Skip to content
BytePatterns

Shared Responsibility & IAM

AWS for Interviews: lesson 1 of 18

AWS secures the cloud; you decide who may call what inside it.

Lesson 1 of 18 · 6 min

Shared Responsibility & IAM

Step 1 of 10

The split first: AWS secures the hardware, network and hypervisor. What you configure — data, OS patches, who may call what — is yours.

The Idea

AWS secures the cloud itself: facilities, hardware, network and the virtualization layer. You secure what you put in it: your data, guest OS patches, firewall rules, encryption — and IAM, which decides who may call which API. Every request is denied by default, allowed only by an explicit Allow, and an explicit Deny beats any Allow.

Real-World Example

An app on EC2 needs to read one S3 bucket. Instead of an access key in a config file, it gets an IAM role through an instance profile. The role's credentials are temporary and updated automatically, and its policy allows s3:GetObject on that bucket and nothing more.

The Tradeoff

Least privilege is slower at first: permissions are added as the code needs them. IAM Access Analyzer can generate a policy from the access activity CloudTrail recorded, so start narrow and widen with evidence.

Hands-On

# illustrative — needs an AWS account; names are placeholders
aws iam create-role --role-name app-reader \
  --assume-role-policy-document file://trust-ec2.json
aws iam put-role-policy --role-name app-reader --policy-name read-photos \
  --policy-document file://read-photos.json
# read-photos.json
# {"Version": "2012-10-17", "Statement": [{"Effect": "Allow",
#   "Action": "s3:GetObject", "Resource": "arn:aws:s3:::photos-bucket/*"}]}

Your turn

Put the steps in the right order.

  1. Check every applicable policy for an explicit Deny
  2. If nothing allowed the request, deny it by default
  3. The app signs its request with the role's temporary credentials
  4. Look for an explicit Allow that matches the action and resource

Mini quiz

1 / 3

A request matches an explicit Allow in one policy and an explicit Deny in another. The result?

Sources

New lessons land every few weeks

Leave an address and we will tell you when the next one is up. That is the only reason we will use it.

One address, stored so we can email you. Nothing else, ever.