Cutting Cloud IAM Down to Least Privilege
By Richard Augenti
Find the over-permissioned roles in a cloud account, use access data to derive the permissions actually in use, and tighten the policies without breaking the workloads.
Free to browse. Takes about 60 minutes once you start.
Lab Overview
The reporting-service role can do anything to S3 and anything to IAM - s3:* and iam:* on *. It needs three actions.
Over-permissive roles are the most common serious cloud misconfiguration there is, because a compromised workload inherits every permission its role holds. In this lab you use a record of what the role actually did to write a least-privilege policy, then prove with the real AWS IAM policy simulator that it still allows the work and no longer allows the danger.
This lab reaches a live AWS endpoint: the IAM policy simulator, called through the instance's own role. The simulator evaluates policies and nothing more - it does not deploy, create or change any resource.
What to Expect
- Environment: a single Ubuntu machine you connect to over SSH, with the access data and policy documents already in place. No cluster required.
- Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
- Live AWS, read-only: the instance's own IAM role is permitted to call the policy simulator. Policies are evaluated, never applied - nothing in any cloud account changes.
- Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.
What are hands-on labs?
A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.
Real tooling
The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.
Break it freely
Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.
Useful on Monday
Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.