Shared Responsibility & IAM
AWS for Interviews: lesson 1 of 18
AWS secures the cloud; you decide who may call what inside it.
Lesson 1 of 18 · 6 min
Shared Responsibility & IAM
Step 1 of 10
The split first: AWS secures the hardware, network and hypervisor. What you configure — data, OS patches, who may call what — is yours.
The Idea
AWS secures the cloud itself: facilities, hardware, network and the virtualization layer. You secure what you put in it: your data, guest OS patches, firewall rules, encryption — and IAM, which decides who may call which API. Every request is denied by default, allowed only by an explicit Allow, and an explicit Deny beats any Allow.
Real-World Example
An app on EC2 needs to read one S3 bucket. Instead of an access key in a config file, it gets an IAM role through an instance profile. The role's credentials are temporary and updated automatically, and its policy allows s3:GetObject on that bucket and nothing more.
The Tradeoff
Least privilege is slower at first: permissions are added as the code needs them. IAM Access Analyzer can generate a policy from the access activity CloudTrail recorded, so start narrow and widen with evidence.
Hands-On
# illustrative — needs an AWS account; names are placeholders
aws iam create-role --role-name app-reader \
--assume-role-policy-document file://trust-ec2.json
aws iam put-role-policy --role-name app-reader --policy-name read-photos \
--policy-document file://read-photos.json
# read-photos.json
# {"Version": "2012-10-17", "Statement": [{"Effect": "Allow",
# "Action": "s3:GetObject", "Resource": "arn:aws:s3:::photos-bucket/*"}]}
Your turn
Put the steps in the right order.
- Check every applicable policy for an explicit Deny
- If nothing allowed the request, deny it by default
- The app signs its request with the role's temporary credentials
- Look for an explicit Allow that matches the action and resource
Mini quiz
1 / 3
A request matches an explicit Allow in one policy and an explicit Deny in another. The result?
Sources
- Shared Responsibility Model — AWS
- Policy evaluation: how requests are allowed or denied — IAM User Guide
- Use an IAM role for applications on EC2 — IAM User Guide
- Security best practices in IAM — IAM User Guide