Skip to content

Permissions and IAM are confusing and error-prone

DevOps and infra13 posts from 13 people13d active+33 posts in the last 7 days, 1 the 7 days before (rising)

Posts per day

Posts per day13 posts, Aug 26 to Sep 25

The posts behind it

13, newest first
PostDate
RBAC Challenges...some growth, internal restructuring and wider IT transformation, and it has exposed a lack of proper role-based access controls for new joiners and internal transfers.. Historically, we relied upon ‘user to copy’ in the new user request, and leveraging automation in our ITSM...r/sysadminu/mythumbsclickSep 24yesterday
NewVuln64: duckdb_secrets() Exposes Secret Metadata and Credentials Without Access Control### What happens? Two separate issues compound to create a credential-exposure vulnerability. **Issue A: allow_unredacted_secrets flag does not protect secret_string.** `DuckDBSecretsFunction()` in `src/function/table/system/duckdb_secrets.cpp` returns the full `secret_string`...duckdb/duckdbylwango613Sep 232 days ago
Configuration management...some Secrets too); - Infisical: it is very expensive and I have just found that you can't get a Pro licence for a self-hosted instance, but you have to go directly to Enterprise, or use their Cloud solution (and I don't find too safe to write my sensitive information in a Cloud...r/devopsu/AkelGe-1970Sep 223 days ago
Allow List vs Deny List for ACLs### Describe the current behavior After talking this through with Marvin (https://prefect-community.slack.com/archives/C04DZJC94DC/p1788888525925399), my understanding of RBAC and ACLs in prefect is that basically entities (Users, Teams, Service Accounts) can be given roles,...PrefectHQ/prefectrh-kmSep 1411 days ago
How do you provision RDS & DocumentDB users cleanly? Dual Terraform + Pulumi setup feels redundant.Hi everyone, looking for a sanity check and some advice on DB user management.. Context & Current Setup: . Team: ~10 developers.. Infra: Everything is provisioned with Terraform.. The Catch: Pulumi is used exclusively to connect through a bastion host to create users in RDS...r/devopsu/Witty_Philosopher284Sep 102 weeks ago
scan_iceberg ignores catalog-vended credentials on the pyiceberg Table's FileIO...This bypasses the intended catalog RBAC + vended credential mechanism. Current Workaround: Request: When source is a pyiceberg Table and storage_options is None, derive them from `table.io.properties` Verified on 1.43.2.pola-rs/polarsscarter93Sep 92 weeks ago
[BUG] basic-auth: fail-closed authorization denies `GET /` (the web UI) to every user without the server-wide `is_admin` flag> [!WARNING] > Before submitting a PR, please make sure that: > - A maintainer has triaged this issue and applied the `ready` label > - This issue has no assignee > - No duplicate PR exists > > PRs not meeting these requirements may be automatically closed. ## Issues Policy...mlflow/mlflowmkBGDSep 72 weeks ago
...The list goes on. None of those friction points apply to hobby hosting, really. IAM is annoying because the alternative isn’t “fill out 7 forms and host 12 meetings to get a new vendor in”. You also get less of the benefits. Low volume SQS can be trivially replaced, but if you...Hacker News commentseverforwardSep 62 weeks ago
Windows: _is_pid_alive treats access-denied as dead, so live locks are removed as stale### Bug summary On Windows, `_is_pid_alive` reports a live process as dead whenever `OpenProcess` is denied. `FileSystemLockManager` then treats the lock as stale and removes it while the holder is still running. `src/prefect/locking/_filelock.py:18-44` has two branches that...PrefectHQ/prefectethanstonerSep 43 weeks ago
Flow run reports Completed then immediately gets overwritten to Crashed after a benign post-completion SIGTERM (Cloud Run push work pool)## Description A very short-lived flow (< 1s of work) sometimes has its flow run state flip from `Completed` to `Crashed` a couple of seconds after successfully finishing, on a Cloud Run V2 push work pool. The flow itself does not error - the engine has already reported...PrefectHQ/prefectmattimollerSep 33 weeks ago
setup.sh fails for non-root sudo users: "docker is installed but the daemon is not running" (actually a permission error on docker.sock)...actionable message (e.g. "add your user to the docker group or run as root") instead of failing later inside a helper script. Additionally, `add-new-auth-keys.sh` should distinguish "daemon not running" from "permission denied" (e.g. by not discarding stderr of `docker info`),...supabase/supabaseoliveresAug 303 weeks ago
Allow users to create personal access tokens in Grafana OSS**Why is this needed**: Grafana OSS users who need API access currently depend on an Organization Admin to create and manage a service account for them. **What would you like to be added**: Allow users to create and revoke personal access tokens tied to their own identity and...grafana/grafanapznamenskyAug 284 weeks ago
OAUTH_WWW_AUTHENTICATE_CHALLENGE error when signing in via custom OIDC SSO (Oracle IAM) on v2.35.4n8n CommunityyushaojianAug 264 weeks ago

Companies and products named

Company or productPosts naming it
GitHub4
Prefect3
AWS2
Apache Kafka1
Oracle1
n8n1
About this problem

Evidence

13 posts from 13 people in 10 places, about 3 a week over 30 days. Mostly on PrefectHQ/prefect, r/devops, Hacker News comments. Tools named alongside: GitHub, Prefect, AWS, Apache Kafka.

Frustration Frustration 1 of 3· Seen on GitHub issues, Reddit, Hacker News, Community forums

How it was grouped

Posts that state a pain and match the "permissions" rule. First post Aug 26, 2026, latest Sep 24, 2026. Corroborated: 3 or more posts from 2 or more people or places. Method

History

  • 2026-09-25 Momentum: steady to rising
  • 2026-09-25 Corroboration: unverified to corroborated
  • 2026-09-25 Momentum: fading to steady
  • 2026-09-25 Added: Permissions and IAM are confusing and error-prone (2 posts)

Rising problems by email

Mondays: the problems in data, tech and AI that grew fastest that week.

Double opt-in. Unsubscribe any time.