Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED


1 America’s Sweethearts: Dallas Cowboys Cheerleaders Season 2 - Tryouts, Tears, & Texas 32:48
#44 AWS Security: Stephen Kuenzli and Andreas Wittig on IAM
Manage episode 320442873 series 2570451
Notes
Stephen Kuenzli and I lead several cloud migration projects. In this conversation, we shared our learnings focusing on AWS security and IAM (Identity and Access Management). The result is advice and inspiration that will help you in your daily work. Our conversation is available as a video or podcast episode. In the following, you will also find a summary of our discussion.
As Michael is on parental leave, I invited Stephen to the cloudonaut podcast. Listen to our conversation on AWS security and IAM. Stephen has written a book for engineers who design, develop, and review AWS IAM security policies in their daily work: Effective IAM for Amazon Web Services. Besides that, Stephen is the founder of k9 Security with the mission to help organizations use the Cloud to improve security and manage risks to the organization and its customers.
Check out the blog post for details and links: AWS Security: Stephen Kuenzli and Andreas Wittig on IAM
Newsletter
Every week, we write about all things AWS. For example, we unbox or review new AWS services. We also share pitfalls that we learned about the hard way ourselves. On top of that, we provide code examples for Infrastructure as Code and Serverless applications.
Subscribe to our newsletter for free!
Support us
We launched cloudonaut.io in 2015. Since then, we have published hundreds of articles, podcast episodes, and videos. It's all free and means a lot of work in our spare time. We enjoy sharing our AWS knowledge with you.
Have you learned something new by reading, listening, or watching our content? If so, we kindly ask you to support us in producing high-quality & independent AWS content. We look forward to sharing our AWS knowledge with you.
Feedback
We ask for feedback! Please rate or review our podcast on Apple Podcasts or wherever you listen to your favorite shows. Or send us a message via Twitter (Andreas and Michael) or LinkedIn (Andreas and Michael) or send us an email.
93 episodes
Manage episode 320442873 series 2570451
Notes
Stephen Kuenzli and I lead several cloud migration projects. In this conversation, we shared our learnings focusing on AWS security and IAM (Identity and Access Management). The result is advice and inspiration that will help you in your daily work. Our conversation is available as a video or podcast episode. In the following, you will also find a summary of our discussion.
As Michael is on parental leave, I invited Stephen to the cloudonaut podcast. Listen to our conversation on AWS security and IAM. Stephen has written a book for engineers who design, develop, and review AWS IAM security policies in their daily work: Effective IAM for Amazon Web Services. Besides that, Stephen is the founder of k9 Security with the mission to help organizations use the Cloud to improve security and manage risks to the organization and its customers.
Check out the blog post for details and links: AWS Security: Stephen Kuenzli and Andreas Wittig on IAM
Newsletter
Every week, we write about all things AWS. For example, we unbox or review new AWS services. We also share pitfalls that we learned about the hard way ourselves. On top of that, we provide code examples for Infrastructure as Code and Serverless applications.
Subscribe to our newsletter for free!
Support us
We launched cloudonaut.io in 2015. Since then, we have published hundreds of articles, podcast episodes, and videos. It's all free and means a lot of work in our spare time. We enjoy sharing our AWS knowledge with you.
Have you learned something new by reading, listening, or watching our content? If so, we kindly ask you to support us in producing high-quality & independent AWS content. We look forward to sharing our AWS knowledge with you.
Feedback
We ask for feedback! Please rate or review our podcast on Apple Podcasts or wherever you listen to your favorite shows. Or send us a message via Twitter (Andreas and Michael) or LinkedIn (Andreas and Michael) or send us an email.
93 episodes
All episodes
×
1 #093 Getting ISO 27001 certified as a 2-person company 35:29






1 #084 Aurora Serverless is dead, long live Aurora Serverless! 33:39


1 #082 Generating boring CloudFormation templates with the CDK 25:10

1 #081 AWS JavaScript SDK v3 + CloudWatch Dashboard Custom Widgets 29:36

1 #080 Self-hosted GitHub Runners on AWS + S3 Object Lambda + AWS Community Day Germany 31:20

