profile avatar

Kyler Middleton

@kymidd
USA Central Time
Cloud IAM Advocate at IAM Pulse
Joined On Sep 14, 2021
1 Followers / 2 Following
5 Articles Published
16 Policies Published
1 Comments Posted

DevNetSecOps, DevRel 🥑, IAM Pulse's Cloud Security Chick. She/Her 🏳️‍⚧️🏳️‍🌈, INFJ-A, support the EFF!

Followed Topics

Published Articles

Published Policies

AWS ECR: Permit Cross Account Image Upload

Grant n AWS accounts, any principal, to connect to ECR resource and upload images with any tag

Added on Jun 20, 2022 by Kyler Middleton

AWS ECR, Permit Cross Account Image Download

Grant n other accounts access to this ECR, account-wide. Use more specific principal for better security

Added on Jun 20, 2022 by Kyler Middleton

Principal Policy - Permit Access to Cross-Account Secret and KMS Key

Policy for principal (User, Service) to access cross-account secret and KMS CMK (decryption key)

Added on Jun 20, 2022 by Kyler Middleton

S3: Permit Only CloudFront Specific Distribution

For public access, permit only specific CloudFront distribution

Added on Jun 20, 2022 by Kyler Middleton

Assume Role Trust Policy with Conditional to Limit to Specific Role

IAM assume role trust policy which permits assuming only from specific role(s)

Added on Jun 20, 2022 by Kyler Middleton

Assume Role Trust Policy from EC2 Instance

Permit EC2 instance to assume IAM role with this trust policy

Added on Jun 20, 2022 by Kyler Middleton

Assume Role Policy to Permit ECS Task to Assume IAM Role

Trust policy on an IAM role to permit an ECS task (launched container) to assume the role

Added on Jun 20, 2022 by Kyler Middleton

(WARNING) Block All S3 Access Except Root

Don't apply this policy - it will block all console and API access, and require root user or TAC to recover

Added on Jun 20, 2022 by Kyler Middleton

Limit S3 Web Access to Specific Public IPs

Useful for dev/stage web development, where site is stored in s3. Can use many public IPs, all other are blocked

Added on Jun 20, 2022 by Kyler Middleton

Join the beta waitlist

Enter your email to get notified when our product becomes available to try.

Sign Up for the community

Create your member profile to get involved with our content, programs, and events.