Rowan

@rowanu.bsky.social

AWS IAM, cloud security, and serverless

Do you have an S3 bucket or DDB table with your companies crown jewels? 👑💎 Now IAM Access Analyzer tells you all the users and roles in your organization that have access to them gems. 🧵 (1/8)

AWS IAM updates last week: - SecurityAudit got an update 🥳 mostly S3 tables - network-firewall getting flow operations - route53-recovery-control-config (???) getting resource policies I'm still not sure why every week there seem to be version updates to some policies, but without actual changes?!

Bild

Vibe coding digrams #FAIL GenAI remains a key part of my daily workflow, but it feels like I'm running in to more limitations - anyone else? In this case, the LLM kept trying the same thing, even though it detected there was a problem with it (very neat!)

Bild

As more "stuff" gets made (code/blogs/etc) by AI, don't underestimate the power of giving presentations/speaking to advance your career! Speaking at meetups and conferences has given me such a high ROI for the effort, and it gets easier the more you do it!

Bild

Having access to the actual resource providers that CloudFormation uses to provision resources has saved me a few times! This is repo is a great compilation by Pat Myron Just remember, if you use CDK, you use CloudFormation too 😉

GitHub - PatMyron/cloudformation-resource-providers: automated monorepo of public CloudFormation AWS resource providers

automated monorepo of public CloudFormation AWS resource providers - PatMyron/cloudformation-resource-providers

github.com

Interesting (maybe) AWS IAM action/policy updates from last week (ending 23/3): - deeplens gone 🔪🤖 - cleanrooms gets protected (?) jobs - connect gets data lake integration 15 separate updates detected this week, which is more than usual, but not to show for it...

Bild

Here's my dependency diagram for YourPublic.Cloud Each one of these is its own AWS CloudFormation stack, with its own deployment, tests, etc The complexity of SaaS is 🤯 no wonder it took me so long... and it's not finished yet!

Bild

Anyone here actually HAPPY with how their company is using GenAI/LLMs today? I heard on a podcast that ~50% of people use AI in their work, but only ~7% of companies... and that just doesn't add up! 😅 Do you have a good approach? If so, share it with us please! 🙏

Interesting AWS IAM action updates from last week: - Bedrock gets prompt routing - Support will allow starting and getting interactions - Batch will get consumable resources (?) - Can't set challenge questions for your account anymore It's not often you see IAM actions removed, but it can happen!

Bild

Early bird sponsorship for AWS Community Day Australia 2025 is only available for another week! It's on August 15 in Brisbane. A bunch of sponsorship packages have already been sold, so if you want to get the best price reach out ASAP! awscommunitydayaus.com/

Bild

Bitten by a subtle async bug today, and Claude.ai saved me Using the array index notion on what would *eventually* be an array was instead trying to access the Promise object... and failing silently 🤦‍♂️ It didn't pick it up until I asked very specifically about this logic, but the answer was spot on

Bild

Interesting AWS IAM policy & action updates from last week: - New iotmanagedintegrations action namespace - New gameliftstreams action namespace - CloudWatch RUM getting resource policies soon - AWSFaultInjectionSimulatorECSAccess new version, but only the CreateDate changed? 🤨

Bild

Shout out to Brigid Johnson for one of the best explainers of AWS Resource Control Policies (RCPs) out there! Eventually I'll have time to go through the docs in detail 😆

Bild

How did you learn to use AWS? This thread made me realise I was lucky - I learnt AWS when there were only a few services (not even IAM!) I guess there's got to be *some* upside to getting old 👴

Bild

I wanted one scan per day (for free accounts - paid get more), but I also want to fail reports that take too long. Unfortunately I used the same interval for both checks, so a report would be PENDING up until the interval, then it would be marked FAIL‍ED. Super. Efficient. Fail. #buildinpublic

Bild

Interesting AWS IAM policy updates from last week: * New qdeveloper action namespace (no API yet) * bedrock invocation and session actions * Backup Search Operator managed policy * cloudshell gets ApproveCommand * SageMaker Studio gets more Bedrock specific managed policies

I've got limited space for another short-term/async consulting client. I specialise in AWS IAM and security reviews, keeping cost and compliance on AWS under control, and building serverless solutions to business problems. If you need help on AWS, let me know!

I'm thinking about running another workshop: For beginners, covering ALL the different AWS policy types (I'm looking at you, Resource Control Policies!) with plenty of service-specific examples. Let me know if that's interesting to you, or tag someone who might be!

Bild