Look Ma, No Keys!!!

10
OSH Day 2016 – CF Summit Santa Clara ook Ma,No Keys!!! Sean Keery

Transcript of Look Ma, No Keys!!!

Page 1: Look Ma, No Keys!!!

BOSH Day 2016 – CF Summit Santa ClaraLook Ma,No Keys!!!

Sean Keery

Page 2: Look Ma, No Keys!!!

Sean Keery

Page 3: Look Ma, No Keys!!!

Anybody ever put their keys in source control?

I’ve seen 6 figure bill$ due to this ^

Page 4: Look Ma, No Keys!!!

Amazon wants to help

Identity and Access Management

IAM

Page 5: Look Ma, No Keys!!!

Instances

RolesProfile

AWS Account

Instance

STS

LongestLived

Shortest🔒

🔒

Page 6: Look Ma, No Keys!!!

Security Token Service STS

Least PrivilegesWell-known Expirations

Temporary Security Credentials

Page 7: Look Ma, No Keys!!!

Jumpbox/Bastion

Instance Groups

BOSHDeployments

Page 8: Look Ma, No Keys!!!

Rotate

Record

RepaveRe

pair

Page 9: Look Ma, No Keys!!!

Rotate, Repave http://bit.ly/1TSUsjzBosh Docs http://bit.ly/1syk9Qa

Page 10: Look Ma, No Keys!!!

BOSH Day 2016 – CF Summit Santa ClaraLook Ma, No Keys!!!

Sean [email protected]@zgrinch