iAM Flashcards
1
Q
iAM Users and Groups
A
iAM is a global service.
User is single entity.
Groups only contain users
2
Q
iAM Policies
A
iAM Group is attached a policy which defines the access control to a resource
Structure is Effect (Allow/Deny), Action(API calls), Resource (What resource access is allowed)
3
Q
iAM Role
A
iAM roles are used by AWS services to access resources on users behalf.
Permissions are assigned to the iAM role in order to do that.
E.g. - EC2 instance roles, Lambda function roles, CloudFormation roles
4
Q
iAM Role application
A
- Add new role
- Choose the AWS service like EC2, Lambda, etc…
- Attach a policy