Q: You need to give a third-party vendor access to a specific S3 bucket without giving them AWS credentials. How?
Use IAM Cross-Account Role Assumption:
#AWS #IAM & Security #L2 #Cloud #Infrastructure #S3
🎙️ Candidate Opening & Architectural Context
""When an interviewer asks how I troubleshoot this in AWS, I frame it through my hands-on production experience. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Use IAM Cross-Account Role Assumption:
- In your AWS account, create an IAM role with S3 permissions on the bucket.
- Set the trust policy to allow the vendor's AWS account ID to assume the role.
- The vendor calls
sts:AssumeRolefrom their account and gets temporary credentials. - They use those credentials to access only what the role allows.
2️⃣
Remediation & Permanent Safeguards
Benefits: Alternatively for simpler cases: create an IAM user with programmatic access (access key/secret) scoped only to that bucket. Less ideal — long-term credentials.
- No long-term credentials shared.
- You can revoke access instantly by deleting the role.
- All access is auditable in CloudTrail.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: In your AWS account, create an IAM role with S3 permissions on the bucket.."
⚡ 60-Second Elevator Pitch Talking Points
- In your AWS account, create an IAM role with S3 permissions on the bucket.
- Set the trust policy to allow the vendor's AWS account ID to assume the role.
- The vendor calls sts:AssumeRole from their account and gets temporary credentials.
Advertisement