Ignoring all the warts of how schizophrenic the different AWS layers are, I personally like the policy document format.
I wouldn’t mind a similar style at the OS/kernel level for control groups and other permissions of that type. Having a list of principals and allowed operations would be easier to reason about (imho) than systemd unit files, or selinux, or filesystem permissions, or firewall rules, or the rest of the mess which is Linux security.
I think Fuchsia is doing something exactly like that?
I wouldn’t mind a similar style at the OS/kernel level for control groups and other permissions of that type. Having a list of principals and allowed operations would be easier to reason about (imho) than systemd unit files, or selinux, or filesystem permissions, or firewall rules, or the rest of the mess which is Linux security.
I think Fuchsia is doing something exactly like that?