Course 2 · after Fountain: The IAM repo · lesson 12 (I12)
The concierge
- Properties
- V Named secrets, least privilege, VIII Escalate the judgment, IX Attributable
- Goal
- TODO
- Done when
- TODO
- Restart from
- Fountain lessons 4, 7 and 8 and lesson 6 (the lesson whose checkpoint to reload if this one breaks)
- Mode
- self-paced or live · about 45 min
Watch
TODO: video
Do · 45 min
Context
- The desk in repo mode takes a request in words, edits one file, runs
terraform plan, runscheck-no-new-access, renders the access delta and opens a PR with a PR-only token. The merge is the approval (decision 18). The sandbox holds no cloud credential. - The worked request is “site-publisher needs read on waterpark-artifacts”. An unmapped requester gets a refusal that names the enrollment path. A request that needs the boundary changed gets a refusal that names the platform path.
- The desk’s rows join the credential table from Fountain lesson 4. The parts table is filled from the propose loop page.
Watch
TODO: Video script or link. Optional.Do
TODO: Numbered steps. Imperative. One job.- TODO
- TODO
- TODO
Self-paced
TODO: What Floci or your own machine can and cannot show.Live
TODO: What the room sees. Timing. The line to say.Further reading
- The AWS desk
- The propose loop
- Agentic
- Decisions 14, 15, 17, 18 and 30