--
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue