<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>IAM on Samuel Tillman</title><link>https://samueltillman.com/tags/iam/</link><description>Recent content in IAM on Samuel Tillman</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://samueltillman.com/tags/iam/index.xml" rel="self" type="application/rss+xml"/><item><title>Layer 0: Bootstrapping an AWS Org Without a Single Stored Credential</title><link>https://samueltillman.com/posts/refplatform/layer-0-bootstrapping-an-aws-org/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://samueltillman.com/posts/refplatform/layer-0-bootstrapping-an-aws-org/</guid><description>&lt;p>&lt;a href="https://samueltillman.com/posts/refplatform/building-an-aws-eks-platform-in-public/">Last week I laid out the whole platform&lt;/a>
: five accounts, an EKS-based internal developer platform, built in the open in layers. This week I want to go all the way down to the floor, Layer 0, the org bootstrap, because it&amp;rsquo;s where the most interesting tension in any infrastructure-as-code project lives: &lt;strong>something has to exist before Terraform can run, and I refuse to store a secret in a public repo to make that happen.&lt;/strong>&lt;/p></description></item></channel></rss>