⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE AWS AWS S3 & IAM Security AWS Security

Q: How would you give access to a specific file in an S3 bucket to a user from another organization/account, and what is the difference between S3 Bucket Policy, IAM Policy, and Pre-signed URL?

Architectural decision matrix for sharing specific S3 objects across AWS accounts: evaluating Resource-based Bucket Policies, Identity-based IAM Policies, and temporary Pre-signed URLs.

#AWS #S3 #IAM #Security #Cross-Account
🎙️ Candidate Opening & Architectural Context
"Access to S3 objects cross-account can be achieved via three distinct mechanisms depending on whether the requester is authenticated within an external AWS account or is an anonymous third-party user needing temporary access."
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1

Mechanism 1: Pre-signed URL (Best for Temporary Access)

If a user from another company needs temporary access to download a specific file without needing an AWS IAM identity, generate a pre-signed URL with an explicit expiration window.

aws s3 presign s3://company-reports/audit-2026.pdf --expires-in 3600
2

Mechanism 2: S3 Bucket Policy (Cross-Account AWS Identity)

Add an explicit Bucket Policy in the resource account granting s3:GetObject on the specific ARN to the external account's Principal ARN.

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {"AWS": "arn:aws:iam::111122223333:role/ExternalAuditorRole"},
    "Action": "s3:GetObject",
    "Resource": "arn:aws:s3:::company-reports/audit-2026.pdf"
  }]
}
3

Comparison Summary

IAM Policies: applied to users/roles within your own account. Bucket Policies: applied to the S3 bucket to allow external principals. Pre-signed URLs: time-bounded bearer tokens for anyone with the URL.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pre-signed URLs are best for temporary non-AWS users. S3 Bucket Policies grant programmatic access to external AWS Principal ARNs on exact object prefixes."
⚡ 60-Second Elevator Pitch Talking Points
  • Pre-signed URLs: generate temporary, signed URLs (up to 7 days) without requiring AWS accounts.
  • Bucket Policy: specify the external AWS account Principal ARN with s3:GetObject on the exact object key ARN.
  • IAM Policy: must be paired with bucket policy so the external user has permission in their own account.
  • Verify S3 Block Public Access and KMS key permissions if the bucket is encrypted with SSE-KMS.
Advertisement
Want more AWS scenarios?
Explore our complete collection of scenario-based AWS interview runbooks.
Browse All AWS Questions →

📚 Related Production Scenarios in AWS