4 ms·
Permissions Policies are confusing because they can get very complex... because enterprises need that functionality. IDK, maybe I'm in the minority but I don't
by ptcrash 5y ago
Permissions Policies are confusing because they can get very complex... because enterprises need that functionality. IDK, maybe I'm in the minority but I don't think IAM is something that can/should be watered down.
- akdor1154 5y agoLast I checked there are four separate access control mechanisms for S3, of which IAM (both principal and resource policies) is a single one.
- ptcrash 5y agoACLs are deprecated and IAM is a single mechanism with multiple policy types (which again, I don’t think should be simpler… if anything, I find it’s not complex enough to handle some niche access requirements). Can you share what the other separate access control mechanisms you see for S3?
- akdor1154 5y ago- ACLs / object ownership (which aren't deprecated - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-policy-alternatives-guidelines.html https://docs.aws.amazon.com/AmazonS3/latest/userguide/access...) - IAM / Bucket Policies as mentioned - S3 Block Public Access (yes this is the name of a distinct feature) - S3 Access Points The interactions between all four of the above need to be taken into account to determine the access a consumer has to a bucket or its objects. I'm not taking a swing at IAM - it's a great system. My grudge is with AWS having disparate interacting security controls for different services (of which S3 is probably the worst offender). To heave back onto the topic at hand, let's hope R2 can do better having the benefit of a clean slate to build off!
- dopylitty 5y agoDon’t forget KMS key policies which also apply if you are using SSE-KMS.