4 ms·
ACLs are deprecated and IAM is a single mechanism with multiple policy types (which again, I don’t think should be simpler… if anything, I find it’s not complex
by ptcrash 5y ago
ACLs are deprecated and IAM is a single mechanism with multiple policy types (which again, I don’t think should be simpler… if anything, I find it’s not complex enough to handle some niche access requirements). Can you share what the other separate access control mechanisms you see for S3?
- akdor1154 5y ago- ACLs / object ownership (which aren't deprecated - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-policy-alternatives-guidelines.html https://docs.aws.amazon.com/AmazonS3/latest/userguide/access...) - IAM / Bucket Policies as mentioned - S3 Block Public Access (yes this is the name of a distinct feature) - S3 Access Points The interactions between all four of the above need to be taken into account to determine the access a consumer has to a bucket or its objects. I'm not taking a swing at IAM - it's a great system. My grudge is with AWS having disparate interacting security controls for different services (of which S3 is probably the worst offender). To heave back onto the topic at hand, let's hope R2 can do better having the benefit of a clean slate to build off!
- dopylitty 5y agoDon’t forget KMS key policies which also apply if you are using SSE-KMS.