Skip to content

Clean up Reich Lab AWS IAM users #230

Description

@bsweger

[Not really a reichlab.io issues, just needed to park it somewhere]

Background

As part of a recent security review, we identified a number of IAM users in the Reich Lab AWS account that likely no longer need access.

Definition of done

For each of the users on this list, find out:

  • Do they need access to the AWS account
  • If yes, are they logging in to the AWS console or programmatically access resources via an access key
  • Does user have an active access key that has been unused longer than a year?

We should remove users who don't access the AWS account and remove console access for anyone who uses AWS for programmatic access to resources. Active access keys that have been unused for longer than a year should be disabled.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

securityUpdates related to security

Type

Projects

  • Status
    In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions