ARNs
Amazon Resource Names
- uniquely identify resources
Starts with:
arn: partition:service:region:account_id:
ex: arn:aws:rds:us-east1:123456789012:
Can ends with:
What does :: mean in an ARN?
region omitted
- only works when the service doesn’t require a region, like IAM
What does * mean within an ARN?
wildcard
- for example, to denote all instances within a region
IAM policies
Permission Boundaries
- prevent privilege escalation or unnecessarily broad permissions
Permission Boundaries Use Cases