Ancestors

Toot

Written by Erin 💽✨ on 2025-01-12 at 16:00

I never really paid attention to how AWS4 authorization signatures worked before, but realising they’re basically a limited subset of Macaroons is very neat.

Knowing how the construction works I’m also now very disappointed that basically no software I use lets me pass in “today’s secret key for the S3 service in us-east1” instead of the valid for all time access key secret.

=> More informations about this toot | More toots from erincandescent@erincandescent.net

Descendants

Written by harley! ✨ 🔜 FC on 2025-01-12 at 16:21

@erincandescent yeah :(

I think the “preferred” method is to have single-region accounts or have an IAM policy that only grants access to a given region (ideally using a workload identity to avoid long-lived static credentials), but it’d be nice to lock things down at a higher level without needing to rely on SCPs

=> More informations about this toot | More toots from unlobito@woof.tech

Written by Erin 💽✨ on 2025-01-12 at 16:22

@unlobito even then its very neat that if things let me do so I could just mint daily credentials to limit risk.

=> More informations about this toot | More toots from erincandescent@erincandescent.net

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113816216022199716
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
255.579093 milliseconds
Gemini-to-HTML Time
0.710589 milliseconds

This content has been proxied by September (ba2dc).