
Kyler Middleton
DevNetSecOps, DevRel 🥑, IAM Pulse's Cloud Security Chick. She/Her 🏳️⚧️🏳️🌈, INFJ-A, support the EFF!
Followed Topics
Published Articles
Published Policies
AWS ECR Resource Policy: Block Outside Specific Public IP Range
Permits connection from only a specific public IP range
Added on Jun 20, 2022 by Kyler Middleton
AWS ECR: Permit Cross Account Image Upload
Grant n AWS accounts, any principal, to connect to ECR resource and upload images with any tag
Added on Jun 20, 2022 by Kyler Middleton
AWS ECR, Permit Cross Account Image Download
Grant n other accounts access to this ECR, account-wide. Use more specific principal for better security
Added on Jun 20, 2022 by Kyler Middleton
Principal Policy - Permit Access to Cross-Account Secret and KMS Key
Policy for principal (User, Service) to access cross-account secret and KMS CMK (decryption key)
Added on Jun 20, 2022 by Kyler Middleton
S3: Permit Only CloudFront Specific Distribution
For public access, permit only specific CloudFront distribution
Added on Jun 20, 2022 by Kyler Middleton
Assume Role Trust Policy with Conditional to Limit to Specific Role
IAM assume role trust policy which permits assuming only from specific role(s)
Added on Jun 20, 2022 by Kyler Middleton
Assume Role Trust Policy from EC2 Instance
Permit EC2 instance to assume IAM role with this trust policy
Added on Jun 20, 2022 by Kyler Middleton
Assume Role Policy to Permit ECS Task to Assume IAM Role
Trust policy on an IAM role to permit an ECS task (launched container) to assume the role
Added on Jun 20, 2022 by Kyler Middleton
(WARNING) Block All S3 Access Except Root
Don't apply this policy - it will block all console and API access, and require root user or TAC to recover
Added on Jun 20, 2022 by Kyler Middleton
Limit S3 Web Access to Specific Public IPs
Useful for dev/stage web development, where site is stored in s3. Can use many public IPs, all other are blocked
Added on Jun 20, 2022 by Kyler Middleton
Join the beta waitlist
Enter your email to get notified when our product becomes available to try.
Sign Up for the community
Create your member profile to get involved with our content, programs, and events.