Skip to main content

28.AWS-IAM-User-Role-Polocies

28.AWS-IAM-User-Role-Polocies


28.AWS-IAM-User-Role-Polocies;
Security, Identity, & Compliance:(IAM, )


1.IAM:Globlelly Applicabale.

 Groups,Users,Roles,Polices,

..User Permission And Role Permission Differnce Below explained..

.Deploy EC2 machine(for user1)-Give S3permision for One Group(User)- COpy userlogin URl and pasr in other browser-
-create another VM (For user2) -in EC2 not having ARN No..,(so we used Tages..) -
create polices- google -Restrict aws user ec2 instance- go-  https://aws.amazon.com/premiumsupport/knowledge-center/restrict-ec2-iam/
- 24.00 - edit code add tages(server1) ,Owner id, and past into valid json- then create custom police-give name of that policey-
similarly server-2 change Tages, and create policey..

So now add that two differnt polices to two servers..assined
 then loginto user console- now i am login user-1 i can visable 2vms but i can operating only one- other one i am not having permision..
 simillary- User-2, having same-...


.(30.57),if i am lauching ec2-getting error-that error can decode- goole decode aws error message-...



similarlley we can restrict VPC Also.. in abou  separt Permision on machines for different users..,,


Google-Restrict aws user vpc-.. , google -aws iam policey flow..

https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html




Roles;;; 44.43

CROSS ROLE ACCESS(ONE A/C TO OTHER A/C SERVICES ACCING USING Roles..)

..1 masteraws a/c - 10 aws a/c @ the time 10roles created in Master and given that 10 aws a/c respectivally..

(Mavric a/c logine using ShreeHarsha ..(Master) a/c ..)...
steps-(52.00)

1.login Shreeharsha A/C-create role- selcct another a/c-(a/cid) - give admin access-Give role name-created.

2.login Mavirik A/C- Create Police-(google- aws assume role policey. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_policy-examples.html)
 - copy Role ARN in Shreeharsha A/C- go mavric a/c-Past into this code create role policey-
-givename-createpolicey..Apply this policey to user in Mavric a/c--


3.Login to mavric user a/c - youcan not do any thing in this a/c-switch role-Account,Role,Displaynam,cloure,-switch role- now you can comto mavilrole in Harsha A/C


So in this way all slave a/c we create Role and give permision in Master a/c ...

[..her Mavric slave ( aws asume policy role crated heare )  and
  Sree Harsha ( Create role to Other a/c give marvic a/c id- permision Admin acess. ) Master A/C Account,.]


for moore,,,,
https://www.reancloud.com/blog/providing-cross-account-s3-access-for-kms-encrypted-objects/



--------------------------------------------------------------------------------------------------


Comments

Popular posts from this blog

36.Migration & Transfer

36.Migration & Transfer Migration & Transfer:::...... .............................................. 1.Snowball::(data moving only,like box, 10gb connectivety, 80terrabytes supportes one box,encripted for portable purpouse ,aws snow mobi- like truck 40gb connectivety bunch of snow balles in side truck, we use this services for not having enf bandwidth, snowball edge.study dock) 2.Server Migration Service:: ( virtual servers not for physical servers, free tool,  google search aws sms limits, onprimisess to cloude, to over com use 3rd party tools lik platespin migrate aws,cloud endure,zerto aws )  15.54 .. video harshas desktop..(google - aws sms user guide,planning diffuclt but implementation easy,  google - aws 6r , acess key and security key required,replication,finally creating AMI) 3.Database Migration Service(crating one instnce to take replication from on premisiss to stor in aws RDS,or more given directions,trasfer over vpn) 4.AWS Migration...

42-AWS-PROJECT-CERTIFATION

42-AWS-PROJECT-CERTIFATION ... GOOGLE....aws 6r..... 1. 2. 3. 4. 5. 6. PRE SALE -POST SALE::: DPR: Detailed PROJECT REPORT. RFI : REQUSTE FOR INF. RFP : REQUEST FOR PROPEROSAL RFQ : REQ     FOR QOOTE POC: PROOF OF CONCEPT HLD: HIGH LEVEL DEGINE  CEO,LEVEL,  HIG LEVEL DIAGROM LLD: LOW LEVEL DEGINE  .. AWS , VPC, ...... BUILD SHETT: FULL DETIALS OF IP NO.. ALL PIN TO PIN UAT: USER ACCEPTANCEY TEST ORT: OPERATION REDINESS TEST SING OFF : REMAINING AMOUT COLLECT CLOSE ARCHITECTURE: AWS CERTIFICATION: Jayandra Patil AWS .............. AWS sysops bluprint

43-Dev-git cmds

43-Dev-git cmds Harsha Veerapalli... .git clone https://github.com/username/repository  git clone https://github.com/NAVEENMJ/1 git status .git init .git status ... getting red cloure  ( a.txt ) .git add file.txt or  (git add .) .git push .git push -u origin master .................. .git branch ---list of branches .git checkout -b branch ...Creaing branches .git merge branch ... presnt in master then merge.. ................................... .git status .git init .git status ... getting red cloure  ( a.txt ) .git add file.txt .git status .... getting green cloure  ( new file: a.txt) [if multipull files in folder use git add .] .git commit -m "COMMIT-1" .. Hear COMMIT-1 Means giving name in genralli changed  name given .git log ......changes ...times.. modifi that file a.txt...... .git status .git add . .git status .git commit -m "COMMIT-2" .cls .git log ..........i want go before comited version....