Posts Tagged "IAM"
Put Dex In Front of Google OAuth
Google OAuth has two surprises that make every internal-service auth story uglier than it should be. The standard workaround involves domain-wide delegation and a service account JSON key shipped to every application that wants group-based authorization. There is a much better answer that doesn't require any of that.
Read Post
IAM Beyond AWS or Hacking Hacks, and the Hackers who Hack Them
How I built a system to impersonate the AWS metadata service on developer laptops, providing passwordless, expiring STS credentials linked to user identities via SSH key authentication.
Read Post