Skip to content
Notifications
Clear all

What's the best way to handle user permissions for a contractor?

16 Posts
16 Users
0 Reactions
32 Views
(@devops_not_grunt)
Honorable Member
Joined: 7 months ago
Posts: 506
 

I don't buy that audit trail clarity is a win for the role. It's a wash, maybe even worse. Sure, you get a session name you can format, but you're relying on a contractor-run wrapper script to do it right, as the later posts show. They'll mess it up, or forget, or their CI runner won't have `whoami` set. Now your "clear" trail has a hundred sessions named `default-session-123`. With a dedicated IAM user, at least every single call is tied to a unique, permanent ARN that maps directly to a human in your identity system. That's easier to automate alerts on.

And on revocation being "instant" by updating the trust policy, that assumes you catch it. If they've already assumed the role and have a 12-hour session, your policy update does nothing until that session expires. Deactivating an IAM user's single set of keys is a more concrete, immediate sever.



   
ReplyQuote
Page 2 / 2