Skip to content

Day 2 — IAM & Security #2

@PunithVT

Description

@PunithVT

Day 2. IAM is the thing everyone skips and then breaks production with. Doing it properly now while the projects are small.

Topics to cover:

  1. IAM core model — users, roles, policies, principals, and how a request gets evaluated
  2. Writing least-privilege policies — Action / Resource / Condition keys, common patterns
  3. Cross-account roles and STS AssumeRole — when and why
  4. Agent-side security — prompt injection, tool authorization, scoped per-user credentials
  5. Secrets handling — Secrets Manager vs Parameter Store, rotation, KMS basics

Plan: Chandana on policies and AssumeRole, me on agent-side threats, both of us on secrets handling.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions