Skip to content

Clean up Reich Lab AWS IAM users #230

@bsweger

Description

@bsweger

[Not really a reichlab.io issues, just needed to park it somewhere]

Background

As part of a recent security review, we identified a number of IAM users in the Reich Lab AWS account that likely no longer need access.

Definition of done

For each of the users on this list, find out:

  • Do they need access to the AWS account
  • If yes, are they logging in to the AWS console or programmatically access resources via an access key
  • Does user have an active access key that has been unused longer than a year?

We should remove users who don't access the AWS account and remove console access for anyone who uses AWS for programmatic access to resources. Active access keys that have been unused for longer than a year should be disabled.

Metadata

Metadata

Labels

securityUpdates related to security

Type

Projects

Status

In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions