IAMeasy0-2 years

A Spring Boot service that worked yesterday now fails every upload with `AccessDenied` on `s3:PutObject` for `arn:aws:s3:::orders-uploads/invoices/2026/09/30/...`. Nobody admits to changing a policy. What are the only possible causes, and what is the first command you run?

IAM denies everything unless a policy allows it, and an explicit deny beats any allow. So an AccessDenied has exactly three causes: no policy allows this action on this resource, an explicit deny somewhere forbids it, or the caller is not the principal you think (a different role was assumed, or credentials for another user are in the environment). The third is the cheapest to rule out and the one people skip, so the first command is aws sts get-caller-identity, run with the same credentials the service uses. If the ARN it prints is the role you expected, read that role's policies and the bucket policy for the action and resource named in the error. If it is not, the policy was never the problem.

The lesson behind it →
More on IAM