Project 07 — Read-Only IAM User

Guided practice13 min
Duration
35 to 50 min
Module
4/7
You will build
an IAM user to which you attach the ReadOnlyAccess managed policy, with no console password and no Access Key
Deliverable
the four outputs (account_id, readonly_user_name, readonly_user_arn, attached_policy_arn), an AWS Console screenshot of the Permissions tab, the proof that terraform destroy was run
Cost
none — IAM bills nothing, but destroy remains mandatory to keep a clean account

How to read this page. Each major section is folded under its heading: click "Show …" to open it. Reading order: Objective, then In short, then The code, then Terraform, in the terminal, then AWS console, in the browser. The complete step by step is in a single appendix: A for Windows (PowerShell), B for Linux, macOS, WSL 2 and Git Bash. Only open the one for your system; C gathers the failures of both.

Preview — the rest of the lesson is for enrolled readers.

Already enrolled with a code?

Your access is tied to your account, not to this link. Sign in with the same email you used in class: your course is waiting, no need to enter the code again.

Sign inNo account yet? Create one
This lesson is part of the “State, Security, Network and Identities” module

The first modules of the course are open to everyone. For the rest you have three options: buy this course once and for all, subscribe, or enter the code handed out in class.

Are you a student on this course?

The code is tied to your account: sign in or create an account and it will be applied automatically when you come back.

No account yet? Create one