Q: How would you give access to a specific file in an S3 bucket to a user from another organization/account, and what is the difference between S3 Bucket Policy, IAM Policy, and Pre-signed URL?
Architectural decision matrix for sharing specific S3 objects across AWS accounts: evaluating Resource-based Bucket Policies, Identity-based IAM Policies, and temporary Pre-signed URLs.
#AWS #S3 #IAM #Security #Cross-Account
🎙️ Candidate Opening & Architectural Context
"Access to S3 objects cross-account can be achieved via three distinct mechanisms depending on whether the requester is authenticated within an external AWS account or is an anonymous third-party user needing temporary access."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1
Mechanism 1: Pre-signed URL (Best for Temporary Access)
If a user from another company needs temporary access to download a specific file without needing an AWS IAM identity, generate a pre-signed URL with an explicit expiration window.
aws s3 presign s3://company-reports/audit-2026.pdf --expires-in 3600
2
Mechanism 2: S3 Bucket Policy (Cross-Account AWS Identity)
Add an explicit Bucket Policy in the resource account granting s3:GetObject on the specific ARN to the external account's Principal ARN.
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": {"AWS": "arn:aws:iam::111122223333:role/ExternalAuditorRole"},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::company-reports/audit-2026.pdf"
}]
}
3
Comparison Summary
IAM Policies: applied to users/roles within your own account. Bucket Policies: applied to the S3 bucket to allow external principals. Pre-signed URLs: time-bounded bearer tokens for anyone with the URL.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pre-signed URLs are best for temporary non-AWS users. S3 Bucket Policies grant programmatic access to external AWS Principal ARNs on exact object prefixes."
⚡ 60-Second Elevator Pitch Talking Points
- Pre-signed URLs: generate temporary, signed URLs (up to 7 days) without requiring AWS accounts.
- Bucket Policy: specify the external AWS account Principal ARN with s3:GetObject on the exact object key ARN.
- IAM Policy: must be paired with bucket policy so the external user has permission in their own account.
- Verify S3 Block Public Access and KMS key permissions if the bucket is encrypted with SSE-KMS.
Advertisement