awslabs / awslabs/ssosync

Service Account with minimal Permissions and scope

Open
#322 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
666
Forks
213
Avg merge
1d 7h
Merged PRs (30d)
4

Description

**Is your feature request related to a problem? Please describe.**
Taking from Pull Request [#202 Feature: Avoid Impersonation](https://github.com/awslabs/ssosync/pull/202)
has already demonstrated the changes required, however it is currently a very breaking change.

**Describe the solution you'd like**
Accept the above PR into a feature branch, then:
- re-instate the existing mechanism alongside it.
- update QuickStarts Templates to use the method
- update documentation
- lab guide to show this method

Contributor guide

Open the contributing guide

Research direction

Start by reading Pull Request #202 to understand the proposed service-account method and why it is breaking. Then inspect the QuickStarts Templates, documentation, and lab guide mentioned in the issue. Done means the new method and existing mechanism coexist, with the templates and user-facing guidance updated accordingly.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go
Domain
cloud, documentation, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.