Invention Grant
- Patent Title: Controlling permissions for remote management of computing resources
-
Application No.: US15989836Application Date: 2018-05-25
-
Publication No.: US10771337B1Publication Date: 2020-09-08
- Inventor: Munindra N. Das , Patrick McFalls , Amjad Hussain , Anantharam Vaidyanathan
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Lee & Hayes, P.C.
- Main IPC: G06F15/173
- IPC: G06F15/173 ; H04L12/24 ; H04L12/911 ; H04L29/06 ; G06F9/455

Abstract:
This disclosure describes techniques for defining a set of permissions, or privileges, for users who manage resources of a network-based service provisioned in a network-based service platform managed by a service provider. The techniques may include mapping cloud identities of the users to operating system (OS) user groups defined local to the resources that specify the set of permissions for user group members. Systems-manager agents that execute locally on the resources may determine to which OS user group the user belongs based on their cloud identity, and launch shells that are restricted by the set of permissions. Using these shells, a network-based service platform may allow users to remotely manage resources of the network-based service in various ways, such as through batch run commands and/or remote user sessions, while ensuring that the users are unable to execute commands on the resources that are outside the set of permissions.
Information query