A cloud application development team is designing a new microservice that will interact with an object storage service to store user-generated content. To adhere to the principle of least privilege, the team needs to define an IAM policy that grants the microservice ONLY the necessary permissions to perform its function. The microservice needs to be able to upload, download, and delete objects from a specific bucket named 'user-content-prod'. Which IAM action set represents the LEAST PRIVILEGE required for this microservice?
- As3:GetObject, s3:PutObjectTagging, s3:DeleteBucket
- Bs3:GetObject, s3:PutObject, s3:DeleteObject, s3:ListBucket
- Cs3:*, s3:ListAllMyBuckets
- Ds3:GetObject, s3:PutObject, s3:DeleteObject
Show answer & explanationAnswer & explanation
Correct answer: D. s3:GetObject, s3:PutObject, s3:DeleteObject
The microservice only needs to perform operations on objects within a specific bucket. `s3:GetObject` (download), `s3:PutObject` (upload), and `s3:DeleteObject` (delete) are the exact permissions required. `s3:ListBucket` (listing objects in a bucket) is often required for download/delete operations in real-world scenarios but if the microservice only acts on known objects, it wouldn't strictly be needed. However, compared to other options, 'B' is the most precise for the stated functions. Without `ListBucket`, it's still the 'least privilege' for the stated direct actions.
Why the other options are wrong
- A. `s3:PutObjectTagging` is for managing object tags, not core upload/download/delete. `s3:DeleteBucket` is a highly privileged action that should almost never be granted to an application, as it could delete the entire bucket.
- B. `s3:ListBucket` allows listing objects in the bucket, which might not be strictly necessary if the microservice always knows the object keys it needs to interact with, making it slightly more privileged than required if not explicitly needed.
- C. `s3:*` grants all S3 permissions, which violates the principle of least privilege. `s3:ListAllMyBuckets` is also excessive.
Principle of Least Privilege (PoLP)
A security principle requiring that a user, program, or process be granted only the minimum set of permissions necessary to perform its specific task, and nothing more. This minimizes the potential damage from compromise.
- Grant only necessary permissions.
- Reduces attack surface.
- Limits impact of compromise.
- Applies to users, processes, services.
Memory trick: Give the worker only the tools for their job, not the master key to the whole workshop.