Q: What is the difference between an IAM policy attached to a user vs a resource policy attached to an S3 bucket?
- Identity policy (attached to IAM user/role/group) — defines what that identity CAN do across AWS.
#AWS #IAM & Security #L2 #Cloud #Infrastructure #S3
🎙️ Candidate Opening & Architectural Context
""AWS reliability requires differentiating between AWS control plane limits and host-level resource exhaustion. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Example: An S3 bucket policy can grant access to an IAM user in a different AWS account — the identity policy alone can't cross account boundaries without a resource policy (or role trust policy) on the other side.
- Identity policy (attached to IAM user/role/group) — defines what that identity CAN do across AWS.
- Resource policy (attached to S3 bucket, KMS key, SNS topic) — defines WHO can access that specific resource.
2️⃣
Remediation & Permanent Safeguards
When both exist: for same-account access, the union of both policies is the effective permission. For cross-account: both must allow the action. Explicit Deny anywhere always wins, regardless of Allows.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Identity policy (attached to IAM user/role/group) — defines what that identity CAN do across AWS.."
⚡ 60-Second Elevator Pitch Talking Points
- Identity policy (attached to IAM user/role/group) — defines what that identity CAN do across AWS.
- Resource policy (attached to S3 bucket, KMS key, SNS topic) — defines WHO can access that specifi...
Advertisement