Skip to content

Day 2 — IAM & Security #2

Description

@PunithVT

Day 2. IAM is the thing everyone skips and then breaks production with. Doing it properly now while the projects are small.

Topics to cover:

  1. IAM core model — users, roles, policies, principals, and how a request gets evaluated
  2. Writing least-privilege policies — Action / Resource / Condition keys, common patterns
  3. Cross-account roles and STS AssumeRole — when and why
  4. Agent-side security — prompt injection, tool authorization, scoped per-user credentials
  5. Secrets handling — Secrets Manager vs Parameter Store, rotation, KMS basics

Plan: Chandana on policies and AssumeRole, me on agent-side threats, both of us on secrets handling.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions