S3 IAM Policy
Bucket policy
- - “resource-based “ policy
Bucket permissions
specify:
Bucket Policies
ACLs
S3 Bucket Policies
Resources
– used to identify resources with ARNs
Actions
– an explicit deny always overrides an explicit allow
Effect
– defines whether to allow or deny the above action
Principal
– an account or user that this policy applies to
– specific to s3 bucket policies, not user policies
MFA
Shared Responsibility – User responsibility
AWS responsibility
EC2 instance hypervisor isolation
– independent of each other.
AWS auditing – AWS provides
AWS auditing - customer provides