Is it really not possible to federate to an IAM role, from a Cognito client credential flow access token? Due to missing audience claim. Paging knowledgeable @ben11kehoe@__steele
@julian_wood in your talk “best practices for serverless developers”(svs401) at re:Invent, you make the point that serverless allows you to ship functionality faster. I buy the arguments, but do we have any data to back this up?
@julian_wood@davidand393@bigheadoreilly@MarkMcCann I have been running serverless workloads for several years and enjoy it! But it causes some friction internally - especially due to the ergonomics of developing (testing, observability). So the TCO argument needs to be clear. Which I am not certain it is right now.
@julian_wood Fantastic talk! Yes, it is probably still a bit too anecdotal for me. Including the Deloitte report. I appreciate that this is not a straightforward experiment to do, but I was just wondering if there was a structured assessment carried out across projects.
Yay, great to see this out! We describe how to enforce data and service access control at scale, without constraining developer velocity(too much). For us it turned out to be a mix of RBAC and ABAC and combinations of the two. Mixing #okta and #aws is a great for authn and authz.
@jeremy_daly I had the S3 service team reach out and ask if it was on purpose we were saturating the S3 api. S3 object event -> lambda -> write multiple objects back quickly maxes out the account concurrency.
@zoph@BarakSchoster@kmcquade3 I get the opposition. However if you set it up right, it is literally just another way of writing cloudformation. Are you thinking from an organisational perspective?
We wrote a bit on how we approach application design when thinking about data management at scale! Give it a read, and provide comments/feedback https://t.co/JW6ctZ1B97
New Big Data post by Alessandro Fior, Anwar Rizal, Hassen Riahi, Jonatan Selsing, Kumari Ramar and Moses Arthur:
How Novo Nordisk built a modern data architecture on AWS
https://t.co/mjiwRZdaLG
@Benoit_Boure API destinations in EventBridge has a OAuth Client Credentials as auth mode. Which exactly handles the token rotation. We use this pattern to have asynchronous invoked API calls from events.