IAM or security complexity
IAM: an explicit deny you cannot find.
Identity policies, resource policies, permission boundaries, SCPs, session policies and ACLs, evaluated together, with an implicit deny underneath and an explicit deny that beats everything. The policy simulator disagrees with production. The error says access denied and names nothing. Complexity is a security problem in its own right: a permission model nobody can reason about produces wide-open policies written by exhausted people.
Meanwhile, elsewhere on AWS Sucks
Filed under other categories, by people it happened to.
They suspended my account, took my email server down with it, then told me to read the email they sent me
AWS suspended the account running my mail server. The suspension notice was delivered by email. To the mailbox they had just switched off. Recovery depended on DNS I still controlled.
Verified anonymous