A person or application needs to use an AWS resource, but should not receive control of the whole account. AWS Identity and Access Management (IAM) determines which identities can perform which actions on AWS resources.

An IAM role can be assumed by an allowed identity and supplies temporary credentials. Its trust policy says who may assume it; its permissions say what it may do. Start with one concrete task, such as reading a particular test resource, and include a denied action in your check. Being recognized as an identity is different from being allowed to perform an operation.

Try it in a lab

Design a lab role for one narrowly defined operation. Describe who may assume it, what it may access and which operations should fail. Test with a disposable non-production resource if an account is available.

Check your understanding

Record both allowed and denied cases. Explain how temporary credentials expire and how you would remove access without changing unrelated identities.

Before you start

Do not experiment with root credentials, broad administrative policies or live production resources. Keep credentials out of examples and shell history.

Read the official guide

Use the project documentation for version-specific commands and prerequisites. Record the versions and results of your own exercise. This page proposes a learning activity; it does not report a Kubedex test.

This is a newly written study reference at an address from the original Kubedex course outline. The original lesson was not recovered. It does not include course enrolment, progress tracking or a certificate.

Sources & further reading

  1. Primary learning documentation

Spotted something that needs another look?

Help improve this page →