Introduction

AWS IAM Identity and Access Management 是 AWS 用于 Access Control 的服务,可以实现对于所有 AWS resource 的:

IAM features

  • Shared access to your AWS account
  • Granular permissions
  • Secure access to AWS resources for applications that run on Amazon EC2
  • Multi-factor authentication -> mfa
  • Identity federation
  • PCI DSS Compliance
  • Eventually Consistent

How IAM works

Identities

Users

User groups

Roles

Access Management

Policies and permissions

Managing IAM policies

Reference