The policy that does too much
A workload role grants s3:*. The candidate has the role, the calling service and CloudTrail.
Whether they read CloudTrail to scope down without breaking the job.
- · a real Linux box in the browser
- · kubectl, docker, terraform, jq, yq
- · cluster, repo and cloud creds pre-wired
- · auto-checks running in the background
- · every keystroke + every command
- · terminal + screen recording
- · auto-graded pass/fail per check
