Score:1

Is it possible to grant a "read everything" role in AWS?

ru flag

Is there a default policy that can provide read-only access to all services with AWS? Is there are naming convention for permissions that could be followed such as "Allow" : "Get*" in an IAM policy to achieve this type of result?

I know that AWS provides readonly policies for each service, but considering the frequency that new services are added, I'm wondering if there is an aggregate "read-all" policy that they provide?

Score:3
gp flag
Tim

AWS defines some policies that are available in every account. As new services are added these policies are updated so the policy always has read only access. Some of them are job function policies, some are mmore general.

The most relevant ones are:

These policies can be attached to a Group, User, Role, etc.

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.