Skip to content

Instantly share code, notes, and snippets.

Fabian Fischer nodomain

  • Nuremberg, Germany
Block or report user

Report or block nodomain

Hide content and notifications from this user.

Learn more about blocking users

Contact Support about this user’s behavior.

Learn more about reporting abuse

Report abuse
View GitHub Profile
nodomain /
Created Oct 25, 2018 — forked from holyjak/
IAM policy to allow Continuous Integration user to deploy to AWS Elastic Beanstalk

IAM policy to allow Continuous Integration user to deploy to AWS Elastic Beanstalk

IAM policy that we attach to CI users so that our CI server can deploy new versions of our applications to our EB environments without giving them too many permissions. When some permissions are missing, deploys may fail with the useless and misleading ERROR event log

Service:AmazonCloudFormation, Message:TemplateURL must reference a valid S3 object to which you have access.

(Notice that in many cases the error has nothing to do with S3 but can be caused by any missing permissions, for instance autoscaling:SuspendProcesse. Yes, it sucks.)

The policy can certainly be tightened more, it is not the most restrictive policy that works. As Kyle points out, the full EC2 rights are likely the biggest problem.

View Windows 10 DNS requests
root@pi:/home/pi# cat /var/log/dnsmasq | grep microsoft | grep | cut -d" " -f7 | sort | uniq

Keybase proof

I hereby claim:

  • I am nodomain on github.
  • I am nodomain ( on keybase.
  • I have a public key whose fingerprint is 0B15 D3A5 247C 3684 F2AC 50C2 8100 9D89 2FB4 A3DE

To claim this, I am signing this object:

nodomain / crontab
Last active Dec 20, 2015
I needed a simple bash script for monitoring website changes. Inspired by I adapted it a bit to fit my needs. Run via cron on my Raspberry Pi.
View crontab
# m h dom mon dow command
* */3 * * *<--->/usr/bin/cronic /home/pi/bin/
You can’t perform that action at this time.