Failing to Scale: Bumps in the Road While Scaling Cloud Access

Failing to Scale: Bumps in the Road While Scaling Cloud Access

Source: YouTube · SANS Cloud Security · published Nov 29, 2023 · 31:41

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

HashiCorp’s security leaders detail the operational and cultural hurdles of scaling from 40 to over 23,000 AWS accounts, emphasizing the critical shift from static identity management to dynamic, least-privileged access models.

Key Takeaways:
• Scaling beyond 5,000 AWS accounts requires managing multiple organizations and automating enterprise support enablement, as manual processes fail at this scale 0:22.
• HashiCorp adopted direct federation over Hub-and-Spoke to avoid role-chaining limits and support ephemeral, least-privileged access for developers, moving away from default access models 0:57.
• Traditional tools like Terraform OSS and Google Groups hit severe performance limits at scale, necessitating custom internal tooling and parallel processing architectures to manage infrastructure and identity efficiently 0:26.

Scaling cloud security requires continuous adaptation of tools and processes to maintain both safety and speed as organizational complexity increases.

Sources:

  • 0:22 Introduction to the topic of scaling challenges.
  • 0:57 Overview of the speaker's role in cloud security.
  • 0:26 Discussion on the nature of scaling cloud access.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

I was in the back furiously trying to get better imagery into our deck and then realized that we submitted the Powerpoints ahead of time so there was no saving our images so apologies in advance but we're here today to talk about failing to scale or essentially the bumps on the road that we hit as we scaled our Cloud presence there at hashy corpse so bumps in the road while we're scaling Cloud access for those that haven't met me before I'm will bingson I'm the senior director of security engineering at Hashi Corp I've been there about four years now I think a week and a half will be my official fouryear Mark I've pre previously worked at Capital One Netflix small startups uh but I've been in the cloud space for many many years now and I'm privileged to be here with a colleague of mine Dev…