1 #079 Delayed scaling due to inactive SQS queue 25:29

1 Does AWS Support provide more value than ChatGPT? 26:43

1 Monitoring AWS Inspector + Terraform AWS Provider + Spot Pricing 25:29



1 Advanced Monitoring with EventBridge + Amazon Linux 2 Container 26:28

1 Serverless and DevOps a match made in heaven | Builder's Diary Vol. 006 47:01

1 Scaling On-Demand and Spot Instances + On-Premises VPC Endpoints 23:07

1 ElastiCache vs. MemoryDB + SLA 99.99% + Terraform ignore_tags 15:02

1 S3 Permission Debugging + AWS Region Drift + Self-hosted GitHub Runner + SQS Scale-In Workaround 32:24


1 #67 EventBridge Scheduler + Packer AMI + AWS Debug Games 19:28

1 #66 ECS Anywhere Hybrid Cloud Containers | Builder's Diary Vol. 5 30:17

1 #65 [Hot off the Cloud] Year in Review + CloudWatch Metrics Insights + SaaS Free Trail 30:44

1 #64 [Hot off the Cloud] ECS Service Connect + Auto Scaling Target Tracking 30:53

1 #63 Serverless Software Engineering | Builder's Diary Vol. 4 34:45

1 #62 [Hot off the Cloud] re:Invent + CodeCatalyst + EventBrige Pipes + Step Functions Distributed Map 29:10

1 #61 [Hot off the Cloud] re:Invent + Cross-Account CloudWatch + AuthZ Verified Permissions + ELB Resilience 26:04

1 #60 [Hot off the Cloud] AppSync JavaScript Resolvers + IAM MFA + CloudFront CD 30:48

1 #59 [Hot off the Cloud] EventBridge Scheduler + Resource Explorer + ECS scale-in protection 30:02

1 #58 [Hot off the Cloud] Neptune Serverless + WAF Bot Control + Private App Runner + Fault Injection Simulator 33:35

1 #57 Infrastructure Pipeline with GitLab and Terraform Cloud | Builder's Diary Vol. 3 44:22

1 #56 [Hot off the Cloud] Lambda Parameters + Dark Mode + SQS FIFO + Nitro Enclaves + Interactive Video Service 30:04

1 #55 Serverless ETL with Athena and Airflow | Builder's Diary Vol. 2 50:33

1 #54 [Hot off the Cloud] Lambda event filtering Kafka + Athena query engine v3 + more 25:49

1 #53 [Hot off the Cloud] Monitor VPC Network Address Usage + Aurora Serverless v2 + AWS IQ 53:22

1 #52 [Hot off the Cloud] Amazon File Cache + EBS Snapshots Archive + EC2 Auto Recovery 39:34

1 #51 AWS-to-go Vol. 4: Programming your infrastructure 45:51

1 #50 AWS-to-go Vol. 3: Using Virtual Machines EC2 46:43

1 #49 AWS-to-go Vol. 2: WordPress in Fifteen Minutes - an Example 33:09

1 #48 AWS-to-go Vol. 1: What's Amazon Web Services? 46:48

1 #47 Builder's Diary Vol. 1: Successful Cloud Migrations 40:04


1 #44 AWS Security: Stephen Kuenzli and Andreas Wittig on IAM 52:53

1 #42 EC2 Checklist: 7 things to do after launching an instance 20:56

1 #41 Getting Started with Free Templates for AWS CloudFormation 20:54

1 #40 Review: AWS Fault Injection Simulator (FIS) 31:58


1 #38 5 good reasons not to get AWS certified 31:47


1 #36 re:Invent 2020: Recap of Werner Vogels's Keynote 32:03

1 #35 3½ ways to workaround missing CloudFormation support 32:09

1 #34 A recap of the re:Invent 2020 Keynote with Andy Jassy 46:27

1 #33 ECS vs. Fargate: What's the difference? 35:27



1 #28 How to choose a container registry? 1:00:41

1 #27 Record AWS API calls to improve IAM Policies 29:49



1 #20 End-user monitoring of your website with CloudWatch Synthetics 34:49

1 #19 Scaling Container Clusters on AWS: ECS and EKS 58:23



1 #14 What's the best AWS Compute option for your project? 36:13

1 #12 EC2 Instances 2.0 - Time to Update Your Toolbox 34:59

1 #11 10 Success Factors for Starting Your Cloud Journey 39:25

1 #10 All you need to know about AWS re:Invent in 2019 55:44





1 #3 How to sell pay per use SaaS to AWS customers in the AWS Marketplace 28:28

1 #2 EC2 Instance Connect is an insecure default! 11:07
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.