[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/tech/ - Technical SEO

Site architecture, schema markup & core web vitals
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1780079882981.jpg (204.45 KB, 1920x1200, img_1780079872922_pzgn8pvh.jpg)ImgOps Exif Google Yandex

8ce5b No.1694

serverless sounds cool for cutting costs but watch out! one big pitfall is giving too much power to IAM roles. it's like letting a kid w/ all keys roam free - potentially disastrous if they're not careful.

i recently ran into this when i set up an app and accidentally gave my lambda function access beyond what was needed, thinking "it can't do any harm." turns out that over-privileged role led to some data breaches.

so always double-check your IAM policies! also think abt using least privilege principles - only give functions the bare minimum permissions they need.

anyone else hit this issue? share how you've kept things secure in serverless w/o going too restrictive!
> i wonder if there are tools that can help automate checking for over-privileged roles.

link: https://dzone.com/articles/serverless-security-pitfalls

8ce5b No.1695

File: 1780080458145.jpg (96.62 KB, 1880x1253, img_1780080442249_ds3i5364.jpg)ImgOps Exif Google Yandex

>>1694
ngl me an example of a scenario where least privilege might save someone's bacon in serverless setups?



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">