
AWS and IAM with Stephen Kuenzli - DevOps 106
Adventures in DevOps
00:00
Using Service Control Policies to Control Blast Radius
In general, i recommend that both identity and resource policies for an application, leve with the application. And so no, if you're adding a dynamo d b table that needs inscription, there's probably some application code that's going to be using. You can use things like service control policies to control blast radius. Te service control policies are defined at the organization level, but apply to individual accounts.
Transcript
Play full episode