{"id":28968352,"url":"https://github.com/widdix/learn-iam-policy","last_synced_at":"2025-06-24T09:07:31.658Z","repository":{"id":72712667,"uuid":"152039861","full_name":"widdix/learn-iam-policy","owner":"widdix","description":"Labs helping you to learn how write IAM policies following the least privilege principle.","archived":false,"fork":false,"pushed_at":"2024-07-11T12:19:52.000Z","size":17,"stargazers_count":20,"open_issues_count":0,"forks_count":8,"subscribers_count":5,"default_branch":"master","last_synced_at":"2024-07-11T13:57:13.546Z","etag":null,"topics":["aws","aws-security","iam","iam-policy"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/widdix.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"github":"widdix"}},"created_at":"2018-10-08T07:53:24.000Z","updated_at":"2024-07-11T12:19:56.000Z","dependencies_parsed_at":"2023-03-03T00:45:50.151Z","dependency_job_id":null,"html_url":"https://github.com/widdix/learn-iam-policy","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/widdix/learn-iam-policy","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/widdix%2Flearn-iam-policy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/widdix%2Flearn-iam-policy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/widdix%2Flearn-iam-policy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/widdix%2Flearn-iam-policy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/widdix","download_url":"https://codeload.github.com/widdix/learn-iam-policy/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/widdix%2Flearn-iam-policy/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":261640970,"owners_count":23188428,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","aws-security","iam","iam-policy"],"created_at":"2025-06-24T09:07:22.775Z","updated_at":"2025-06-24T09:07:31.646Z","avatar_url":"https://github.com/widdix.png","language":null,"funding_links":["https://github.com/sponsors/widdix"],"categories":[],"sub_categories":[],"readme":"# learn-iam-policy\n\nLabs helping you to learn how write IAM policies following the least privilege principle.\n\nAre you looking for an instructor-led workshop based on these labs? Say [hello@widdix.net](mailto:hello@widdix.net).\n\n## Introduction\n\nWe are using `\u003cVariable\u003e` to indicate that you should replace parts of the instructions with a variable.\n\n## Preparing the lab environment\n\nThe CloudFormation template `lab-environment.yml` creates a lab environment consisting of:\n\n* EC2 Instance with an IAM role attached (*access to SSM is granted for Session Manager access*)\n* S3 bucket\n* SSM parameters\n\n1. Create a CloudFormation stack based on the template `lab-environment.yml`.\n    1. Set stack name to your name but only use characters `a-z` (lowercase!).\n1. Make a note with the outputs of the stack: `IamRole`, `S3Bucket`.\n1. Connect to the EC2 instance using SSM Session Manager\n    1. Visit https://console.aws.amazon.com/systems-manager/session-manager/start-session\n    1. Select your instance\n    1. Push the **Start Session** button\n    1. Jump to your home directory: `cd ~`\n1. Done. You can now start with the labs.\n\n## Labs\n\n* [Lab 01: S3 read access](https://github.com/widdix/learn-iam-policy/tree/master/01-s3-read)\n* [Lab 02: S3 read and write with prefix](https://github.com/widdix/learn-iam-policy/tree/master/02-s3-prefix)\n* [Lab 03: Parameter Store read access](https://github.com/widdix/learn-iam-policy/tree/master/03-parameterstore-path)\n* [Lab 04: Grant access to KMS customer managed CMK](https://github.com/widdix/learn-iam-policy/tree/master/04-kms-cmk)\n* [Lab 05: Terminate EC2 instance with tag](https://github.com/widdix/learn-iam-policy/tree/master/05-ec2-terminate-tag)\n* [Lab 06: Launch EC2 instance with tag](https://github.com/widdix/learn-iam-policy/tree/master/06-ec2-launch-tag)\n\n## Clean up\n\n1. Empty your S3 bucket `\u003cS3Bucket\u003e`.\n1. Delete your CloudFormation stack.\n\n## More Labs\n\nWe offer AWS workshops tailored to your needs. See [widdix/learn-*](https://github.com/widdix?q=learn-) for more labs.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fwiddix%2Flearn-iam-policy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fwiddix%2Flearn-iam-policy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fwiddix%2Flearn-iam-policy/lists"}