From the course: Complete Guide to AWS Security and Compliance Management
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Understanding S3 access control lists - Amazon Web Services (AWS) Tutorial
From the course: Complete Guide to AWS Security and Compliance Management
Understanding S3 access control lists
- [Instructor] S3 Access Control Lists, or ACLs, are another tool that exists for controlling access to objects stored in S3. Let's understand what they are and see how they work and appreciate why they are dangerous. The first thing to understand about ACLs is that they can apply to every object you put into S3. With literally trillions of objects, in S3, that's potentially a lot of ACLs. Imagine the chaos if each object was managed with its own unique ACL. Maintenance would be an administrative nightmare. Another thing to understand is that with S3 being one of the oldest services in AWS, access control lists came into being long before IAM policies and bucket policies existed. Let's get into the console to gain an appreciation of why you need to be very careful if you decide to use ACLs. Here I am logged into the web console, looking at my S3 buckets. Let's take a look at my public-assets bucket. Clicking on the name of that bucket takes me to a page that lists all of the objects…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
-
-
-
Exploring S3 management options5m 6s
-
(Locked)
Accessing S3 privately3m 15s
-
(Locked)
Configuring private S3 access6m 13s
-
(Locked)
Managing S3 with IAM3m
-
(Locked)
Restricting S3 access with IAM11m 27s
-
(Locked)
Validating custom IAM S3 policy4m 9s
-
(Locked)
Leveraging S3 IAM policies in EC25m 57s
-
(Locked)
Creating an S3 bucket policy8m 5s
-
(Locked)
Illustrating S3 bucket policies with CLI4m 29s
-
(Locked)
Understanding S3 access control lists5m 16s
-
(Locked)
Understanding public access in S37m 11s
-
(Locked)
S3 public access best practices4m 19s
-
(Locked)
Exploring pre-signed URLs10m 16s
-
(Locked)
Understanding S3 Access Grants4m 37s
-
(Locked)
Understanding S3 Access Points5m 28s
-
(Locked)
Exploring S3 Access Points9m 32s
-
(Locked)
Understanding data protection schemes7m 30s
-
(Locked)
S3 security and compliance best practices4m 44s
-
(Locked)
Challenge: S3 replication challenge1m 52s
-
(Locked)
Solution: S3 replication challenge10m 36s
-
(Locked)
Challenge: S3 lifecycle challenge56s
-
(Locked)
Solution: S3 lifecycle challenge4m 32s
-
-
-