Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IAM is complicated but it doesn’t have to be, as long as you keep things organized.

- Use AWS Organizations to organize your teams into Organizational Units

- use SCP to limit permissions of the OUs.

- let the OUs create new aws accounts for every project/workload

- now you have permissions and costs organized per project/workload

Don’t be afraid to create many AWS accounts, this is encouraged and considered best practice.



This! Every team and product gets AWS account or two, this is all you need at a basic level.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: