Skip to main content

28.AWS-IAM-User-Role-Polocies

28.AWS-IAM-User-Role-Polocies


28.AWS-IAM-User-Role-Polocies;
Security, Identity, & Compliance:(IAM, )


1.IAM:Globlelly Applicabale.

 Groups,Users,Roles,Polices,

..User Permission And Role Permission Differnce Below explained..

.Deploy EC2 machine(for user1)-Give S3permision for One Group(User)- COpy userlogin URl and pasr in other browser-
-create another VM (For user2) -in EC2 not having ARN No..,(so we used Tages..) -
create polices- google -Restrict aws user ec2 instance- go-  https://aws.amazon.com/premiumsupport/knowledge-center/restrict-ec2-iam/
- 24.00 - edit code add tages(server1) ,Owner id, and past into valid json- then create custom police-give name of that policey-
similarly server-2 change Tages, and create policey..

So now add that two differnt polices to two servers..assined
 then loginto user console- now i am login user-1 i can visable 2vms but i can operating only one- other one i am not having permision..
 simillary- User-2, having same-...


.(30.57),if i am lauching ec2-getting error-that error can decode- goole decode aws error message-...



similarlley we can restrict VPC Also.. in abou  separt Permision on machines for different users..,,


Google-Restrict aws user vpc-.. , google -aws iam policey flow..

https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html




Roles;;; 44.43

CROSS ROLE ACCESS(ONE A/C TO OTHER A/C SERVICES ACCING USING Roles..)

..1 masteraws a/c - 10 aws a/c @ the time 10roles created in Master and given that 10 aws a/c respectivally..

(Mavric a/c logine using ShreeHarsha ..(Master) a/c ..)...
steps-(52.00)

1.login Shreeharsha A/C-create role- selcct another a/c-(a/cid) - give admin access-Give role name-created.

2.login Mavirik A/C- Create Police-(google- aws assume role policey. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_policy-examples.html)
 - copy Role ARN in Shreeharsha A/C- go mavric a/c-Past into this code create role policey-
-givename-createpolicey..Apply this policey to user in Mavric a/c--


3.Login to mavric user a/c - youcan not do any thing in this a/c-switch role-Account,Role,Displaynam,cloure,-switch role- now you can comto mavilrole in Harsha A/C


So in this way all slave a/c we create Role and give permision in Master a/c ...

[..her Mavric slave ( aws asume policy role crated heare )  and
  Sree Harsha ( Create role to Other a/c give marvic a/c id- permision Admin acess. ) Master A/C Account,.]


for moore,,,,
https://www.reancloud.com/blog/providing-cross-account-s3-access-for-kms-encrypted-objects/



--------------------------------------------------------------------------------------------------


Comments

Popular posts from this blog

43-Dev-git cmds

43-Dev-git cmds Harsha Veerapalli... .git clone https://github.com/username/repository  git clone https://github.com/NAVEENMJ/1 git status .git init .git status ... getting red cloure  ( a.txt ) .git add file.txt or  (git add .) .git push .git push -u origin master .................. .git branch ---list of branches .git checkout -b branch ...Creaing branches .git merge branch ... presnt in master then merge.. ................................... .git status .git init .git status ... getting red cloure  ( a.txt ) .git add file.txt .git status .... getting green cloure  ( new file: a.txt) [if multipull files in folder use git add .] .git commit -m "COMMIT-1" .. Hear COMMIT-1 Means giving name in genralli changed  name given .git log ......changes ...times.. modifi that file a.txt...... .git status .git add . .git status .git commit -m "COMMIT-2" .cls .git log ..........i want go before comited version....

Azure Devops tutorial

 Azure Devops tutorial: web sit-  Projects - Home (azure.com) AZURE DEVOPS - Organization - Projects Under project- --------- Under Pipelines ---> Pipelines( CI ) -  Under Pipelines --->Releases( CD ) -  ------------------------------------------------------------------------------------------------------------------------- Azure Pipelines:--- Pipeline structure:- A pipeline is one or more stages that describe a CI/CD process. Stages are the major divisions in a pipeline. The stages "Build this app," "Run these tests," and "Deploy to preproduction" are good examples. A stage is one or more jobs, which are units of work assignable to the same machine. You can arrange both stages and jobs into dependency graphs. Examples include "Run this stage before that one" and "This job depends on the output of that job." A job is a linear series of steps. Steps can be tasks, scripts, or references to external templates. This hierarchy is refle...

42-AWS-PROJECT-CERTIFATION

42-AWS-PROJECT-CERTIFATION ... GOOGLE....aws 6r..... 1. 2. 3. 4. 5. 6. PRE SALE -POST SALE::: DPR: Detailed PROJECT REPORT. RFI : REQUSTE FOR INF. RFP : REQUEST FOR PROPEROSAL RFQ : REQ     FOR QOOTE POC: PROOF OF CONCEPT HLD: HIGH LEVEL DEGINE  CEO,LEVEL,  HIG LEVEL DIAGROM LLD: LOW LEVEL DEGINE  .. AWS , VPC, ...... BUILD SHETT: FULL DETIALS OF IP NO.. ALL PIN TO PIN UAT: USER ACCEPTANCEY TEST ORT: OPERATION REDINESS TEST SING OFF : REMAINING AMOUT COLLECT CLOSE ARCHITECTURE: AWS CERTIFICATION: Jayandra Patil AWS .............. AWS sysops bluprint