Richard Harvey
In the video, you stated very strongly to use groups which is understandable. But in your example where you added an IAM policy binding to myHappyVM, you added a user (me@example.com) to the role. Can a group’s email be used here instead of a user? I’m guessing yes… But this is a bit confusing.