AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A startup is building a multi-tenant SaaS application on AWS. Each tenant's data must be logically isolated and accessible only by that tenant. The application uses Amazon S3 to store tenant-specific files. How can the startup enforce strict tenant data isolation for S3 objects?
- ACreate a separate S3 bucket for each tenant and apply individual bucket policies.
- BImplement IAM policies attached to roles assumed by the application, granting access based on tenant ID in the object key.
- CUse S3 bucket policies to deny access to objects not prefixed with the tenant's ID.
- DUtilize S3 Object ACLs to grant specific tenant users access to their respective objects.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement IAM policies attached to roles assumed by the application, granting access based on tenant ID in the object key.
Using IAM policies attached to application roles allows for programmatic and dynamic access control based on the tenant ID embedded in the object key. This is scalable and aligns with the principle of least privilege, ensuring the application can only access data for the current tenant.
Why the other options are wrong
- A. Creating a separate S3 bucket for each tenant is possible but leads to operational overhead (managing hundreds or thousands of buckets) and is not as scalable or cost-effective as using prefixes within a single bucket and IAM policies.
- C. While bucket policies can restrict by prefix, attaching them directly to the bucket might become complex and less dynamic for many tenants. IAM policies are generally preferred for fine-grained, dynamic access control when assumed by an application.
- D. S3 Object ACLs are an older access control mechanism and are generally not recommended for fine-grained access control. They are difficult to manage at scale and IAM policies offer more flexibility and power.
S3 Multi-Tenant Access Control
For multi-tenant applications storing data in S3, use IAM policies with role assumption and object key prefixes (e.g., tenant ID) to enforce logical data isolation.
- IAM policies are preferred for granular control.
- Object key prefixes (e.g., tenant ID) enable logical isolation.
- IAM roles allow applications to assume specific permissions.
Memory trick: IAM: Isolate Access Multi-tenant