Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
dads friend steve
Dec 24, 2004

Our cloud architect guy got all hyped up when he found out that cdktf had its GA release. He showed it to me and I didn’t understand why you would use it. Like just use CDK or use Terraform?

Adbot
ADBOT LOVES YOU

dads friend steve
Dec 24, 2004

Startyde posted:

I know Batch is a bad word in lots of shops

I didn’t know this. Any insights as to why? I’ve got a team looking to run, effectively, batch processing jobs and I’m sorely tempted to recommend they throw away the custom job allocation code they’re writing and just switch to Batch. Are there some catches or some other reason it doesn’t live up to how AWS portrays it in their doc?

dads friend steve
Dec 24, 2004

BaseballPCHiker posted:

Speaking of IAM....

Anyone ever setup IAM Roles Anywhere? I sort of want to take on a project myself to get it and CA setup to put the final nail in the coffin for my remaining access key IAM users. But Ive got no experience with it, and I'm about to have baby brain and be out on paternity leave for a while so Im a bit hesitant to start it now.

I’ve been on-and-off nagging my org to use it, since we already have an existing internal PKI. I’ve played around with it a bit and it more-or-less does what it says on the tin. One thing I haven’t looked into deeply is root / intermediate cert rollovers and how you’d handle that.

One thing to be aware of is your IAM Roles’ trust policies need to be constructed with some care to avoid being overly permissive with which certs allow assuming the role.

In my (admittedly limited) experience, if you have a lot of on-prem workloads it’s a pain in the rear end to manage their AWS access no matter what. So it’s really a matter of picking whichever solution sucks least.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply