The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Foundations · Module 8: Security and safe-change basics

Least Privilege, Everywhere

Every permission is a path an attacker or a mistake can walk. This lesson narrows identities so the compromise of one cannot become the compromise of all.

10 min reading

Objectives

  • Grant identities only the permissions their job needs, nothing more
  • Explain what breaks safely when a narrow identity is compromised
  • Review a permission set and name the grant to remove first
  • Separate human, service and pipeline identities with different rules

Why this matters

A monitoring service runs with cluster admin because setup was easier that way; a vulnerability in its dashboard becomes full control of every workload. Or a developer's personal key holds production write for three ex-employees because nobody tracks grants. Breach reports read like sophisticated attacks that were actually broad permissions waiting for any trigger. Narrowing is the cheapest security control that exists, and it is mostly deletion.

Concepts

Least privilege has three questions per identity: what job does it do, what is the minimum set that job needs, and what happens when this identity is stolen. Answer in writing, grant the minimum, and the theft scenario bounds the blast radius by construction. Review on schedule and on role change: permissions accrete (temporary grants become permanent), so every grant carries an expiry or a review date, and the review removes more than it adds.

Identity classes with different rules. Humans get named accounts with roles that change as jobs change, plus short sessions instead of eternal keys; shared accounts destroy attribution, so the incident can never name who. Services get dedicated identities per workload, never one shared super identity across the fleet, so one compromised service cannot read its neighbors. Pipelines get per-job scoped tokens from M06 lesson 4, minted per run where the platform allows.

Defaults deny, exceptions explain themselves. New identities start with nothing and earn grants through requests that state the job and the duration; the request history is the audit trail. Wildcard grants (all actions, all resources) are the chmod 777 of access control from M01: occasionally necessary at 3am, always recorded, always narrowed afterwards. A permission nobody can explain is a permission nobody needs.

Worked example

A service account holds read-write on every bucket including backups. The review:

svc-reports: s3:Get, s3:Put, s3:Delete on arn:: job: generate weekly CSV reports from events-bucket needs: Get on events-bucket/inputs/, Put on reports-bucket/out/* blast radius today: every byte including backups, deletable

Expected reading: the job needs two narrow paths and holds the entire estate with delete. The repair scopes to the two paths, drops Delete entirely (reports never delete), and adds the review date. Verify by replaying the job green plus a denied attempt at the old reach, both in the record. Lab L22 requires this shape on a local service user: narrow, prove the job works, prove the old reach is gone.

The common wrong move

Copying the admin policy to make something work, then never revisiting. It fixes the ticket in minutes and mortgages every future incident: each debugging session now runs as god, each log line carries full power. Urgent broadening is sometimes correct; unrecorded permanent broadening is the breach before the breach. Record, expire, narrow.

Lab and next step

Lab L22 narrows an over-privileged local service user with job-proof and denial-proof. Next, lesson 2 handles the most leaked asset class: secrets and the configuration around them.

Quick check

An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.

Lesson feedback

No published feedback yet.

Log in and complete the lesson to leave feedback.

Exercise

Pick three identities (one human, one service, one pipeline role). For each, write the job, the minimum set, and the theft scenario. Narrow one over-wide grant and show the job still green plus the old reach denied.

Pass criteria

Three identities documented with job, minimum and theft scenario; one narrowing applied with green-job plus denied-reach proof.

Sources

Log in to track progressFree account: stores only your lesson progress and quiz results.